nonemorepunk
2010-03-05, 21:43
Hey, I ran that scan. Here's the log file;
OTS.txt
OTS logfile created on: 05/03/2010 19:37:13 - Run 1
OTS by OldTimer - Version 3.1.25.0 Folder = C:\Users\admin\Desktop\desktop various\Tv Shows\Without A Trace
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.65 Gb Total Space | 266.42 Gb Free Space | 57.21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 5.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADMIN-PC
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> C:\Users\admin\Desktop\desktop various\Tv Shows\Without A Trace\OTS.exe -> [2010/03/05 19:34:57 | 000,636,928 | ---- | M] (OldTimer Tools)
superantispyware.exe -> C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE -> [2010/03/05 18:39:08 | 002,012,912 | ---- | M] (SUPERAntiSpyware.com)
firefox.exe -> C:\Program Files\Mozilla Firefox\firefox.exe -> [2010/02/18 04:17:52 | 000,908,248 | ---- | M] (Mozilla Corporation)
avgtray.exe -> C:\Program Files\AVG\AVG8\avgtray.exe -> [2009/12/16 14:41:41 | 002,043,160 | ---- | M] (AVG Technologies CZ, s.r.o.)
hidemyipsrv.exe -> C:\Program Files\Hide My IP\HideMyIpSrv.exe -> [2009/11/28 09:39:24 | 002,396,464 | ---- | M] ()
avgcsrvx.exe -> C:\Program Files\AVG\AVG8\avgcsrvx.exe -> [2009/10/21 13:25:22 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgemc.exe -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009/10/21 13:25:21 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgnsx.exe -> C:\Program Files\AVG\AVG8\avgnsx.exe -> [2009/10/21 13:25:21 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> C:\Program Files\AVG\AVG8\avgrsx.exe -> [2009/10/21 13:25:21 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009/10/21 13:25:21 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
mediadetector.exe -> C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe -> [2009/07/07 16:29:58 | 000,282,624 | ---- | M] (BlazeVideo Company)
sdwinsec.exe -> C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.)
nmsaccess32.exe -> C:\Program Files\Blaze Media Pro\NMSAccess32.exe -> [2009/01/12 12:15:52 | 000,071,096 | ---- | M] ()
msascui.exe -> C:\Program Files\Windows Defender\MSASCui.exe -> [2008/01/19 07:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation)
dlcxmon.exe -> C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe -> [2007/01/12 10:57:28 | 000,292,336 | ---- | M] ()
dlcxcoms.exe -> C:\Windows\System32\dlcxcoms.exe -> [2006/11/03 16:07:04 | 000,537,480 | ---- | M] ( )
memcard.exe -> C:\Program Files\Dell Photo AIO Printer 926\memcard.exe -> [2006/11/03 16:04:46 | 000,304,008 | ---- | M] ()
pdvddxsrv.exe -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe -> [2006/10/20 16:23:38 | 000,118,784 | ---- | M] (CyberLink Corp.)
[Modules - Safe List]
ots.exe -> C:\Users\admin\Desktop\desktop various\Tv Shows\Without A Trace\OTS.exe -> [2010/03/05 19:34:57 | 000,636,928 | ---- | M] (OldTimer Tools)
comctl32.dll -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll -> [2009/04/11 06:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(HideMyIpSRV) HideMyIpSRV [On_Demand | Running] -> C:\Program Files\Hide My IP\HideMyIpSrv.exe -> [2009/11/28 09:39:24 | 002,396,464 | ---- | M] ()
(avg8emc) AVG Free8 E-mail Scanner [Auto | Running] -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009/10/21 13:25:21 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG Free8 WatchDog [Auto | Running] -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009/10/21 13:25:21 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
(FontCache) Windows Font Cache Service [On_Demand | Stopped] -> C:\Windows\System32\FntCache.dll -> [2009/09/25 01:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation)
(SBSDWSCService) SBSD Security Center Service [Auto | Running] -> C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.)
(NMSAccess) NMSAccess [Auto | Running] -> C:\Program Files\Blaze Media Pro\NMSAccess32.exe -> [2009/01/12 12:15:52 | 000,071,096 | ---- | M] ()
(WinDefend) Windows Defender [Auto | Running] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008/01/19 07:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation)
(dlcx_device) dlcx_device [Auto | Running] -> C:\Windows\System32\dlcxcoms.exe -> [2006/11/03 16:07:04 | 000,537,480 | ---- | M] ( )
[Driver Services - Safe List]
(SASDIFSV) SASDIFSV [Kernel | System | Stopped] -> C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -> [2010/03/05 18:39:10 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
(SASKUTIL) SASKUTIL [Kernel | System | Running] -> C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -> [2010/03/05 18:39:07 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
(SASENUM) SASENUM [Kernel | On_Demand | Running] -> C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -> [2010/03/05 18:39:07 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | System | Running] -> C:\Windows\System32\Drivers\avgtdix.sys -> [2009/10/21 13:25:28 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> C:\Windows\System32\Drivers\avgldx86.sys -> [2009/10/21 13:25:24 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> C:\Windows\System32\Drivers\avgmfx86.sys -> [2009/10/21 13:25:23 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.)
(iaStorV) Intel RAID Controller Vista [Kernel | Boot | Running] -> C:\Windows\system32\drivers\iastorv.sys -> [2008/01/19 07:42:51 | 000,235,064 | ---- | M] (Intel Corporation)
(e1express) Intel(R) PRO/1000 PCI Express Network Connection Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\e1e6032.sys -> [2008/01/19 04:25:05 | 000,220,672 | ---- | M] (Intel Corporation)
(BELKIN) Belkin Wireless G USB Network Adapter [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\BLKWGU.sys -> [2007/06/01 05:11:28 | 000,252,416 | R--- | M] (Belkin Corporation. )
(viaide) viaide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\viaide.sys -> [2007/02/21 19:48:03 | 000,017,512 | ---- | M] (VIA Technologies, Inc.)
(cmdide) cmdide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\cmdide.sys -> [2007/02/21 19:48:03 | 000,016,488 | ---- | M] (CMD Technology, Inc.)
(aliide) aliide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\aliide.sys -> [2007/02/21 19:48:03 | 000,014,952 | ---- | M] (Acer Laboratories Inc.)
(nvstor) nvstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvstor.sys -> [2007/01/06 05:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation)
(nvraid) NVIDIA nForce(tm) RAID Class Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvraid.sys -> [2007/01/06 05:59:34 | 000,086,096 | ---- | M] (NVIDIA Corporation)
(ql2300) QLogic Fibre Channel Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql2300.sys -> [2006/11/02 09:51:45 | 000,900,712 | ---- | M] (QLogic Corporation)
(adp94xx) adp94xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adp94xx.sys -> [2006/11/02 09:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.)
(elxstor) elxstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\elxstor.sys -> [2006/11/02 09:51:34 | 000,316,520 | ---- | M] (Emulex)
(adpahci) adpahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpahci.sys -> [2006/11/02 09:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.)
(uliahci) uliahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\uliahci.sys -> [2006/11/02 09:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.)
(adpu320) adpu320 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu320.sys -> [2006/11/02 09:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.)
(ulsata2) ulsata2 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata2.sys -> [2006/11/02 09:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.)
(vsmraid) vsmraid [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\vsmraid.sys -> [2006/11/02 09:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd)
(ql40xx) QLogic iSCSI Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql40xx.sys -> [2006/11/02 09:50:35 | 000,106,088 | ---- | M] (QLogic Corporation)
(UlSata) UlSata [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata.sys -> [2006/11/02 09:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.)
(adpu160m) adpu160m [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu160m.sys -> [2006/11/02 09:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.)
(nfrd960) nfrd960 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nfrd960.sys -> [2006/11/02 09:50:19 | 000,045,160 | ---- | M] (IBM Corporation)
(iirsp) iirsp [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iirsp.sys -> [2006/11/02 09:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH)
(SiSRaid4) SiSRaid4 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sisraid4.sys -> [2006/11/02 09:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems)
(aic78xx) aic78xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\djsvs.sys -> [2006/11/02 09:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.)
(arcsas) arcsas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arcsas.sys -> [2006/11/02 09:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.)
(LSI_SCSI) LSI_SCSI [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_scsi.sys -> [2006/11/02 09:50:10 | 000,065,640 | ---- | M] (LSI Logic)
(SiSRaid2) SiSRaid2 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sisraid2.sys -> [2006/11/02 09:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.)
(HpCISSs) HpCISSs [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\hpcisss.sys -> [2006/11/02 09:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company)
(arc) arc [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arc.sys -> [2006/11/02 09:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.)
(iteraid) ITERAID_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteraid.sys -> [2006/11/02 09:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.)
(iteatapi) ITEATAPI_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteatapi.sys -> [2006/11/02 09:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.)
(LSI_SAS) LSI_SAS [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_sas.sys -> [2006/11/02 09:50:05 | 000,065,640 | ---- | M] (LSI Logic)
(Symc8xx) Symc8xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\symc8xx.sys -> [2006/11/02 09:50:05 | 000,035,944 | ---- | M] (LSI Logic)
(LSI_FC) LSI_FC [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_fc.sys -> [2006/11/02 09:50:04 | 000,065,640 | ---- | M] (LSI Logic)
(Sym_u3) Sym_u3 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_u3.sys -> [2006/11/02 09:50:03 | 000,034,920 | ---- | M] (LSI Logic)
(Mraid35x) Mraid35x [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\mraid35x.sys -> [2006/11/02 09:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation)
(Sym_hi) Sym_hi [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_hi.sys -> [2006/11/02 09:49:56 | 000,031,848 | ---- | M] (LSI Logic)
(megasas) megasas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasas.sys -> [2006/11/02 09:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation)
(Brserid) Brother MFC Serial Port Interface Driver (WDM) [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserid.sys -> [2006/11/02 08:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.)
(BrUsbSer) Brother MFC USB Serial WDM Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brusbser.sys -> [2006/11/02 08:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.)
(BrFiltUp) Brother USB Mass-Storage Upper Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltup.sys -> [2006/11/02 08:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.)
(BrFiltLo) Brother USB Mass-Storage Lower Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltlo.sys -> [2006/11/02 08:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.)
(BrSerWdm) Brother WDM Serial driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserwdm.sys -> [2006/11/02 08:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.)
(BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brusbmdm.sys -> [2006/11/02 08:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.)
(VSTHWBS2) VSTHWBS2 [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\VSTBS23.SYS -> [2006/11/02 07:41:53 | 000,251,904 | ---- | M] (Conexant Systems, Inc.)
(VST_DPV) VST_DPV [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\VSTDPV3.SYS -> [2006/11/02 07:41:50 | 000,987,648 | ---- | M] (Conexant Systems, Inc.)
(winachsf) winachsf [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\VSTCNXT3.SYS -> [2006/11/02 07:41:48 | 000,654,336 | ---- | M] (Conexant Systems, Inc.)
(ntrigdigi) N-trig HID Tablet Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ntrigdigi.sys -> [2006/11/02 07:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies)
(R300) R300 [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\atikmdag.sys -> [2006/11/02 07:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.)
(E1G60) Intel(R) PRO/1000 NDIS 6 Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\E1G60I32.sys -> [2006/11/02 07:30:54 | 000,117,760 | ---- | M] (Intel Corporation)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\] > -> ->
HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\: Main\\"Start Page" -> http://www.google.ie/ ->
HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\: Main\\"StartPageCache" -> 1 ->
HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:\Users\admin\AppData\Roaming\Mozilla\FireFox\Profiles\cqb02jme.default\prefs.js ->
browser.startup.homepage -> "http://www.google.ie" ->
extensions.enabledItems -> toolbar@ask.com:3.5.0.145 ->
extensions.enabledItems -> {2763565c-cc55-fb76-3817-a3f5e73bfb7b}:1.3 ->
extensions.enabledItems -> staff@hide-my-ip.com:1.0 ->
extensions.enabledItems -> {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:10.1.0 ->
extensions.enabledItems -> firefox@tvunetworks.com:2 ->
extensions.enabledItems -> 5 ->
extensions.enabledItems -> 0 ->
extensions.enabledItems -> 1 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components -> C:\Program Files\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2010/02/18 04:17:54 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins -> C:\Program Files\Mozilla Firefox\plugins [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2010/02/24 16:22:52 | 000,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Users\admin\AppData\Roaming\Mozilla\Extensions -> [2009/10/23 16:29:57 | 000,000,000 | ---D | M]
-> C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\cqb02jme.default\extensions -> [2010/03/05 00:34:12 | 000,000,000 | ---D | M]
Microsoft .NET Framework Assistant -> C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\cqb02jme.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/10/23 16:52:39 | 000,000,000 | ---D | M]
CPA Blocker -> C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\cqb02jme.default\extensions\{2763565c-cc55-fb76-3817-a3f5e73bfb7b} -> [2009/12/31 21:18:22 | 000,000,000 | ---D | M]
Tamper Data -> C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\cqb02jme.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947} -> [2009/12/31 21:04:41 | 000,000,000 | ---D | M]
-> C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\cqb02jme.default\extensions\firefox@tvunetworks.com -> [2010/01/15 20:13:54 | 000,000,000 | ---D | M]
-> C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\cqb02jme.default\extensions\toolbar@ask.com -> [2010/02/16 02:17:30 | 000,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:\Program Files\Mozilla Firefox\extensions -> [2010/01/24 20:04:34 | 000,000,000 | ---D | M]
-> C:\Program Files\Mozilla Firefox\extensions\staff@hide-my-ip.com -> [2010/01/24 20:04:34 | 000,000,000 | ---D | M]
< HOSTS File > ([2006/09/18 21:41:30 | 000,000,761 | ---- | M] - 20 lines) -> C:\Windows\System32\drivers\etc\hosts ->
Reset Hosts
127.0.0.1 localhost
::1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/12/16 14:41:43 | 001,111,320 | ---- | M] (AVG Technologies CZ, s.r.o.)
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2009/01/26 15:31:02 | 001,879,896 | ---- | M] (Safer Networking Limited)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AVG8_TRAY" -> C:\Program Files\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/12/16 14:41:41 | 002,043,160 | ---- | M] (AVG Technologies CZ, s.r.o.)
"DLCXCATS" -> C:\Windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL [rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16] -> [2006/10/15 23:31:56 | 000,106,496 | ---- | M] ()
"dlcxmon.exe" -> C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe ["C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"] -> [2007/01/12 10:57:28 | 000,292,336 | ---- | M] ()
"Malwarebytes Anti-Malware (reboot)" -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe ["C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript] -> [2010/01/07 16:07:10 | 001,394,000 | ---- | M] (Malwarebytes Corporation)
"MediaFace Integration" -> C:\Program Files\Fellowes\MediaFACE 5.0\SetHook.exe [C:\Program Files\Fellowes\MediaFACE 5.0\SetHook.exe] -> [2005/10/27 04:43:38 | 000,053,248 | ---- | M] (Fellowes, Inc.)
"MemoryCardManager" -> C:\Program Files\Dell Photo AIO Printer 926\memcard.exe ["C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"] -> [2006/11/03 16:04:46 | 000,304,008 | ---- | M] ()
"PDVDDXSrv" -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe ["C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"] -> [2006/10/20 16:23:38 | 000,118,784 | ---- | M] (CyberLink Corp.)
"WinampAgent" -> C:\Program Files\Winamp\winampa.exe ["C:\Program Files\Winamp\winampa.exe"] -> [2009/07/01 16:37:06 | 000,037,888 | ---- | M] ()
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008/01/19 07:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"BlazeServoTool" -> C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe ["C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"] -> [2009/07/07 16:29:58 | 000,282,624 | ---- | M] (BlazeVideo Company)
"SUPERAntiSpyware" -> C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE [C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe] -> [2010/03/05 18:39:08 | 002,012,912 | ---- | M] (SUPERAntiSpyware.com)
< Software Policy Settings [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000] -> [2009/08/17 22:48:08 | 018,341,216 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2008/10/25 07:52:00 | 000,604,056 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2008/10/25 07:52:00 | 000,604,056 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 04:04:56 | 000,039,464 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 001,879,896 | ---- | M] (Safer Networking Limited)
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\] > -> HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-3653965289-3811730237-1107722408-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.1.254 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{AD719AD1-67F0-4F34-93B5-245DDD841164}\\DhcpNameServer -> 192.168.1.254 (Intel(R) 82566DC Gigabit Network Connection) ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
C:\Windows\System32\avgrsstx.dll -> C:\Windows\System32\avgrsstx.dll -> [2009/10/21 13:25:29 | 000,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\Windows\explorer.exe -> [2009/04/11 06:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
!SASWinLogon -> C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -> [2009/09/03 14:21:42 | 000,548,352 | ---- | M] (SUPERAntiSpyware.com)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" [HKLM] -> C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [] -> [2008/05/13 09:13:36 | 000,077,824 | ---- | M] (SuperAdBlocker.com)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" [HKLM] -> Reg Error: Key error. [] -> File not found
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\autoexec.bat [REM Dummy file for NTVDM | ] -> C:\autoexec.bat [ NTFS ] -> [2006/09/18 21:43:36 | 000,000,024 | ---- | M] ()
E:\autorun.exe [MZ | ] -> E:\autorun.exe [ UDF ] -> [2009/09/04 06:10:21 | 000,214,408 | R--- | M] (Konami Digital Entertainment Co., Ltd.)
E:\Autorun.inf [[autorun] | open=autorun.exe | icon=autorun.exe | ] -> E:\Autorun.inf [ UDF ] -> [2009/09/04 06:10:21 | 000,000,047 | R--- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< AppCertDlls [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls ->
[Files/Folders - Created Within 30 Days]
mbamswissarmy.sys -> C:\Windows\System32\drivers\mbamswissarmy.sys -> [2010/03/05 17:36:26 | 000,038,224 | ---- | C] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\System32\drivers\mbam.sys -> [2010/03/05 17:36:23 | 000,019,160 | ---- | C] (Malwarebytes Corporation)
$RECYCLE.BIN -> C:\$RECYCLE.BIN -> [2010/03/05 16:39:34 | 000,000,000 | -HSD | C]
temp -> C:\Windows\temp -> [2010/03/05 16:39:31 | 000,000,000 | ---D | C]
temp -> C:\Users\admin\AppData\Local\temp -> [2010/03/05 16:39:31 | 000,000,000 | ---D | C]
SWREG.exe -> C:\Windows\SWREG.exe -> [2010/03/05 16:31:08 | 000,161,792 | ---- | C] (SteelWerX)
SWSC.exe -> C:\Windows\SWSC.exe -> [2010/03/05 16:31:08 | 000,136,704 | ---- | C] (SteelWerX)
NIRCMD.exe -> C:\Windows\NIRCMD.exe -> [2010/03/05 16:31:08 | 000,031,232 | ---- | C] (NirSoft)
ERDNT -> C:\Windows\ERDNT -> [2010/03/05 16:30:54 | 000,000,000 | ---D | C]
pss -> C:\Windows\pss -> [2010/03/05 16:25:23 | 000,000,000 | ---D | C]
Qoobox -> C:\Qoobox -> [2010/03/05 16:13:08 | 000,000,000 | ---D | C]
SWXCACLS.exe -> C:\Windows\SWXCACLS.exe -> [2010/03/05 16:12:53 | 000,212,480 | ---- | C] (SteelWerX)
admin.exe -> C:\Users\admin\Desktop\admin.exe -> [2010/03/04 16:21:04 | 000,401,720 | ---- | C] (Trend Micro Inc.)
rsit -> C:\rsit -> [2010/03/04 16:21:03 | 000,000,000 | ---D | C]
backups -> C:\Users\admin\Desktop\backups -> [2010/02/28 21:24:01 | 000,000,000 | ---D | C]
ImgBurn -> C:\Users\admin\AppData\Roaming\ImgBurn -> [2010/02/28 20:06:53 | 000,000,000 | ---D | C]
ImgBurn -> C:\Program Files\ImgBurn -> [2010/02/28 19:40:03 | 000,000,000 | ---D | C]
MagicISO -> C:\Program Files\MagicISO -> [2010/02/28 19:13:12 | 000,000,000 | ---D | C]
Real -> C:\Users\admin\AppData\Roaming\Real -> [2010/02/26 20:14:15 | 000,000,000 | ---D | C]
Apple -> C:\Users\admin\AppData\Local\Apple -> [2010/02/24 19:41:49 | 000,000,000 | ---D | C]
Spybot - Search & Destroy -> C:\ProgramData\Spybot - Search & Destroy -> [2010/02/24 18:17:13 | 000,000,000 | ---D | C]
Spybot - Search & Destroy -> C:\Program Files\Spybot - Search & Destroy -> [2010/02/24 18:17:13 | 000,000,000 | ---D | C]
spybotsd162.exe -> C:\Users\admin\Desktop\spybotsd162.exe -> [2010/02/24 18:15:40 | 016,409,960 | ---- | C] (Safer Networking Limited )
!KillBox -> C:\!KillBox -> [2010/02/24 17:11:12 | 000,000,000 | ---D | C]
KillBox.exe -> C:\Users\admin\Desktop\KillBox.exe -> [2010/02/24 17:11:05 | 000,092,672 | ---- | C] (Option^Explicit Software vbtechcd@gmail.com)
jscript.dll -> C:\Windows\System32\jscript.dll -> [2010/02/24 16:31:05 | 000,726,528 | ---- | C] (Microsoft Corporation)
tzres.dll -> C:\Windows\System32\tzres.dll -> [2010/02/24 16:30:45 | 000,002,048 | ---- | C] (Microsoft Corporation)
secproc.dll -> C:\Windows\System32\secproc.dll -> [2010/02/24 16:30:11 | 000,471,552 | ---- | C] (Microsoft Corporation)
RMActivate.exe -> C:\Windows\System32\RMActivate.exe -> [2010/02/24 16:30:10 | 000,518,144 | ---- | C] (Microsoft Corporation)
RMActivate_ssp.exe -> C:\Windows\System32\RMActivate_ssp.exe -> [2010/02/24 16:29:56 | 000,347,136 | ---- | C] (Microsoft Corporation)
secproc_ssp.dll -> C:\Windows\System32\secproc_ssp.dll -> [2010/02/24 16:29:56 | 000,152,064 | ---- | C] (Microsoft Corporation)
secproc_isv.dll -> C:\Windows\System32\secproc_isv.dll -> [2010/02/24 16:29:49 | 000,471,552 | ---- | C] (Microsoft Corporation)
RMActivate_isv.exe -> C:\Windows\System32\RMActivate_isv.exe -> [2010/02/24 16:29:48 | 000,526,336 | ---- | C] (Microsoft Corporation)
RMActivate_ssp_isv.exe -> C:\Windows\System32\RMActivate_ssp_isv.exe -> [2010/02/24 16:29:40 | 000,346,624 | ---- | C] (Microsoft Corporation)
secproc_ssp_isv.dll -> C:\Windows\System32\secproc_ssp_isv.dll -> [2010/02/24 16:29:40 | 000,152,576 | ---- | C] (Microsoft Corporation)
msdrm.dll -> C:\Windows\System32\msdrm.dll -> [2010/02/24 16:29:34 | 000,332,288 | ---- | C] (Microsoft Corporation)
GameUXLegacyGDFs.dll -> C:\Windows\System32\GameUXLegacyGDFs.dll -> [2010/02/24 16:29:23 | 004,240,384 | ---- | C] (Microsoft)
gameux.dll -> C:\Windows\System32\gameux.dll -> [2010/02/24 16:29:20 | 001,696,256 | ---- | C] (Microsoft Corporation)
Apphlpdm.dll -> C:\Windows\System32\Apphlpdm.dll -> [2010/02/24 16:29:16 | 000,028,672 | ---- | C] (Microsoft Corporation)
McAfee -> C:\ProgramData\McAfee -> [2010/02/23 23:51:59 | 000,000,000 | ---D | C]
McAfee Security Scan -> C:\Program Files\McAfee Security Scan -> [2010/02/23 23:51:56 | 000,000,000 | ---D | C]
Uniblue -> C:\Users\admin\AppData\Roaming\Uniblue -> [2010/02/23 21:01:44 | 000,000,000 | ---D | C]
Uniblue -> C:\Program Files\Uniblue -> [2010/02/23 21:01:40 | 000,000,000 | ---D | C]
ESET -> C:\Program Files\ESET -> [2010/02/23 17:00:25 | 000,000,000 | ---D | C]
Adobe(40) -> C:\Users\admin\AppData\Local\Adobe(40) -> [2010/02/23 13:36:41 | 000,000,000 | ---D | C]
VundoFix Backups -> C:\VundoFix Backups -> [2010/02/23 05:44:39 | 000,000,000 | ---D | C]
Malwarebytes -> C:\Users\admin\AppData\Roaming\Malwarebytes -> [2010/02/23 05:26:30 | 000,000,000 | ---D | C]
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2010/02/23 05:26:25 | 000,000,000 | ---D | C]
Malwarebytes -> C:\ProgramData\Malwarebytes -> [2010/02/23 05:26:25 | 000,000,000 | ---D | C]
Exterminate It! -> C:\Program Files\Exterminate It! -> [2010/02/23 03:26:57 | 000,000,000 | ---D | C]
DVD Region+CSS Free -> C:\Program Files\DVD Region+CSS Free -> [2010/02/22 16:10:28 | 000,000,000 | ---D | C]
DVD Region Free -> C:\Users\admin\Desktop\DVD Region Free -> [2010/02/22 16:09:16 | 000,000,000 | ---D | C]
Neuratron PhotoScore Lite -> C:\Program Files\Neuratron PhotoScore Lite -> [2010/02/13 23:51:12 | 000,000,000 | ---D | C]
NI_DFD_SIBELIUS.dll -> C:\Windows\System32\NI_DFD_SIBELIUS.dll -> [2010/02/13 23:49:11 | 000,065,536 | ---- | C] (Native Instruments Software GmbH)
Native Instruments -> C:\Program Files\Native Instruments -> [2010/02/13 23:49:10 | 000,000,000 | ---D | C]
Sibelius Software -> C:\Program Files\Sibelius Software -> [2010/02/13 23:48:10 | 000,000,000 | ---D | C]
MACDll.dll -> C:\Windows\System32\MACDll.dll -> [2010/02/12 21:38:43 | 000,364,544 | ---- | C] (Matthew T. Ashland)
unicows.dll -> C:\Windows\System32\unicows.dll -> [2010/02/12 21:38:43 | 000,246,424 | ---- | C] (Microsoft Corporation)
Monkey's Audio -> C:\Program Files\Monkey's Audio -> [2010/02/12 21:38:43 | 000,000,000 | ---D | C]
ntkrnlpa.exe -> C:\Windows\System32\ntkrnlpa.exe -> [2010/02/10 16:46:45 | 003,600,456 | ---- | C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\System32\ntoskrnl.exe -> [2010/02/10 16:46:45 | 003,548,216 | ---- | C] (Microsoft Corporation)
quartz.dll -> C:\Windows\System32\quartz.dll -> [2010/02/10 16:45:20 | 001,314,816 | ---- | C] (Microsoft Corporation)
msvfw32.dll -> C:\Windows\System32\msvfw32.dll -> [2010/02/10 16:45:20 | 000,123,904 | ---- | C] (Microsoft Corporation)
avifil32.dll -> C:\Windows\System32\avifil32.dll -> [2010/02/10 16:45:20 | 000,091,136 | ---- | C] (Microsoft Corporation)
mciavi32.dll -> C:\Windows\System32\mciavi32.dll -> [2010/02/10 16:45:20 | 000,082,944 | ---- | C] (Microsoft Corporation)
witw images -> C:\Users\admin\Desktop\witw images -> [2010/02/09 20:37:56 | 000,000,000 | ---D | C]
Office Genuine Advantage -> C:\ProgramData\Office Genuine Advantage -> [2010/02/03 20:30:13 | 000,000,000 | ---D | C]
Office Genuine Advantage -> C:\Users\admin\Office Genuine Advantage -> [2010/02/03 20:30:10 | 000,000,000 | ---D | C]
dlcxhcp.dll -> C:\Windows\System32\dlcxhcp.dll -> [2009/10/23 16:49:10 | 000,323,584 | ---- | C] ( )
dlcxserv.dll -> C:\Windows\System32\dlcxserv.dll -> [2009/10/23 16:34:23 | 001,224,704 | ---- | C] ( )
dlcxusb1.dll -> C:\Windows\System32\dlcxusb1.dll -> [2009/10/23 16:34:23 | 000,991,232 | ---- | C] ( )
dlcxhbn3.dll -> C:\Windows\System32\dlcxhbn3.dll -> [2009/10/23 16:34:23 | 000,696,320 | ---- | C] ( )
dlcxcomc.dll -> C:\Windows\System32\dlcxcomc.dll -> [2009/10/23 16:34:23 | 000,684,032 | ---- | C] ( )
dlcxpmui.dll -> C:\Windows\System32\dlcxpmui.dll -> [2009/10/23 16:34:23 | 000,643,072 | ---- | C] ( )
dlcxlmpm.dll -> C:\Windows\System32\dlcxlmpm.dll -> [2009/10/23 16:34:23 | 000,585,728 | ---- | C] ( )
dlcxcomm.dll -> C:\Windows\System32\dlcxcomm.dll -> [2009/10/23 16:34:23 | 000,421,888 | ---- | C] ( )
dlcxinpa.dll -> C:\Windows\System32\dlcxinpa.dll -> [2009/10/23 16:34:23 | 000,413,696 | ---- | C] ( )
dlcxiesc.dll -> C:\Windows\System32\dlcxiesc.dll -> [2009/10/23 16:34:23 | 000,397,312 | ---- | C] ( )
dlcxprox.dll -> C:\Windows\System32\dlcxprox.dll -> [2009/10/23 16:34:23 | 000,163,840 | ---- | C] ( )
dlcxpplc.dll -> C:\Windows\System32\dlcxpplc.dll -> [2009/10/23 16:34:23 | 000,094,208 | ---- | C] ( )
[Files/Folders - Modified Within 30 Days]
ntuser.dat -> C:\Users\admin\ntuser.dat -> [2010/03/05 19:36:35 | 003,670,016 | -HS- | M] ()
PerfStringBackup.INI -> C:\Windows\System32\PerfStringBackup.INI -> [2010/03/05 18:41:57 | 000,690,960 | ---- | M] ()
perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2010/03/05 18:41:57 | 000,599,942 | ---- | M] ()
perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2010/03/05 18:41:57 | 000,105,448 | ---- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2010/03/05 18:37:35 | 000,003,648 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2010/03/05 18:37:35 | 000,003,648 | -H-- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2010/03/05 18:37:33 | 000,000,006 | -H-- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2010/03/05 18:37:28 | 000,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2010/03/05 18:37:25 | 2145,308,672 | -HS- | M] ()
NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\admin\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TMContainer00000000000000000001.regtrans-ms -> [2010/03/05 18:36:36 | 000,524,288 | -HS- | M] ()
NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf -> C:\Users\admin\NTUSER.DAT{3d4e88f1-6a70-11db-b1ba-d64300c9c793}.TM.blf -> [2010/03/05 18:36:36 | 000,065,536 | -HS- | M] ()
incavi.avm -> C:\Windows\System32\drivers\Avg\incavi.avm -> [2010/03/05 18:04:40 | 056,740,234 | ---- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2010/03/05 17:36:28 | 000,000,818 | ---- | M] ()
system.ini -> C:\Windows\system.ini -> [2010/03/05 16:37:48 | 000,000,215 | ---- | M] ()
d3d9caps.dat -> C:\Users\admin\AppData\Local\d3d9caps.dat -> [2010/03/05 16:10:32 | 000,008,268 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2010/03/05 03:34:26 | 000,159,232 | ---- | M] ()
gdn.fbl.ps.100304.footballweekly.mp3 -> C:\Users\admin\Desktop\gdn.fbl.ps.100304.footballweekly.mp3 -> [2010/03/04 22:50:07 | 038,216,295 | ---- | M] ()
Desktop - Shortcut.lnk -> C:\Users\admin\Desktop\Desktop - Shortcut.lnk -> [2010/03/04 17:31:13 | 000,002,146 | ---- | M] ()
Folder.jpg -> C:\Users\admin\Desktop\Folder.jpg -> [2010/03/01 19:26:38 | 000,008,461 | -HS- | M] ()
AlbumArtSmall.jpg -> C:\Users\admin\Desktop\AlbumArtSmall.jpg -> [2010/03/01 19:26:38 | 000,002,301 | -HS- | M] ()
hijackthis 2 -> C:\Users\admin\Desktop\hijackthis 2 -> [2010/02/28 21:28:28 | 000,006,528 | ---- | M] ()
diagwrn.xml -> C:\Windows\diagwrn.xml -> [2010/02/28 20:33:20 | 000,001,905 | ---- | M] ()
diagerr.xml -> C:\Windows\diagerr.xml -> [2010/02/28 20:33:20 | 000,001,905 | ---- | M] ()
ImgBurn.lnk -> C:\Users\Public\Desktop\ImgBurn.lnk -> [2010/02/28 19:40:08 | 000,001,650 | ---- | M] ()
MagicISO.lnk -> C:\Users\admin\Desktop\MagicISO.lnk -> [2010/02/28 19:13:24 | 000,001,608 | ---- | M] ()
SopCast.lnk -> C:\Users\admin\Desktop\SopCast.lnk -> [2010/02/27 13:12:29 | 000,000,788 | ---- | M] ()
rte2-450.asx -> C:\Users\admin\Desktop\rte2-450.asx -> [2010/02/26 19:49:50 | 000,000,072 | ---- | M] ()
GDIPFONTCACHEV1.DAT -> C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT -> [2010/02/24 18:52:39 | 000,107,584 | ---- | M] ()
FNTCACHE.DAT -> C:\Windows\System32\FNTCACHE.DAT -> [2010/02/24 18:51:58 | 000,381,528 | ---- | M] ()
Spybot - Search & Destroy.lnk -> C:\Users\admin\Desktop\Spybot - Search & Destroy.lnk -> [2010/02/24 18:17:21 | 000,001,055 | ---- | M] ()
spybotsd162.exe -> C:\Users\admin\Desktop\spybotsd162.exe -> [2010/02/24 18:16:04 | 016,409,960 | ---- | M] (Safer Networking Limited )
KillBox.exe -> C:\Users\admin\Desktop\KillBox.exe -> [2010/02/24 17:11:07 | 000,092,672 | ---- | M] (Option^Explicit Software vbtechcd@gmail.com)
MpSigStub.exe -> C:\Windows\System32\MpSigStub.exe -> [2010/02/24 09:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation)
IconCache.db -> C:\Users\admin\AppData\Local\IconCache.db -> [2010/02/23 04:32:39 | 003,442,056 | -H-- | M] ()
LC%20Music%20Practicals%20Pre-Conference%20Agenda%202010.doc -> C:\Users\admin\Desktop\LC%20Music%20Practicals%20Pre-Conference%20Agenda%202010.doc -> [2010/02/20 01:37:42 | 000,031,744 | ---- | M] ()
Microsoft Publisher.lnk -> C:\Users\admin\Desktop\Microsoft Publisher.lnk -> [2010/02/15 15:46:29 | 000,002,531 | ---- | M] ()
La Musique du Chant du Monde.sib -> C:\Users\admin\Documents\La Musique du Chant du Monde.sib -> [2010/02/15 14:52:20 | 000,020,138 | ---- | M] ()
Sib practice.sib -> C:\Users\admin\Documents\Sib practice.sib -> [2010/02/15 11:52:31 | 000,018,598 | ---- | M] ()
Microsoft Office Word 2007.lnk -> C:\Users\admin\Desktop\Microsoft Office Word 2007.lnk -> [2010/02/14 23:02:09 | 000,002,627 | ---- | M] ()
Sibelius 3.lnk -> C:\Users\Public\Desktop\Sibelius 3.lnk -> [2010/02/13 23:48:40 | 000,000,916 | ---- | M] ()
Festival%20of%20Russian%20Culture%2015-21%20Feb%202010.pdf -> C:\Users\admin\Desktop\Festival%20of%20Russian%20Culture%2015-21%20Feb%202010.pdf -> [2010/02/11 15:04:08 | 001,477,619 | ---- | M] ()
x-avi-to-dvd-converter - Shortcut.lnk -> C:\Users\admin\Desktop\x-avi-to-dvd-converter - Shortcut.lnk -> [2010/02/04 20:41:19 | 000,000,502 | ---- | M] ()
SyncBack (2).lnk -> C:\Users\admin\Desktop\SyncBack (2).lnk -> [2010/02/04 20:41:14 | 000,000,886 | ---- | M] ()
[Files - No Company Name]
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2010/03/05 17:36:28 | 000,000,818 | ---- | C] ()
PEV.exe -> C:\Windows\PEV.exe -> [2010/03/05 16:31:08 | 000,261,632 | ---- | C] ()
sed.exe -> C:\Windows\sed.exe -> [2010/03/05 16:31:08 | 000,098,816 | ---- | C] ()
grep.exe -> C:\Windows\grep.exe -> [2010/03/05 16:31:08 | 000,080,412 | ---- | C] ()
MBR.exe -> C:\Windows\MBR.exe -> [2010/03/05 16:31:08 | 000,077,312 | ---- | C] ()
zip.exe -> C:\Windows\zip.exe -> [2010/03/05 16:31:08 | 000,068,096 | ---- | C] ()
gdn.fbl.ps.100304.footballweekly.mp3 -> C:\Users\admin\Desktop\gdn.fbl.ps.100304.footballweekly.mp3 -> [2010/03/04 21:17:30 | 038,216,295 | ---- | C] ()
Desktop - Shortcut.lnk -> C:\Users\admin\Desktop\Desktop - Shortcut.lnk -> [2010/03/04 17:31:13 | 000,002,146 | ---- | C] ()
Folder.jpg -> C:\Users\admin\Desktop\Folder.jpg -> [2010/03/01 19:26:38 | 000,008,461 | -HS- | C] ()
AlbumArtSmall.jpg -> C:\Users\admin\Desktop\AlbumArtSmall.jpg -> [2010/03/01 19:26:38 | 000,002,301 | -HS- | C] ()
hijackthis 2 -> C:\Users\admin\Desktop\hijackthis 2 -> [2010/02/28 21:28:28 | 000,006,528 | ---- | C] ()
diagwrn.xml -> C:\Windows\diagwrn.xml -> [2010/02/28 20:27:11 | 000,001,905 | ---- | C] ()
diagerr.xml -> C:\Windows\diagerr.xml -> [2010/02/28 20:27:11 | 000,001,905 | ---- | C] ()
ImgBurn.lnk -> C:\Users\Public\Desktop\ImgBurn.lnk -> [2010/02/28 19:40:08 | 000,001,650 | ---- | C] ()
MagicISO.lnk -> C:\Users\admin\Desktop\MagicISO.lnk -> [2010/02/28 19:13:24 | 000,001,608 | ---- | C] ()
rte2-450.asx -> C:\Users\admin\Desktop\rte2-450.asx -> [2010/02/26 19:49:48 | 000,000,072 | ---- | C] ()
Spybot - Search & Destroy.lnk -> C:\Users\admin\Desktop\Spybot - Search & Destroy.lnk -> [2010/02/24 18:17:21 | 000,001,055 | ---- | C] ()
hiberfil.sys -> C:\hiberfil.sys -> [2010/02/24 16:38:05 | 2145,308,672 | -HS- | C] ()
LC%20Music%20Practicals%20Pre-Conference%20Agenda%202010.doc -> C:\Users\admin\Desktop\LC%20Music%20Practicals%20Pre-Conference%20Agenda%202010.doc -> [2010/02/20 01:37:42 | 000,031,744 | ---- | C] ()
La Musique du Chant du Monde.sib -> C:\Users\admin\Documents\La Musique du Chant du Monde.sib -> [2010/02/15 12:09:45 | 000,020,138 | ---- | C] ()
Sib practice.sib -> C:\Users\admin\Documents\Sib practice.sib -> [2010/02/15 11:52:31 | 000,018,598 | ---- | C] ()
Sibelius 3.lnk -> C:\Users\Public\Desktop\Sibelius 3.lnk -> [2010/02/13 23:48:40 | 000,000,916 | ---- | C] ()
Festival%20of%20Russian%20Culture%2015-21%20Feb%202010.pdf -> C:\Users\admin\Desktop\Festival%20of%20Russian%20Culture%2015-21%20Feb%202010.pdf -> [2010/02/11 15:04:06 | 001,477,619 | ---- | C] ()
x-avi-to-dvd-converter - Shortcut.lnk -> C:\Users\admin\Desktop\x-avi-to-dvd-converter - Shortcut.lnk -> [2010/02/04 20:41:19 | 000,000,502 | ---- | C] ()
SyncBack (2).lnk -> C:\Users\admin\Desktop\SyncBack (2).lnk -> [2010/02/04 20:41:14 | 000,000,886 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\System32\EhStorAuthn.dll -> [2009/10/23 20:08:41 | 000,117,248 | ---- | C] ()
dlcxinst.dll -> C:\Windows\System32\dlcxinst.dll -> [2009/10/23 16:49:10 | 000,274,432 | ---- | C] ()
dlcxutil.dll -> C:\Windows\System32\dlcxutil.dll -> [2009/10/23 16:34:23 | 000,454,656 | ---- | C] ()
dlcxinsb.dll -> C:\Windows\System32\dlcxinsb.dll -> [2009/10/23 16:34:23 | 000,176,128 | ---- | C] ()
dlcxins.dll -> C:\Windows\System32\dlcxins.dll -> [2009/10/23 16:34:23 | 000,176,128 | ---- | C] ()
dlcxcub.dll -> C:\Windows\System32\dlcxcub.dll -> [2009/10/23 16:34:23 | 000,086,016 | ---- | C] ()
dlcxcu.dll -> C:\Windows\System32\dlcxcu.dll -> [2009/10/23 16:34:23 | 000,073,728 | ---- | C] ()
dlcxvs.dll -> C:\Windows\System32\dlcxvs.dll -> [2009/10/23 16:34:23 | 000,040,960 | ---- | C] ()
dlcxcoin.dll -> C:\Windows\System32\dlcxcoin.dll -> [2009/10/23 16:34:22 | 000,344,064 | ---- | C] ()
dlcxgrd.dll -> C:\Windows\System32\dlcxgrd.dll -> [2009/10/23 16:34:22 | 000,188,416 | ---- | C] ()
dlcxjswr.dll -> C:\Windows\System32\dlcxjswr.dll -> [2009/10/23 16:34:22 | 000,139,264 | ---- | C] ()
dlcxinsr.dll -> C:\Windows\System32\dlcxinsr.dll -> [2009/10/23 16:34:22 | 000,106,496 | ---- | C] ()
dlcxcur.dll -> C:\Windows\System32\dlcxcur.dll -> [2009/10/23 16:34:22 | 000,036,864 | ---- | C] ()
ff_vfw.dll -> C:\Windows\System32\ff_vfw.dll -> [2009/09/23 23:46:04 | 000,085,504 | ---- | C] ()
OGACheckControl.dll -> C:\Windows\System32\OGACheckControl.dll -> [2009/08/03 15:07:42 | 000,403,816 | ---- | C] ()
xvidvfw.dll -> C:\Windows\System32\xvidvfw.dll -> [2009/05/29 15:52:26 | 000,204,800 | ---- | C] ()
xvidcore.dll -> C:\Windows\System32\xvidcore.dll -> [2009/05/29 15:47:06 | 000,881,664 | ---- | C] ()
erdmpg-6.dll -> C:\Windows\System32\erdmpg-6.dll -> [2008/10/03 23:07:10 | 003,754,896 | ---- | C] ()
Manipulate.dll -> C:\Windows\System32\Manipulate.dll -> [2008/09/28 17:33:01 | 000,253,952 | ---- | C] ()
ff_vfw.dll.manifest -> C:\Windows\System32\ff_vfw.dll.manifest -> [2008/09/12 15:21:02 | 000,000,547 | ---- | C] ()
comLyricGetter.dll -> C:\Windows\System32\comLyricGetter.dll -> [2008/08/28 11:20:38 | 000,065,536 | ---- | C] ()
Uncommon.dll -> C:\Windows\System32\Uncommon.dll -> [2008/08/28 11:17:22 | 000,097,280 | ---- | C] ()
NormalizeDSP.dll -> C:\Windows\System32\NormalizeDSP.dll -> [2008/08/28 11:17:20 | 000,061,440 | ---- | C] ()
unrar.dll -> C:\Windows\System32\unrar.dll -> [2007/09/04 11:56:10 | 000,164,352 | ---- | C] ()
AviSplitter.INI -> C:\Windows\AviSplitter.INI -> [2007/02/05 19:05:26 | 000,000,038 | ---- | C] ()
lame_enc.dll -> C:\Windows\System32\lame_enc.dll -> [2006/11/06 19:30:38 | 000,262,144 | ---- | C] ()
GlobalUserInterface.CompositeFont -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont -> [2006/11/02 12:37:40 | 000,037,665 | ---- | C] ()
GlobalSerif.CompositeFont -> C:\Windows\Fonts\GlobalSerif.CompositeFont -> [2006/11/02 12:37:40 | 000,029,779 | ---- | C] ()
GlobalSansSerif.CompositeFont -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont -> [2006/11/02 12:37:40 | 000,026,489 | ---- | C] ()
GlobalMonospace.CompositeFont -> C:\Windows\Fonts\GlobalMonospace.CompositeFont -> [2006/11/02 12:37:40 | 000,026,040 | ---- | C] ()
atitmmxx.dll -> C:\Windows\System32\atitmmxx.dll -> [2006/11/02 10:25:44 | 000,159,744 | ---- | C] ()
pacerprf.ini -> C:\Windows\System32\pacerprf.ini -> [2006/11/02 07:40:29 | 000,013,750 | ---- | C] ()
dlcxcaps.dll -> C:\Windows\System32\dlcxcaps.dll -> [2006/09/22 06:42:38 | 000,065,536 | ---- | C] ()
dlcxcfg.dll -> C:\Windows\System32\dlcxcfg.dll -> [2006/09/06 05:13:14 | 000,073,728 | ---- | C] ()
dlcxdrs.dll -> C:\Windows\System32\dlcxdrs.dll -> [2006/08/08 14:58:04 | 000,692,224 | ---- | C] ()
dlcxcnv4.dll -> C:\Windows\System32\dlcxcnv4.dll -> [2006/03/19 18:03:04 | 000,061,440 | ---- | C] ()
lttls13n.dll -> C:\Windows\System32\lttls13n.dll -> [2004/05/24 18:04:56 | 000,147,456 | ---- | C] ()
ltcry13n.dll -> C:\Windows\System32\ltcry13n.dll -> [2004/05/24 18:03:20 | 000,708,608 | ---- | C] ()
lfkodak.dll -> C:\Windows\System32\lfkodak.dll -> [2004/05/24 18:01:02 | 000,118,784 | ---- | C] ()
lffpx7.dll -> C:\Windows\System32\lffpx7.dll -> [2004/05/24 18:00:48 | 000,338,944 | ---- | C] ()
[Alternate Data Streams]
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0CE7F3C9
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:63238B95
< End of report >