Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 21/03/2012 22:53:14 - Run 1
- OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\Gean\Desktop
- 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 9.0.8112.16421)
- Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
- 5,91 Gb Total Physical Memory | 3,71 Gb Available Physical Memory | 62,68% Memory free
- 11,83 Gb Paging File | 9,18 Gb Available in Paging File | 77,61% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 195,35 Gb Total Space | 122,70 Gb Free Space | 62,81% Space Free | Partition Type: NTFS
- Drive D: | 245,41 Gb Total Space | 214,39 Gb Free Space | 87,36% Space Free | Partition Type: NTFS
- Computer Name: GEAN-PC | User Name: Gean | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012/03/21 22:52:46 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Gean\Desktop\OTL.exe
- PRC - [2012/03/18 01:05:11 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- PRC - [2012/03/06 18:37:40 | 000,741,240 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
- PRC - [2012/01/03 10:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- PRC - [2011/11/30 13:28:56 | 001,550,496 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
- PRC - [2011/09/13 12:33:14 | 002,317,312 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
- PRC - [2010/12/20 23:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
- PRC - [2010/12/20 23:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- PRC - [2010/11/20 09:17:02 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
- PRC - [2010/07/19 16:26:00 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
- PRC - [2010/07/09 21:45:00 | 000,984,400 | ---- | M] (Virage Logic Corporation / Sonic Focus) -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
- PRC - [2009/12/15 15:39:38 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
- PRC - [2009/11/02 19:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
- PRC - [2009/06/15 22:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012/03/18 01:05:11 | 001,969,080 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
- MOD - [2012/02/21 16:40:53 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll
- MOD - [2012/02/21 16:40:25 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\02f7846cbc5c02a5dbf50fd34325eb61\PresentationFramework.ni.dll
- MOD - [2012/02/21 16:40:14 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f4b2424c1b32fbd11130482bb899b7ae\PresentationCore.ni.dll
- MOD - [2012/02/21 16:40:04 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll
- MOD - [2012/02/21 16:38:31 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll
- MOD - [2012/02/21 16:38:25 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll
- MOD - [2012/02/21 16:38:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll
- MOD - [2012/02/21 16:38:19 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll
- MOD - [2012/02/21 16:38:08 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
- MOD - [2012/02/21 16:38:03 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
- MOD - [2011/11/30 13:28:56 | 000,211,456 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
- MOD - [2011/09/13 12:33:14 | 001,163,264 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
- MOD - [2011/02/18 23:05:31 | 000,241,664 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_pt-BR_31bf3856ad364e35\PresentationFramework.resources.dll
- MOD - [2011/02/18 23:05:25 | 000,086,016 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\WindowsBase.resources\3.0.0.0_pt-BR_31bf3856ad364e35\WindowsBase.resources.dll
- MOD - [2010/11/12 20:35:07 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
- MOD - [2010/01/21 01:34:10 | 008,793,952 | ---- | M] () -- C:\PROGRA~2\MICROS~1\Office14\1033\GrooveIntlResource.dll
- MOD - [2010/01/09 20:18:18 | 004,254,560 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
- MOD - [2009/11/02 19:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
- MOD - [2009/11/02 19:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
- MOD - [2009/07/18 00:21:00 | 003,883,424 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2012/03/01 19:05:00 | 000,075,384 | ---- | M] (Bitdefender) [On_Demand | Running] -- C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe -- (SafeBox)
- SRV:[b]64bit:[/b] - [2012/03/01 19:04:11 | 001,955,080 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe -- (vsserv)
- SRV:[b]64bit:[/b] - [2012/01/23 18:41:02 | 000,062,512 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe -- (UPDATESRV)
- SRV:[b]64bit:[/b] - [2011/10/14 21:57:26 | 000,466,736 | ---- | M] (BitDefender) [On_Demand | Stopped] -- C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe -- (Update Server)
- SRV:[b]64bit:[/b] - [2011/03/03 21:57:58 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
- SRV:[b]64bit:[/b] - [2010/11/29 20:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost) Intel(R)
- SRV:[b]64bit:[/b] - [2010/09/22 22:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
- SRV:[b]64bit:[/b] - [2009/07/13 22:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
- SRV:[b]64bit:[/b] - [2009/07/13 22:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV - [2012/01/03 10:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
- SRV - [2010/12/20 23:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
- SRV - [2010/12/20 23:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
- SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
- SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
- SRV - [2009/12/15 15:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
- SRV - [2009/06/15 22:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
- SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2012/03/01 19:06:02 | 000,545,064 | ---- | M] (BitDefender) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\avckf.sys -- (avckf)
- DRV:[b]64bit:[/b] - [2012/03/01 19:04:21 | 000,690,872 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avc3.sys -- (avc3)
- DRV:[b]64bit:[/b] - [2011/11/25 13:00:36 | 000,258,736 | ---- | M] (BitDefender) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avchv.sys -- (avchv)
- DRV:[b]64bit:[/b] - [2011/11/17 15:38:34 | 000,079,952 | ---- | M] (BitDefender SRL) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bdsandbox.sys -- (bdsandbox)
- DRV:[b]64bit:[/b] - [2011/11/14 18:16:42 | 000,090,192 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys -- (BdfNdisf)
- DRV:[b]64bit:[/b] - [2011/11/14 18:16:38 | 000,103,504 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys -- (bdfwfpf)
- DRV:[b]64bit:[/b] - [2011/10/27 13:07:05 | 000,329,800 | ---- | M] (BitDefender S.R.L.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\trufos.sys -- (trufos)
- DRV:[b]64bit:[/b] - [2011/10/03 22:49:32 | 002,770,944 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
- DRV:[b]64bit:[/b] - [2011/08/31 18:53:22 | 012,306,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
- DRV:[b]64bit:[/b] - [2011/08/16 12:59:12 | 000,442,088 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\bdfsfltr.sys -- (bdfsfltr)
- DRV:[b]64bit:[/b] - [2011/04/26 00:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
- DRV:[b]64bit:[/b] - [2011/04/20 06:24:56 | 000,169,584 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
- DRV:[b]64bit:[/b] - [2011/04/12 18:18:08 | 000,142,632 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
- DRV:[b]64bit:[/b] - [2011/03/18 02:36:18 | 000,074,840 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
- DRV:[b]64bit:[/b] - [2011/03/11 03:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2011/03/11 03:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2010/11/29 20:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
- DRV:[b]64bit:[/b] - [2010/11/20 10:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2010/11/20 08:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2010/11/20 08:07:06 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2010/11/20 08:03:44 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
- DRV:[b]64bit:[/b] - [2010/10/19 21:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
- DRV:[b]64bit:[/b] - [2010/10/15 05:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
- DRV:[b]64bit:[/b] - [2010/09/23 04:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
- DRV:[b]64bit:[/b] - [2010/01/26 23:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
- DRV:[b]64bit:[/b] - [2010/01/19 17:32:40 | 000,103,944 | ---- | M] (BitDefender) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bdvedisk.sys -- (BDVEDISK)
- DRV:[b]64bit:[/b] - [2009/07/20 06:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
- DRV:[b]64bit:[/b] - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009/07/13 22:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009/06/10 17:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH)
- DRV:[b]64bit:[/b] - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV:[b]64bit:[/b] - [2008/05/23 22:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
- DRV - [2011/05/26 00:06:20 | 000,017,536 | ---- | M] (ASUS) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
- DRV - [2009/07/13 22:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- DRV - [2009/07/02 22:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oquefazernainternet.com/
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.oquefazernainternet.com/
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oquefazernainternet.com/
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
- IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
- IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
- FF - prefs.js..network.proxy.type: 1
- FF - user.js - File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
- FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2012\BDTBEXT\ [2012/02/18 09:52:43 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/18 01:05:12 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/11 15:28:25 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\Program Files\Bitdefender\Bitdefender 2012\bdtbext\ [2012/02/18 09:52:43 | 000,000,000 | ---D | M]
- [2012/02/17 23:36:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gean\AppData\Roaming\mozilla\Extensions
- [2012/03/09 23:00:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gean\AppData\Roaming\mozilla\Firefox\Profiles\eq93kkw5.default\extensions
- [2012/03/09 23:00:21 | 000,000,000 | -HSD | M] (GooglePreview) -- C:\Users\Gean\AppData\Roaming\mozilla\Firefox\Profiles\eq93kkw5.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
- [2012/02/17 23:36:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
- [2012/03/18 01:05:11 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
- [2012/02/16 08:14:56 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml
- [2012/02/16 08:14:56 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml
- [2012/02/16 07:53:03 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
- [2012/02/16 08:14:56 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml
- [2012/02/16 08:14:56 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml
- O1 HOSTS File: ([2011/04/24 22:58:29 | 000,001,211 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 localhost
- O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
- O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
- O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
- O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
- O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
- O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
- O2:[b]64bit:[/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
- O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
- O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
- O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
- O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
- O4:[b]64bit:[/b] - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
- O4:[b]64bit:[/b] - HKLM..\Run: [BDAgent] C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe (Bitdefender)
- O4:[b]64bit:[/b] - HKLM..\Run: [Chew7Hale] C:\Windows\SysNative\hale.exe ()
- O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
- O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
- O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
- O4:[b]64bit:[/b] - HKLM..\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd File not found
- O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
- O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe (ecareme)
- O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
- O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
- O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
- O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
- O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
- O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
- O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
- O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
- O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUS)
- O4 - HKCU..\Run: [AdobeBridge] File not found
- O4 - HKCU..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe (syncables, LLC)
- O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
- O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BD71480F-25A3-40D6-A6D7-ADCBAA42E431}: NameServer = 200.225.197.34 200.225.197.37
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E544D7B3-DC8F-4C1A-AAA4-3447791F93B0}: DhcpNameServer = 192.168.10.2
- O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O32 - HKLM CDRom: AutoRun - 1
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012/03/21 22:52:42 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\Gean\Desktop\OTL.exe
- [2012/03/21 19:57:50 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7336E694-9650-492F-9F49-ECCF41764C99}
- [2012/03/21 19:57:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B0F0DFB5-D8A1-4127-8AF5-752664D60427}
- [2012/03/21 03:00:32 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
- [2012/03/21 03:00:32 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
- [2012/03/20 16:54:40 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{4E41D016-CCED-4278-B72B-1587EC157EF3}
- [2012/03/20 16:54:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A4D5E2F3-95B7-4D0E-9DDE-F81C90FDA2F2}
- [2012/03/20 16:54:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
- [2012/03/20 11:47:47 | 000,000,000 | R--D | C] -- C:\Users\Gean\Documents\Notes
- [2012/03/20 11:31:07 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Journal
- [2012/03/20 11:31:05 | 000,000,000 | ---D | C] -- C:\Windows\ehome
- [2012/03/20 11:31:03 | 000,000,000 | -HSD | C] -- C:\Windows\BitLockerDiscoveryVolumeContents
- [2012/03/20 11:31:03 | 000,000,000 | ---D | C] -- C:\Windows\RemotePackages
- [2012/03/20 11:31:03 | 000,000,000 | ---D | C] -- C:\Windows\CSC
- [2012/03/20 11:30:59 | 000,000,000 | RH-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
- [2012/03/19 23:48:46 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ccleaner Business Edition x64 x86 Tom_Da_Man
- [2012/03/19 23:48:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ccleaner Business Edition x64 x86 Tom_Da_Man
- [2012/03/19 20:54:54 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A71188E5-BEF9-4E95-814D-6E59347DE3C8}
- [2012/03/19 20:54:42 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{BAB869FE-AFBC-49A0-9C37-22745448D700}
- [2012/03/19 11:20:45 | 000,000,000 | ---D | C] -- C:\Windows\pss
- [2012/03/19 08:47:34 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{52B56C8B-5C45-4A26-ACED-9B5EE04D19D3}
- [2012/03/19 08:47:22 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{AE42A59C-80D0-45E4-B7D6-B0C5A86B01F9}
- [2012/03/18 16:11:45 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{8A811FE7-5EB2-4652-87DC-BA45B67B0F5E}
- [2012/03/18 16:11:33 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{18E3CF92-EA96-40B7-BD93-359D04B0BBC0}
- [2012/03/17 20:13:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{415F6271-680C-4C57-A94A-30438E0E30A4}
- [2012/03/17 20:13:16 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{C2F8C2A9-9685-41FA-BFA8-BC45F3866769}
- [2012/03/16 19:38:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CounterStrikev47
- [2012/03/16 12:08:55 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{DA4EF333-2A81-434D-B082-84EBC518DCB9}
- [2012/03/16 12:08:43 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B6D0F064-EC1E-4177-8C59-C50BB3DDECAE}
- [2012/03/15 13:56:43 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E101AA66-478F-4E11-8E21-6BF0611C11C2}
- [2012/03/15 13:56:30 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{9CC6E762-0C48-45FE-8552-A3185593B764}
- [2012/03/15 09:42:57 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\bdch
- [2012/03/14 23:22:22 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\YoudaGames
- [2012/03/14 21:33:44 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
- [2012/03/14 21:33:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
- [2012/03/14 20:42:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\sXe Injected
- [2012/03/14 20:34:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{CC59DD8B-20D4-4DEF-BD44-65F546A55E13}
- [2012/03/14 20:34:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{72D84473-91DC-4A6E-AD8D-E4B6272CB347}
- [2012/03/14 20:08:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Counter-Strike
- [2012/03/14 11:44:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
- [2012/03/14 11:44:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
- [2012/03/14 11:43:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
- [2012/03/14 11:42:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
- [2012/03/14 11:41:46 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
- [2012/03/14 11:41:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
- [2012/03/14 11:39:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
- [2012/03/14 11:39:22 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
- [2012/03/14 11:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
- [2012/03/14 11:38:52 | 000,000,000 | ---D | C] -- C:\Windows\SHELLNEW
- [2012/03/14 11:38:12 | 000,000,000 | RH-D | C] -- C:\MSOCache
- [2012/03/13 21:58:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
- [2012/03/13 21:01:11 | 005,559,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
- [2012/03/13 21:01:10 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
- [2012/03/13 21:01:10 | 003,913,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
- [2012/03/13 20:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Utherverse Digital Inc
- [2012/03/13 20:05:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{972D62E1-53E2-465F-827C-3D0017575DDE}
- [2012/03/13 20:05:14 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{C219F878-0339-4C08-BD1B-9606C9F1F1B0}
- [2012/03/13 18:37:53 | 001,544,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
- [2012/03/13 18:33:17 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
- [2012/03/13 18:33:17 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
- [2012/03/13 18:33:16 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
- [2012/03/13 18:33:16 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
- [2012/03/13 18:33:15 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
- [2012/03/13 18:33:15 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
- [2012/03/12 19:25:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
- [2012/03/12 12:26:46 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{41EB429B-40B8-4B37-9FE2-90C52F7FB2BE}
- [2012/03/12 12:26:33 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5355A10A-F395-4258-8492-A6789BD597D1}
- [2012/03/12 00:25:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5690AFF9-DA74-4A6D-A017-E37A83CBB9D9}
- [2012/03/12 00:25:24 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{C3D3BBD6-AF1A-4EDE-AA08-034133658124}
- [2012/03/11 12:24:16 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{BBE97A00-6388-4B6F-9E67-4801E70CE8BE}
- [2012/03/11 12:24:01 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E4B2F9FE-D062-4F84-8335-751AD96081D9}
- [2012/03/10 23:35:13 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{DD91290A-17AD-4D07-98BC-CAD98190C413}
- [2012/03/10 23:34:59 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{60D4C519-982D-4975-BB74-B654E47CB1F4}
- [2012/03/10 21:46:07 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\Google
- [2012/03/10 21:37:14 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
- [2012/03/10 11:34:14 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{27E86CA6-109D-48B8-AA19-E2BAE94EAB52}
- [2012/03/10 11:34:01 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{536BE992-A5EF-46A9-BCE1-30A0980C7CDA}
- [2012/03/09 11:07:28 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E17F5EC7-7EBF-42CD-9D37-B8C44044C14F}
- [2012/03/09 11:07:14 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{43FC1EF3-3744-4D0A-8D8D-8137F51C6170}
- [2012/03/08 11:41:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E80A9F67-4B1E-4FD7-807C-8E340F70F691}
- [2012/03/08 11:41:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B893D936-40D8-4651-BE77-96CB73BD9F28}
- [2012/03/07 18:00:32 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{85395ECC-9CAE-4133-B03A-1D1F067BC210}
- [2012/03/07 18:00:19 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{924248C5-625A-441F-8D19-787C32BE96CE}
- [2012/03/07 08:43:32 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
- [2012/03/07 08:33:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
- [2012/03/07 08:32:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
- [2012/03/07 08:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
- [2012/03/07 08:19:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
- [2012/03/07 08:18:44 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\Adobe
- [2012/03/06 21:47:00 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7D39EC95-7AF1-442D-954A-3B5024CAF5DF}
- [2012/03/06 21:46:48 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{0751C900-B55D-41BA-BF64-3FE071735453}
- [2012/03/05 23:13:57 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5509AC6E-58ED-45B1-A3F0-E3DDCB7B36C1}
- [2012/03/05 23:13:44 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{142D561C-8ABC-42CA-B48D-CC330D3FC6DF}
- [2012/03/05 11:05:45 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{239BD3AA-A0ED-4002-A987-F3CF80BA667E}
- [2012/03/05 11:05:33 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{4665267F-17E4-49B8-A436-AA6E11CBB104}
- [2012/03/04 20:55:54 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap
- [2012/03/04 20:55:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VDownloader
- [2012/03/04 20:49:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\ProgSense
- [2012/03/04 20:49:37 | 000,000,000 | ---D | C] -- C:\Downloads
- [2012/03/04 20:48:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Orbit
- [2012/03/04 15:56:56 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7F993BD0-AD53-4B0E-ACA0-E0DB6993265F}
- [2012/03/04 15:56:42 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{BCC834AF-0202-4286-BAC6-02E99123926C}
- [2012/03/03 10:27:20 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E3F2AA91-700A-4E0E-B6B9-3B74F4D68AC5}
- [2012/03/03 10:26:57 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A4C8D0BE-4958-4E7C-9831-4E6FCD5AEB97}
- [2012/03/02 17:35:21 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7B07A2B3-D957-463E-9ACB-EBFD83EFB264}
- [2012/03/02 17:35:08 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B421DE10-8726-4CE6-838E-91643ED4060B}
- [2012/03/02 13:02:44 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\ElevatedDiagnostics
- [2012/03/02 12:34:52 | 000,000,000 | ---D | C] -- C:\Windows\en
- [2012/03/02 12:34:49 | 000,000,000 | ---D | C] -- C:\Windows\ar
- [2012/03/02 12:34:46 | 000,000,000 | ---D | C] -- C:\Windows\es
- [2012/03/02 12:34:42 | 000,000,000 | ---D | C] -- C:\Windows\fr
- [2012/03/02 12:34:39 | 000,000,000 | ---D | C] -- C:\Windows\th
- [2012/03/02 12:34:36 | 000,000,000 | ---D | C] -- C:\Windows\tr
- [2012/03/02 12:28:28 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7A93EA29-9FCD-4D40-92D9-8CCACF9A7E0C}
- [2012/03/02 12:28:15 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{DB9D093C-F422-4156-A791-ACF607460E01}
- [2012/03/01 21:23:03 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7FD843EB-3002-46EB-93AA-832A78867241}
- [2012/03/01 21:22:50 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{3953C46C-1F06-481C-A97D-9A27C929DB6A}
- [2012/03/01 19:06:02 | 000,545,064 | ---- | C] (BitDefender) -- C:\Windows\SysNative\drivers\avckf.sys
- [2012/03/01 10:37:51 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{04C75AAF-92FA-489E-A67E-D3A91183C544}
- [2012/03/01 10:37:40 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A019EC7A-7150-444F-AC65-095735EBDCA2}
- [2012/03/01 08:46:22 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Media Player Classic
- [2012/03/01 08:34:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
- [2012/03/01 08:34:39 | 000,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\Windows\SysWow64\lameACM.acm
- [2012/03/01 08:34:39 | 000,630,784 | ---- | C] (On2.com) -- C:\Windows\SysWow64\vp7vfw.dll
- [2012/03/01 08:34:39 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\SysWow64\ac3acm.acm
- [2012/03/01 08:34:39 | 000,039,936 | ---- | C] (Disappearing Inc.) -- C:\Windows\SysWow64\huffyuv.dll
- [2012/03/01 08:34:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack
- [2012/03/01 08:24:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{883F74F2-D150-4D16-BA8D-0789FAEF8518}
- [2012/03/01 08:24:24 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B2D8691D-81D3-4DA8-B2AB-51DBF4DC55D2}
- [2012/02/29 19:27:53 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7A9AAE4D-AD1E-4499-B747-0CF72B893950}
- [2012/02/29 18:24:23 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\GarenaPlus
- [2012/02/29 18:24:00 | 000,000,000 | ---D | C] -- C:\ProgramData\GarenaMessenger
- [2012/02/29 18:09:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
- [2012/02/29 17:10:58 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A8B24115-AA63-4F2E-9B21-BDBFDAC45227}
- [2012/02/29 17:01:12 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
- [2012/02/26 11:27:41 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{4EC80F40-60B5-4E93-9E72-7DB5F1ED1F3A}
- [2012/02/26 11:27:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Windows Live Writer
- [2012/02/26 11:27:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\Windows Live Writer
- [2012/02/25 20:37:45 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\FLEXnet
- [2012/02/25 20:16:06 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5E26A76C-5674-4596-B768-444014D744B6}
- [2012/02/25 19:57:50 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\InstallShield
- [2012/02/25 19:56:18 | 000,000,000 | -H-D | C] -- C:\ASUS.DAT
- [2012/02/25 19:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virage Logic, Corp
- [2012/02/25 19:53:08 | 000,648,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
- [2012/02/25 19:53:05 | 003,048,552 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
- [2012/02/25 19:53:02 | 002,392,168 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
- [2012/02/25 19:53:01 | 001,242,216 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
- [2012/02/25 19:52:49 | 000,084,584 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInst64.dll
- [2012/02/25 19:52:47 | 000,952,320 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoRes64.dat
- [2012/02/25 19:51:30 | 002,075,712 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
- [2012/02/23 09:06:21 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\PlayFirst
- [2012/02/23 09:06:21 | 000,000,000 | ---D | C] -- C:\ProgramData\PlayFirst
- [2012/02/23 08:55:52 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\2DBoy
- [2012/02/23 08:55:52 | 000,000,000 | ---D | C] -- C:\ProgramData\2DBoy
- [2012/02/22 18:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Oberon Media
- [2012/02/22 11:21:21 | 000,082,432 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSXML4r.dll
- [2012/02/22 11:21:20 | 000,044,544 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSXML4a.dll
- [2012/02/22 11:21:19 | 000,626,960 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hpvaut32.dll
- [2012/02/22 11:21:19 | 000,487,424 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hpvcp70.dll
- [2012/02/21 18:48:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard
- [2012/02/21 18:48:18 | 000,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
- [2012/02/21 18:48:15 | 000,327,168 | ---- | C] (InstallShield Software Corporation, Inc.) -- C:\Windows\IsUn0416.exe
- [2012/02/21 18:47:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
- [2012/02/21 18:47:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hewlett-Packard
- [2012/02/21 18:06:16 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{1F32B18D-2E3F-4BA8-802B-F8204F60316F}
- [2012/02/21 14:04:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{63C90230-B37E-4468-BB13-64DC101863E1}
- [2012/02/21 12:36:48 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\gean.anjo
- [2012/02/21 12:36:46 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\SafeBox
- [2012/02/21 10:33:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{880DE715-1389-4AF8-BCD0-0CA0E4313A0F}
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012/03/21 22:55:05 | 000,000,322 | ---- | M] () -- C:\Windows\SysNative\checkdnsid.xml
- [2012/03/21 22:52:46 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Gean\Desktop\OTL.exe
- [2012/03/21 22:36:27 | 000,019,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2012/03/21 22:36:27 | 000,019,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2012/03/21 22:27:02 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2012/03/21 22:23:56 | 000,205,626 | ---- | M] () -- C:\Users\Gean\Desktop\3.png
- [2012/03/21 22:23:09 | 000,205,636 | ---- | M] () -- C:\Users\Gean\Desktop\2.png
- [2012/03/21 22:22:32 | 000,205,481 | ---- | M] () -- C:\Users\Gean\Desktop\1.png
- [2012/03/21 21:29:54 | 000,007,603 | ---- | M] () -- C:\Users\Gean\AppData\Local\resmon.resmoncfg
- [2012/03/21 21:04:26 | 000,045,056 | ---- | M] () -- C:\Windows\SysWow64\acovcnt.exe
- [2012/03/21 21:04:24 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2012/03/21 21:03:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012/03/21 21:03:14 | 467,849,215 | -HS- | M] () -- C:\hiberfil.sys
- [2012/03/21 19:38:56 | 006,550,093 | ---- | M] () -- C:\Windows\SysNative\cwlog.dtl
- [2012/03/21 18:32:23 | 000,002,344 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
- [2012/03/21 18:31:02 | 000,381,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppcommdlg.dll
- [2012/03/21 18:31:01 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll
- [2012/03/21 18:31:00 | 001,008,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
- [2012/03/21 18:30:58 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppwmi.dll
- [2012/03/21 18:30:57 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll
- [2012/03/21 18:29:46 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
- [2012/03/21 18:29:46 | 000,349,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slui.exe
- [2012/03/21 18:29:46 | 000,107,946 | ---- | M] () -- C:\Windows\SysNative\slmgr.vbs
- [2012/03/21 18:29:46 | 000,002,048 | ---- | M] () -- C:\Windows\SysNative\winver.exe
- [2012/03/21 18:29:45 | 002,169,856 | -HS- | M] () -- C:\Windows\SysNative\hale.exe
- [2012/03/21 18:20:34 | 000,203,316 | ---- | M] () -- C:\grldr.bak
- [2012/03/21 18:03:31 | 000,327,367 | RHS- | M] () -- C:\bootmgr
- [2012/03/21 17:42:01 | 001,555,682 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2012/03/21 17:42:01 | 000,678,120 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
- [2012/03/21 17:42:01 | 000,630,324 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2012/03/21 17:42:01 | 000,132,690 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
- [2012/03/21 17:42:01 | 000,110,984 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2012/03/20 11:36:31 | 004,972,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2012/03/19 23:52:36 | 000,000,955 | ---- | M] () -- C:\Windows\wininit.ini
- [2012/03/19 23:48:46 | 000,001,265 | ---- | M] () -- C:\Users\Gean\Desktop\Ccleaner Business Edition.lnk
- [2012/03/14 21:13:31 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
- [2012/03/13 20:57:43 | 000,051,270 | ---- | M] () -- C:\Users\Gean\AppData\Roaming\room_v3.dat
- [2012/03/13 10:33:53 | 000,001,187 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
- [2012/03/01 19:06:02 | 000,545,064 | ---- | M] (BitDefender) -- C:\Windows\SysNative\drivers\avckf.sys
- [2012/03/01 19:04:21 | 000,690,872 | ---- | M] (BitDefender) -- C:\Windows\SysNative\drivers\avc3.sys
- [2012/02/25 20:51:05 | 000,000,024 | ---- | M] () -- C:\Windows\ATKPF.ini
- [2012/02/25 20:05:29 | 000,086,890 | ---- | M] () -- C:\Windows\AsCD_Item_40.jpg
- [2012/02/25 19:56:18 | 000,002,617 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
- [2012/02/22 19:10:39 | 000,000,014 | ---- | M] () -- C:\Windows\popcinfo.dat
- [2012/02/21 18:49:33 | 000,179,084 | ---- | M] () -- C:\Windows\hpdj3500.his
- [2012/02/21 18:49:33 | 000,010,115 | ---- | M] () -- C:\Windows\hpdj3500.ini
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012/03/21 22:23:56 | 000,205,626 | ---- | C] () -- C:\Users\Gean\Desktop\3.png
- [2012/03/21 22:21:29 | 000,205,636 | ---- | C] () -- C:\Users\Gean\Desktop\2.png
- [2012/03/21 22:20:49 | 000,205,481 | ---- | C] () -- C:\Users\Gean\Desktop\1.png
- [2012/03/21 18:30:56 | 006,465,834 | ---- | C] () -- C:\Windows\SysNative\cwlog.dtl
- [2012/03/21 18:29:45 | 002,169,856 | -HS- | C] () -- C:\Windows\SysNative\hale.exe
- [2012/03/21 18:20:51 | 000,203,316 | ---- | C] () -- C:\grldr.bak
- [2012/03/20 11:34:57 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
- [2012/03/20 11:34:52 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
- [2012/03/20 11:27:01 | 000,051,867 | ---- | C] () -- C:\Windows\Ultimate.xml
- [2012/03/20 00:44:26 | 000,002,062 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
- [2012/03/20 00:44:25 | 000,002,617 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
- [2012/03/19 23:48:46 | 000,001,265 | ---- | C] () -- C:\Users\Gean\Desktop\Ccleaner Business Edition.lnk
- [2012/03/19 23:33:30 | 000,000,955 | ---- | C] () -- C:\Windows\wininit.ini
- [2012/03/14 21:36:05 | 000,001,095 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
- [2012/03/14 21:35:21 | 000,001,229 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
- [2012/03/14 21:33:29 | 000,001,191 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
- [2012/03/14 21:33:08 | 000,001,284 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
- [2012/03/14 21:32:13 | 000,001,385 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
- [2012/03/14 21:32:03 | 000,001,557 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
- [2012/03/14 21:13:31 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
- [2012/03/12 19:22:40 | 000,001,064 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2012/03/12 19:22:40 | 000,001,060 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2012/03/11 14:52:35 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
- [2012/03/07 12:50:06 | 000,000,322 | ---- | C] () -- C:\Windows\SysNative\checkdnsid.xml
- [2012/03/07 08:33:15 | 000,000,999 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
- [2012/03/01 08:34:40 | 000,000,414 | ---- | C] () -- C:\Windows\SysWow64\lame_acm.xml
- [2012/03/01 08:34:39 | 004,078,592 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
- [2012/03/01 08:34:39 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
- [2012/03/01 08:34:39 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
- [2012/03/01 08:34:39 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
- [2012/03/01 08:34:39 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
- [2012/03/01 08:34:37 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
- [2012/02/29 17:24:58 | 000,051,270 | ---- | C] () -- C:\Users\Gean\AppData\Roaming\room_v3.dat
- [2012/02/26 11:21:51 | 000,007,603 | ---- | C] () -- C:\Users\Gean\AppData\Local\resmon.resmoncfg
- [2012/02/25 20:05:29 | 000,086,890 | ---- | C] () -- C:\Windows\AsCD_Item_40.jpg
- [2012/02/22 19:10:39 | 000,000,014 | ---- | C] () -- C:\Windows\popcinfo.dat
- [2012/02/21 18:45:05 | 000,179,084 | ---- | C] () -- C:\Windows\hpdj3500.his
- [2012/02/21 18:45:05 | 000,010,115 | ---- | C] () -- C:\Windows\hpdj3500.ini
- [2012/02/20 12:35:08 | 001,565,436 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2012/02/18 09:53:52 | 001,856,058 | ---- | C] () -- C:\ProgramData\1329562271.bdinstall.bin
- [2012/02/18 07:36:24 | 000,021,594 | ---- | C] () -- C:\ProgramData\1329561378.bdinstall.bin
- [2012/02/18 07:34:35 | 000,021,594 | ---- | C] () -- C:\ProgramData\1329561266.bdinstall.bin
- [2012/02/18 07:33:45 | 000,330,231 | ---- | C] () -- C:\ProgramData\1329560463.bdinstall.bin
- [2012/02/18 07:12:19 | 000,000,502 | ---- | C] () -- C:\ProgramData\1329559938.bdinstall.bin
- [2012/02/06 12:06:36 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
- [2012/02/06 11:28:15 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\acovcnt.exe
- [2011/08/31 18:51:16 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
- [2011/08/31 18:46:00 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
- [2011/08/31 18:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
- [2011/07/06 10:29:57 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
- [2011/07/06 10:29:52 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
- [2011/04/12 01:49:32 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 150 bytes -> C:\ProgramData\Temp:41099CE9
- @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:981884E7
- @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:52DBE86F
- @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:81F83028
- @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:3AE22B1A
- @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:D20FFA63
- @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:5D458568
- @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:3E7393FC
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement