Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [code]
- OTS logfile created on: 5/18/2011 16:15:50 - Run 1
- OTS by OldTimer - Version 3.1.42.0 Folder = D:\Internet Downloads\Chrome downloads
- Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.6001.18702)
- Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
- 512.00 Mb Total Physical Memory | 176.00 Mb Available Physical Memory | 34.00% Memory free
- 1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
- Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
- Drive C: | 9.77 Gb Total Space | 2.90 Gb Free Space | 29.65% Space Free | Partition Type: NTFS
- Drive D: | 66.55 Gb Total Space | 0.95 Gb Free Space | 1.43% Space Free | Partition Type: NTFS
- E: Drive not present or media not loaded
- F: Drive not present or media not loaded
- G: Drive not present or media not loaded
- H: Drive not present or media not loaded
- I: Drive not present or media not loaded
- Drive J: | 15.01 Gb Total Space | 1.87 Gb Free Space | 12.46% Space Free | Partition Type: FAT32
- Computer Name: HOME-D52B701C35
- Current User Name: Administrator
- Logged in as Administrator.
- Current Boot Mode: Normal
- Scan Mode: Current user
- Company Name Whitelist: Off
- Skip Microsoft Files: Off
- File Age = 30 Days
- [Processes - Safe List]
- ots.exe -> D:\Internet Downloads\Chrome downloads\OTS.exe -> [2011/05/18 16:09:48 | 000,645,632 | ---- | M] (OldTimer Tools)
- chrome.exe -> C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- admunch.exe -> C:\Program Files\Ad Muncher\AdMunch.exe -> [2011/03/25 22:07:33 | 000,535,752 | ---- | M] (Murray Hurps Corp Pty Ltd)
- explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- ieprivacykeeper.exe -> C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe -> [2005/06/29 14:22:46 | 001,015,808 | ---- | M] (UnH Solutions)
- syncor.exe -> C:\WINDOWS\SynCor.exe -> [2002/08/30 12:59:54 | 000,380,928 | ---- | M] (Analog Devices, Inc.)
- [Modules - Safe List]
- ots.exe -> D:\Internet Downloads\Chrome downloads\OTS.exe -> [2011/05/18 16:09:48 | 000,645,632 | ---- | M] (OldTimer Tools)
- am32-32562.dll -> C:\Program Files\Ad Muncher\AM32-32562.dll -> [2011/03/25 22:07:33 | 000,070,344 | ---- | M] (Murray Hurps Corp Pty Ltd)
- comctl32.dll -> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll -> [2008/11/05 11:21:57 | 001,054,208 | ---- | M] (Microsoft Corporation)
- msvcr80.dll -> C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll -> [2008/07/25 12:17:20 | 000,635,904 | ---- | M] (Microsoft Corporation)
- scrchpg.dll -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll -> [2008/02/08 19:37:54 | 000,158,224 | ---- | M] (Kaspersky Lab)
- miscr3.dll -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll -> [2008/02/08 19:37:48 | 000,088,592 | ---- | M] (Kaspersky Lab)
- fssync.dll -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll -> [2008/02/08 19:37:42 | 000,048,656 | ---- | M] (Kaspersky Lab)
- adialhk.dll -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll -> [2008/02/08 19:37:30 | 000,084,496 | ---- | M] (Kaspersky Lab)
- syncor11.dll -> C:\WINDOWS\system32\Syncor11.dll -> [2002/11/06 20:00:38 | 000,040,820 | ---- | M] (SoundMAX)
- [Win32 Services - Safe List]
- (hpdj00) hpdj00 [Auto | Stopped] -> -> File not found
- (HidServ) Human Interface Device Access [Disabled | Stopped] -> -> File not found
- (MBAMService) MBAMService [Auto | Stopped] -> C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -> [2010/04/29 15:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation)
- (AVP) Kaspersky Internet Security 7.0 [On_Demand | Stopped] -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe -> [2008/02/08 19:36:14 | 000,227,856 | ---- | M] (Kaspersky Lab)
- (SoundMAX Agent Service (default)) SoundMAX Agent Service [Disabled | Stopped] -> C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -> [2002/09/20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.)
- [Driver Services - Safe List]
- (dtsoftbus01) DAEMON Tools Virtual Bus Driver [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\dtsoftbus01.sys -> [2011/04/30 21:00:43 | 000,218,688 | ---- | M] (DT Soft Ltd)
- (MBAMProtector) MBAMProtector [File_System | On_Demand | Running] -> C:\WINDOWS\system32\drivers\mbam.sys -> [2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation)
- (gameenum) Game Port Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\gameenum.sys -> [2008/04/14 02:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation)
- (SISNIC) SiS PCI Fast Ethernet Adapter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\sisnic.sys -> [2008/04/14 00:05:40 | 000,032,768 | ---- | M] (SiS Corporation)
- (klif) klif [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\klif.sys -> [2007/12/28 20:51:04 | 000,195,344 | ---- | M] (Kaspersky Lab)
- (klim5) Kaspersky Anti-Virus NDIS Filter [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\klim5.sys -> [2007/12/13 14:28:40 | 000,024,592 | ---- | M] (Kaspersky Lab)
- (kl1) kl1 [Kernel | Boot | Running] -> C:\WINDOWS\system32\drivers\kl1.sys -> [2007/10/31 14:41:16 | 000,110,096 | ---- | M] (Kaspersky Lab)
- (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ati2mtag.sys -> [2006/05/03 18:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.)
- (DSDrv4) DSDrv4 [Kernel | On_Demand | Stopped] -> C:\Program Files\K!TV\Plugins\S_Bt8x8\DSDrv4.sys -> [2005/02/14 02:00:00 | 000,007,168 | ---- | M] ()
- (Cap713x) Cap713x Video Capture [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\Cap713x.sys -> [2004/10/14 09:19:10 | 000,751,104 | R--- | M] (ASUSTek)
- (SISAGP) SiS AGP Filter [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\SISAGPX.sys -> [2003/02/20 03:18:36 | 000,036,608 | R--- | M] (Silicon Integrated Systems Corporation)
- [Registry - Safe List]
- < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
- HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://start.facemoods.com/?s={searchTerms} ->
- < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
- HKEY_CURRENT_USER\: Main\\"Secondary Start Pages" -> http://www.google.com/ [binary data] ->
- HKEY_CURRENT_USER\: Main\\"Start Page" -> my.daemon-search.com ->
- HKEY_CURRENT_USER\: Main\\"Start Page Redirect Cache" -> http://www.msn.com/ ->
- HKEY_CURRENT_USER\: Main\\"Start Page Redirect Cache AcceptLangs" -> en-us ->
- HKEY_CURRENT_USER\: Main\\"Start Page Redirect Cache_TIMESTAMP" -> 1C 28 7F 29 39 86 CA 01 [binary data] ->
- HKEY_CURRENT_USER\: URLSearchHooks\\"{00000000-6E41-4FD3-8538-502F5495E5FC}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
- HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
- HKEY_CURRENT_USER\: "ProxyServer" -> 127.0.0.1:8118 ->
- < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
- HKLM\software\mozilla\Firefox\extensions -> ->
- HKLM\software\mozilla\Firefox\extensions\\{3ED591BC-7CC7-495B-A526-B2431356EDC1} -> C:\Program Files\Ad Muncher\FirefoxExtension_2.0 [C:\PROGRAM FILES\AD MUNCHER\FIREFOXEXTENSION_2.0] -> [2011/03/25 22:07:34 | 000,000,000 | ---D | M]
- HKLM\software\mozilla\SeaMonkey\Extensions -> ->
- HKLM\software\mozilla\SeaMonkey\Extensions\\{3ED591BC-7CC7-495B-A526-B2431356EDC1} -> C:\Program Files\Ad Muncher\FirefoxExtension_2.0 [C:\PROGRAM FILES\AD MUNCHER\FIREFOXEXTENSION_2.0] -> [2011/03/25 22:07:34 | 000,000,000 | ---D | M]
- < FireFox Extensions [User Folders] > ->
- -> C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions -> [2011/04/27 00:13:45 | 000,000,000 | ---D | M]
- < HOSTS File > ([2010/04/14 21:30:24 | 000,000,738 | ---- | M] - 19 lines) -> C:\WINDOWS\system32\drivers\etc\hosts ->
- Reset Hosts
- 178.32.95.1 paypal.com
- < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
- "{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
- "{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
- "{F053C368-5458-45B2-9B4D-D8914BDDDBFF}" [HKLM] -> C:\Program Files\TextAloud\TAForIE.dll [TextAloud] -> [2009/01/14 13:41:00 | 000,660,992 | ---- | M] ()
- < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
- WebBrowser\\"{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
- < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
- "Ad Muncher" -> C:\Program Files\Ad Muncher\AdMunch.exe ["C:\Program Files\Ad Muncher\AdMunch.exe" /bt] -> [2011/03/25 22:07:33 | 000,535,752 | ---- | M] (Murray Hurps Corp Pty Ltd)
- < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
- "IE Privacy Keeper" -> C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe ["C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -startup] -> [2005/06/29 14:22:46 | 001,015,808 | ---- | M] (UnH Solutions)
- < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
- < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
- < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- \\"HonorAutoRunSetting" -> [1] -> File not found
- < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
- < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- \\"NoDriveTypeAutoRun" -> [145] -> File not found
- < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
- &Download All using 4shared Desktop -> [C:\Program Files\4shared Desktop\down_all.htm] -> File not found
- Block frame with Ad Muncher -> [http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=431398X9&id=menu_ie_frame] -> File not found
- Block image with Ad Muncher -> [http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=431398X9&id=menu_ie_image] -> File not found
- Block link with Ad Muncher -> [http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=431398X9&id=menu_ie_link] -> File not found
- DiaryOne: Save full text -> C:\Program Files\DiaryOne\Script\fullcatcher.htm [C:\Program Files\DiaryOne\Script\fullcatcher.htm] -> [2007/01/21 01:00:00 | 000,000,445 | ---- | M] ()
- DiaryOne: Save selected text -> C:\Program Files\DiaryOne\Script\catcher.htm [C:\Program Files\DiaryOne\Script\catcher.htm] -> [2007/01/21 01:00:00 | 000,000,445 | ---- | M] ()
- Don't filter page with Ad Muncher -> [http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=431398X9&id=menu_ie_exclude] -> File not found
- Report page to the Ad Muncher developers -> [http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=431398X9&id=menu_ie_report] -> File not found
- < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}:{85E0B171-04FA-11D1-B7DA-00A0C90348D6} [HKLM] -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll [Button: Web Anti-Virus statistics] -> [2008/02/08 19:37:52 | 000,223,760 | ---- | M] (Kaspersky Lab)
- < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
- < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
- "" -> http://
- < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
- < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
- < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
- < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
- < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
- {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab [Java Plug-in 1.6.0_24] ->
- {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab [Java Plug-in 1.6.0_24] ->
- {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab [Java Plug-in 1.6.0_24] ->
- < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
- DhcpNameServer -> 192.168.1.1 ->
- < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
- {898E6A54-D71C-4CEE-9B4F-533FA19B3D80}\\DhcpNameServer -> 192.168.1.1 (SiS 900-Based PCI Fast Ethernet Adapter) ->
- < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
- *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
- C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll -> [2008/02/08 19:37:30 | 000,084,496 | ---- | M] (Kaspersky Lab)
- *MultiFile Done* -> ->
- < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
- *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
- Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- *MultiFile Done* -> ->
- < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
- AtiExtEvent -> C:\WINDOWS\System32\ati2evxx.dll -> [2006/05/03 18:44:54 | 000,061,440 | ---- | M] (ATI Technologies Inc.)
- klogon -> C:\WINDOWS\system32\klogon.dll -> [2008/02/08 19:37:44 | 000,219,664 | ---- | M] (Kaspersky Lab)
- WgaLogon -> -> File not found
- < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
- < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
- "C:\Documents and Settings\Administrator\Local Settings\Application Data\IM\Runtime\IncrediMail_Install.exe" -> C:\Documents and Settings\Administrator\Local Settings\Application Data\IM\Runtime\IncrediMail_Install.exe [C:\Documents and Settings\Administrator\Local Settings\Application Data\IM\Runtime\IncrediMail_Install.exe:*:Enabled:IncrediMail Installer] -> [2010/12/17 16:47:39 | 000,448,848 | ---- | M] ()
- "C:\Documents and Settings\Administrator\Local Settings\Temp\ImInstaller\IncrediBackup_installer.exe" -> [C:\Documents and Settings\Administrator\Local Settings\Temp\ImInstaller\IncrediBackup_installer.exe:*:Enabled:IncrediMail Installer] -> File not found
- "C:\Program Files\IncrediMail\Bin\ImApp.exe" -> C:\Program Files\IncrediMail\Bin\ImApp.exe [C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail] -> [2011/03/06 18:01:02 | 000,255,432 | ---- | M] (IncrediMail, Ltd.)
- "C:\Program Files\IncrediMail\Bin\ImpCnt.exe" -> C:\Program Files\IncrediMail\Bin\ImpCnt.exe [C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail] -> [2011/03/06 17:54:46 | 000,112,072 | ---- | M] (IncrediMail, Ltd.)
- "C:\Program Files\IncrediMail\Bin\IncMail.exe" -> C:\Program Files\IncrediMail\Bin\IncMail.exe [C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail] -> [2011/03/06 18:01:02 | 000,353,736 | ---- | M] (IncrediMail, Ltd.)
- "C:\Program Files\K!TV\K!TV.exe" -> C:\Program Files\K!TV\K!TV.exe [C:\Program Files\K!TV\K!TV.exe:*:Disabled:K!TV] -> [2005/03/09 00:15:22 | 001,400,832 | ---- | M] (K!)
- "C:\Program Files\uTorrent\uTorrent.exe" -> C:\Program Files\uTorrent\uTorrent.exe [C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent] -> [2010/04/29 18:34:03 | 000,289,584 | ---- | M] (BitTorrent, Inc.)
- < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
- < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
- "AutoRun" -> 1 ->
- "DisplayName" -> CD-ROM Driver ->
- "ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
- < Drives with AutoRun files > -> ->
- C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2009/12/26 16:06:37 | 000,000,000 | ---- | M] ()
- < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
- < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
- comfile [open] -> "%1" %* ->
- exefile [open] -> "%1" %* ->
- < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
- .com [@ = comfile] -> "%1" %* ->
- .exe [@ = exefile] -> "%1" %* ->
- [Registry - Additional Scans - Safe List]
- < Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state ->
- "bootini" -> 0 ->
- "services" -> 0 ->
- "startup" -> 2 ->
- "system.ini" -> 0 ->
- "win.ini" -> 0 ->
- < Drivers32 [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 ->
- "MIDI1" -> C:\WINDOWS\System32\Syncor11.dll [SYNCOR11.DLL] -> [2002/11/06 20:00:38 | 000,040,820 | ---- | M] (SoundMAX)
- "msacm.divxa32" -> C:\WINDOWS\System32\msaud32_divx.acm [msaud32_divx.acm] -> [2003/02/03 08:01:02 | 000,186,368 | ---- | M] (Microsoft Corporation)
- "msacm.iac2" -> C:\WINDOWS\system32\iac25_32.ax [C:\WINDOWS\system32\iac25_32.ax] -> [2008/04/14 17:00:00 | 000,199,680 | ---- | M] (Intel Corporation)
- "msacm.l3acm" -> C:\WINDOWS\system32\l3codeca.acm [C:\WINDOWS\system32\l3codeca.acm] -> [2008/04/14 17:00:00 | 000,290,816 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS)
- "msacm.sl_anet" -> C:\WINDOWS\System32\sl_anet.acm [sl_anet.acm] -> [2008/04/14 17:00:00 | 000,086,016 | ---- | M] (Sipro Lab Telecom Inc.)
- "msacm.trspch" -> C:\WINDOWS\System32\tssoft32.acm [tssoft32.acm] -> [2008/04/14 17:00:00 | 000,008,192 | ---- | M] (DSP GROUP, INC.)
- "MSVideo8" -> C:\WINDOWS\System32\vfwwdm32.dll [VfWWDM32.dll] -> [2008/04/14 06:42:10 | 000,053,760 | ---- | M] (Microsoft Corporation)
- "vidc.cvid" -> C:\WINDOWS\System32\iccvid.dll [iccvid.dll] -> [2008/04/14 17:00:00 | 000,080,384 | ---- | M] (Radius Inc.)
- "vidc.iv31" -> C:\WINDOWS\System32\ir32_32.dll [ir32_32.dll] -> [2008/04/14 17:00:00 | 000,199,168 | ---- | M] ()
- "vidc.iv32" -> C:\WINDOWS\System32\ir32_32.dll [ir32_32.dll] -> [2008/04/14 17:00:00 | 000,199,168 | ---- | M] ()
- "vidc.iv41" -> C:\WINDOWS\System32\ir41_32.ax [ir41_32.ax] -> [2008/04/14 17:00:00 | 000,848,384 | ---- | M] (Intel Corporation)
- "vidc.iv50" -> C:\WINDOWS\System32\ir50_32.dll [ir50_32.dll] -> [2008/04/14 17:00:00 | 000,755,200 | ---- | M] (Intel Corporation)
- < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->
- *netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->
- 6to4 -> -> File not found
- HidServ -> -> File not found
- Ias -> -> File not found
- Iprip -> -> File not found
- Irmon -> -> File not found
- NWCWorkstation -> -> File not found
- Nwsapagent -> -> File not found
- WmdmPmSp -> -> File not found
- SSHNAS -> -> File not found
- *MultiFile Done* -> ->
- < SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ ->
- {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
- {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
- {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
- {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
- {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
- {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
- {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
- {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
- {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
- {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
- {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
- {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
- {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
- Base -> Driver Group
- Boot Bus Extender -> Driver Group
- Boot file system -> Driver Group
- File system -> Driver Group
- Filter -> Driver Group
- PCI Configuration -> Driver Group
- PNP Filter -> Driver Group
- Primary disk -> Driver Group
- SCSI Class -> Driver Group
- sermouse.sys -> Driver
- System Bus Extender -> Driver Group
- vga.sys -> Driver
- < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
- batfile [open] -> "%1" %* ->
- cmdfile [open] -> "%1" %* ->
- comfile [open] -> "%1" %* ->
- cplfile [cplopen] -> rundll32.exe shell32.dll,Control_RunDLL "%1",%* ->
- exefile [open] -> "%1" %* ->
- piffile [open] -> "%1" %* ->
- scrfile [config] -> "%1" ->
- scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l ->
- scrfile [open] -> "%1" /S ->
- Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 ->
- Directory [AddToPlaylistVLC] -> "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" -> [2010/08/27 01:34:22 | 000,107,008 | ---- | M] ()
- Directory [find] -> %SystemRoot%\Explorer.exe -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- Directory [PlayWithVLC] -> "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" -> [2010/08/27 01:34:22 | 000,107,008 | ---- | M] ()
- Folder [open] -> %SystemRoot%\Explorer.exe /idlist,%I,%L -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- Folder [explore] -> %SystemRoot%\Explorer.exe /e,/idlist,%I,%L -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- Drive [find] -> %SystemRoot%\Explorer.exe -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- < EventViewer Logs - Last 10 Errors > -> Event Information -> Description
- Application [ Error ] 4/26/2011 20:00:14 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\2BD1954B\3452ED62\AutoImager.chm. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 4/26/2011 20:00:15 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\34B1ABD7\3452ED62\AutoImager.exe. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 4/26/2011 20:00:15 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\F3E7E16F\23D9A40A\gdpdfplug.dll. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 4/26/2011 20:00:16 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\C63355D2\23D9A40A\gdimgplug.dll. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 4/26/2011 20:00:16 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\1B4A311B\195A321D\GDIPLUS.DLL. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 4/26/2011 20:00:16 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\E2307DE4\195A321D\gdpicturepro5.ocx. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 4/26/2011 20:00:18 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11904 -> Description = Product: AutoImager -- Error 1904. Module C:\WINDOWS\system32\gdpicturepro5.ocx failed to register. HRESULT -2147024770. Contact your support personnel.
- Application [ Error ] 4/26/2011 20:02:15 Computer Name = HOME-D52B701C35 | Source = MsiInstaller | ID = 11309 -> Description = Product: AutoImager -- Error 1309. Error reading from file: C:\DOCUME~1\ALLUSE~1\APPLIC~1\{5F7EB~1\OFFLINE\2BD1954B\3452ED62\AutoImager.chm. System error 3. Verify that the file exists and that you can access it.
- Application [ Error ] 5/9/2011 20:58:43 Computer Name = HOME-D52B701C35 | Source = Application Error | ID = 1000 -> Description = Faulting application mbam.exe, version 1.50.0.0, faulting module mbamcore.dll, version 1.50.0.0, fault address 0x0000de41.
- Application [ Error ] 5/9/2011 22:16:33 Computer Name = HOME-D52B701C35 | Source = Application Error | ID = 1000 -> Description = Faulting application mbam.exe, version 1.50.0.0, faulting module mbamcore.dll, version 1.50.0.0, fault address 0x0000de41.
- OSession [ Error ] 4/28/2010 19:55:03 Computer Name = HOME-D52B701C35 | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash.
- System [ Error ] 1/7/2011 02:54:38 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load: TfFsMon TfSysMon
- System [ Error ] 1/7/2011 16:29:04 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7000 -> Description = The gupdate service failed to start due to the following error: %%2
- System [ Error ] 1/7/2011 16:29:04 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7000 -> Description = The NetGroup Packet Filter Driver service failed to start due to the following error: %%2
- System [ Error ] 1/7/2011 16:29:04 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load: TfFsMon TfSysMon
- System [ Error ] 1/7/2011 20:47:06 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7034 -> Description = The DNS Client service terminated unexpectedly. It has done this 1 time(s).
- System [ Error ] 1/7/2011 20:47:25 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7034 -> Description = The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
- System [ Error ] 1/7/2011 20:47:25 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7031 -> Description = The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
- System [ Error ] 1/7/2011 20:47:25 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7034 -> Description = The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
- System [ Error ] 1/7/2011 20:47:38 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7031 -> Description = The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
- System [ Error ] 1/7/2011 20:49:19 Computer Name = HOME-D52B701C35 | Source = Service Control Manager | ID = 7034 -> Description = The Ralink Registry Writer service terminated unexpectedly. It has done this 1 time(s).
- [Files/Folders - Created Within 30 Days]
- D'Accord Guitar Chord Dictionary 3.0 -> C:\Documents and Settings\All Users\Start Menu\Programs\D'Accord Guitar Chord Dictionary 3.0 -> [2011/05/17 21:18:30 | 000,000,000 | ---D | C]
- D'Accord Music Software -> C:\Program Files\D'Accord Music Software -> [2011/05/17 21:18:28 | 000,000,000 | ---D | C]
- Recent -> C:\Documents and Settings\Administrator\Recent -> [2011/05/17 20:50:05 | 000,000,000 | RH-D | C]
- Malwarebytes -> C:\Documents and Settings\Administrator\Application Data\Malwarebytes -> [2011/05/16 15:16:58 | 000,000,000 | ---D | C]
- Malwarebytes' Anti-Malware -> C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware -> [2011/05/16 15:16:53 | 000,000,000 | ---D | C]
- mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2011/05/16 15:16:49 | 000,020,952 | ---- | C] (Malwarebytes Corporation)
- Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2011/05/16 15:16:49 | 000,000,000 | ---D | C]
- AllMyMovies -> C:\Documents and Settings\All Users\Application Data\AllMyMovies -> [2011/05/15 12:32:32 | 000,000,000 | ---D | C]
- New Folder -> C:\Documents and Settings\Administrator\Desktop\New Folder -> [2011/05/09 00:09:26 | 000,000,000 | ---D | C]
- Config.Msi -> C:\Config.Msi -> [2011/05/08 21:56:46 | 000,000,000 | -HSD | C]
- DAEMON Tools Lite -> C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite -> [2011/05/08 21:44:40 | 000,000,000 | ---D | C]
- TextAloud -> C:\Documents and Settings\All Users\Start Menu\Programs\TextAloud -> [2011/05/08 19:53:37 | 000,000,000 | ---D | C]
- TextAloud -> C:\Program Files\TextAloud -> [2011/05/08 19:53:35 | 000,000,000 | ---D | C]
- NextUp-ScanSoft -> C:\Program Files\NextUp-ScanSoft -> [2011/05/08 18:31:55 | 000,000,000 | ---D | C]
- EurekaLog -> C:\Documents and Settings\Administrator\Application Data\EurekaLog -> [2011/05/08 15:08:26 | 000,000,000 | ---D | C]
- NextUp -> C:\Documents and Settings\Administrator\Local Settings\Application Data\NextUp -> [2011/05/08 02:12:28 | 000,000,000 | ---D | C]
- Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2011/05/07 10:30:24 | 000,000,000 | ---D | C]
- mp4sds32.ax -> C:\WINDOWS\System32\mp4sds32.ax -> [2011/05/01 21:06:48 | 000,245,760 | ---- | C] (Microsoft Corporation)
- MXRestore.exe -> C:\WINDOWS\System32\MXRestore.exe -> [2011/05/01 21:06:23 | 000,430,080 | ---- | C] (MAGIX AG)
- DLLRES32.dll -> C:\WINDOWS\System32\DLLRES32.dll -> [2011/05/01 21:06:23 | 000,188,416 | ---- | C] (PoINT Software & Systems GmbH)
- DLLTPO32.dll -> C:\WINDOWS\System32\DLLTPO32.dll -> [2011/05/01 21:06:23 | 000,057,344 | ---- | C] (PoINT Software & Systems GmbH)
- STRING32.dll -> C:\WINDOWS\System32\STRING32.dll -> [2011/05/01 21:06:23 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH)
- TTIC32.dll -> C:\WINDOWS\System32\TTIC32.dll -> [2011/05/01 21:06:23 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH)
- TTI32.dll -> C:\WINDOWS\System32\TTI32.dll -> [2011/05/01 21:06:23 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH)
- DLLDEV32.dll -> C:\WINDOWS\System32\DLLDEV32.dll -> [2011/05/01 21:06:22 | 000,163,840 | ---- | C] (PoINT Software & Systems GmbH)
- DLLDRV32.dll -> C:\WINDOWS\System32\DLLDRV32.dll -> [2011/05/01 21:06:22 | 000,151,552 | ---- | C] (PoINT Software & Systems GmbH)
- DLLCPY32.dll -> C:\WINDOWS\System32\DLLCPY32.dll -> [2011/05/01 21:06:22 | 000,094,208 | ---- | C] (PoINT Software & Systems GmbH)
- DLLPTL32.dll -> C:\WINDOWS\System32\DLLPTL32.dll -> [2011/05/01 21:06:22 | 000,065,536 | ---- | C] (PoINT Software & Systems GmbH)
- DLLCDF32.dll -> C:\WINDOWS\System32\DLLCDF32.dll -> [2011/05/01 21:06:22 | 000,061,440 | ---- | C] (PoINT Software & Systems GmbH)
- DLLPRJ32.dll -> C:\WINDOWS\System32\DLLPRJ32.dll -> [2011/05/01 21:06:22 | 000,053,248 | ---- | C] (PoINT Software & Systems GmbH)
- DLLIO32.dll -> C:\WINDOWS\System32\DLLIO32.dll -> [2011/05/01 21:06:22 | 000,053,248 | ---- | C] (PoINT Software & Systems GmbH)
- DLLPRF32.dll -> C:\WINDOWS\System32\DLLPRF32.dll -> [2011/05/01 21:06:22 | 000,049,152 | ---- | C] (PoINT Software & Systems GmbH)
- DLLIMG32.dll -> C:\WINDOWS\System32\DLLIMG32.dll -> [2011/05/01 21:06:22 | 000,045,056 | ---- | C] (PoINT Software & Systems GmbH)
- DLLRD32.dll -> C:\WINDOWS\System32\DLLRD32.dll -> [2011/05/01 21:06:22 | 000,040,960 | ---- | C] (PoINT Software & Systems GmbH)
- DLLPNT32.dll -> C:\WINDOWS\System32\DLLPNT32.dll -> [2011/05/01 21:06:22 | 000,036,864 | ---- | C] (PoINT Software & Systems GmbH)
- DLLMSC32.dll -> C:\WINDOWS\System32\DLLMSC32.dll -> [2011/05/01 21:06:22 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH)
- DLLISO32.dll -> C:\WINDOWS\System32\DLLISO32.dll -> [2011/05/01 21:06:22 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH)
- DLLDIR32.dll -> C:\WINDOWS\System32\DLLDIR32.dll -> [2011/05/01 21:06:22 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH)
- DLLIX.dll -> C:\WINDOWS\System32\DLLIX.dll -> [2011/05/01 21:06:22 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH)
- DLLAV32.dll -> C:\WINDOWS\System32\DLLAV32.dll -> [2011/05/01 21:06:21 | 000,487,424 | ---- | C] (PoINT Software & Systems GmbH)
- DLLCDA32.dll -> C:\WINDOWS\System32\DLLCDA32.dll -> [2011/05/01 21:06:21 | 000,114,688 | ---- | C] (PoINT Software & Systems GmbH)
- MAGIX Shared -> C:\Program Files\Common Files\MAGIX Shared -> [2011/05/01 21:06:15 | 000,000,000 | ---D | C]
- ROBOEX32.DLL -> C:\WINDOWS\System32\ROBOEX32.DLL -> [2011/05/01 21:05:59 | 001,089,536 | ---- | C] (eHelp Corporation.)
- HtmlWH.dll -> C:\WINDOWS\System32\HtmlWH.dll -> [2011/05/01 21:05:59 | 000,085,504 | ---- | C] (Blue Sky Software Corporation.)
- INETWH32.dll -> C:\WINDOWS\System32\INETWH32.dll -> [2011/05/01 21:05:59 | 000,049,152 | ---- | C] (Blue Sky Software Corporation.)
- mgxoschk.dll -> C:\WINDOWS\System32\mgxoschk.dll -> [2011/05/01 21:05:19 | 000,663,552 | ---- | C] (MAGIX AG)
- MAGIX -> C:\WINDOWS\System32\MAGIX -> [2011/05/01 21:05:19 | 000,000,000 | ---D | C]
- EuroTalk -> C:\Documents and Settings\Administrator\Application Data\EuroTalk -> [2011/04/30 21:02:23 | 000,000,000 | ---D | C]
- EuroTalk Interactive -> C:\Documents and Settings\All Users\Start Menu\Programs\EuroTalk Interactive -> [2011/04/30 21:02:22 | 000,000,000 | ---D | C]
- EuroTalk -> C:\Program Files\EuroTalk -> [2011/04/30 21:02:21 | 000,000,000 | ---D | C]
- dtsoftbus01.sys -> C:\WINDOWS\System32\drivers\dtsoftbus01.sys -> [2011/04/30 21:00:43 | 000,218,688 | ---- | C] (DT Soft Ltd)
- DAEMON Tools Lite -> C:\Documents and Settings\All Users\Start Menu\Programs\DAEMON Tools Lite -> [2011/04/30 21:00:36 | 000,000,000 | ---D | C]
- DAEMON Tools Lite -> C:\Program Files\DAEMON Tools Lite -> [2011/04/30 21:00:33 | 000,000,000 | ---D | C]
- ftpcache -> C:\WINDOWS\ftpcache -> [2011/04/27 19:02:59 | 000,000,000 | -HSD | C]
- DAEMON Tools Lite -> C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite -> [2011/04/27 14:55:36 | 000,000,000 | ---D | C]
- Transparent -> C:\Documents and Settings\All Users\Application Data\Transparent -> [2011/04/25 18:50:36 | 000,000,000 | ---D | C]
- Transparent Language, Inc -> C:\Documents and Settings\All Users\Start Menu\Programs\Transparent Language, Inc -> [2011/04/25 18:50:35 | 000,000,000 | ---D | C]
- Transparent -> C:\Program Files\Transparent -> [2011/04/25 18:50:35 | 000,000,000 | ---D | C]
- Platypus -> C:\Documents and Settings\All Users\Start Menu\Programs\Platypus -> [2011/04/23 22:52:01 | 000,000,000 | ---D | C]
- Platypus -> C:\Program Files\Platypus -> [2011/04/23 22:51:54 | 000,000,000 | ---D | C]
- ReflexiveArcade -> C:\Program Files\ReflexiveArcade -> [2011/04/23 22:51:46 | 000,000,000 | ---D | C]
- Google Earth -> C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth -> [2011/04/20 20:02:55 | 000,000,000 | ---D | C]
- NSV -> C:\Program Files\Common Files\NSV -> [2011/04/18 19:59:49 | 000,000,000 | ---D | C]
- [Files/Folders - Modified Within 30 Days]
- fidbox.dat -> C:\WINDOWS\System32\drivers\fidbox.dat -> [2011/05/18 16:21:27 | 000,166,688 | -HS- | M] ()
- GoogleUpdateTaskUserS-1-5-21-1935655697-813497703-1606980848-500UA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-813497703-1606980848-500UA.job -> [2011/05/18 16:19:00 | 000,001,010 | ---- | M] ()
- fidbox.idx -> C:\WINDOWS\System32\drivers\fidbox.idx -> [2011/05/18 16:13:59 | 000,000,032 | -HS- | M] ()
- GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2011/05/18 16:10:01 | 000,000,900 | ---- | M] ()
- fidbox2.dat -> C:\WINDOWS\System32\drivers\fidbox2.dat -> [2011/05/18 16:09:45 | 003,436,576 | -HS- | M] ()
- NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2011/05/18 16:07:31 | 000,000,116 | ---- | M] ()
- Scheduled Update for Ask Toolbar.job -> C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job -> [2011/05/18 16:01:00 | 000,000,250 | ---- | M] ()
- GoogleUpdateTaskUserS-1-5-21-1935655697-813497703-1606980848-500Core.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-813497703-1606980848-500Core.job -> [2011/05/17 23:19:00 | 000,000,958 | ---- | M] ()
- Guitar Chord Dictionary 3.0.lnk -> C:\Documents and Settings\Administrator\Desktop\Guitar Chord Dictionary 3.0.lnk -> [2011/05/17 22:11:24 | 000,001,171 | ---- | M] ()
- GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2011/05/17 21:10:01 | 000,000,896 | ---- | M] ()
- perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2011/05/17 14:32:49 | 000,441,260 | ---- | M] ()
- perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2011/05/17 14:32:49 | 000,071,196 | ---- | M] ()
- bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2011/05/17 14:27:46 | 000,002,048 | --S- | M] ()
- hiberfil.sys -> C:\hiberfil.sys -> [2011/05/17 14:27:39 | 536,449,024 | -HS- | M] ()
- fidbox2.idx -> C:\WINDOWS\System32\drivers\fidbox2.idx -> [2011/05/17 00:12:41 | 000,328,016 | -HS- | M] ()
- DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2011/05/16 18:41:32 | 000,014,848 | ---- | M] ()
- Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2011/05/16 15:16:53 | 000,000,696 | ---- | M] ()
- An Atlas of Erectile Dysfunction, Second Edition.pdf -> C:\Documents and Settings\Administrator\Desktop\An Atlas of Erectile Dysfunction, Second Edition.pdf -> [2011/05/13 20:37:51 | 005,833,503 | ---- | M] ()
- wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2011/05/13 15:01:29 | 000,002,206 | ---- | M] ()
- Splinting for Radial Nerve Palsy.pdf -> C:\Documents and Settings\Administrator\Desktop\Splinting for Radial Nerve Palsy.pdf -> [2011/05/10 02:14:29 | 000,133,177 | ---- | M] ()
- Exercise therapy with the PNF concept.pdf -> C:\Documents and Settings\Administrator\Desktop\Exercise therapy with the PNF concept.pdf -> [2011/05/10 01:26:32 | 000,300,897 | ---- | M] ()
- FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2011/05/09 14:22:50 | 000,270,984 | ---- | M] ()
- TextAloud.lnk -> C:\Documents and Settings\Administrator\Desktop\TextAloud.lnk -> [2011/05/08 19:53:37 | 000,001,407 | ---- | M] ()
- Skype.lnk -> C:\Documents and Settings\All Users\Desktop\Skype.lnk -> [2011/05/06 21:12:27 | 000,002,265 | ---- | M] ()
- wttbb.sys -> C:\WINDOWS\System32\drivers\wttbb.sys -> [2011/05/05 23:44:33 | 000,054,016 | ---- | M] ()
- mgxoschk.ini -> C:\WINDOWS\mgxoschk.ini -> [2011/05/01 21:06:58 | 000,005,817 | ---- | M] ()
- boot.ini -> C:\boot.ini -> [2011/04/30 23:16:43 | 000,000,211 | -HS- | M] ()
- Talk Now Plus!.lnk -> C:\Documents and Settings\All Users\Desktop\Talk Now Plus!.lnk -> [2011/04/30 21:02:22 | 000,001,661 | ---- | M] ()
- dtsoftbus01.sys -> C:\WINDOWS\System32\drivers\dtsoftbus01.sys -> [2011/04/30 21:00:43 | 000,218,688 | ---- | M] (DT Soft Ltd)
- Byki 4 Express.lnk -> C:\Documents and Settings\All Users\Desktop\Byki 4 Express.lnk -> [2011/04/25 18:50:39 | 000,001,800 | ---- | M] ()
- VGANGMJYMWSN.SYS -> C:\WINDOWS\System32\VGANGMJYMWSN.SYS -> [2011/04/24 15:28:50 | 000,000,010 | ---- | M] ()
- Platypus.lnk -> C:\Documents and Settings\Administrator\Desktop\Platypus.lnk -> [2011/04/23 22:52:01 | 000,001,371 | ---- | M] ()
- BASSMOD.dll -> C:\WINDOWS\System32\BASSMOD.dll -> [2011/04/23 18:18:04 | 000,034,308 | ---- | M] ()
- ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2011/04/22 23:25:35 | 000,000,028 | ---- | M] ()
- [Files - No Company Name]
- Guitar Chord Dictionary 3.0.lnk -> C:\Documents and Settings\Administrator\Desktop\Guitar Chord Dictionary 3.0.lnk -> [2011/05/17 22:11:24 | 000,001,171 | ---- | C] ()
- Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2011/05/16 15:16:53 | 000,000,696 | ---- | C] ()
- An Atlas of Erectile Dysfunction, Second Edition.pdf -> C:\Documents and Settings\Administrator\Desktop\An Atlas of Erectile Dysfunction, Second Edition.pdf -> [2011/05/13 20:37:51 | 005,833,503 | ---- | C] ()
- Splinting for Radial Nerve Palsy.pdf -> C:\Documents and Settings\Administrator\Desktop\Splinting for Radial Nerve Palsy.pdf -> [2011/05/10 02:14:34 | 000,133,177 | ---- | C] ()
- Exercise therapy with the PNF concept.pdf -> C:\Documents and Settings\Administrator\Desktop\Exercise therapy with the PNF concept.pdf -> [2011/05/10 01:26:54 | 000,300,897 | ---- | C] ()
- TextAloud.lnk -> C:\Documents and Settings\Administrator\Desktop\TextAloud.lnk -> [2011/05/08 19:53:37 | 000,001,407 | ---- | C] ()
- wttbb.sys -> C:\WINDOWS\System32\drivers\wttbb.sys -> [2011/05/05 23:44:33 | 000,054,016 | ---- | C] ()
- DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2011/05/02 01:12:36 | 000,014,848 | ---- | C] ()
- DLLAV32.lib -> C:\WINDOWS\System32\DLLAV32.lib -> [2011/05/01 21:06:21 | 000,014,182 | ---- | C] ()
- mgxoschk.ini -> C:\WINDOWS\mgxoschk.ini -> [2011/05/01 21:05:19 | 000,005,817 | ---- | C] ()
- unrar.dll -> C:\WINDOWS\System32\unrar.dll -> [2011/05/01 15:39:24 | 000,175,616 | ---- | C] ()
- Talk Now Plus!.lnk -> C:\Documents and Settings\All Users\Desktop\Talk Now Plus!.lnk -> [2011/04/30 21:02:22 | 000,001,661 | ---- | C] ()
- Byki 4 Express.lnk -> C:\Documents and Settings\All Users\Desktop\Byki 4 Express.lnk -> [2011/04/25 18:50:39 | 000,001,800 | ---- | C] ()
- Platypus.lnk -> C:\Documents and Settings\Administrator\Desktop\Platypus.lnk -> [2011/04/23 22:52:01 | 000,001,371 | ---- | C] ()
- GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2011/04/20 20:00:44 | 000,000,900 | ---- | C] ()
- GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2011/04/20 20:00:43 | 000,000,896 | ---- | C] ()
- ezsidmv.dat -> C:\WINDOWS\System32\ezsidmv.dat -> [2010/10/17 03:58:11 | 000,000,056 | -H-- | C] ()
- AegisI5.exe -> C:\WINDOWS\System32\AegisI5.exe -> [2010/10/10 23:08:18 | 000,311,296 | ---- | C] ()
- Install6x.dll -> C:\WINDOWS\System32\Install6x.dll -> [2010/10/10 23:08:18 | 000,081,920 | ---- | C] ()
- RT2661.bin -> C:\WINDOWS\System32\drivers\RT2661.bin -> [2010/10/10 23:08:18 | 000,008,192 | ---- | C] ()
- RT2561s.bin -> C:\WINDOWS\System32\drivers\RT2561s.bin -> [2010/10/10 23:08:18 | 000,008,192 | ---- | C] ()
- RT2561.bin -> C:\WINDOWS\System32\drivers\RT2561.bin -> [2010/10/10 23:08:18 | 000,008,192 | ---- | C] ()
- rmc_rtspdl.dll -> C:\WINDOWS\System32\rmc_rtspdl.dll -> [2010/09/26 02:27:13 | 000,237,568 | ---- | C] ()
- BSL.INI -> C:\WINDOWS\BSL.INI -> [2010/09/25 17:39:43 | 000,000,029 | ---- | C] ()
- BASSMOD.dll -> C:\WINDOWS\System32\BASSMOD.dll -> [2010/09/23 18:50:24 | 000,034,308 | ---- | C] ()
- impborl.dll -> C:\WINDOWS\impborl.dll -> [2010/08/31 11:17:30 | 000,012,288 | ---- | C] ()
- pdfpage.INI -> C:\WINDOWS\pdfpage.INI -> [2010/06/02 20:52:12 | 000,000,344 | ---- | C] ()
- pdfpg.dat -> C:\WINDOWS\System32\pdfpg.dat -> [2010/06/02 20:52:03 | 000,001,024 | ---- | C] ()
- ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2010/04/03 03:51:49 | 000,000,028 | ---- | C] ()
- apset.ini -> C:\WINDOWS\System32\apset.ini -> [2010/04/03 02:00:36 | 000,000,272 | ---- | C] ()
- pdfmonnt.dll -> C:\WINDOWS\System32\pdfmonnt.dll -> [2010/01/27 17:02:24 | 000,116,224 | ---- | C] ()
- pdf2word.INI -> C:\WINDOWS\pdf2word.INI -> [2010/01/27 17:01:45 | 000,000,348 | ---- | C] ()
- VGANGMJYMWSN.SYS -> C:\WINDOWS\System32\VGANGMJYMWSN.SYS -> [2009/12/31 00:37:44 | 000,000,010 | ---- | C] ()
- NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2009/12/29 23:06:00 | 000,000,116 | ---- | C] ()
- FontCache3.0.0.0.dat -> C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat -> [2009/12/27 04:42:23 | 000,064,200 | ---- | C] ()
- ati2sgag.exe -> C:\WINDOWS\System32\ati2sgag.exe -> [2009/12/27 02:33:47 | 000,520,192 | ---- | C] ()
- WININIT.INI -> C:\WINDOWS\WININIT.INI -> [2009/12/27 02:23:45 | 000,000,010 | ---- | C] ()
- klin.dat -> C:\WINDOWS\System32\drivers\klin.dat -> [2009/12/26 22:31:20 | 000,115,267 | ---- | C] ()
- klick.dat -> C:\WINDOWS\System32\drivers\klick.dat -> [2009/12/26 22:31:20 | 000,097,859 | ---- | C] ()
- fidbox2.dat -> C:\WINDOWS\System32\drivers\fidbox2.dat -> [2009/12/26 22:30:48 | 003,436,576 | -HS- | C] ()
- fidbox.dat -> C:\WINDOWS\System32\drivers\fidbox.dat -> [2009/12/26 22:30:48 | 000,159,520 | -HS- | C] ()
- hpdj3740.ini -> C:\WINDOWS\hpdj3740.ini -> [2009/12/26 21:42:59 | 000,000,266 | ---- | C] ()
- ODBCINST.INI -> C:\WINDOWS\ODBCINST.INI -> [2009/12/26 16:44:47 | 000,004,161 | ---- | C] ()
- FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2009/12/26 16:42:47 | 000,270,984 | ---- | C] ()
- nsreg.dat -> C:\WINDOWS\nsreg.dat -> [2009/12/26 16:41:44 | 000,000,000 | ---- | C] ()
- msssc.dll -> C:\WINDOWS\System32\msssc.dll -> [2009/12/26 16:28:30 | 000,000,044 | ---- | C] ()
- Ascd_tmp.ini -> C:\WINDOWS\Ascd_tmp.ini -> [2009/12/26 16:25:45 | 000,003,471 | ---- | C] ()
- ASUSHWIO.SYS -> C:\WINDOWS\System32\drivers\ASUSHWIO.SYS -> [2009/12/26 16:25:43 | 000,005,824 | ---- | C] ()
- bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/12/26 16:11:00 | 000,002,048 | --S- | C] ()
- emptyregdb.dat -> C:\WINDOWS\System32\emptyregdb.dat -> [2009/12/26 15:58:07 | 000,021,640 | ---- | C] ()
- secupd.dat -> C:\WINDOWS\System32\secupd.dat -> [2009/04/19 01:41:06 | 000,004,569 | ---- | C] ()
- oembios.bin -> C:\WINDOWS\System32\oembios.bin -> [2008/04/14 17:00:00 | 013,107,200 | ---- | C] ()
- mlang.dat -> C:\WINDOWS\System32\mlang.dat -> [2008/04/14 17:00:00 | 000,673,088 | ---- | C] ()
- perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2008/04/14 17:00:00 | 000,441,260 | ---- | C] ()
- perfi009.dat -> C:\WINDOWS\System32\perfi009.dat -> [2008/04/14 17:00:00 | 000,272,128 | ---- | C] ()
- dssec.dat -> C:\WINDOWS\System32\dssec.dat -> [2008/04/14 17:00:00 | 000,218,003 | ---- | C] ()
- perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2008/04/14 17:00:00 | 000,071,196 | ---- | C] ()
- mib.bin -> C:\WINDOWS\System32\mib.bin -> [2008/04/14 17:00:00 | 000,046,258 | ---- | C] ()
- perfd009.dat -> C:\WINDOWS\System32\perfd009.dat -> [2008/04/14 17:00:00 | 000,028,626 | ---- | C] ()
- oembios.dat -> C:\WINDOWS\System32\oembios.dat -> [2008/04/14 17:00:00 | 000,004,463 | ---- | C] ()
- Dcache.bin -> C:\WINDOWS\System32\Dcache.bin -> [2008/04/14 17:00:00 | 000,001,804 | ---- | C] ()
- noise.dat -> C:\WINDOWS\System32\noise.dat -> [2008/04/14 17:00:00 | 000,000,741 | ---- | C] ()
- klopp.dat -> C:\WINDOWS\System32\drivers\klopp.dat -> [2008/02/08 19:35:42 | 000,023,604 | ---- | C] ()
- atiicdxx.dat -> C:\WINDOWS\System32\atiicdxx.dat -> [2006/04/28 22:05:14 | 000,127,614 | ---- | C] ()
- [File - Lop Check]
- DAEMON Tools Lite -> C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite -> [2011/04/27 14:57:11 | 000,000,000 | ---D | M]
- EurekaLog -> C:\Documents and Settings\Administrator\Application Data\EurekaLog -> [2011/05/08 15:08:26 | 000,000,000 | ---D | M]
- EuroTalk -> C:\Documents and Settings\Administrator\Application Data\EuroTalk -> [2011/04/30 21:02:23 | 000,000,000 | ---D | M]
- Obsidium -> C:\Documents and Settings\Administrator\Application Data\Obsidium -> [2011/04/06 19:14:47 | 000,000,000 | ---D | M]
- Thinstall -> C:\Documents and Settings\Administrator\Application Data\Thinstall -> [2011/04/01 21:53:16 | 000,000,000 | ---D | M]
- UnH Solutions -> C:\Documents and Settings\Administrator\Application Data\UnH Solutions -> [2009/12/26 23:01:01 | 000,000,000 | ---D | M]
- URSoft -> C:\Documents and Settings\Administrator\Application Data\URSoft -> [2009/12/26 23:47:44 | 000,000,000 | ---D | M]
- uTorrent -> C:\Documents and Settings\Administrator\Application Data\uTorrent -> [2011/05/18 04:40:45 | 000,000,000 | ---D | M]
- Windows Desktop Search -> C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search -> [2009/12/26 16:13:49 | 000,000,000 | ---D | M]
- Ad Muncher -> C:\Documents and Settings\All Users\Application Data\Ad Muncher -> [2011/02/02 00:24:42 | 000,000,000 | ---D | M]
- AllMyMovies -> C:\Documents and Settings\All Users\Application Data\AllMyMovies -> [2011/05/15 12:32:32 | 000,000,000 | ---D | M]
- DAEMON Tools Lite -> C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite -> [2011/05/08 21:44:40 | 000,000,000 | ---D | M]
- IM -> C:\Documents and Settings\All Users\Application Data\IM -> [2009/12/26 22:05:58 | 000,000,000 | ---D | M]
- IncrediMail -> C:\Documents and Settings\All Users\Application Data\IncrediMail -> [2009/12/26 22:05:07 | 000,000,000 | ---D | M]
- Screentime -> C:\Documents and Settings\All Users\Application Data\Screentime -> [2010/04/14 03:23:25 | 000,000,000 | ---D | M]
- TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2011/05/15 23:32:01 | 000,000,000 | ---D | M]
- Transparent -> C:\Documents and Settings\All Users\Application Data\Transparent -> [2011/04/25 18:50:36 | 000,000,000 | ---D | M]
- Scheduled Update for Ask Toolbar.job -> C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job -> [2011/05/18 16:01:00 | 000,000,250 | ---- | M] ()
- [Custom Scans]
- < netsvcs >
- < %SYSTEMDRIVE%\*.exe >
- < MD5 Scans Start>
- < %systemdrive%\EXPLORER.EXE /md5 /s >
- explorer.exe : MD5=2BB75B7F548D82A099125D0C5971DE7D -> C:\WINDOWS\explorer.exe -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- explorer.exe : MD5=2BB75B7F548D82A099125D0C5971DE7D -> C:\WINDOWS\system32\dllcache\explorer.exe -> [2008/07/03 16:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation)
- < %systemdrive%\SVCHOST.EXE /md5 /s >
- svchost.exe : MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -> C:\WINDOWS\system32\dllcache\svchost.exe -> [2008/04/14 17:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation)
- svchost.exe : MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -> C:\WINDOWS\system32\svchost.exe -> [2008/04/14 17:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation)
- < %systemdrive%\USERINIT.EXE /md5 /s >
- userinit.exe : MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -> C:\WINDOWS\system32\dllcache\userinit.exe -> [2008/04/14 17:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation)
- userinit.exe : MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -> C:\WINDOWS\system32\userinit.exe -> [2008/04/14 17:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation)
- < %systemdrive%\WINLOGON.EXE /md5 /s >
- winlogon.exe : MD5=5DFCBA4E70DA51CF67022F7C207FEAA8 -> C:\WINDOWS\system32\dllcache\winlogon.exe -> [2009/01/07 18:00:58 | 000,509,440 | ---- | M] (Microsoft Corporation)
- winlogon.exe : MD5=5DFCBA4E70DA51CF67022F7C207FEAA8 -> C:\WINDOWS\system32\winlogon.exe -> [2009/01/07 18:00:58 | 000,509,440 | ---- | M] (Microsoft Corporation)
- < MD5 Scans End>
- < %systemroot%\*. /mp /s >
- < hklm\software\clients\startmenuinternet|command /rs >
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\ -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE"] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\ -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE"] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand -> C:\WINDOWS\System32\IE4UINIT.EXE ["C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL] -> [2010/02/24 11:54:25 | 000,173,056 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand -> C:\WINDOWS\System32\IE4UINIT.EXE ["C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE] -> [2010/02/24 11:54:25 | 000,173,056 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand -> C:\WINDOWS\System32\IE4UINIT.EXE ["C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW] -> [2010/02/24 11:54:25 | 000,173,056 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\ -> C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE ["C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF] -> [2009/03/08 18:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\ -> C:\Program Files\Internet Explorer\iexplore.exe [C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] -> [2009/03/08 18:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
- < hklm\software\clients\startmenuinternet|command /64 /rs >
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\ -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE"] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\ -> C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ["C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE"] -> [2011/04/28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand -> C:\WINDOWS\System32\IE4UINIT.EXE ["C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL] -> [2010/02/24 11:54:25 | 000,173,056 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand -> C:\WINDOWS\System32\IE4UINIT.EXE ["C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE] -> [2010/02/24 11:54:25 | 000,173,056 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand -> C:\WINDOWS\System32\IE4UINIT.EXE ["C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW] -> [2010/02/24 11:54:25 | 000,173,056 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\ -> C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE ["C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF] -> [2009/03/08 18:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command -> ->
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\ -> C:\Program Files\Internet Explorer\iexplore.exe [C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] -> [2009/03/08 18:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
- Restore point Set: OTS Restore Point (0)
- [Alternate Data Streams]
- @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
- @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
- @Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D96771C
- @Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:21F11E8D
- @Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B7177954
- @Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51
- < End of report >
- [/code]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement