OTS logfile created on: 12/27/2009 4:42:08 PM - Run 1
OTS by OldTimer - Version 3.1.14.1 Folder = F:\Documents and Settings\AkumaHokoru\My Documents\INCOMING!!!
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 931.51 Gb Total Space | 633.39 Gb Free Space | 68.00% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 849.34 Gb Free Space | 91.18% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 499.90 Gb Free Space | 53.67% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 196.38 Gb Free Space | 42.16% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 74.31 Gb Total Space | 40.72 Gb Free Space | 54.81% Space Free | Partition Type: FAT32
Drive I: | 7.71 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: AKUMA
Current User Name: AkumaHokoru
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> F:\Documents and Settings\AkumaHokoru\My Documents\INCOMING!!!\OTS.exe -> [2009/12/27 16:31:10 | 00,599,040 | ---- | M] (OldTimer Tools)
mbamservice.exe -> F:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -> [2009/12/03 16:14:02 | 00,276,816 | ---- | M] (Malwarebytes Corporation)
nod32krn.exe -> F:\Program Files\ESET\nod32krn.exe -> [2009/11/18 19:00:56 | 00,552,064 | ---- | M] (Eset )
jqs.exe -> F:\Program Files\Java\jre6\bin\jqs.exe -> [2009/11/18 14:28:41 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.)
jusched.exe -> F:\Program Files\Java\jre6\bin\jusched.exe -> [2009/11/18 14:28:41 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
ituneshelper.exe -> F:\Program Files\iTunes\iTunesHelper.exe -> [2009/10/28 20:21:26 | 00,141,600 | ---- | M] (Apple Inc.)
ipodservice.exe -> F:\Program Files\iPod\bin\iPodService.exe -> [2009/10/28 20:21:14 | 00,545,568 | ---- | M] (Apple Inc.)
applemobiledeviceservice.exe -> F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.)
nvsvc32.exe -> F:\WINDOWS\system32\nvsvc32.exe -> [2009/01/15 08:19:00 | 00,163,908 | ---- | M] (NVIDIA Corporation)
mdnsresponder.exe -> F:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
explorer.exe -> F:\WINDOWS\explorer.exe -> [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
rthdcpl.exe -> F:\WINDOWS\RTHDCPL.exe -> [2006/06/01 03:48:00 | 16,208,384 | R--- | M] (Realtek Semiconductor Corp.)
jmraidtool.exe -> F:\WINDOWS\system32\JMRaidTool.exe -> [2006/04/24 21:52:24 | 00,385,024 | R--- | M] (JMicron Technology Corp.)
[Modules - Safe List]
ots.exe -> F:\Documents and Settings\AkumaHokoru\My Documents\INCOMING!!!\OTS.exe -> [2009/12/27 16:31:10 | 00,599,040 | ---- | M] (OldTimer Tools)
[Win32 Services - Safe List]
(MBAMService) MBAMService [Auto | Running] -> F:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -> [2009/12/03 16:14:02 | 00,276,816 | ---- | M] (Malwarebytes Corporation)
(NOD32krn) NOD32 Kernel Service [Auto | Running] -> F:\Program Files\Eset\nod32krn.exe -> [2009/11/18 19:00:56 | 00,552,064 | ---- | M] (Eset )
(JavaQuickStarterService) Java Quick Starter [Auto | Running] -> F:\Program Files\Java\jre6\bin\jqs.exe -> [2009/11/18 14:28:41 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.)
(iPod Service) iPod Service [On_Demand | Running] -> F:\Program Files\iPod\bin\iPodService.exe -> [2009/10/28 20:21:14 | 00,545,568 | ---- | M] (Apple Inc.)
(Apple Mobile Device) Apple Mobile Device [Auto | Running] -> F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.)
(DAUpdaterSvc) Dragon Age: Origins - Content Updater [On_Demand | Stopped] -> F:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe -> [2009/07/26 06:43:14 | 00,025,832 | ---- | M] (BioWare)
(NVSvc) NVIDIA Display Driver Service [Auto | Running] -> F:\WINDOWS\system32\nvsvc32.exe -> [2009/01/15 08:19:00 | 00,163,908 | ---- | M] (NVIDIA Corporation)
(Bonjour Service) Bonjour Service [Auto | Running] -> F:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
[Driver Services - Safe List]
(MBAMProtector) MBAMProtector [File_System | On_Demand | Running] -> F:\WINDOWS\system32\drivers\mbam.sys -> [2009/12/03 16:13:56 | 00,019,160 | ---- | M] (Malwarebytes Corporation)
(AMON) AMON [Kernel | Auto | Running] -> F:\WINDOWS\system32\drivers\amon.sys -> [2009/11/18 19:00:57 | 00,512,096 | ---- | M] (Eset )
(nod32drv) nod32drv [Kernel | System | Running] -> F:\WINDOWS\system32\drivers\nod32drv.sys -> [2009/11/18 19:00:56 | 00,015,424 | ---- | M] ()
(sptd) sptd [Kernel | Boot | Running] -> F:\WINDOWS\System32\Drivers\sptd.sys -> [2009/11/18 14:09:36 | 00,691,696 | ---- | M] ()
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\usbaapl.sys -> [2009/08/28 19:42:52 | 00,040,448 | ---- | M] (Apple, Inc.)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\GEARAspiWDM.sys -> [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.)
(xusb21) Xbox 360 Wireless Receiver Driver Service 21 [Kernel | On_Demand | Stopped] -> F:\WINDOWS\system32\drivers\xusb21.sys -> [2009/04/08 14:29:52 | 00,056,448 | ---- | M] (Microsoft Corporation)
(nv) nv [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\nv4_mini.sys -> [2009/01/15 08:19:00 | 06,301,248 | ---- | M] (NVIDIA Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> F:\WINDOWS\system32\drivers\secdrv.sys -> [2008/04/13 11:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\hdaudbus.sys -> [2008/04/13 11:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\RtkHDAud.Sys -> [2006/06/05 23:09:26 | 04,284,928 | R--- | M] (Realtek Semiconductor Corp.)
(JRAID) JRAID [Kernel | Boot | Running] -> F:\WINDOWS\system32\DRIVERS\jraid.sys -> [2006/05/19 03:16:14 | 00,042,880 | R--- | M] (JMicron Technology Corp.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\ptilink.sys -> [2006/02/28 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Running] -> F:\WINDOWS\system32\drivers\Rtnicxp.sys -> [2006/02/26 16:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation )
(JGOGO) JMicron Hot-Plug Driver [Kernel | Boot | Running] -> F:\WINDOWS\system32\DRIVERS\JGOGO.sys -> [2006/02/07 06:52:58 | 00,006,912 | R--- | M] (JMicron )
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\] > -> ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\: Main\\"Start Page" -> http://www.msn.com/ ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\: SearchURL\\"provider" -> ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\: "ProxyOverride" -> *.local ->
< FireFox Settings [Prefs.js] > -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\FireFox\Profiles\hi6oec7u.default\prefs.js ->
browser.startup.homepage -> "" ->
extensions.enabledItems -> {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 ->
extensions.enabledItems -> {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.6 ->
extensions.enabledItems -> {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.15 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components -> F:\Program Files\Mozilla Firefox\components [F:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/12/15 21:33:01 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins -> F:\Program Files\Mozilla Firefox\plugins [F:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/12/23 20:05:21 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Extensions -> [2009/12/15 21:33:06 | 00,000,000 | ---D | M]
-> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\9y85ykx7.default\extensions -> [2009/12/27 04:53:53 | 00,000,000 | ---D | M]
NoScript -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\9y85ykx7.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} -> [2009/12/15 21:39:28 | 00,000,000 | ---D | M]
Password Exporter -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\9y85ykx7.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492} -> [2009/12/15 21:41:39 | 00,000,000 | ---D | M]
Download Statusbar -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\9y85ykx7.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} -> [2009/12/15 21:54:04 | 00,000,000 | ---D | M]
-> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\9y85ykx7.default\extensions\justintvpublisher@justin.tv -> [2009/12/22 19:47:41 | 00,000,000 | ---D | M]
-> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\hi6oec7u.default\extensions -> [2009/11/18 04:04:56 | 00,000,000 | ---D | M]
NoScript -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\hi6oec7u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} -> [2009/11/18 04:04:50 | 00,000,000 | ---D | M]
FireFTP -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\hi6oec7u.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} -> [2009/11/18 04:04:50 | 00,000,000 | ---D | M]
Download Statusbar -> F:\Documents and Settings\AkumaHokoru\Application Data\Mozilla\Firefox\Profiles\hi6oec7u.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} -> [2009/11/18 04:04:53 | 00,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> F:\Program Files\Mozilla Firefox\extensions -> [2009/12/27 04:53:53 | 00,000,000 | ---D | M]
< HOSTS File > (734 bytes and 19 lines) -> F:\WINDOWS\system32\drivers\etc\hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> F:\Program Files\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/11/18 14:28:41 | 00,041,760 | ---- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/11/18 14:28:43 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Alcmtr" -> F:\WINDOWS\Alcmtr.exe [ALCMTR.EXE] -> [2005/05/03 05:43:28 | 00,069,632 | R--- | M] (Realtek Semiconductor Corp.)
"IMJPMIG8.1" -> F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE ["F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2006/02/28 07:00:00 | 00,208,952 | ---- | M] (Microsoft Corporation)
"iTunesHelper" -> F:\Program Files\iTunes\iTunesHelper.exe ["F:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/10/28 20:21:26 | 00,141,600 | ---- | M] (Apple Inc.)
"JMB36X Configure" -> F:\WINDOWS\System32\JMRaidTool.exe [F:\WINDOWS\system32\JMRaidTool.exe boot] -> [2006/04/24 21:52:24 | 00,385,024 | R--- | M] (JMicron Technology Corp.)
"Malwarebytes' Anti-Malware" -> F:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe ["F:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray] -> [2009/12/03 16:14:02 | 00,429,392 | ---- | M] (Malwarebytes Corporation)
"nod32kui" -> F:\Program Files\Eset\nod32kui.exe ["F:\Program Files\Eset\nod32kui.exe" /WAITSERVICE] -> [2009/11/18 19:00:57 | 00,949,376 | ---- | M] (Eset )
"NvCplDaemon" -> F:\WINDOWS\System32\NvCpl.DLL [RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2009/01/15 08:19:00 | 13,680,640 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> F:\WINDOWS\System32\NvMcTray.DLL [RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2009/01/15 08:19:00 | 00,086,016 | ---- | M] (NVIDIA Corporation)
"nwiz" -> F:\WINDOWS\System32\nwiz.exe [nwiz.exe /install] -> [2009/01/15 08:19:00 | 01,657,376 | ---- | M] ()
"PHIME2002A" -> F:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2006/02/28 07:00:00 | 00,455,168 | ---- | M] (Microsoft Corporation)
"PHIME2002ASync" -> F:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2006/02/28 07:00:00 | 00,455,168 | ---- | M] (Microsoft Corporation)
"QuickTime Task" -> F:\Program Files\QuickTime\QTTask.exe ["F:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2009/09/05 01:54:42 | 00,417,792 | ---- | M] (Apple Inc.)
"RTHDCPL" -> F:\WINDOWS\RTHDCPL.exe [RTHDCPL.EXE] -> [2006/06/01 03:48:00 | 16,208,384 | R--- | M] (Realtek Semiconductor Corp.)
"SkyTel" -> F:\WINDOWS\SkyTel.exe [SkyTel.EXE] -> [2006/05/16 05:04:26 | 02,879,488 | R--- | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" -> F:\Program Files\Java\jre6\bin\jusched.exe ["F:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/11/18 14:28:41 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
"UnlockerAssistant" -> F:\Program Files\Unlocker\UnlockerAssistant.exe ["F:\Program Files\Unlocker\UnlockerAssistant.exe"] -> [2008/05/01 23:15:46 | 00,015,872 | ---- | M] ()
< Run [HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\] > -> HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"DAEMON Tools Lite" -> F:\Program Files\DAEMON Tools Lite\DTLite.exe ["F:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun] -> [2009/10/30 06:57:08 | 00,369,200 | ---- | M] (DT Soft Ltd)
< AkumaHokoru Startup Folder > -> F:\Documents and Settings\AkumaHokoru\Start Menu\Programs\Startup ->
F:\Documents and Settings\AkumaHokoru\Start Menu\Programs\Startup\Trillian.lnk -> F:\Program Files\Trillian\trillian.exe -> [2008/06/13 13:13:12 | 01,462,144 | ---- | M] (Cerulean Studios)
< All Users Startup Folder > -> F:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
< Default User Startup Folder > -> F:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003] > -> HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003] > -> HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\] > -> HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\] > -> HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-842925246-1844237615-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab [Java Plug-in 1.6.0_17] ->
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab [Java Plug-in 1.6.0_17] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab [Java Plug-in 1.6.0_17] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.0.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{CF8A9FDD-23D6-4082-8FE0-4348FE6A9B93}\\DhcpNameServer -> 192.168.0.1 (Realtek RTL8169/8110 Family Gigabit Ethernet NIC) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> F:\WINDOWS\explorer.exe -> [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"F:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> F:\Program Files\Windows Live\Messenger\wlcsdk.exe [F:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"F:\Program Files\Bonjour\mDNSResponder.exe" -> F:\Program Files\Bonjour\mDNSResponder.exe [F:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
"F:\Program Files\Dragon Age\bin_ship\daorigins.exe" -> F:\Program Files\Dragon Age\bin_ship\daorigins.exe [F:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game] -> [2009/10/27 01:07:30 | 09,909,480 | ---- | M] (BioWare)
"F:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe" -> F:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe [F:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater] -> [2009/07/26 06:43:14 | 00,025,832 | ---- | M] (BioWare)
"F:\Program Files\Dragon Age\DAOriginsLauncher.exe" -> F:\Program Files\Dragon Age\DAOriginsLauncher.exe [F:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher] -> [2009/08/10 10:59:08 | 01,246,440 | ---- | M] (BioWare)
"F:\Program Files\iTunes\iTunes.exe" -> F:\Program Files\iTunes\iTunes.exe [F:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2009/10/28 20:21:22 | 10,358,048 | ---- | M] (Apple Inc.)
"F:\Program Files\Skype\Phone\Skype.exe" -> F:\Program Files\Skype\Phone\Skype.exe [F:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [2009/10/09 13:11:12 | 25,623,336 | R--- | M] (Skype Technologies S.A.)
"F:\Program Files\Steam\Steam.exe" -> F:\Program Files\Steam\Steam.exe [F:\Program Files\Steam\Steam.exe:*:Enabled:Steam] -> [2009/11/18 06:46:22 | 01,217,808 | ---- | M] (Valve Corporation)
"F:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe" -> F:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe [F:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2] -> [2009/11/18 09:59:48 | 00,385,024 | ---- | M] ()
"F:\Program Files\Steam\steamapps\common\street fighter iv\SF4Launcher.exe" -> F:\Program Files\Steam\steamapps\common\street fighter iv\SF4Launcher.exe [F:\Program Files\Steam\steamapps\common\street fighter iv\SF4Launcher.exe:*:Enabled:Street Fighter IV] -> [2009/11/18 09:06:03 | 01,970,176 | ---- | M] (CAPCOM U.S.A., INC.)
"F:\Program Files\uTorrent\uTorrent.exe" -> F:\Program Files\uTorrent\uTorrent.exe [F:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent] -> [2009/12/15 13:18:02 | 00,289,584 | ---- | M] (BitTorrent, Inc.)
"F:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> F:\Program Files\Windows Live\Messenger\wlcsdk.exe [F:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2009/11/18 06:10:03 | 00,000,000 | ---- | M] ()
I:\autorun.exe [MZ | ] -> I:\autorun.exe [ CDFS ] -> [2009/07/16 17:13:07 | 01,246,440 | R--- | M] (BioWare)
I:\autorun.inf [[autorun] | OPEN=autorun.exe -auto | ICON=data\autorun.ico | ] -> I:\autorun.inf [ CDFS ] -> [2009/04/13 22:17:18 | 00,000,058 | R--- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{f39df11a-d494-11de-be78-0019213afbc3}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f39df11a-d494-11de-be78-0019213afbc3}\Shell
\{f39df11a-d494-11de-be78-0019213afbc3}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f39df11a-d494-11de-be78-0019213afbc3}\Shell\AutoRun
\{f39df11a-d494-11de-be78-0019213afbc3}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f39df11a-d494-11de-be78-0019213afbc3}\Shell\AutoRun\command
\{f39df11a-d494-11de-be78-0019213afbc3}\Shell\AutoRun\command\\"" -> I:\autorun.exe [I:\autorun.exe -auto] -> [2009/07/16 17:13:07 | 01,246,440 | R--- | M] (BioWare)
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
[Files/Folders - Created Within 30 Days]
Identities -> F:\Documents and Settings\AkumaHokoru\Local Settings\Application Data\Identities -> [2009/12/27 16:05:08 | 00,000,000 | ---D | C]
Help -> F:\Documents and Settings\AkumaHokoru\Local Settings\Application Data\Help -> [2009/12/26 02:26:04 | 00,000,000 | ---D | C]
mbamswissarmy.sys -> F:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/12/23 21:40:33 | 00,038,224 | ---- | C] (Malwarebytes Corporation)
mbam.sys -> F:\WINDOWS\System32\drivers\mbam.sys -> [2009/12/23 21:40:31 | 00,019,160 | ---- | C] (Malwarebytes Corporation)
Adobe -> F:\WINDOWS\System32\Adobe -> [2009/12/22 21:11:00 | 00,000,000 | ---D | C]
d3dx10_42.dll -> F:\WINDOWS\System32\d3dx10_42.dll -> [2009/12/20 22:19:53 | 00,453,456 | ---- | C] (Microsoft Corporation)
D3DX9_42.dll -> F:\WINDOWS\System32\D3DX9_42.dll -> [2009/12/20 22:19:51 | 01,892,184 | ---- | C] (Microsoft Corporation)
CAPCOM -> F:\Documents and Settings\AkumaHokoru\Local Settings\Application Data\CAPCOM -> [2009/12/20 22:19:33 | 00,000,000 | ---D | C]
xlive -> F:\WINDOWS\System32\xlive -> [2009/12/20 22:16:08 | 00,000,000 | ---D | C]
Microsoft Games for Windows - LIVE -> F:\Program Files\Microsoft Games for Windows - LIVE -> [2009/12/20 22:16:08 | 00,000,000 | ---D | C]
Schtserv PsoBB -> F:\Program Files\Schtserv PsoBB -> [2009/12/18 14:39:57 | 00,000,000 | ---D | C]
Malwarebytes' Anti-Malware -> F:\Program Files\Malwarebytes' Anti-Malware -> [2009/12/15 21:55:13 | 00,000,000 | ---D | C]
Downloads -> F:\Documents and Settings\AkumaHokoru\My Documents\Downloads -> [2009/12/15 21:50:57 | 00,000,000 | ---D | C]
ERDNT -> F:\WINDOWS\ERDNT -> [2009/12/15 21:46:30 | 00,000,000 | ---D | C]
Trend Micro -> F:\Program Files\Trend Micro -> [2009/12/15 20:07:15 | 00,000,000 | ---D | C]
abgx360 -> F:\Documents and Settings\AkumaHokoru\Application Data\abgx360 -> [2009/12/14 23:47:27 | 00,000,000 | ---D | C]
MSCOMCTL.OCX -> F:\WINDOWS\System32\MSCOMCTL.OCX -> [2009/12/11 06:10:34 | 01,066,176 | ---- | C] (Microsoft Corporation)
AWC -> F:\Program Files\AWC -> [2009/12/11 06:07:18 | 00,000,000 | ---D | C]
My Games -> F:\Documents and Settings\AkumaHokoru\My Documents\My Games -> [2009/12/09 18:22:08 | 00,000,000 | ---D | C]
D3DCompiler_41.dll -> F:\WINDOWS\System32\D3DCompiler_41.dll -> [2009/12/09 18:18:14 | 01,846,632 | ---- | C] (Microsoft Corporation)
d3dx10_41.dll -> F:\WINDOWS\System32\d3dx10_41.dll -> [2009/12/09 18:18:14 | 00,453,456 | ---- | C] (Microsoft Corporation)
D3DX9_41.dll -> F:\WINDOWS\System32\D3DX9_41.dll -> [2009/12/09 18:18:12 | 04,178,264 | ---- | C] (Microsoft Corporation)
XAudio2_4.dll -> F:\WINDOWS\System32\XAudio2_4.dll -> [2009/12/09 18:18:11 | 00,517,448 | ---- | C] (Microsoft Corporation)
XAPOFX1_3.dll -> F:\WINDOWS\System32\XAPOFX1_3.dll -> [2009/12/09 18:18:11 | 00,069,448 | ---- | C] (Microsoft Corporation)
xactengine3_4.dll -> F:\WINDOWS\System32\xactengine3_4.dll -> [2009/12/09 18:18:09 | 00,235,352 | ---- | C] (Microsoft Corporation)
X3DAudio1_6.dll -> F:\WINDOWS\System32\X3DAudio1_6.dll -> [2009/12/09 18:18:08 | 00,022,360 | ---- | C] (Microsoft Corporation)
D3DCompiler_40.dll -> F:\WINDOWS\System32\D3DCompiler_40.dll -> [2009/12/09 18:18:07 | 02,036,576 | ---- | C] (Microsoft Corporation)
d3dx10_40.dll -> F:\WINDOWS\System32\d3dx10_40.dll -> [2009/12/09 18:18:07 | 00,452,440 | ---- | C] (Microsoft Corporation)
D3DX9_40.dll -> F:\WINDOWS\System32\D3DX9_40.dll -> [2009/12/09 18:18:05 | 04,379,984 | ---- | C] (Microsoft Corporation)
XAudio2_3.dll -> F:\WINDOWS\System32\XAudio2_3.dll -> [2009/12/09 18:18:04 | 00,514,384 | ---- | C] (Microsoft Corporation)
XAPOFX1_2.dll -> F:\WINDOWS\System32\XAPOFX1_2.dll -> [2009/12/09 18:18:04 | 00,070,992 | ---- | C] (Microsoft Corporation)
xactengine3_3.dll -> F:\WINDOWS\System32\xactengine3_3.dll -> [2009/12/09 18:18:03 | 00,235,856 | ---- | C] (Microsoft Corporation)
X3DAudio1_5.dll -> F:\WINDOWS\System32\X3DAudio1_5.dll -> [2009/12/09 18:18:01 | 00,023,376 | ---- | C] (Microsoft Corporation)
XAudio2_2.dll -> F:\WINDOWS\System32\XAudio2_2.dll -> [2009/12/09 18:18:00 | 00,509,448 | ---- | C] (Microsoft Corporation)
XAPOFX1_1.dll -> F:\WINDOWS\System32\XAPOFX1_1.dll -> [2009/12/09 18:18:00 | 00,068,616 | ---- | C] (Microsoft Corporation)
xactengine3_2.dll -> F:\WINDOWS\System32\xactengine3_2.dll -> [2009/12/09 18:17:59 | 00,238,088 | ---- | C] (Microsoft Corporation)
D3DCompiler_39.dll -> F:\WINDOWS\System32\D3DCompiler_39.dll -> [2009/12/09 18:17:57 | 01,493,528 | ---- | C] (Microsoft Corporation)
d3dx10_39.dll -> F:\WINDOWS\System32\d3dx10_39.dll -> [2009/12/09 18:17:57 | 00,467,984 | ---- | C] (Microsoft Corporation)
D3DX9_39.dll -> F:\WINDOWS\System32\D3DX9_39.dll -> [2009/12/09 18:17:56 | 03,851,784 | ---- | C] (Microsoft Corporation)
XAudio2_1.dll -> F:\WINDOWS\System32\XAudio2_1.dll -> [2009/12/09 18:17:54 | 00,507,400 | ---- | C] (Microsoft Corporation)
XAPOFX1_0.dll -> F:\WINDOWS\System32\XAPOFX1_0.dll -> [2009/12/09 18:17:54 | 00,065,032 | ---- | C] (Microsoft Corporation)
xactengine3_1.dll -> F:\WINDOWS\System32\xactengine3_1.dll -> [2009/12/09 18:17:53 | 00,238,088 | ---- | C] (Microsoft Corporation)
X3DAudio1_4.dll -> F:\WINDOWS\System32\X3DAudio1_4.dll -> [2009/12/09 18:17:52 | 00,025,608 | ---- | C] (Microsoft Corporation)
D3DCompiler_38.dll -> F:\WINDOWS\System32\D3DCompiler_38.dll -> [2009/12/09 18:17:51 | 01,491,992 | ---- | C] (Microsoft Corporation)
d3dx10_38.dll -> F:\WINDOWS\System32\d3dx10_38.dll -> [2009/12/09 18:17:50 | 00,467,984 | ---- | C] (Microsoft Corporation)
D3DX9_38.dll -> F:\WINDOWS\System32\D3DX9_38.dll -> [2009/12/09 18:17:49 | 03,850,760 | ---- | C] (Microsoft Corporation)
XAudio2_0.dll -> F:\WINDOWS\System32\XAudio2_0.dll -> [2009/12/09 18:17:48 | 00,479,752 | ---- | C] (Microsoft Corporation)
xactengine3_0.dll -> F:\WINDOWS\System32\xactengine3_0.dll -> [2009/12/09 18:17:47 | 00,238,088 | ---- | C] (Microsoft Corporation)
X3DAudio1_3.dll -> F:\WINDOWS\System32\X3DAudio1_3.dll -> [2009/12/09 18:17:46 | 00,025,608 | ---- | C] (Microsoft Corporation)
D3DCompiler_37.dll -> F:\WINDOWS\System32\D3DCompiler_37.dll -> [2009/12/09 18:17:45 | 01,420,824 | ---- | C] (Microsoft Corporation)
d3dx10_37.dll -> F:\WINDOWS\System32\d3dx10_37.dll -> [2009/12/09 18:17:45 | 00,462,864 | ---- | C] (Microsoft Corporation)
D3DX9_37.dll -> F:\WINDOWS\System32\D3DX9_37.dll -> [2009/12/09 18:17:43 | 03,786,760 | ---- | C] (Microsoft Corporation)
Logs -> F:\WINDOWS\Logs -> [2009/12/09 18:16:38 | 00,000,000 | ---D | C]
1C Company -> F:\Program Files\1C Company -> [2009/12/09 18:05:15 | 00,000,000 | ---D | C]
NOS -> F:\Documents and Settings\All Users\Application Data\NOS -> [2009/12/09 17:27:27 | 00,000,000 | ---D | C]
Malwarebytes -> F:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2009/12/09 10:24:25 | 00,000,000 | ---D | C]
UserData -> F:\Documents and Settings\AkumaHokoru\UserData -> [2009/12/09 06:05:12 | 00,000,000 | --SD | C]
VirtualDub-1.9.7 -> F:\Program Files\VirtualDub-1.9.7 -> [2009/11/30 03:22:52 | 00,000,000 | ---D | C]
Apple -> F:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple -> [2009/11/23 09:30:01 | 00,000,000 | ---D | M]
Microsoft -> F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft -> [2009/11/18 18:23:18 | 00,000,000 | ---D | M]
Microsoft -> F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft -> [2009/11/18 06:12:53 | 00,000,000 | ---D | M]
Microsoft -> F:\Documents and Settings\NetworkService\Application Data\Microsoft -> [2009/11/18 06:09:59 | 00,000,000 | --SD | M]
Microsoft -> F:\Documents and Settings\LocalService\Application Data\Microsoft -> [2009/11/18 06:09:59 | 00,000,000 | --SD | M]
5 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp ->
1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp ->
[Files/Folders - Modified Within 30 Days]
nvapps.xml -> F:\WINDOWS\System32\nvapps.xml -> [2009/12/23 23:11:01 | 00,206,530 | ---- | M] ()
wpa.dbl -> F:\WINDOWS\System32\wpa.dbl -> [2009/12/23 23:11:00 | 00,013,704 | ---- | M] ()
SA.DAT -> F:\WINDOWS\tasks\SA.DAT -> [2009/12/23 23:10:43 | 00,000,006 | -H-- | M] ()
emscavou.job -> F:\WINDOWS\tasks\emscavou.job -> [2009/12/23 23:10:42 | 00,000,322 | -HS- | M] ()
bootstat.dat -> F:\WINDOWS\bootstat.dat -> [2009/12/23 23:10:41 | 00,002,048 | --S- | M] ()
NTUSER.DAT -> F:\Documents and Settings\AkumaHokoru\NTUSER.DAT -> [2009/12/23 23:09:38 | 04,456,448 | -H-- | M] ()
Mozilla Firefox.lnk -> F:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk -> [2009/12/22 21:10:16 | 00,001,606 | ---- | M] ()
AppleSoftwareUpdate.job -> F:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2009/12/21 09:30:01 | 00,000,284 | ---- | M] ()
_online.exe -> F:\Documents and Settings\AkumaHokoru\_online.exe -> [2009/12/19 15:26:14 | 01,530,368 | ---- | M] ()
MSCOMCTL.OCX -> F:\WINDOWS\System32\MSCOMCTL.OCX -> [2009/12/11 06:10:37 | 01,066,176 | ---- | M] (Microsoft Corporation)
PerfStringBackup.INI -> F:\WINDOWS\System32\PerfStringBackup.INI -> [2009/12/11 06:00:15 | 00,509,942 | ---- | M] ()
perfh009.dat -> F:\WINDOWS\System32\perfh009.dat -> [2009/12/11 06:00:15 | 00,433,324 | ---- | M] ()
perfc009.dat -> F:\WINDOWS\System32\perfc009.dat -> [2009/12/11 06:00:15 | 00,067,836 | ---- | M] ()
imsins.BAK -> F:\WINDOWS\imsins.BAK -> [2009/12/11 03:41:31 | 00,001,393 | ---- | M] ()
regwizx.dll -> F:\WINDOWS\System32\regwizx.dll -> [2009/12/09 03:51:01 | 00,108,032 | RHS- | M] ()
mlfcache.dat -> F:\WINDOWS\System32\mlfcache.dat -> [2009/12/05 22:01:39 | 00,021,220 | -H-- | M] ()
mbamswissarmy.sys -> F:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/12/03 16:14:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> F:\WINDOWS\System32\drivers\mbam.sys -> [2009/12/03 16:13:56 | 00,019,160 | ---- | M] (Malwarebytes Corporation)
58 F:\Documents and Settings\AkumaHokoru\Local Settings\Temp\*.tmp files -> F:\Documents and Settings\AkumaHokoru\Local Settings\Temp\*.tmp ->
58 F:\Documents and Settings\AkumaHokoru\Local Settings\Temp\*.tmp files -> F:\Documents and Settings\AkumaHokoru\Local Settings\Temp\*.tmp ->
58 F:\Documents and Settings\AkumaHokoru\Local Settings\Temp\*.tmp files -> F:\Documents and Settings\AkumaHokoru\Local Settings\Temp\*.tmp ->
5 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp ->
3 F:\WINDOWS\Temp\*.tmp files -> F:\WINDOWS\Temp\*.tmp ->
1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp ->
[Files - No Company Name]
Mozilla Firefox.lnk -> F:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk -> [2009/12/22 21:10:15 | 00,001,606 | ---- | C] ()
_online.exe -> F:\Documents and Settings\AkumaHokoru\_online.exe -> [2009/12/18 14:53:39 | 01,530,368 | ---- | C] ()
regwizx.dll -> F:\WINDOWS\System32\regwizx.dll -> [2009/12/09 03:51:01 | 00,108,032 | RHS- | C] ()
emscavou.job -> F:\WINDOWS\tasks\emscavou.job -> [2009/12/09 03:51:01 | 00,000,322 | -HS- | C] ()
mlfcache.dat -> F:\WINDOWS\System32\mlfcache.dat -> [2009/12/05 22:01:39 | 00,021,220 | -H-- | C] ()
nod32drv.sys -> F:\WINDOWS\System32\drivers\nod32drv.sys -> [2009/11/18 18:27:18 | 00,015,424 | ---- | C] ()
sptd.sys -> F:\WINDOWS\System32\drivers\sptd.sys -> [2009/11/18 14:09:35 | 00,691,696 | ---- | C] ()
RtlCPAPI.dll -> F:\WINDOWS\System32\RtlCPAPI.dll -> [2009/11/18 08:22:07 | 00,135,168 | R--- | C] ()
xlive.dll.cat -> F:\WINDOWS\System32\xlive.dll.cat -> [2009/11/06 10:58:04 | 00,178,975 | ---- | C] ()
nvwdmcpl.dll -> F:\WINDOWS\System32\nvwdmcpl.dll -> [2009/01/15 08:19:00 | 01,724,416 | ---- | C] ()
nview.dll -> F:\WINDOWS\System32\nview.dll -> [2009/01/15 08:19:00 | 01,507,328 | ---- | C] ()
nvwimg.dll -> F:\WINDOWS\System32\nvwimg.dll -> [2009/01/15 08:19:00 | 01,101,824 | ---- | C] ()
nvshell.dll -> F:\WINDOWS\System32\nvshell.dll -> [2009/01/15 08:19:00 | 00,466,944 | ---- | C] ()
physxcudart_20.dll -> F:\WINDOWS\System32\physxcudart_20.dll -> [2008/10/07 09:13:30 | 00,197,912 | ---- | C] ()
AgCPanelTraditionalChinese.dll -> F:\WINDOWS\System32\AgCPanelTraditionalChinese.dll -> [2008/10/07 09:13:22 | 00,058,648 | ---- | C] ()
AgCPanelSwedish.dll -> F:\WINDOWS\System32\AgCPanelSwedish.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelSpanish.dll -> F:\WINDOWS\System32\AgCPanelSpanish.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelSimplifiedChinese.dll -> F:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelPortugese.dll -> F:\WINDOWS\System32\AgCPanelPortugese.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelKorean.dll -> F:\WINDOWS\System32\AgCPanelKorean.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelJapanese.dll -> F:\WINDOWS\System32\AgCPanelJapanese.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelGerman.dll -> F:\WINDOWS\System32\AgCPanelGerman.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
AgCPanelFrench.dll -> F:\WINDOWS\System32\AgCPanelFrench.dll -> [2008/10/07 09:13:20 | 00,058,648 | ---- | C] ()
GlobalUserInterface.CompositeFont -> F:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont -> [2006/06/29 14:58:52 | 00,030,808 | ---- | C] ()
GlobalSansSerif.CompositeFont -> F:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont -> [2006/06/29 14:53:56 | 00,026,489 | ---- | C] ()
GlobalSerif.CompositeFont -> F:\WINDOWS\Fonts\GlobalSerif.CompositeFont -> [2006/04/18 15:39:28 | 00,029,779 | ---- | C] ()
GlobalMonospace.CompositeFont -> F:\WINDOWS\Fonts\GlobalMonospace.CompositeFont -> [2006/04/18 15:39:28 | 00,026,040 | ---- | C] ()
< End of report >