- OTL logfile created on: 07/05/2012 12:29:31 - Run 4
- OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\user\Downloads
- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7601.17514)
- Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
- 1023,55 Mb Total Physical Memory | 667,73 Mb Available Physical Memory | 65,24% Memory free
- 2,00 Gb Paging File | 1,43 Gb Available in Paging File | 71,50% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
- Drive C: | 29,90 Gb Total Space | 21,69 Gb Free Space | 72,54% Space Free | Partition Type: NTFS
- Drive D: | 43,37 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
- Computer Name: USER-PC | User Name: user | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user
- Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012/04/23 19:27:36 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\user\Downloads\OTL.exe
- PRC - [2012/04/17 23:20:10 | 000,738,168 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
- PRC - [2012/04/17 23:04:56 | 002,980,016 | ---- | M] (SpeedBit Ltd.) -- C:\Program Files\DAP\DAP.exe
- PRC - [2012/02/03 17:50:18 | 003,508,624 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
- PRC - [2012/02/02 12:55:22 | 003,209,216 | ---- | M] (Ares Development Group) -- C:\Program Files\Ares\Ares.exe
- PRC - [2011/12/12 01:33:46 | 001,760,328 | ---- | M] (ManyCam LLC) -- C:\Program Files\ManyCam\Bin\ManyCam.exe
- PRC - [2010/11/20 18:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
- PRC - [2010/11/20 18:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012/04/17 23:04:54 | 000,053,248 | ---- | M] () -- C:\Program Files\DAP\zlib.dll
- MOD - [2011/12/12 01:33:52 | 000,498,760 | ---- | M] () -- C:\Program Files\ManyCam\Bin\cximagecrt.dll
- MOD - [2011/12/12 01:33:48 | 000,123,976 | ---- | M] () -- C:\Program Files\ManyCam\Bin\CrashRpt.dll
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV - [2009/07/13 22:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
- SRV - [2009/07/13 22:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\user\AppData\Local\Temp\catchme.sys -- (catchme)
- DRV - [2011/12/19 09:48:24 | 000,227,632 | ---- | M] (Oracle Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\VBoxSF.sys -- (VBoxSF)
- DRV - [2011/12/19 09:48:24 | 000,107,312 | ---- | M] (Oracle Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\VBoxGuest.sys -- (VBoxGuest)
- DRV - [2011/12/19 09:48:22 | 000,085,808 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxMouse.sys -- (VBoxMouse)
- DRV - [2011/12/19 09:48:20 | 000,104,240 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxVideo.sys -- (VBoxVideo)
- DRV - [2011/09/29 04:04:22 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ManyCam.sys -- (ManyCam)
- DRV - [2010/11/20 18:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV - [2010/11/20 18:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV - [2009/07/13 20:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKLM\..\SearchScopes,DefaultScope =
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 12 2E 19 B7 04 1D CD 01 [binary data]
- IE - HKCU\..\SearchScopes,DefaultScope =
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultengine: "Google"
- FF - prefs.js..browser.search.defaultenginename: "Google"
- FF - prefs.js..browser.search.defaultthis.engineName: ""
- FF - prefs.js..browser.search.defaulturl: ""
- FF - prefs.js..browser.search.order.1: ""
- FF - prefs.js..browser.search.selectedEngine: ""
- FF - prefs.js..network.proxy.type: 2
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\user\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\user\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/17 23:09:12 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
- [2012/04/20 14:51:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Extensions
- [2012/04/29 15:58:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\extensions
- () (No name found) -- C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\S3XQ4PCB.DEFAULT\EXTENSIONS\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}.XPI
- [2012/01/29 13:34:12 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
- [2012/01/29 11:20:59 | 000,001,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\buscape.xml
- [2012/01/29 11:20:59 | 000,001,212 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mercadolivre.xml
- [2012/01/29 10:55:01 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
- [2012/01/29 11:20:59 | 000,001,168 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-br.xml
- [2012/01/29 11:20:59 | 000,000,952 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-br.xml
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: Google (Enabled)
- CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
- CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
- CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
- CHR - plugin: registryAccess (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaodnbkkemkkaekocofmphoadofkdh\7.14.1.0_0\background/registryAccess.dll
- CHR - plugin: Chrome SVD extension (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcpfkccckpeeghiklnhienllljccglb\2.0.5_0\lib/npdownloaderchrome.dll
- CHR - plugin: Chrome DAP extension (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb\2.0.10_0\lib/npdapchrome.dll
- CHR - plugin: Google Update (Enabled) = C:\Users\user\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
- O1 HOSTS File: ([2012/05/03 22:45:08 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 localhost
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
- O2 - BHO: (SBCONVERT Class) - {92A9ACF4-9333-43AE-9698-DB283326F87F} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
- O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\Grabber.dll (SpeedBit)
- O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
- O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
- O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
- O4 - HKCU..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
- O4 - HKCU..\Run: [DownloadAccelerator] C:\Program Files\DAP\DAP.EXE (SpeedBit Ltd.)
- O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
- O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
- O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
- O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
- O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
- O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
- O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 200.222.123.101 192.168.0.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22C13D65-2EBE-49EA-BEAE-913F2420F62D}: DhcpNameServer = 200.222.123.101 192.168.0.1
- O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2009/06/10 18:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
- O32 - AutoRun File - [2011/08/16 17:00:22 | 000,000,647 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
- O32 - AutoRun File - [2011/12/19 10:02:20 | 000,006,966 | R--- | M] () - D:\autorun.sh -- [ CDFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = ComFile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- NetSvcs: FastUserSwitchingCompatibility - File not found
- NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
- NetSvcs: Nla - File not found
- NetSvcs: Ntmssvc - File not found
- NetSvcs: NWCWorkstation - File not found
- NetSvcs: Nwsapagent - File not found
- NetSvcs: SRService - File not found
- NetSvcs: WmdmPmSp - File not found
- NetSvcs: LogonHours - File not found
- NetSvcs: PCAudit - File not found
- NetSvcs: helpsvc - File not found
- NetSvcs: uploadmgr - File not found
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012/05/03 23:00:36 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
- [2012/05/03 23:00:34 | 000,000,000 | ---D | C] -- C:\Windows\temp
- [2012/05/03 22:37:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
- [2012/05/03 22:37:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
- [2012/05/03 22:37:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
- [2012/05/03 22:37:43 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
- [2012/05/03 22:37:40 | 000,000,000 | ---D | C] -- C:\Qoobox
- [2012/05/03 22:28:05 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Apple Computer
- [2012/05/03 22:28:03 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Apple Computer
- [2012/04/29 15:45:19 | 000,000,000 | ---D | C] -- C:\_OTL
- [2012/04/23 14:05:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\GetRightToGo
- [2012/04/23 14:05:47 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Downloads
- [2012/04/20 16:32:39 | 000,000,000 | ---D | C] -- C:\Program Files\Social Bookmarking Automation Software Blog Comment Software
- [2012/04/20 16:25:31 | 001,140,472 | ---- | C] (Infragistics, Inc.) -- C:\Windows\System32\IGUltraGrid20.ocx
- [2012/04/20 16:25:31 | 000,361,256 | ---- | C] (Namtuk.com) -- C:\Windows\System32\MyCommandbutton.ocx
- [2012/04/20 16:25:31 | 000,349,968 | ---- | C] (Infragistics, Inc.) -- C:\Windows\System32\IGThreed40.ocx
- [2012/04/20 16:25:31 | 000,246,304 | ---- | C] (Namtuk.com) -- C:\Windows\System32\MyFramePanel.ocx
- [2012/04/20 16:25:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftwareDepo.com
- [2012/04/20 16:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\SoftwareDepo.com
- [2012/04/20 16:20:05 | 000,000,000 | ---D | C] -- C:\Config.Msi
- [2012/04/20 16:14:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
- [2012/04/20 16:14:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
- [2012/04/20 16:13:45 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
- [2012/04/20 16:13:45 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
- [2012/04/20 16:13:45 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
- [2012/04/20 16:13:45 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
- [2012/04/20 16:13:22 | 000,000,000 | ---D | C] -- C:\Program Files\Java
- [2012/04/20 15:36:01 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\WinRAR
- [2012/04/20 15:35:51 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
- [2012/04/20 15:35:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
- [2012/04/20 15:35:46 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
- [2012/04/20 15:13:52 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ElevatedDiagnostics
- [2012/04/20 15:07:10 | 000,000,000 | ---D | C] -- C:\temp
- [2012/04/20 14:51:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Mozilla
- [2012/04/20 14:51:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Mozilla
- [2012/04/20 14:31:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Samsung
- [2012/04/20 14:31:23 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Samsung
- [2012/04/20 14:31:11 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\samsung
- [2012/04/17 23:20:27 | 000,000,000 | ---D | C] -- C:\1d628acdf504dd45e237e0148547
- [2012/04/17 23:19:41 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XP Codec Pack 2.5.1
- [2012/04/17 23:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XP Codec Pack 2.5.1
- [2012/04/17 23:19:39 | 000,000,000 | ---D | C] -- C:\Program Files\XP Codec Pack
- [2012/04/17 23:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
- [2012/04/17 23:19:25 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
- [2012/04/17 23:19:02 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
- [2012/04/17 23:18:03 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Macromedia
- [2012/04/17 23:18:03 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Adobe
- [2012/04/17 23:17:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\uTorrent
- [2012/04/17 23:16:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
- [2012/04/17 23:16:33 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
- [2012/04/17 23:15:41 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
- [2012/04/17 23:15:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
- [2012/04/17 23:15:07 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
- [2012/04/17 23:15:05 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Apple
- [2012/04/17 23:15:04 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
- [2012/04/17 23:15:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
- [2012/04/17 23:14:19 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxthon
- [2012/04/17 23:14:17 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Maxthon3
- [2012/04/17 23:14:09 | 000,000,000 | ---D | C] -- C:\Program Files\Maxthon3
- [2012/04/17 23:13:39 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\APN
- [2012/04/17 23:12:58 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ManyCam
- [2012/04/17 23:12:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ManyCam
- [2012/04/17 23:12:46 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\ManyCam
- [2012/04/17 23:12:42 | 000,000,000 | ---D | C] -- C:\Program Files\ManyCam
- [2012/04/17 23:11:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
- [2012/04/17 23:11:03 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\System32\Redemption.dll
- [2012/04/17 23:10:55 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\System32\dgderapi.dll
- [2012/04/17 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
- [2012/04/17 23:10:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
- [2012/04/17 23:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
- [2012/04/17 23:09:53 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Downloaded Installations
- [2012/04/17 23:09:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geany
- [2012/04/17 23:09:25 | 000,000,000 | ---D | C] -- C:\Program Files\Geany
- [2012/04/17 23:09:12 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
- [2012/04/17 23:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SPEEDbit Video Downloader
- [2012/04/17 23:08:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Speedbit
- [2012/04/17 23:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\SPEEDbit Video Downloader
- [2012/04/17 23:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\SearchPredict
- [2012/04/17 23:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink
- [2012/04/17 23:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\DVD Shrink
- [2012/04/17 23:08:20 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
- [2012/04/17 23:05:11 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
- [2012/04/17 23:05:08 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit
- [2012/04/17 23:05:08 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\My DAP Downloads
- [2012/04/17 23:05:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Download Accelerator Plus (DAP)
- [2012/04/17 23:05:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeedBit
- [2012/04/17 23:05:05 | 000,000,000 | ---D | C] -- C:\Program Files\DAP
- [2012/04/17 23:04:54 | 000,172,032 | ---- | C] (Jin Hui E-mail: jinhui@jcomsoft.com Web: http://www.jcomsoft.com) -- C:\Windows\System32\AniGIF.ocx
- [2012/04/17 23:04:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
- [2012/04/17 23:04:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
- [2012/04/17 23:04:22 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\OpenCandy
- [2012/04/17 23:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
- [2012/04/17 23:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\DsNET Corp
- [2012/04/17 23:02:59 | 000,000,000 | ---D | C] -- C:\Users\user\Desktop\My Shared Folder
- [2012/04/17 23:02:58 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Ares
- [2012/04/17 23:02:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ares
- [2012/04/17 23:02:55 | 000,000,000 | ---D | C] -- C:\Program Files\Ares
- [2012/04/17 23:02:45 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Opera
- [2012/04/17 23:02:44 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Opera
- [2012/04/17 23:02:40 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
- [2012/04/17 23:00:45 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
- [2012/04/17 23:00:44 | 000,000,000 | ---D | C] -- C:\Program Files\Twitter
- [2012/04/17 23:00:16 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
- [2012/04/17 22:54:31 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
- [2012/04/17 22:47:19 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Google
- [2012/04/17 22:46:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Apps
- [2012/04/17 22:46:48 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Deployment
- [2012/04/17 22:41:38 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox Guest Additions
- [2012/04/17 22:39:11 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
- [2012/04/12 18:03:45 | 000,000,000 | ---D | C] -- C:\Windows\Panther
- [2012/04/12 13:31:56 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- [2012/04/12 13:31:56 | 000,000,000 | R--D | C] -- C:\Users\user\Searches
- [2012/04/12 13:31:56 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- [2012/04/12 13:31:55 | 000,000,000 | -H-D | C] -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
- [2012/04/12 13:31:39 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Identities
- [2012/04/12 13:24:55 | 000,000,000 | ---D | C] -- C:\found.000
- [2012/04/12 13:18:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
- [2012/04/12 13:11:38 | 000,000,000 | R--D | C] -- C:\Users\user\Contacts
- [2012/04/12 13:11:27 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\VirtualStore
- [2012/04/12 13:11:26 | 000,000,000 | --SD | C] -- C:\Users\user\AppData\Roaming\Microsoft
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Videos
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Saved Games
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Pictures
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Music
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Links
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Favorites
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Downloads
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Documents
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Desktop
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\Temporary Internet Files
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Templates
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Start Menu
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\SendTo
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Recent
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\PrintHood
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\NetHood
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Videos
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Pictures
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Music
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\My Documents
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Local Settings
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\History
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Cookies
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Application Data
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\Application Data
- [2012/04/12 13:11:26 | 000,000,000 | -H-D | C] -- C:\Users\user\AppData
- [2012/04/12 13:11:26 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Temp
- [2012/04/12 13:11:26 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Microsoft
- [2012/04/12 13:11:26 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Media Center Programs
- [2012/04/12 13:11:10 | 000,000,000 | ---D | C] -- C:\Recovery
- [2012/04/12 13:05:21 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
- [2012/04/12 13:04:19 | 000,000,000 | -HSD | C] -- C:\System Volume Information
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012/05/07 12:31:15 | 000,028,320 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2012/05/07 12:31:15 | 000,028,320 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2012/05/07 12:26:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012/05/07 12:22:41 | 000,014,386 | ---- | M] () -- C:\Users\user\Desktop\Untitled.png
- [2012/05/03 23:01:28 | 000,001,074 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA.job
- [2012/05/03 22:52:17 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core.job
- [2012/05/03 22:45:08 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
- [2012/05/03 22:31:46 | 000,088,280 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
- [2012/05/03 22:31:09 | 000,001,388 | ---- | M] () -- C:\Users\user\Desktop\My DAP Downloads.lnk
- [2012/04/25 18:55:35 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
- [2012/04/25 18:55:35 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
- [2012/04/20 16:20:24 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
- [2012/04/20 16:13:24 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
- [2012/04/20 16:13:24 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
- [2012/04/20 16:13:24 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
- [2012/04/20 16:13:23 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
- [2012/04/17 23:20:10 | 000,000,937 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
- [2012/04/17 23:20:10 | 000,000,913 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
- [2012/04/17 23:19:44 | 000,001,060 | ---- | M] () -- C:\Users\user\Desktop\Media Player Classic.lnk
- [2012/04/17 23:16:55 | 000,001,208 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
- [2012/04/17 23:15:53 | 000,002,503 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
- [2012/04/17 23:15:53 | 000,002,479 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
- [2012/04/17 23:14:19 | 000,001,048 | ---- | M] () -- C:\Users\user\Desktop\Maxthon 3.lnk
- [2012/04/17 23:12:58 | 000,001,097 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam.lnk
- [2012/04/17 23:12:58 | 000,001,073 | ---- | M] () -- C:\Users\user\Desktop\ManyCam.lnk
- [2012/04/17 23:12:23 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
- [2012/04/17 23:11:06 | 000,001,923 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
- [2012/04/17 23:09:27 | 000,001,035 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Geany.lnk
- [2012/04/17 23:09:27 | 000,001,011 | ---- | M] () -- C:\Users\Public\Desktop\Geany.lnk
- [2012/04/17 23:09:13 | 000,001,088 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
- [2012/04/17 23:08:45 | 000,001,991 | ---- | M] () -- C:\Users\user\Desktop\SPEEDbit Video Downloader.lnk
- [2012/04/17 23:08:45 | 000,001,614 | ---- | M] () -- C:\Users\user\Desktop\My Video Downloads .lnk
- [2012/04/17 23:08:20 | 000,000,953 | ---- | M] () -- C:\Users\user\Desktop\DVD Shrink 3.2.lnk
- [2012/04/17 23:07:53 | 000,000,893 | ---- | M] () -- C:\Users\user\Desktop\Download Accelerator Plus (DAP).lnk
- [2012/04/17 23:04:56 | 000,109,216 | ---- | M] () -- C:\Windows\System32\EasyHook64.dll
- [2012/04/17 23:04:56 | 000,084,480 | ---- | M] () -- C:\Windows\System32\EasyHook32.dll
- [2012/04/17 23:04:54 | 000,172,032 | ---- | M] (Jin Hui E-mail: jinhui@jcomsoft.com Web: http://www.jcomsoft.com) -- C:\Windows\System32\AniGIF.ocx
- [2012/04/17 23:04:39 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2012/04/17 23:04:22 | 000,002,072 | ---- | M] () -- C:\Users\Public\Desktop\MP3 Downloader.lnk
- [2012/04/17 23:04:22 | 000,002,068 | ---- | M] () -- C:\Users\Public\Desktop\Video Search.lnk
- [2012/04/17 23:04:21 | 000,001,144 | ---- | M] () -- C:\Users\Public\Desktop\aTube Catcher.lnk
- [2012/04/17 23:02:56 | 000,000,909 | ---- | M] () -- C:\Users\Public\Desktop\Ares.lnk
- [2012/04/17 23:02:41 | 000,001,775 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
- [2012/04/17 22:54:32 | 000,002,306 | ---- | M] () -- C:\Users\user\Desktop\Google Chrome.lnk
- [2012/04/17 22:43:49 | 000,001,407 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2012/04/12 13:09:42 | 000,265,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
- [2012/04/12 13:07:01 | 000,115,640 | ---- | M] () -- C:\Windows\System32\license.rtf
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012/05/07 12:22:41 | 000,014,386 | ---- | C] () -- C:\Users\user\Desktop\Untitled.png
- [2012/05/03 22:37:46 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
- [2012/05/03 22:37:46 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
- [2012/05/03 22:37:46 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
- [2012/05/03 22:37:46 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
- [2012/05/03 22:37:46 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
- [2012/05/03 22:31:46 | 000,088,280 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
- [2012/04/23 14:13:42 | 000,001,576 | ---- | C] () -- C:\Users\user\Desktop\Online Business Komplett Paket.LNK
- [2012/04/20 16:32:39 | 000,000,920 | ---- | C] () -- C:\Users\user\Desktop\Social Bookmarking Automation Software Blog Comment Software.LNK
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
- [2012/04/20 14:42:40 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
- [2012/04/17 23:19:44 | 000,001,060 | ---- | C] () -- C:\Users\user\Desktop\Media Player Classic.lnk
- [2012/04/17 23:19:42 | 000,421,888 | ---- | C] () -- C:\Windows\System32\ac3filter.acm
- [2012/04/17 23:19:02 | 000,000,937 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
- [2012/04/17 23:19:02 | 000,000,913 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
- [2012/04/17 23:16:55 | 000,001,208 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
- [2012/04/17 23:15:53 | 000,002,503 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
- [2012/04/17 23:15:53 | 000,002,491 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
- [2012/04/17 23:15:53 | 000,002,479 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
- [2012/04/17 23:15:04 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
- [2012/04/17 23:14:19 | 000,001,048 | ---- | C] () -- C:\Users\user\Desktop\Maxthon 3.lnk
- [2012/04/17 23:12:58 | 000,001,097 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam.lnk
- [2012/04/17 23:12:58 | 000,001,073 | ---- | C] () -- C:\Users\user\Desktop\ManyCam.lnk
- [2012/04/17 23:12:23 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
- [2012/04/17 23:11:06 | 000,001,923 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
- [2012/04/17 23:09:27 | 000,001,035 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Geany.lnk
- [2012/04/17 23:09:27 | 000,001,011 | ---- | C] () -- C:\Users\Public\Desktop\Geany.lnk
- [2012/04/17 23:09:13 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
- [2012/04/17 23:09:13 | 000,001,088 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
- [2012/04/17 23:08:45 | 000,001,991 | ---- | C] () -- C:\Users\user\Desktop\SPEEDbit Video Downloader.lnk
- [2012/04/17 23:08:45 | 000,001,614 | ---- | C] () -- C:\Users\user\Desktop\My Video Downloads .lnk
- [2012/04/17 23:08:20 | 000,000,953 | ---- | C] () -- C:\Users\user\Desktop\DVD Shrink 3.2.lnk
- [2012/04/17 23:07:53 | 000,001,388 | ---- | C] () -- C:\Users\user\Desktop\My DAP Downloads.lnk
- [2012/04/17 23:07:53 | 000,000,893 | ---- | C] () -- C:\Users\user\Desktop\Download Accelerator Plus (DAP).lnk
- [2012/04/17 23:05:06 | 000,109,216 | ---- | C] () -- C:\Windows\System32\EasyHook64.dll
- [2012/04/17 23:05:06 | 000,084,480 | ---- | C] () -- C:\Windows\System32\EasyHook32.dll
- [2012/04/17 23:04:39 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2012/04/17 23:04:22 | 000,002,072 | ---- | C] () -- C:\Users\Public\Desktop\MP3 Downloader.lnk
- [2012/04/17 23:04:22 | 000,002,068 | ---- | C] () -- C:\Users\Public\Desktop\Video Search.lnk
- [2012/04/17 23:04:21 | 000,001,144 | ---- | C] () -- C:\Users\Public\Desktop\aTube Catcher.lnk
- [2012/04/17 23:02:56 | 000,000,909 | ---- | C] () -- C:\Users\Public\Desktop\Ares.lnk
- [2012/04/17 23:02:42 | 000,001,787 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
- [2012/04/17 23:02:41 | 000,001,775 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
- [2012/04/17 22:54:32 | 000,002,306 | ---- | C] () -- C:\Users\user\Desktop\Google Chrome.lnk
- [2012/04/17 22:47:20 | 000,001,074 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA.job
- [2012/04/17 22:47:20 | 000,001,022 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core.job
- [2012/04/17 22:43:49 | 000,001,407 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2012/04/12 13:31:59 | 000,001,413 | ---- | C] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
- [2012/04/12 13:11:26 | 000,000,290 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
- [2012/04/12 13:11:26 | 000,000,272 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
- [2012/04/12 13:06:54 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
- [2012/04/12 13:06:48 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
- [2012/01/31 18:15:44 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
- [2012/01/31 18:15:42 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
- [2012/01/31 18:15:42 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
- [2012/01/31 18:15:42 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
- [2012/01/31 18:15:42 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
- [color=#E56717]========== LOP Check ==========[/color]
- [2012/04/23 14:06:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\GetRightToGo
- [2012/04/20 14:30:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ManyCam
- [2012/04/17 23:14:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Maxthon3
- [2012/04/17 23:04:33 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenCandy
- [2012/04/17 23:02:44 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Opera
- [2012/04/20 14:31:23 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Samsung
- [2012/05/07 12:31:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\uTorrent
- [2009/07/14 01:53:46 | 000,009,320 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2009/06/10 18:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
- [2012/05/03 23:00:32 | 000,015,088 | ---- | M] () -- C:\ComboFix.txt
- [2009/06/10 18:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
- [2012/05/07 12:26:06 | 1073,741,824 | -HS- | M] () -- C:\pagefile.sys
- [2012/04/29 15:57:38 | 000,000,361 | ---- | M] () -- C:\rkill.log
- [2012/05/03 22:32:35 | 000,003,544 | ---- | M] () -- C:\TDSSKiller.2.7.34.0_03.05.2012_22.32.24_log.txt
- [2012/05/03 22:35:54 | 000,111,990 | ---- | M] () -- C:\TDSSKiller.2.7.34.0_03.05.2012_22.32.48_log.txt
- [2012/05/07 12:17:26 | 000,112,344 | ---- | M] () -- C:\TDSSKiller.2.7.34.0_07.05.2012_12.11.57_log.txt
- [color=#A23BEC]< %systemdrive%\drivers\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\drivers\*.* /90 >[/color]
- [2012/02/17 01:14:08 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\rdpwd.sys
- [2012/02/17 01:13:22 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\tdtcp.sys
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [2009/07/14 01:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
- [color=#A23BEC]< %LOCALAPPDATA%\*.exe >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.txt >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.ini >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.dll >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.dat >[/color]
- [2012/04/17 22:46:51 | 000,057,560 | ---- | M] () -- C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.txt >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.ini >[/color]
- [2012/04/12 13:11:26 | 000,000,020 | -HS- | M] () -- C:\Users\user\ntuser.ini
- [color=#A23BEC]< %USERPROFILE%\*.dll >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.dat /30 >[/color]
- [2012/05/07 12:32:42 | 002,621,440 | -HS- | M] () -- C:\Users\user\NTUSER.DAT
- [color=#A23BEC]< %appdata%\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\tasks\*.* >[/color]
- [2012/04/17 22:47:20 | 000,003,650 | ---- | M] () -- C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core
- [2012/04/17 22:47:20 | 000,004,046 | ---- | M] () -- C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA
- [color=#A23BEC]< %windir%\tasks\*.* >[/color]
- [2012/05/03 22:52:17 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core.job
- [2012/05/03 23:01:28 | 000,001,074 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA.job
- [2012/05/07 12:26:15 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
- [2009/07/14 01:53:46 | 000,009,320 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
- [color=#A23BEC]< C:\Users\user\AppData\Roaming\*.* /10 /s >[/color]
- [2012/05/03 22:32:27 | 000,002,390 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Preferences\com.apple.Safari.plist
- [2012/05/03 22:28:19 | 000,005,472 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\Bookmarks.plist
- [2012/05/03 22:28:28 | 000,019,555 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\Configurations.plist.signed
- [2012/05/03 22:32:19 | 000,000,449 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\History.plist
- [2012/05/03 22:32:37 | 000,001,118 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\LastSession.plist
- [2012/05/03 22:28:41 | 000,000,822 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\TopSites.plist
- [2012/05/03 22:32:37 | 000,001,406 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\Cookies\Cookies.binarycookies
- [2012/05/03 22:30:10 | 000,001,023 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\PubSub\Clients.plist
- [2012/05/03 22:31:43 | 000,123,904 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\PubSub\Database\Database.sqlite3
- [2012/05/03 22:31:40 | 000,050,091 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\PubSub\Feeds\98faf8d5aa51181d8bc7cd3a329798a89e67d2b2.xml
- [2012/05/07 12:17:17 | 000,000,037 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LQ9PD5YC\mail.google.com\wakeup.sol
- [2012/05/07 12:18:15 | 000,000,068 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LQ9PD5YC\static.anonymousdmp.com\pus.sol
- [2012/05/07 12:18:15 | 000,000,403 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
- [2012/05/07 12:17:17 | 000,000,085 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mail.google.com\settings.sol
- [2012/05/07 12:18:15 | 000,000,093 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.anonymousdmp.com\settings.sol
- [2012/05/07 12:25:38 | 000,182,059 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Bear Mask.mce
- [2012/05/07 12:25:38 | 000,116,641 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Cow Mask.mce
- [2012/05/07 12:25:38 | 000,165,606 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Frog Mask.mce
- [2012/05/07 12:25:38 | 000,140,218 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Rabbit Mask.mce
- [2012/05/07 12:25:38 | 000,182,457 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Santa Mask.mce
- [2012/05/07 12:25:38 | 000,165,891 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\Canadian Flag.mce
- [2012/05/07 12:25:38 | 000,139,185 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\French Flag.mce
- [2012/05/07 12:25:38 | 000,138,619 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\German Flag.mce
- [2012/05/07 12:25:38 | 000,152,862 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\Italian Flag.mce
- [2012/05/07 12:25:38 | 000,302,579 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\UK Flag.mce
- [2012/05/07 12:25:38 | 000,280,846 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\USA Flag.mce
- [2012/05/07 12:25:38 | 000,083,659 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Ballon.mce
- [2012/05/07 12:25:38 | 000,738,913 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Be Right Back.mce
- [2012/05/07 12:25:38 | 000,084,325 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Frog.mce
- [2012/05/07 12:25:38 | 000,026,872 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Gun.mce
- [2012/05/07 12:25:38 | 000,138,793 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Hearts.mce
- [2012/05/07 12:25:38 | 000,096,690 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Sun.mce
- [2012/05/07 12:25:38 | 000,072,412 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Bell.mce
- [2012/05/07 12:25:38 | 000,181,553 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Candle.mce
- [2012/05/07 12:25:38 | 000,113,940 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Candy Cane.mce
- [2012/05/07 12:25:38 | 000,155,707 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Christmas Tree.mce
- [2012/05/07 12:25:38 | 000,097,213 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Snow Man.mce
- [2012/05/07 12:25:38 | 000,001,907 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Profile.xml
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\Playlist.pst
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\PlaylistImages.pst
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\PlaylistMovies.pst
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\PlaylistSnapshots.pst
- [2012/05/07 12:25:38 | 000,000,850 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\Profile.xml
- [2012/04/29 15:27:19 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\354d1e6dd896821481eceb6b6d98e358_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/02 16:40:49 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\3c9fe8b3ea6152be71a4622b06bc9994_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/03 22:27:17 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\607f8bd8106e111b63b6aec6c55b27b6_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:26:26 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\6affdd226ed39a5fa79c3e10cbc8bea5_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:10:33 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\aa171eaf484a69d982d3688e6a5ad587_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/02 15:20:03 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\b7d3d6213566f49e3aa12073fd6622ea_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/02 21:45:42 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\cdc240ef9e6a171148ab9eb6cb634a5a_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/04/29 15:52:18 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\e4405e8fa71ed0bdba16a296444c26dc_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:02:41 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\f7d6794d1ba34a5f731c9b258e0cc114_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:32:39 | 000,032,768 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- [2012/05/07 12:11:22 | 000,000,704 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@ad.yieldmanager[2].txt
- [2012/04/29 15:28:22 | 000,000,100 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@adnetwork[1].txt
- [2012/05/02 21:48:44 | 000,000,404 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@adnxs[1].txt
- [2012/04/29 15:27:52 | 000,000,897 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@ask[2].txt
- [2012/05/02 21:48:43 | 000,000,192 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@atdmt[1].txt
- [2012/05/02 21:48:40 | 000,000,649 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@br.msn[2].txt
- [2012/04/29 15:32:59 | 000,000,419 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@brothersoftextreme.ourtoolbar[2].txt
- [2012/05/02 21:48:31 | 000,000,210 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@c.atdmt[2].txt
- [2012/05/02 21:48:36 | 000,000,071 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@c.br.msn[1].txt
- [2012/05/02 21:48:33 | 000,000,101 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@doubleclick[1].txt
- [2012/05/07 12:11:16 | 000,000,365 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@fileratings[1].txt
- [2012/05/02 21:48:42 | 000,000,113 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@ia.nspmotion[1].txt
- [2012/05/02 21:48:37 | 000,000,696 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@mfa.unilever.predicta[2].txt
- [2012/05/02 21:48:36 | 000,000,388 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@msn[2].txt
- [2012/05/02 21:48:42 | 000,000,109 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@nspmotion[2].txt
- [2012/05/02 15:20:53 | 000,000,297 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@pixer.meaningtool[2].txt
- [2012/05/02 21:48:37 | 000,000,110 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@predicta[1].txt
- [2012/04/29 15:32:14 | 000,000,365 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@printitgreen[3].txt
- [2012/04/29 15:28:23 | 000,000,099 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@quantserve[1].txt
- [2012/05/02 21:48:29 | 000,000,206 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@scorecardresearch[2].txt
- [2012/04/29 15:31:24 | 000,000,164 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@search.conduit[2].txt
- [2012/05/02 21:48:37 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@unilever.predicta[1].txt
- [2012/04/29 15:28:20 | 000,000,089 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@yahoo[1].txt
- [2012/04/29 15:32:52 | 000,032,768 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
- [2012/05/07 12:18:53 | 000,262,144 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- [2012/05/02 21:48:17 | 000,065,536 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
- [2012/05/03 22:31:10 | 000,000,429 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\Downloads.lnk
- [2012/05/07 12:15:41 | 000,000,357 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\Local Disk (C).lnk
- [2012/05/03 22:34:27 | 000,000,676 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\TDSSKiller.2.7.34.0_03.05.2012_22.32.24_log.txt.lnk
- [2012/05/07 12:13:59 | 000,000,676 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\TDSSKiller.2.7.34.0_03.05.2012_22.32.48_log.txt.lnk
- [2012/05/07 12:15:41 | 000,000,676 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\TDSSKiller.2.7.34.0_07.05.2012_12.11.57_log.txt.lnk
- [2012/05/03 22:31:09 | 000,000,482 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\tdsskiller.zip.lnk
- [2012/05/07 12:22:41 | 000,000,456 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\Untitled.png.lnk
- [2012/05/07 12:22:41 | 000,010,240 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
- [2012/05/07 12:14:39 | 000,008,704 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms
- [2012/05/07 12:15:41 | 000,007,680 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\918e0ecb43d17e23.automaticDestinations-ms
- [2012/05/07 12:22:41 | 000,003,072 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\b3f13480c2785ae.automaticDestinations-ms
- [2012/05/03 22:31:14 | 000,017,120 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms
- [2012/04/29 15:35:22 | 000,006,648 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms
- [2012/05/07 12:27:26 | 000,013,492 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms
- [2012/04/29 16:10:04 | 000,018,812 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms
- [2012/04/29 15:35:58 | 000,008,336 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms
- [2012/04/29 15:58:02 | 000,425,984 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\addons.sqlite
- [2012/04/29 15:58:02 | 000,131,616 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\addons.sqlite-journal
- [2012/04/29 16:00:03 | 000,013,339 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\blocklist.xml
- [2012/05/03 22:35:45 | 000,065,536 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\cert8.db
- [2012/05/03 22:35:29 | 000,098,304 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\chromeappsstore.sqlite
- [2012/05/03 22:35:16 | 000,000,186 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\compatibility.ini
- [2012/05/03 22:35:45 | 000,524,288 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\cookies.sqlite
- [2012/04/29 15:56:10 | 000,065,536 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\downloads.sqlite
- [2012/05/02 21:46:52 | 000,000,170 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\extensions.ini
- [2012/05/02 21:46:52 | 000,393,216 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\extensions.sqlite
- [2012/05/03 22:35:45 | 000,016,384 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\key3.db
- [2012/05/03 22:35:45 | 000,001,885 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\localstore.rdf
- [2012/05/02 21:48:26 | 010,485,760 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\places.sqlite
- [2012/05/03 22:47:26 | 000,878,949 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\prefs.js
- [2012/05/03 22:47:26 | 000,878,955 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\prefs.js.BAK
- [2012/04/29 15:53:54 | 000,008,550 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\search.json
- [2012/04/29 15:53:54 | 000,065,536 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\search.sqlite
- [2012/05/02 21:48:26 | 000,000,883 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\sessionstore.bak
- [2012/05/03 22:35:45 | 000,000,784 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\sessionstore.js
- [2012/05/03 22:35:20 | 000,000,154 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\urlclassifierkey3.txt
- [2012/05/03 22:47:26 | 000,000,326 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\user.js
- [2012/05/03 22:47:26 | 000,000,328 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\user.js.BAK
- [2012/05/02 21:48:26 | 000,003,199 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\bookmarkbackups\bookmarks-2012-05-02.json
- [2012/05/03 22:35:45 | 000,003,199 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\bookmarkbackups\bookmarks-2012-05-03.json
- [2012/05/03 22:28:08 | 000,001,440 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\autoupdate_response.xml
- [2012/05/03 22:31:16 | 000,000,862 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\cookies4.dat
- [2012/05/03 22:31:16 | 000,000,437 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\download.dat
- [2012/05/03 22:31:14 | 000,002,009 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\global_history.dat
- [2012/05/03 22:31:16 | 000,026,258 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opcacrt6.dat
- [2012/05/03 22:31:14 | 000,001,709 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\operaprefs.ini
- [2012/05/03 22:31:16 | 000,009,042 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opicacrt6.dat
- [2012/05/03 22:31:16 | 000,004,096 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\oprand.dat
- [2012/05/03 22:31:16 | 000,011,635 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opssl6.dat
- [2012/05/03 22:31:16 | 000,000,012 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\optrust.dat
- [2012/05/03 22:31:16 | 000,000,012 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opuntrust.dat
- [2012/05/03 22:27:49 | 000,000,431 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\tasks.xml
- [2012/05/03 22:31:14 | 000,000,291 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\tips.ini
- [2012/05/03 22:31:14 | 000,000,473 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\typed_history.xml
- [2012/05/03 22:31:16 | 000,000,012 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\vlink4.dat
- [2012/05/03 22:31:14 | 000,001,559 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\sessions\autosave.win
- [2012/05/03 22:31:14 | 000,001,559 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
- [2012/05/03 22:31:14 | 000,000,035 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\webserver\users.xml
- [2012/05/07 12:25:38 | 000,004,456 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dht.dat
- [2012/05/07 12:31:26 | 000,000,002 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dht_feed.dat
- [2012/05/07 12:25:38 | 000,000,002 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dht_feed.dat.old
- [2012/05/07 12:25:38 | 000,000,099 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\resume.dat
- [2012/05/07 12:20:52 | 000,000,099 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\resume.dat.old
- [2012/05/07 12:26:27 | 000,010,658 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\settings.dat
- [2012/05/07 12:26:26 | 000,010,658 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\settings.dat.old
- [2012/05/07 12:26:29 | 000,039,755 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dlimagecache\32F529521A3DEC709F97F761F192AABF29BDC408
- [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections >[/color]
- "DefaultConnectionSettings" = [Binary data over 100 bytes]
- "SavedLegacySettings" = [Binary data over 100 bytes]
- [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations >[/color]
- [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments >[/color]
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:553CA6CA
- < End of report >OTL logfile created on: 07/05/2012 12:29:31 - Run 4
- OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\user\Downloads
- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7601.17514)
- Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
- 1023,55 Mb Total Physical Memory | 667,73 Mb Available Physical Memory | 65,24% Memory free
- 2,00 Gb Paging File | 1,43 Gb Available in Paging File | 71,50% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
- Drive C: | 29,90 Gb Total Space | 21,69 Gb Free Space | 72,54% Space Free | Partition Type: NTFS
- Drive D: | 43,37 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
- Computer Name: USER-PC | User Name: user | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user
- Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012/04/23 19:27:36 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\user\Downloads\OTL.exe
- PRC - [2012/04/17 23:20:10 | 000,738,168 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
- PRC - [2012/04/17 23:04:56 | 002,980,016 | ---- | M] (SpeedBit Ltd.) -- C:\Program Files\DAP\DAP.exe
- PRC - [2012/02/03 17:50:18 | 003,508,624 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
- PRC - [2012/02/02 12:55:22 | 003,209,216 | ---- | M] (Ares Development Group) -- C:\Program Files\Ares\Ares.exe
- PRC - [2011/12/12 01:33:46 | 001,760,328 | ---- | M] (ManyCam LLC) -- C:\Program Files\ManyCam\Bin\ManyCam.exe
- PRC - [2010/11/20 18:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
- PRC - [2010/11/20 18:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012/04/17 23:04:54 | 000,053,248 | ---- | M] () -- C:\Program Files\DAP\zlib.dll
- MOD - [2011/12/12 01:33:52 | 000,498,760 | ---- | M] () -- C:\Program Files\ManyCam\Bin\cximagecrt.dll
- MOD - [2011/12/12 01:33:48 | 000,123,976 | ---- | M] () -- C:\Program Files\ManyCam\Bin\CrashRpt.dll
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV - [2009/07/13 22:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
- SRV - [2009/07/13 22:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\user\AppData\Local\Temp\catchme.sys -- (catchme)
- DRV - [2011/12/19 09:48:24 | 000,227,632 | ---- | M] (Oracle Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\VBoxSF.sys -- (VBoxSF)
- DRV - [2011/12/19 09:48:24 | 000,107,312 | ---- | M] (Oracle Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\VBoxGuest.sys -- (VBoxGuest)
- DRV - [2011/12/19 09:48:22 | 000,085,808 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxMouse.sys -- (VBoxMouse)
- DRV - [2011/12/19 09:48:20 | 000,104,240 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxVideo.sys -- (VBoxVideo)
- DRV - [2011/09/29 04:04:22 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ManyCam.sys -- (ManyCam)
- DRV - [2010/11/20 18:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV - [2010/11/20 18:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV - [2009/07/13 20:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKLM\..\SearchScopes,DefaultScope =
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 12 2E 19 B7 04 1D CD 01 [binary data]
- IE - HKCU\..\SearchScopes,DefaultScope =
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultengine: "Google"
- FF - prefs.js..browser.search.defaultenginename: "Google"
- FF - prefs.js..browser.search.defaultthis.engineName: ""
- FF - prefs.js..browser.search.defaulturl: ""
- FF - prefs.js..browser.search.order.1: ""
- FF - prefs.js..browser.search.selectedEngine: ""
- FF - prefs.js..network.proxy.type: 2
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\user\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\user\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/17 23:09:12 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
- [2012/04/20 14:51:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Extensions
- [2012/04/29 15:58:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\extensions
- () (No name found) -- C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\S3XQ4PCB.DEFAULT\EXTENSIONS\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}.XPI
- [2012/01/29 13:34:12 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
- [2012/01/29 11:20:59 | 000,001,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\buscape.xml
- [2012/01/29 11:20:59 | 000,001,212 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mercadolivre.xml
- [2012/01/29 10:55:01 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
- [2012/01/29 11:20:59 | 000,001,168 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-br.xml
- [2012/01/29 11:20:59 | 000,000,952 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-br.xml
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: Google (Enabled)
- CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
- CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
- CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
- CHR - plugin: registryAccess (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaodnbkkemkkaekocofmphoadofkdh\7.14.1.0_0\background/registryAccess.dll
- CHR - plugin: Chrome SVD extension (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcpfkccckpeeghiklnhienllljccglb\2.0.5_0\lib/npdownloaderchrome.dll
- CHR - plugin: Chrome DAP extension (Enabled) = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb\2.0.10_0\lib/npdapchrome.dll
- CHR - plugin: Google Update (Enabled) = C:\Users\user\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
- O1 HOSTS File: ([2012/05/03 22:45:08 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 localhost
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
- O2 - BHO: (SBCONVERT Class) - {92A9ACF4-9333-43AE-9698-DB283326F87F} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
- O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\Grabber.dll (SpeedBit)
- O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
- O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll ()
- O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
- O4 - HKCU..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
- O4 - HKCU..\Run: [DownloadAccelerator] C:\Program Files\DAP\DAP.EXE (SpeedBit Ltd.)
- O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
- O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
- O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
- O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
- O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
- O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
- O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 200.222.123.101 192.168.0.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22C13D65-2EBE-49EA-BEAE-913F2420F62D}: DhcpNameServer = 200.222.123.101 192.168.0.1
- O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2009/06/10 18:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
- O32 - AutoRun File - [2011/08/16 17:00:22 | 000,000,647 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
- O32 - AutoRun File - [2011/12/19 10:02:20 | 000,006,966 | R--- | M] () - D:\autorun.sh -- [ CDFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = ComFile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- NetSvcs: FastUserSwitchingCompatibility - File not found
- NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
- NetSvcs: Nla - File not found
- NetSvcs: Ntmssvc - File not found
- NetSvcs: NWCWorkstation - File not found
- NetSvcs: Nwsapagent - File not found
- NetSvcs: SRService - File not found
- NetSvcs: WmdmPmSp - File not found
- NetSvcs: LogonHours - File not found
- NetSvcs: PCAudit - File not found
- NetSvcs: helpsvc - File not found
- NetSvcs: uploadmgr - File not found
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012/05/03 23:00:36 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
- [2012/05/03 23:00:34 | 000,000,000 | ---D | C] -- C:\Windows\temp
- [2012/05/03 22:37:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
- [2012/05/03 22:37:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
- [2012/05/03 22:37:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
- [2012/05/03 22:37:43 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
- [2012/05/03 22:37:40 | 000,000,000 | ---D | C] -- C:\Qoobox
- [2012/05/03 22:28:05 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Apple Computer
- [2012/05/03 22:28:03 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Apple Computer
- [2012/04/29 15:45:19 | 000,000,000 | ---D | C] -- C:\_OTL
- [2012/04/23 14:05:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\GetRightToGo
- [2012/04/23 14:05:47 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Downloads
- [2012/04/20 16:32:39 | 000,000,000 | ---D | C] -- C:\Program Files\Social Bookmarking Automation Software Blog Comment Software
- [2012/04/20 16:25:31 | 001,140,472 | ---- | C] (Infragistics, Inc.) -- C:\Windows\System32\IGUltraGrid20.ocx
- [2012/04/20 16:25:31 | 000,361,256 | ---- | C] (Namtuk.com) -- C:\Windows\System32\MyCommandbutton.ocx
- [2012/04/20 16:25:31 | 000,349,968 | ---- | C] (Infragistics, Inc.) -- C:\Windows\System32\IGThreed40.ocx
- [2012/04/20 16:25:31 | 000,246,304 | ---- | C] (Namtuk.com) -- C:\Windows\System32\MyFramePanel.ocx
- [2012/04/20 16:25:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftwareDepo.com
- [2012/04/20 16:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\SoftwareDepo.com
- [2012/04/20 16:20:05 | 000,000,000 | ---D | C] -- C:\Config.Msi
- [2012/04/20 16:14:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
- [2012/04/20 16:14:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
- [2012/04/20 16:13:45 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
- [2012/04/20 16:13:45 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
- [2012/04/20 16:13:45 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
- [2012/04/20 16:13:45 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
- [2012/04/20 16:13:22 | 000,000,000 | ---D | C] -- C:\Program Files\Java
- [2012/04/20 15:36:01 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\WinRAR
- [2012/04/20 15:35:51 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
- [2012/04/20 15:35:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
- [2012/04/20 15:35:46 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
- [2012/04/20 15:13:52 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ElevatedDiagnostics
- [2012/04/20 15:07:10 | 000,000,000 | ---D | C] -- C:\temp
- [2012/04/20 14:51:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Mozilla
- [2012/04/20 14:51:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Mozilla
- [2012/04/20 14:31:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Samsung
- [2012/04/20 14:31:23 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Samsung
- [2012/04/20 14:31:11 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\samsung
- [2012/04/17 23:20:27 | 000,000,000 | ---D | C] -- C:\1d628acdf504dd45e237e0148547
- [2012/04/17 23:19:41 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XP Codec Pack 2.5.1
- [2012/04/17 23:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XP Codec Pack 2.5.1
- [2012/04/17 23:19:39 | 000,000,000 | ---D | C] -- C:\Program Files\XP Codec Pack
- [2012/04/17 23:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
- [2012/04/17 23:19:25 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
- [2012/04/17 23:19:02 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
- [2012/04/17 23:18:03 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Macromedia
- [2012/04/17 23:18:03 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Adobe
- [2012/04/17 23:17:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\uTorrent
- [2012/04/17 23:16:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
- [2012/04/17 23:16:33 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
- [2012/04/17 23:15:41 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
- [2012/04/17 23:15:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
- [2012/04/17 23:15:07 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
- [2012/04/17 23:15:05 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Apple
- [2012/04/17 23:15:04 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
- [2012/04/17 23:15:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
- [2012/04/17 23:14:19 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxthon
- [2012/04/17 23:14:17 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Maxthon3
- [2012/04/17 23:14:09 | 000,000,000 | ---D | C] -- C:\Program Files\Maxthon3
- [2012/04/17 23:13:39 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\APN
- [2012/04/17 23:12:58 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ManyCam
- [2012/04/17 23:12:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ManyCam
- [2012/04/17 23:12:46 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\ManyCam
- [2012/04/17 23:12:42 | 000,000,000 | ---D | C] -- C:\Program Files\ManyCam
- [2012/04/17 23:11:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
- [2012/04/17 23:11:03 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\System32\Redemption.dll
- [2012/04/17 23:10:55 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\System32\dgderapi.dll
- [2012/04/17 23:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
- [2012/04/17 23:10:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
- [2012/04/17 23:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
- [2012/04/17 23:09:53 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Downloaded Installations
- [2012/04/17 23:09:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geany
- [2012/04/17 23:09:25 | 000,000,000 | ---D | C] -- C:\Program Files\Geany
- [2012/04/17 23:09:12 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
- [2012/04/17 23:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SPEEDbit Video Downloader
- [2012/04/17 23:08:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Speedbit
- [2012/04/17 23:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\SPEEDbit Video Downloader
- [2012/04/17 23:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\SearchPredict
- [2012/04/17 23:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink
- [2012/04/17 23:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\DVD Shrink
- [2012/04/17 23:08:20 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
- [2012/04/17 23:05:11 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
- [2012/04/17 23:05:08 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit
- [2012/04/17 23:05:08 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\My DAP Downloads
- [2012/04/17 23:05:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Download Accelerator Plus (DAP)
- [2012/04/17 23:05:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeedBit
- [2012/04/17 23:05:05 | 000,000,000 | ---D | C] -- C:\Program Files\DAP
- [2012/04/17 23:04:54 | 000,172,032 | ---- | C] (Jin Hui E-mail: jinhui@jcomsoft.com Web: http://www.jcomsoft.com) -- C:\Windows\System32\AniGIF.ocx
- [2012/04/17 23:04:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
- [2012/04/17 23:04:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
- [2012/04/17 23:04:22 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\OpenCandy
- [2012/04/17 23:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
- [2012/04/17 23:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\DsNET Corp
- [2012/04/17 23:02:59 | 000,000,000 | ---D | C] -- C:\Users\user\Desktop\My Shared Folder
- [2012/04/17 23:02:58 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Ares
- [2012/04/17 23:02:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ares
- [2012/04/17 23:02:55 | 000,000,000 | ---D | C] -- C:\Program Files\Ares
- [2012/04/17 23:02:45 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Opera
- [2012/04/17 23:02:44 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Opera
- [2012/04/17 23:02:40 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
- [2012/04/17 23:00:45 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
- [2012/04/17 23:00:44 | 000,000,000 | ---D | C] -- C:\Program Files\Twitter
- [2012/04/17 23:00:16 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
- [2012/04/17 22:54:31 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
- [2012/04/17 22:47:19 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Google
- [2012/04/17 22:46:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Apps
- [2012/04/17 22:46:48 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Deployment
- [2012/04/17 22:41:38 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox Guest Additions
- [2012/04/17 22:39:11 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
- [2012/04/12 18:03:45 | 000,000,000 | ---D | C] -- C:\Windows\Panther
- [2012/04/12 13:31:56 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- [2012/04/12 13:31:56 | 000,000,000 | R--D | C] -- C:\Users\user\Searches
- [2012/04/12 13:31:56 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- [2012/04/12 13:31:55 | 000,000,000 | -H-D | C] -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
- [2012/04/12 13:31:39 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Identities
- [2012/04/12 13:24:55 | 000,000,000 | ---D | C] -- C:\found.000
- [2012/04/12 13:18:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
- [2012/04/12 13:11:38 | 000,000,000 | R--D | C] -- C:\Users\user\Contacts
- [2012/04/12 13:11:27 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\VirtualStore
- [2012/04/12 13:11:26 | 000,000,000 | --SD | C] -- C:\Users\user\AppData\Roaming\Microsoft
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Videos
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Saved Games
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Pictures
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Music
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Links
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Favorites
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Downloads
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Documents
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\Desktop
- [2012/04/12 13:11:26 | 000,000,000 | R--D | C] -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\Temporary Internet Files
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Templates
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Start Menu
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\SendTo
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Recent
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\PrintHood
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\NetHood
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Videos
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Pictures
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Music
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\My Documents
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Local Settings
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\History
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Cookies
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\Application Data
- [2012/04/12 13:11:26 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\Application Data
- [2012/04/12 13:11:26 | 000,000,000 | -H-D | C] -- C:\Users\user\AppData
- [2012/04/12 13:11:26 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Temp
- [2012/04/12 13:11:26 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Microsoft
- [2012/04/12 13:11:26 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Media Center Programs
- [2012/04/12 13:11:10 | 000,000,000 | ---D | C] -- C:\Recovery
- [2012/04/12 13:05:21 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
- [2012/04/12 13:04:19 | 000,000,000 | -HSD | C] -- C:\System Volume Information
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012/05/07 12:31:15 | 000,028,320 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2012/05/07 12:31:15 | 000,028,320 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2012/05/07 12:26:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012/05/07 12:22:41 | 000,014,386 | ---- | M] () -- C:\Users\user\Desktop\Untitled.png
- [2012/05/03 23:01:28 | 000,001,074 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA.job
- [2012/05/03 22:52:17 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core.job
- [2012/05/03 22:45:08 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
- [2012/05/03 22:31:46 | 000,088,280 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
- [2012/05/03 22:31:09 | 000,001,388 | ---- | M] () -- C:\Users\user\Desktop\My DAP Downloads.lnk
- [2012/04/25 18:55:35 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
- [2012/04/25 18:55:35 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
- [2012/04/20 16:20:24 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
- [2012/04/20 16:13:24 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
- [2012/04/20 16:13:24 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
- [2012/04/20 16:13:24 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
- [2012/04/20 16:13:23 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
- [2012/04/17 23:20:10 | 000,000,937 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
- [2012/04/17 23:20:10 | 000,000,913 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
- [2012/04/17 23:19:44 | 000,001,060 | ---- | M] () -- C:\Users\user\Desktop\Media Player Classic.lnk
- [2012/04/17 23:16:55 | 000,001,208 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
- [2012/04/17 23:15:53 | 000,002,503 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
- [2012/04/17 23:15:53 | 000,002,479 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
- [2012/04/17 23:14:19 | 000,001,048 | ---- | M] () -- C:\Users\user\Desktop\Maxthon 3.lnk
- [2012/04/17 23:12:58 | 000,001,097 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam.lnk
- [2012/04/17 23:12:58 | 000,001,073 | ---- | M] () -- C:\Users\user\Desktop\ManyCam.lnk
- [2012/04/17 23:12:23 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
- [2012/04/17 23:11:06 | 000,001,923 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
- [2012/04/17 23:09:27 | 000,001,035 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Geany.lnk
- [2012/04/17 23:09:27 | 000,001,011 | ---- | M] () -- C:\Users\Public\Desktop\Geany.lnk
- [2012/04/17 23:09:13 | 000,001,088 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
- [2012/04/17 23:08:45 | 000,001,991 | ---- | M] () -- C:\Users\user\Desktop\SPEEDbit Video Downloader.lnk
- [2012/04/17 23:08:45 | 000,001,614 | ---- | M] () -- C:\Users\user\Desktop\My Video Downloads .lnk
- [2012/04/17 23:08:20 | 000,000,953 | ---- | M] () -- C:\Users\user\Desktop\DVD Shrink 3.2.lnk
- [2012/04/17 23:07:53 | 000,000,893 | ---- | M] () -- C:\Users\user\Desktop\Download Accelerator Plus (DAP).lnk
- [2012/04/17 23:04:56 | 000,109,216 | ---- | M] () -- C:\Windows\System32\EasyHook64.dll
- [2012/04/17 23:04:56 | 000,084,480 | ---- | M] () -- C:\Windows\System32\EasyHook32.dll
- [2012/04/17 23:04:54 | 000,172,032 | ---- | M] (Jin Hui E-mail: jinhui@jcomsoft.com Web: http://www.jcomsoft.com) -- C:\Windows\System32\AniGIF.ocx
- [2012/04/17 23:04:39 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2012/04/17 23:04:22 | 000,002,072 | ---- | M] () -- C:\Users\Public\Desktop\MP3 Downloader.lnk
- [2012/04/17 23:04:22 | 000,002,068 | ---- | M] () -- C:\Users\Public\Desktop\Video Search.lnk
- [2012/04/17 23:04:21 | 000,001,144 | ---- | M] () -- C:\Users\Public\Desktop\aTube Catcher.lnk
- [2012/04/17 23:02:56 | 000,000,909 | ---- | M] () -- C:\Users\Public\Desktop\Ares.lnk
- [2012/04/17 23:02:41 | 000,001,775 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
- [2012/04/17 22:54:32 | 000,002,306 | ---- | M] () -- C:\Users\user\Desktop\Google Chrome.lnk
- [2012/04/17 22:43:49 | 000,001,407 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2012/04/12 13:09:42 | 000,265,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
- [2012/04/12 13:07:01 | 000,115,640 | ---- | M] () -- C:\Windows\System32\license.rtf
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012/05/07 12:22:41 | 000,014,386 | ---- | C] () -- C:\Users\user\Desktop\Untitled.png
- [2012/05/03 22:37:46 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
- [2012/05/03 22:37:46 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
- [2012/05/03 22:37:46 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
- [2012/05/03 22:37:46 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
- [2012/05/03 22:37:46 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
- [2012/05/03 22:31:46 | 000,088,280 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
- [2012/04/23 14:13:42 | 000,001,576 | ---- | C] () -- C:\Users\user\Desktop\Online Business Komplett Paket.LNK
- [2012/04/20 16:32:39 | 000,000,920 | ---- | C] () -- C:\Users\user\Desktop\Social Bookmarking Automation Software Blog Comment Software.LNK
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
- [2012/04/20 14:42:40 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
- [2012/04/17 23:19:44 | 000,001,060 | ---- | C] () -- C:\Users\user\Desktop\Media Player Classic.lnk
- [2012/04/17 23:19:42 | 000,421,888 | ---- | C] () -- C:\Windows\System32\ac3filter.acm
- [2012/04/17 23:19:02 | 000,000,937 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
- [2012/04/17 23:19:02 | 000,000,913 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
- [2012/04/17 23:16:55 | 000,001,208 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
- [2012/04/17 23:15:53 | 000,002,503 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
- [2012/04/17 23:15:53 | 000,002,491 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
- [2012/04/17 23:15:53 | 000,002,479 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
- [2012/04/17 23:15:04 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
- [2012/04/17 23:14:19 | 000,001,048 | ---- | C] () -- C:\Users\user\Desktop\Maxthon 3.lnk
- [2012/04/17 23:12:58 | 000,001,097 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam.lnk
- [2012/04/17 23:12:58 | 000,001,073 | ---- | C] () -- C:\Users\user\Desktop\ManyCam.lnk
- [2012/04/17 23:12:23 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
- [2012/04/17 23:11:06 | 000,001,923 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
- [2012/04/17 23:09:27 | 000,001,035 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Geany.lnk
- [2012/04/17 23:09:27 | 000,001,011 | ---- | C] () -- C:\Users\Public\Desktop\Geany.lnk
- [2012/04/17 23:09:13 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
- [2012/04/17 23:09:13 | 000,001,088 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
- [2012/04/17 23:08:45 | 000,001,991 | ---- | C] () -- C:\Users\user\Desktop\SPEEDbit Video Downloader.lnk
- [2012/04/17 23:08:45 | 000,001,614 | ---- | C] () -- C:\Users\user\Desktop\My Video Downloads .lnk
- [2012/04/17 23:08:20 | 000,000,953 | ---- | C] () -- C:\Users\user\Desktop\DVD Shrink 3.2.lnk
- [2012/04/17 23:07:53 | 000,001,388 | ---- | C] () -- C:\Users\user\Desktop\My DAP Downloads.lnk
- [2012/04/17 23:07:53 | 000,000,893 | ---- | C] () -- C:\Users\user\Desktop\Download Accelerator Plus (DAP).lnk
- [2012/04/17 23:05:06 | 000,109,216 | ---- | C] () -- C:\Windows\System32\EasyHook64.dll
- [2012/04/17 23:05:06 | 000,084,480 | ---- | C] () -- C:\Windows\System32\EasyHook32.dll
- [2012/04/17 23:04:39 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2012/04/17 23:04:22 | 000,002,072 | ---- | C] () -- C:\Users\Public\Desktop\MP3 Downloader.lnk
- [2012/04/17 23:04:22 | 000,002,068 | ---- | C] () -- C:\Users\Public\Desktop\Video Search.lnk
- [2012/04/17 23:04:21 | 000,001,144 | ---- | C] () -- C:\Users\Public\Desktop\aTube Catcher.lnk
- [2012/04/17 23:02:56 | 000,000,909 | ---- | C] () -- C:\Users\Public\Desktop\Ares.lnk
- [2012/04/17 23:02:42 | 000,001,787 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
- [2012/04/17 23:02:41 | 000,001,775 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
- [2012/04/17 22:54:32 | 000,002,306 | ---- | C] () -- C:\Users\user\Desktop\Google Chrome.lnk
- [2012/04/17 22:47:20 | 000,001,074 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA.job
- [2012/04/17 22:47:20 | 000,001,022 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core.job
- [2012/04/17 22:43:49 | 000,001,407 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2012/04/12 13:31:59 | 000,001,413 | ---- | C] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
- [2012/04/12 13:11:26 | 000,000,290 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
- [2012/04/12 13:11:26 | 000,000,272 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
- [2012/04/12 13:06:54 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
- [2012/04/12 13:06:48 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
- [2012/01/31 18:15:44 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
- [2012/01/31 18:15:42 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
- [2012/01/31 18:15:42 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
- [2012/01/31 18:15:42 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
- [2012/01/31 18:15:42 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
- [color=#E56717]========== LOP Check ==========[/color]
- [2012/04/23 14:06:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\GetRightToGo
- [2012/04/20 14:30:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ManyCam
- [2012/04/17 23:14:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Maxthon3
- [2012/04/17 23:04:33 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenCandy
- [2012/04/17 23:02:44 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Opera
- [2012/04/20 14:31:23 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Samsung
- [2012/05/07 12:31:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\uTorrent
- [2009/07/14 01:53:46 | 000,009,320 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2009/06/10 18:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
- [2012/05/03 23:00:32 | 000,015,088 | ---- | M] () -- C:\ComboFix.txt
- [2009/06/10 18:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
- [2012/04/20 16:20:31 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
- [2012/05/07 12:26:06 | 1073,741,824 | -HS- | M] () -- C:\pagefile.sys
- [2012/04/29 15:57:38 | 000,000,361 | ---- | M] () -- C:\rkill.log
- [2012/05/03 22:32:35 | 000,003,544 | ---- | M] () -- C:\TDSSKiller.2.7.34.0_03.05.2012_22.32.24_log.txt
- [2012/05/03 22:35:54 | 000,111,990 | ---- | M] () -- C:\TDSSKiller.2.7.34.0_03.05.2012_22.32.48_log.txt
- [2012/05/07 12:17:26 | 000,112,344 | ---- | M] () -- C:\TDSSKiller.2.7.34.0_07.05.2012_12.11.57_log.txt
- [color=#A23BEC]< %systemdrive%\drivers\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\drivers\*.* /90 >[/color]
- [2012/02/17 01:14:08 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\rdpwd.sys
- [2012/02/17 01:13:22 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\tdtcp.sys
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [2009/07/14 01:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
- [color=#A23BEC]< %LOCALAPPDATA%\*.exe >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.txt >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.ini >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.dll >[/color]
- [color=#A23BEC]< %LOCALAPPDATA%\*.dat >[/color]
- [2012/04/17 22:46:51 | 000,057,560 | ---- | M] () -- C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.txt >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.ini >[/color]
- [2012/04/12 13:11:26 | 000,000,020 | -HS- | M] () -- C:\Users\user\ntuser.ini
- [color=#A23BEC]< %USERPROFILE%\*.dll >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.dat /30 >[/color]
- [2012/05/07 12:32:42 | 002,621,440 | -HS- | M] () -- C:\Users\user\NTUSER.DAT
- [color=#A23BEC]< %appdata%\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\tasks\*.* >[/color]
- [2012/04/17 22:47:20 | 000,003,650 | ---- | M] () -- C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core
- [2012/04/17 22:47:20 | 000,004,046 | ---- | M] () -- C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA
- [color=#A23BEC]< %windir%\tasks\*.* >[/color]
- [2012/05/03 22:52:17 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001Core.job
- [2012/05/03 23:01:28 | 000,001,074 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-502584883-899378009-3667950772-1001UA.job
- [2012/05/07 12:26:15 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
- [2009/07/14 01:53:46 | 000,009,320 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
- [color=#A23BEC]< C:\Users\user\AppData\Roaming\*.* /10 /s >[/color]
- [2012/05/03 22:32:27 | 000,002,390 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Preferences\com.apple.Safari.plist
- [2012/05/03 22:28:19 | 000,005,472 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\Bookmarks.plist
- [2012/05/03 22:28:28 | 000,019,555 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\Configurations.plist.signed
- [2012/05/03 22:32:19 | 000,000,449 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\History.plist
- [2012/05/03 22:32:37 | 000,001,118 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\LastSession.plist
- [2012/05/03 22:28:41 | 000,000,822 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\TopSites.plist
- [2012/05/03 22:32:37 | 000,001,406 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\Cookies\Cookies.binarycookies
- [2012/05/03 22:30:10 | 000,001,023 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\PubSub\Clients.plist
- [2012/05/03 22:31:43 | 000,123,904 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\PubSub\Database\Database.sqlite3
- [2012/05/03 22:31:40 | 000,050,091 | ---- | M] () -- C:\Users\user\AppData\Roaming\Apple Computer\Safari\PubSub\Feeds\98faf8d5aa51181d8bc7cd3a329798a89e67d2b2.xml
- [2012/05/07 12:17:17 | 000,000,037 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LQ9PD5YC\mail.google.com\wakeup.sol
- [2012/05/07 12:18:15 | 000,000,068 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LQ9PD5YC\static.anonymousdmp.com\pus.sol
- [2012/05/07 12:18:15 | 000,000,403 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
- [2012/05/07 12:17:17 | 000,000,085 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mail.google.com\settings.sol
- [2012/05/07 12:18:15 | 000,000,093 | ---- | M] () -- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.anonymousdmp.com\settings.sol
- [2012/05/07 12:25:38 | 000,182,059 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Bear Mask.mce
- [2012/05/07 12:25:38 | 000,116,641 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Cow Mask.mce
- [2012/05/07 12:25:38 | 000,165,606 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Frog Mask.mce
- [2012/05/07 12:25:38 | 000,140,218 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Rabbit Mask.mce
- [2012/05/07 12:25:38 | 000,182,457 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Avatars\Santa Mask.mce
- [2012/05/07 12:25:38 | 000,165,891 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\Canadian Flag.mce
- [2012/05/07 12:25:38 | 000,139,185 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\French Flag.mce
- [2012/05/07 12:25:38 | 000,138,619 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\German Flag.mce
- [2012/05/07 12:25:38 | 000,152,862 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\Italian Flag.mce
- [2012/05/07 12:25:38 | 000,302,579 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\UK Flag.mce
- [2012/05/07 12:25:38 | 000,280,846 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Flags\USA Flag.mce
- [2012/05/07 12:25:38 | 000,083,659 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Ballon.mce
- [2012/05/07 12:25:38 | 000,738,913 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Be Right Back.mce
- [2012/05/07 12:25:38 | 000,084,325 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Frog.mce
- [2012/05/07 12:25:38 | 000,026,872 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Gun.mce
- [2012/05/07 12:25:38 | 000,138,793 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Hearts.mce
- [2012/05/07 12:25:38 | 000,096,690 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Fun\Sun.mce
- [2012/05/07 12:25:38 | 000,072,412 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Bell.mce
- [2012/05/07 12:25:38 | 000,181,553 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Candle.mce
- [2012/05/07 12:25:38 | 000,113,940 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Candy Cane.mce
- [2012/05/07 12:25:38 | 000,155,707 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Christmas Tree.mce
- [2012/05/07 12:25:38 | 000,097,213 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Effects\Objects\Holidays\Snow Man.mce
- [2012/05/07 12:25:38 | 000,001,907 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Profile.xml
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\Playlist.pst
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\PlaylistImages.pst
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\PlaylistMovies.pst
- [2012/05/07 12:25:38 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\PlaylistSnapshots.pst
- [2012/05/07 12:25:38 | 000,000,850 | ---- | M] () -- C:\Users\user\AppData\Roaming\ManyCam\Settings\Layer0\Profile.xml
- [2012/04/29 15:27:19 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\354d1e6dd896821481eceb6b6d98e358_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/02 16:40:49 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\3c9fe8b3ea6152be71a4622b06bc9994_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/03 22:27:17 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\607f8bd8106e111b63b6aec6c55b27b6_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:26:26 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\6affdd226ed39a5fa79c3e10cbc8bea5_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:10:33 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\aa171eaf484a69d982d3688e6a5ad587_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/02 15:20:03 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\b7d3d6213566f49e3aa12073fd6622ea_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/02 21:45:42 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\cdc240ef9e6a171148ab9eb6cb634a5a_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/04/29 15:52:18 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\e4405e8fa71ed0bdba16a296444c26dc_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:02:41 | 000,001,483 | --S- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-502584883-899378009-3667950772-1001\f7d6794d1ba34a5f731c9b258e0cc114_147c45ed-c645-4a42-a6f1-692c606382e3
- [2012/05/07 12:32:39 | 000,032,768 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- [2012/05/07 12:11:22 | 000,000,704 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@ad.yieldmanager[2].txt
- [2012/04/29 15:28:22 | 000,000,100 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@adnetwork[1].txt
- [2012/05/02 21:48:44 | 000,000,404 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@adnxs[1].txt
- [2012/04/29 15:27:52 | 000,000,897 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@ask[2].txt
- [2012/05/02 21:48:43 | 000,000,192 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@atdmt[1].txt
- [2012/05/02 21:48:40 | 000,000,649 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@br.msn[2].txt
- [2012/04/29 15:32:59 | 000,000,419 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@brothersoftextreme.ourtoolbar[2].txt
- [2012/05/02 21:48:31 | 000,000,210 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@c.atdmt[2].txt
- [2012/05/02 21:48:36 | 000,000,071 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@c.br.msn[1].txt
- [2012/05/02 21:48:33 | 000,000,101 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@doubleclick[1].txt
- [2012/05/07 12:11:16 | 000,000,365 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@fileratings[1].txt
- [2012/05/02 21:48:42 | 000,000,113 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@ia.nspmotion[1].txt
- [2012/05/02 21:48:37 | 000,000,696 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@mfa.unilever.predicta[2].txt
- [2012/05/02 21:48:36 | 000,000,388 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@msn[2].txt
- [2012/05/02 21:48:42 | 000,000,109 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@nspmotion[2].txt
- [2012/05/02 15:20:53 | 000,000,297 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@pixer.meaningtool[2].txt
- [2012/05/02 21:48:37 | 000,000,110 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@predicta[1].txt
- [2012/04/29 15:32:14 | 000,000,365 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@printitgreen[3].txt
- [2012/04/29 15:28:23 | 000,000,099 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@quantserve[1].txt
- [2012/05/02 21:48:29 | 000,000,206 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@scorecardresearch[2].txt
- [2012/04/29 15:31:24 | 000,000,164 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@search.conduit[2].txt
- [2012/05/02 21:48:37 | 000,000,202 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@unilever.predicta[1].txt
- [2012/04/29 15:28:20 | 000,000,089 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\user@yahoo[1].txt
- [2012/04/29 15:32:52 | 000,032,768 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
- [2012/05/07 12:18:53 | 000,262,144 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- [2012/05/02 21:48:17 | 000,065,536 | -HS- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
- [2012/05/03 22:31:10 | 000,000,429 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\Downloads.lnk
- [2012/05/07 12:15:41 | 000,000,357 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\Local Disk (C).lnk
- [2012/05/03 22:34:27 | 000,000,676 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\TDSSKiller.2.7.34.0_03.05.2012_22.32.24_log.txt.lnk
- [2012/05/07 12:13:59 | 000,000,676 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\TDSSKiller.2.7.34.0_03.05.2012_22.32.48_log.txt.lnk
- [2012/05/07 12:15:41 | 000,000,676 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\TDSSKiller.2.7.34.0_07.05.2012_12.11.57_log.txt.lnk
- [2012/05/03 22:31:09 | 000,000,482 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\tdsskiller.zip.lnk
- [2012/05/07 12:22:41 | 000,000,456 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\Untitled.png.lnk
- [2012/05/07 12:22:41 | 000,010,240 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
- [2012/05/07 12:14:39 | 000,008,704 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms
- [2012/05/07 12:15:41 | 000,007,680 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\918e0ecb43d17e23.automaticDestinations-ms
- [2012/05/07 12:22:41 | 000,003,072 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\b3f13480c2785ae.automaticDestinations-ms
- [2012/05/03 22:31:14 | 000,017,120 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms
- [2012/04/29 15:35:22 | 000,006,648 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms
- [2012/05/07 12:27:26 | 000,013,492 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms
- [2012/04/29 16:10:04 | 000,018,812 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms
- [2012/04/29 15:35:58 | 000,008,336 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms
- [2012/04/29 15:58:02 | 000,425,984 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\addons.sqlite
- [2012/04/29 15:58:02 | 000,131,616 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\addons.sqlite-journal
- [2012/04/29 16:00:03 | 000,013,339 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\blocklist.xml
- [2012/05/03 22:35:45 | 000,065,536 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\cert8.db
- [2012/05/03 22:35:29 | 000,098,304 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\chromeappsstore.sqlite
- [2012/05/03 22:35:16 | 000,000,186 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\compatibility.ini
- [2012/05/03 22:35:45 | 000,524,288 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\cookies.sqlite
- [2012/04/29 15:56:10 | 000,065,536 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\downloads.sqlite
- [2012/05/02 21:46:52 | 000,000,170 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\extensions.ini
- [2012/05/02 21:46:52 | 000,393,216 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\extensions.sqlite
- [2012/05/03 22:35:45 | 000,016,384 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\key3.db
- [2012/05/03 22:35:45 | 000,001,885 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\localstore.rdf
- [2012/05/02 21:48:26 | 010,485,760 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\places.sqlite
- [2012/05/03 22:47:26 | 000,878,949 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\prefs.js
- [2012/05/03 22:47:26 | 000,878,955 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\prefs.js.BAK
- [2012/04/29 15:53:54 | 000,008,550 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\search.json
- [2012/04/29 15:53:54 | 000,065,536 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\search.sqlite
- [2012/05/02 21:48:26 | 000,000,883 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\sessionstore.bak
- [2012/05/03 22:35:45 | 000,000,784 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\sessionstore.js
- [2012/05/03 22:35:20 | 000,000,154 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\urlclassifierkey3.txt
- [2012/05/03 22:47:26 | 000,000,326 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\user.js
- [2012/05/03 22:47:26 | 000,000,328 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\user.js.BAK
- [2012/05/02 21:48:26 | 000,003,199 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\bookmarkbackups\bookmarks-2012-05-02.json
- [2012/05/03 22:35:45 | 000,003,199 | ---- | M] () -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\s3xq4pcb.default\bookmarkbackups\bookmarks-2012-05-03.json
- [2012/05/03 22:28:08 | 000,001,440 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\autoupdate_response.xml
- [2012/05/03 22:31:16 | 000,000,862 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\cookies4.dat
- [2012/05/03 22:31:16 | 000,000,437 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\download.dat
- [2012/05/03 22:31:14 | 000,002,009 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\global_history.dat
- [2012/05/03 22:31:16 | 000,026,258 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opcacrt6.dat
- [2012/05/03 22:31:14 | 000,001,709 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\operaprefs.ini
- [2012/05/03 22:31:16 | 000,009,042 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opicacrt6.dat
- [2012/05/03 22:31:16 | 000,004,096 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\oprand.dat
- [2012/05/03 22:31:16 | 000,011,635 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opssl6.dat
- [2012/05/03 22:31:16 | 000,000,012 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\optrust.dat
- [2012/05/03 22:31:16 | 000,000,012 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\opuntrust.dat
- [2012/05/03 22:27:49 | 000,000,431 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\tasks.xml
- [2012/05/03 22:31:14 | 000,000,291 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\tips.ini
- [2012/05/03 22:31:14 | 000,000,473 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\typed_history.xml
- [2012/05/03 22:31:16 | 000,000,012 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\vlink4.dat
- [2012/05/03 22:31:14 | 000,001,559 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\sessions\autosave.win
- [2012/05/03 22:31:14 | 000,001,559 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
- [2012/05/03 22:31:14 | 000,000,035 | ---- | M] () -- C:\Users\user\AppData\Roaming\Opera\Opera\webserver\users.xml
- [2012/05/07 12:25:38 | 000,004,456 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dht.dat
- [2012/05/07 12:31:26 | 000,000,002 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dht_feed.dat
- [2012/05/07 12:25:38 | 000,000,002 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dht_feed.dat.old
- [2012/05/07 12:25:38 | 000,000,099 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\resume.dat
- [2012/05/07 12:20:52 | 000,000,099 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\resume.dat.old
- [2012/05/07 12:26:27 | 000,010,658 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\settings.dat
- [2012/05/07 12:26:26 | 000,010,658 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\settings.dat.old
- [2012/05/07 12:26:29 | 000,039,755 | ---- | M] () -- C:\Users\user\AppData\Roaming\uTorrent\dlimagecache\32F529521A3DEC709F97F761F192AABF29BDC408
- [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections >[/color]
- "DefaultConnectionSettings" = [Binary data over 100 bytes]
- "SavedLegacySettings" = [Binary data over 100 bytes]
- [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations >[/color]
- [color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments >[/color]
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:553CA6CA
- < End of report >