

Mar 21st, 2012
text 57.89 KB | None | 0 0
  1. OTL logfile created on: 21/03/2012 22:53:14 - Run 1
  2. OTL by OldTimer - Version Folder = C:\Users\Gean\Desktop
  3. 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.0.8112.16421)
  5. Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
  7. 5,91 Gb Total Physical Memory | 3,71 Gb Available Physical Memory | 62,68% Memory free
  8. 11,83 Gb Paging File | 9,18 Gb Available in Paging File | 77,61% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 195,35 Gb Total Space | 122,70 Gb Free Space | 62,81% Space Free | Partition Type: NTFS
  13. Drive D: | 245,41 Gb Total Space | 214,39 Gb Free Space | 87,36% Space Free | Partition Type: NTFS
  15. Computer Name: GEAN-PC | User Name: Gean | Logged in as Administrator.
  16. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
  17. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  19. [color=#E56717]========== Processes (SafeList) ==========[/color]
  21. PRC - [2012/03/21 22:52:46 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Gean\Desktop\OTL.exe
  22. PRC - [2012/03/18 01:05:11 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  23. PRC - [2012/03/06 18:37:40 | 000,741,240 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
  24. PRC - [2012/01/03 10:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
  25. PRC - [2011/11/30 13:28:56 | 001,550,496 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
  26. PRC - [2011/09/13 12:33:14 | 002,317,312 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
  27. PRC - [2010/12/20 23:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
  28. PRC - [2010/12/20 23:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
  29. PRC - [2010/11/20 09:17:02 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
  30. PRC - [2010/07/19 16:26:00 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
  31. PRC - [2010/07/09 21:45:00 | 000,984,400 | ---- | M] (Virage Logic Corporation / Sonic Focus) -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
  32. PRC - [2009/12/15 15:39:38 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
  33. PRC - [2009/11/02 19:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
  34. PRC - [2009/06/15 22:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
  37. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  39. MOD - [2012/03/18 01:05:11 | 001,969,080 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
  40. MOD - [2012/02/21 16:40:53 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\
  41. MOD - [2012/02/21 16:40:25 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\02f7846cbc5c02a5dbf50fd34325eb61\
  42. MOD - [2012/02/21 16:40:14 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f4b2424c1b32fbd11130482bb899b7ae\
  43. MOD - [2012/02/21 16:40:04 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\
  44. MOD - [2012/02/21 16:38:31 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\
  45. MOD - [2012/02/21 16:38:25 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\
  46. MOD - [2012/02/21 16:38:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\
  47. MOD - [2012/02/21 16:38:19 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\
  48. MOD - [2012/02/21 16:38:08 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\
  49. MOD - [2012/02/21 16:38:03 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\
  50. MOD - [2011/11/30 13:28:56 | 000,211,456 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
  51. MOD - [2011/09/13 12:33:14 | 001,163,264 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
  52. MOD - [2011/02/18 23:05:31 | 000,241,664 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\\PresentationFramework.resources.dll
  53. MOD - [2011/02/18 23:05:25 | 000,086,016 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\WindowsBase.resources\\WindowsBase.resources.dll
  54. MOD - [2010/11/12 20:35:07 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll
  55. MOD - [2010/01/21 01:34:10 | 008,793,952 | ---- | M] () -- C:\PROGRA~2\MICROS~1\Office14\1033\GrooveIntlResource.dll
  56. MOD - [2010/01/09 20:18:18 | 004,254,560 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
  57. MOD - [2009/11/02 19:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
  58. MOD - [2009/11/02 19:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
  59. MOD - [2009/07/18 00:21:00 | 003,883,424 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
  62. [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
  64. SRV:[b]64bit:[/b] - [2012/03/01 19:05:00 | 000,075,384 | ---- | M] (Bitdefender) [On_Demand | Running] -- C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe -- (SafeBox)
  65. SRV:[b]64bit:[/b] - [2012/03/01 19:04:11 | 001,955,080 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe -- (vsserv)
  66. SRV:[b]64bit:[/b] - [2012/01/23 18:41:02 | 000,062,512 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe -- (UPDATESRV)
  67. SRV:[b]64bit:[/b] - [2011/10/14 21:57:26 | 000,466,736 | ---- | M] (BitDefender) [On_Demand | Stopped] -- C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe -- (Update Server)
  68. SRV:[b]64bit:[/b] - [2011/03/03 21:57:58 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
  69. SRV:[b]64bit:[/b] - [2010/11/29 20:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost) Intel(R)
  70. SRV:[b]64bit:[/b] - [2010/09/22 22:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
  71. SRV:[b]64bit:[/b] - [2009/07/13 22:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
  72. SRV:[b]64bit:[/b] - [2009/07/13 22:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
  73. SRV - [2012/01/03 10:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
  74. SRV - [2010/12/20 23:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
  75. SRV - [2010/12/20 23:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
  76. SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
  77. SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
  78. SRV - [2009/12/15 15:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
  79. SRV - [2009/06/15 22:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
  80. SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  83. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  85. DRV:[b]64bit:[/b] - [2012/03/01 19:06:02 | 000,545,064 | ---- | M] (BitDefender) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\avckf.sys -- (avckf)
  86. DRV:[b]64bit:[/b] - [2012/03/01 19:04:21 | 000,690,872 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avc3.sys -- (avc3)
  87. DRV:[b]64bit:[/b] - [2011/11/25 13:00:36 | 000,258,736 | ---- | M] (BitDefender) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avchv.sys -- (avchv)
  88. DRV:[b]64bit:[/b] - [2011/11/17 15:38:34 | 000,079,952 | ---- | M] (BitDefender SRL) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bdsandbox.sys -- (bdsandbox)
  89. DRV:[b]64bit:[/b] - [2011/11/14 18:16:42 | 000,090,192 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys -- (BdfNdisf)
  90. DRV:[b]64bit:[/b] - [2011/11/14 18:16:38 | 000,103,504 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys -- (bdfwfpf)
  91. DRV:[b]64bit:[/b] - [2011/10/27 13:07:05 | 000,329,800 | ---- | M] (BitDefender S.R.L.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\trufos.sys -- (trufos)
  92. DRV:[b]64bit:[/b] - [2011/10/03 22:49:32 | 002,770,944 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
  93. DRV:[b]64bit:[/b] - [2011/08/31 18:53:22 | 012,306,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
  94. DRV:[b]64bit:[/b] - [2011/08/16 12:59:12 | 000,442,088 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\bdfsfltr.sys -- (bdfsfltr)
  95. DRV:[b]64bit:[/b] - [2011/04/26 00:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
  96. DRV:[b]64bit:[/b] - [2011/04/20 06:24:56 | 000,169,584 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
  97. DRV:[b]64bit:[/b] - [2011/04/12 18:18:08 | 000,142,632 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
  98. DRV:[b]64bit:[/b] - [2011/03/18 02:36:18 | 000,074,840 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
  99. DRV:[b]64bit:[/b] - [2011/03/11 03:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  100. DRV:[b]64bit:[/b] - [2011/03/11 03:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  101. DRV:[b]64bit:[/b] - [2010/11/29 20:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
  102. DRV:[b]64bit:[/b] - [2010/11/20 10:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  103. DRV:[b]64bit:[/b] - [2010/11/20 08:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  104. DRV:[b]64bit:[/b] - [2010/11/20 08:07:06 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
  105. DRV:[b]64bit:[/b] - [2010/11/20 08:03:44 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
  106. DRV:[b]64bit:[/b] - [2010/10/19 21:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
  107. DRV:[b]64bit:[/b] - [2010/10/15 05:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
  108. DRV:[b]64bit:[/b] - [2010/09/23 04:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
  109. DRV:[b]64bit:[/b] - [2010/01/26 23:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
  110. DRV:[b]64bit:[/b] - [2010/01/19 17:32:40 | 000,103,944 | ---- | M] (BitDefender) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bdvedisk.sys -- (BDVEDISK)
  111. DRV:[b]64bit:[/b] - [2009/07/20 06:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
  112. DRV:[b]64bit:[/b] - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  113. DRV:[b]64bit:[/b] - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  114. DRV:[b]64bit:[/b] - [2009/07/13 22:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  115. DRV:[b]64bit:[/b] - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  116. DRV:[b]64bit:[/b] - [2009/06/10 17:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH)
  117. DRV:[b]64bit:[/b] - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  118. DRV:[b]64bit:[/b] - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  119. DRV:[b]64bit:[/b] - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  120. DRV:[b]64bit:[/b] - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  121. DRV:[b]64bit:[/b] - [2008/05/23 22:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
  122. DRV - [2011/05/26 00:06:20 | 000,017,536 | ---- | M] (ASUS) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
  123. DRV - [2009/07/13 22:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  124. DRV - [2009/07/02 22:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
  127. [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
  130. [color=#E56717]========== Internet Explorer ==========[/color]
  132. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
  133. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  134. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" ={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
  135. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
  136. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  137. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
  138. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
  139. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
  140. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
  141. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  142. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" ={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
  143. IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
  144. IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
  146. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
  147. IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  148. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  150. [color=#E56717]========== FireFox ==========[/color]
  152. FF - prefs.js..browser.startup.homepage: ""
  153. FF - 1
  154. FF - user.js - File not found
  156. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
  157. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  158. FF - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
  159. FF - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
  160. FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
  161. FF - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
  162. FF - HKLM\Software\MozillaPlugins\,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
  163. FF - HKLM\Software\MozillaPlugins\,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  164. FF - HKLM\Software\MozillaPlugins\,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  165. FF - HKLM\Software\MozillaPlugins\,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  166. FF - HKLM\Software\MozillaPlugins\,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  167. FF - HKLM\Software\MozillaPlugins\,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  168. FF - HKLM\Software\MozillaPlugins\ Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
  169. FF - HKLM\Software\MozillaPlugins\ Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
  170. FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  172. 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\ C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2012\BDTBEXT\ [2012/02/18 09:52:43 | 000,000,000 | ---D | M]
  173. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/18 01:05:12 | 000,000,000 | ---D | M]
  174. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/11 15:28:25 | 000,000,000 | ---D | M]
  175. FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\ C:\Program Files\Bitdefender\Bitdefender 2012\bdtbext\ [2012/02/18 09:52:43 | 000,000,000 | ---D | M]
  177. [2012/02/17 23:36:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gean\AppData\Roaming\mozilla\Extensions
  178. [2012/03/09 23:00:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gean\AppData\Roaming\mozilla\Firefox\Profiles\eq93kkw5.default\extensions
  179. [2012/03/09 23:00:21 | 000,000,000 | -HSD | M] (GooglePreview) -- C:\Users\Gean\AppData\Roaming\mozilla\Firefox\Profiles\eq93kkw5.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
  180. [2012/02/17 23:36:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
  181. [2012/03/18 01:05:11 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
  182. [2012/02/16 08:14:56 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml
  183. [2012/02/16 08:14:56 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml
  184. [2012/02/16 07:53:03 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
  185. [2012/02/16 08:14:56 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml
  186. [2012/02/16 08:14:56 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml
  188. O1 HOSTS File: ([2011/04/24 22:58:29 | 000,001,211 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  189. O1 - Hosts: localhost
  190. O1 - Hosts:
  191. O1 - Hosts:
  192. O1 - Hosts: practivate.adobe practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp
  193. O1 - Hosts:
  194. O1 - Hosts:
  195. O1 - Hosts: CRL.VERISIGN.NET
  196. O2:[b]64bit:[/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
  197. O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
  198. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
  199. O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
  200. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
  201. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
  202. O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
  203. O4:[b]64bit:[/b] - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
  204. O4:[b]64bit:[/b] - HKLM..\Run: [BDAgent] C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe (Bitdefender)
  205. O4:[b]64bit:[/b] - HKLM..\Run: [Chew7Hale] C:\Windows\SysNative\hale.exe ()
  206. O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
  207. O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
  208. O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
  209. O4:[b]64bit:[/b] - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
  210. O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
  211. O4:[b]64bit:[/b] - HKLM..\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd File not found
  212. O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
  213. O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\\AsusWSPanel.exe (ecareme)
  214. O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
  215. O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
  216. O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
  217. O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
  218. O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
  219. O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
  220. O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
  221. O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
  222. O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUS)
  223. O4 - HKCU..\Run: [AdobeBridge] File not found
  224. O4 - HKCU..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe (syncables, LLC)
  225. O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
  226. O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
  227. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  228. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  229. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
  230. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  231. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
  232. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
  233. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
  234. O13[b]64bit:[/b] - gopher Prefix: missing
  235. O13 - gopher Prefix: missing
  236. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BD71480F-25A3-40D6-A6D7-ADCBAA42E431}: NameServer =
  237. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E544D7B3-DC8F-4C1A-AAA4-3447791F93B0}: DhcpNameServer =
  238. O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
  239. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
  240. O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
  241. O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
  242. O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
  243. O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
  244. O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
  245. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  246. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  247. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  248. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
  249. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  250. O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
  251. O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
  252. O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
  253. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  254. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  255. O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
  256. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
  257. O32 - HKLM CDRom: AutoRun - 1
  258. O34 - HKLM BootExecute: (autocheck autochk *)
  259. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  260. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  261. O35 - HKLM\..comfile [open] -- "%1" %*
  262. O35 - HKLM\..exefile [open] -- "%1" %*
  263. O37:[b]64bit:[/b] - HKLM\ [@ = comfile] -- "%1" %*
  264. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  265. O37 - HKLM\ [@ = comfile] -- "%1" %*
  266. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  268. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  270. [2012/03/21 22:52:42 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\Gean\Desktop\OTL.exe
  271. [2012/03/21 19:57:50 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7336E694-9650-492F-9F49-ECCF41764C99}
  272. [2012/03/21 19:57:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B0F0DFB5-D8A1-4127-8AF5-752664D60427}
  273. [2012/03/21 03:00:32 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
  274. [2012/03/21 03:00:32 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
  275. [2012/03/20 16:54:40 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{4E41D016-CCED-4278-B72B-1587EC157EF3}
  276. [2012/03/20 16:54:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A4D5E2F3-95B7-4D0E-9DDE-F81C90FDA2F2}
  277. [2012/03/20 16:54:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
  278. [2012/03/20 11:47:47 | 000,000,000 | R--D | C] -- C:\Users\Gean\Documents\Notes
  279. [2012/03/20 11:31:07 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Journal
  280. [2012/03/20 11:31:05 | 000,000,000 | ---D | C] -- C:\Windows\ehome
  281. [2012/03/20 11:31:03 | 000,000,000 | -HSD | C] -- C:\Windows\BitLockerDiscoveryVolumeContents
  282. [2012/03/20 11:31:03 | 000,000,000 | ---D | C] -- C:\Windows\RemotePackages
  283. [2012/03/20 11:31:03 | 000,000,000 | ---D | C] -- C:\Windows\CSC
  284. [2012/03/20 11:30:59 | 000,000,000 | RH-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
  285. [2012/03/19 23:48:46 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ccleaner Business Edition x64 x86 Tom_Da_Man
  286. [2012/03/19 23:48:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ccleaner Business Edition x64 x86 Tom_Da_Man
  287. [2012/03/19 20:54:54 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A71188E5-BEF9-4E95-814D-6E59347DE3C8}
  288. [2012/03/19 20:54:42 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{BAB869FE-AFBC-49A0-9C37-22745448D700}
  289. [2012/03/19 11:20:45 | 000,000,000 | ---D | C] -- C:\Windows\pss
  290. [2012/03/19 08:47:34 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{52B56C8B-5C45-4A26-ACED-9B5EE04D19D3}
  291. [2012/03/19 08:47:22 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{AE42A59C-80D0-45E4-B7D6-B0C5A86B01F9}
  292. [2012/03/18 16:11:45 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{8A811FE7-5EB2-4652-87DC-BA45B67B0F5E}
  293. [2012/03/18 16:11:33 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{18E3CF92-EA96-40B7-BD93-359D04B0BBC0}
  294. [2012/03/17 20:13:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{415F6271-680C-4C57-A94A-30438E0E30A4}
  295. [2012/03/17 20:13:16 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{C2F8C2A9-9685-41FA-BFA8-BC45F3866769}
  296. [2012/03/16 19:38:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CounterStrikev47
  297. [2012/03/16 12:08:55 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{DA4EF333-2A81-434D-B082-84EBC518DCB9}
  298. [2012/03/16 12:08:43 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B6D0F064-EC1E-4177-8C59-C50BB3DDECAE}
  299. [2012/03/15 13:56:43 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E101AA66-478F-4E11-8E21-6BF0611C11C2}
  300. [2012/03/15 13:56:30 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{9CC6E762-0C48-45FE-8552-A3185593B764}
  301. [2012/03/15 09:42:57 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\bdch
  302. [2012/03/14 23:22:22 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\YoudaGames
  303. [2012/03/14 21:33:44 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
  304. [2012/03/14 21:33:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
  305. [2012/03/14 20:42:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\sXe Injected
  306. [2012/03/14 20:34:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{CC59DD8B-20D4-4DEF-BD44-65F546A55E13}
  307. [2012/03/14 20:34:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{72D84473-91DC-4A6E-AD8D-E4B6272CB347}
  308. [2012/03/14 20:08:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Counter-Strike
  309. [2012/03/14 11:44:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
  310. [2012/03/14 11:44:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
  311. [2012/03/14 11:43:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
  312. [2012/03/14 11:42:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
  313. [2012/03/14 11:41:46 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
  314. [2012/03/14 11:41:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
  315. [2012/03/14 11:39:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
  316. [2012/03/14 11:39:22 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
  317. [2012/03/14 11:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
  318. [2012/03/14 11:38:52 | 000,000,000 | ---D | C] -- C:\Windows\SHELLNEW
  319. [2012/03/14 11:38:12 | 000,000,000 | RH-D | C] -- C:\MSOCache
  320. [2012/03/13 21:58:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
  321. [2012/03/13 21:01:11 | 005,559,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
  322. [2012/03/13 21:01:10 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
  323. [2012/03/13 21:01:10 | 003,913,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
  324. [2012/03/13 20:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Utherverse Digital Inc
  325. [2012/03/13 20:05:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{972D62E1-53E2-465F-827C-3D0017575DDE}
  326. [2012/03/13 20:05:14 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{C219F878-0339-4C08-BD1B-9606C9F1F1B0}
  327. [2012/03/13 18:37:53 | 001,544,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
  328. [2012/03/13 18:33:17 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
  329. [2012/03/13 18:33:17 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
  330. [2012/03/13 18:33:16 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
  331. [2012/03/13 18:33:16 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
  332. [2012/03/13 18:33:15 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
  333. [2012/03/13 18:33:15 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
  334. [2012/03/12 19:25:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
  335. [2012/03/12 12:26:46 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{41EB429B-40B8-4B37-9FE2-90C52F7FB2BE}
  336. [2012/03/12 12:26:33 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5355A10A-F395-4258-8492-A6789BD597D1}
  337. [2012/03/12 00:25:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5690AFF9-DA74-4A6D-A017-E37A83CBB9D9}
  338. [2012/03/12 00:25:24 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{C3D3BBD6-AF1A-4EDE-AA08-034133658124}
  339. [2012/03/11 12:24:16 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{BBE97A00-6388-4B6F-9E67-4801E70CE8BE}
  340. [2012/03/11 12:24:01 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E4B2F9FE-D062-4F84-8335-751AD96081D9}
  341. [2012/03/10 23:35:13 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{DD91290A-17AD-4D07-98BC-CAD98190C413}
  342. [2012/03/10 23:34:59 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{60D4C519-982D-4975-BB74-B654E47CB1F4}
  343. [2012/03/10 21:46:07 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\Google
  344. [2012/03/10 21:37:14 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
  345. [2012/03/10 11:34:14 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{27E86CA6-109D-48B8-AA19-E2BAE94EAB52}
  346. [2012/03/10 11:34:01 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{536BE992-A5EF-46A9-BCE1-30A0980C7CDA}
  347. [2012/03/09 11:07:28 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E17F5EC7-7EBF-42CD-9D37-B8C44044C14F}
  348. [2012/03/09 11:07:14 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{43FC1EF3-3744-4D0A-8D8D-8137F51C6170}
  349. [2012/03/08 11:41:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E80A9F67-4B1E-4FD7-807C-8E340F70F691}
  350. [2012/03/08 11:41:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B893D936-40D8-4651-BE77-96CB73BD9F28}
  351. [2012/03/07 18:00:32 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{85395ECC-9CAE-4133-B03A-1D1F067BC210}
  352. [2012/03/07 18:00:19 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{924248C5-625A-441F-8D19-787C32BE96CE}
  353. [2012/03/07 08:43:32 | 000,000,000 | ---D | C] -- C:\ProgramData\
  354. [2012/03/07 08:33:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
  355. [2012/03/07 08:32:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
  356. [2012/03/07 08:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
  357. [2012/03/07 08:19:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
  358. [2012/03/07 08:18:44 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\Adobe
  359. [2012/03/06 21:47:00 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7D39EC95-7AF1-442D-954A-3B5024CAF5DF}
  360. [2012/03/06 21:46:48 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{0751C900-B55D-41BA-BF64-3FE071735453}
  361. [2012/03/05 23:13:57 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5509AC6E-58ED-45B1-A3F0-E3DDCB7B36C1}
  362. [2012/03/05 23:13:44 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{142D561C-8ABC-42CA-B48D-CC330D3FC6DF}
  363. [2012/03/05 11:05:45 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{239BD3AA-A0ED-4002-A987-F3CF80BA667E}
  364. [2012/03/05 11:05:33 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{4665267F-17E4-49B8-A436-AA6E11CBB104}
  365. [2012/03/04 20:55:54 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap
  366. [2012/03/04 20:55:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VDownloader
  367. [2012/03/04 20:49:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\ProgSense
  368. [2012/03/04 20:49:37 | 000,000,000 | ---D | C] -- C:\Downloads
  369. [2012/03/04 20:48:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Orbit
  370. [2012/03/04 15:56:56 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7F993BD0-AD53-4B0E-ACA0-E0DB6993265F}
  371. [2012/03/04 15:56:42 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{BCC834AF-0202-4286-BAC6-02E99123926C}
  372. [2012/03/03 10:27:20 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{E3F2AA91-700A-4E0E-B6B9-3B74F4D68AC5}
  373. [2012/03/03 10:26:57 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A4C8D0BE-4958-4E7C-9831-4E6FCD5AEB97}
  374. [2012/03/02 17:35:21 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7B07A2B3-D957-463E-9ACB-EBFD83EFB264}
  375. [2012/03/02 17:35:08 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B421DE10-8726-4CE6-838E-91643ED4060B}
  376. [2012/03/02 13:02:44 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\ElevatedDiagnostics
  377. [2012/03/02 12:34:52 | 000,000,000 | ---D | C] -- C:\Windows\en
  378. [2012/03/02 12:34:49 | 000,000,000 | ---D | C] -- C:\Windows\ar
  379. [2012/03/02 12:34:46 | 000,000,000 | ---D | C] -- C:\Windows\es
  380. [2012/03/02 12:34:42 | 000,000,000 | ---D | C] -- C:\Windows\fr
  381. [2012/03/02 12:34:39 | 000,000,000 | ---D | C] -- C:\Windows\th
  382. [2012/03/02 12:34:36 | 000,000,000 | ---D | C] -- C:\Windows\tr
  383. [2012/03/02 12:28:28 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7A93EA29-9FCD-4D40-92D9-8CCACF9A7E0C}
  384. [2012/03/02 12:28:15 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{DB9D093C-F422-4156-A791-ACF607460E01}
  385. [2012/03/01 21:23:03 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7FD843EB-3002-46EB-93AA-832A78867241}
  386. [2012/03/01 21:22:50 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{3953C46C-1F06-481C-A97D-9A27C929DB6A}
  387. [2012/03/01 19:06:02 | 000,545,064 | ---- | C] (BitDefender) -- C:\Windows\SysNative\drivers\avckf.sys
  388. [2012/03/01 10:37:51 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{04C75AAF-92FA-489E-A67E-D3A91183C544}
  389. [2012/03/01 10:37:40 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A019EC7A-7150-444F-AC65-095735EBDCA2}
  390. [2012/03/01 08:46:22 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Media Player Classic
  391. [2012/03/01 08:34:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
  392. [2012/03/01 08:34:39 | 000,839,680 | ---- | C] ( -- C:\Windows\SysWow64\lameACM.acm
  393. [2012/03/01 08:34:39 | 000,630,784 | ---- | C] ( -- C:\Windows\SysWow64\vp7vfw.dll
  394. [2012/03/01 08:34:39 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\SysWow64\ac3acm.acm
  395. [2012/03/01 08:34:39 | 000,039,936 | ---- | C] (Disappearing Inc.) -- C:\Windows\SysWow64\huffyuv.dll
  396. [2012/03/01 08:34:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack
  397. [2012/03/01 08:24:37 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{883F74F2-D150-4D16-BA8D-0789FAEF8518}
  398. [2012/03/01 08:24:24 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{B2D8691D-81D3-4DA8-B2AB-51DBF4DC55D2}
  399. [2012/02/29 19:27:53 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{7A9AAE4D-AD1E-4499-B747-0CF72B893950}
  400. [2012/02/29 18:24:23 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\GarenaPlus
  401. [2012/02/29 18:24:00 | 000,000,000 | ---D | C] -- C:\ProgramData\GarenaMessenger
  402. [2012/02/29 18:09:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
  403. [2012/02/29 17:10:58 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{A8B24115-AA63-4F2E-9B21-BDBFDAC45227}
  404. [2012/02/29 17:01:12 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
  405. [2012/02/26 11:27:41 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{4EC80F40-60B5-4E93-9E72-7DB5F1ED1F3A}
  406. [2012/02/26 11:27:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\Windows Live Writer
  407. [2012/02/26 11:27:26 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\Windows Live Writer
  408. [2012/02/25 20:37:45 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\FLEXnet
  409. [2012/02/25 20:16:06 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{5E26A76C-5674-4596-B768-444014D744B6}
  410. [2012/02/25 19:57:50 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\InstallShield
  411. [2012/02/25 19:56:18 | 000,000,000 | -H-D | C] -- C:\ASUS.DAT
  412. [2012/02/25 19:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virage Logic, Corp
  413. [2012/02/25 19:53:08 | 000,648,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
  414. [2012/02/25 19:53:05 | 003,048,552 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
  415. [2012/02/25 19:53:02 | 002,392,168 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
  416. [2012/02/25 19:53:01 | 001,242,216 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
  417. [2012/02/25 19:52:49 | 000,084,584 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInst64.dll
  418. [2012/02/25 19:52:47 | 000,952,320 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoRes64.dat
  419. [2012/02/25 19:51:30 | 002,075,712 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
  420. [2012/02/23 09:06:21 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Roaming\PlayFirst
  421. [2012/02/23 09:06:21 | 000,000,000 | ---D | C] -- C:\ProgramData\PlayFirst
  422. [2012/02/23 08:55:52 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\2DBoy
  423. [2012/02/23 08:55:52 | 000,000,000 | ---D | C] -- C:\ProgramData\2DBoy
  424. [2012/02/22 18:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Oberon Media
  425. [2012/02/22 11:21:21 | 000,082,432 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSXML4r.dll
  426. [2012/02/22 11:21:20 | 000,044,544 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSXML4a.dll
  427. [2012/02/22 11:21:19 | 000,626,960 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hpvaut32.dll
  428. [2012/02/22 11:21:19 | 000,487,424 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hpvcp70.dll
  429. [2012/02/21 18:48:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard
  430. [2012/02/21 18:48:18 | 000,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
  431. [2012/02/21 18:48:15 | 000,327,168 | ---- | C] (InstallShield Software Corporation, Inc.) -- C:\Windows\IsUn0416.exe
  432. [2012/02/21 18:47:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
  433. [2012/02/21 18:47:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hewlett-Packard
  434. [2012/02/21 18:06:16 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{1F32B18D-2E3F-4BA8-802B-F8204F60316F}
  435. [2012/02/21 14:04:39 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{63C90230-B37E-4468-BB13-64DC101863E1}
  436. [2012/02/21 12:36:48 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\gean.anjo
  437. [2012/02/21 12:36:46 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\SafeBox
  438. [2012/02/21 10:33:27 | 000,000,000 | ---D | C] -- C:\Users\Gean\AppData\Local\{880DE715-1389-4AF8-BCD0-0CA0E4313A0F}
  440. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  442. [2012/03/21 22:55:05 | 000,000,322 | ---- | M] () -- C:\Windows\SysNative\checkdnsid.xml
  443. [2012/03/21 22:52:46 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Gean\Desktop\OTL.exe
  444. [2012/03/21 22:36:27 | 000,019,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  445. [2012/03/21 22:36:27 | 000,019,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  446. [2012/03/21 22:27:02 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  447. [2012/03/21 22:23:56 | 000,205,626 | ---- | M] () -- C:\Users\Gean\Desktop\3.png
  448. [2012/03/21 22:23:09 | 000,205,636 | ---- | M] () -- C:\Users\Gean\Desktop\2.png
  449. [2012/03/21 22:22:32 | 000,205,481 | ---- | M] () -- C:\Users\Gean\Desktop\1.png
  450. [2012/03/21 21:29:54 | 000,007,603 | ---- | M] () -- C:\Users\Gean\AppData\Local\resmon.resmoncfg
  451. [2012/03/21 21:04:26 | 000,045,056 | ---- | M] () -- C:\Windows\SysWow64\acovcnt.exe
  452. [2012/03/21 21:04:24 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  453. [2012/03/21 21:03:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  454. [2012/03/21 21:03:14 | 467,849,215 | -HS- | M] () -- C:\hiberfil.sys
  455. [2012/03/21 19:38:56 | 006,550,093 | ---- | M] () -- C:\Windows\SysNative\cwlog.dtl
  456. [2012/03/21 18:32:23 | 000,002,344 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
  457. [2012/03/21 18:31:02 | 000,381,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppcommdlg.dll
  458. [2012/03/21 18:31:01 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll
  459. [2012/03/21 18:31:00 | 001,008,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
  460. [2012/03/21 18:30:58 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppwmi.dll
  461. [2012/03/21 18:30:57 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll
  462. [2012/03/21 18:29:46 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
  463. [2012/03/21 18:29:46 | 000,349,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slui.exe
  464. [2012/03/21 18:29:46 | 000,107,946 | ---- | M] () -- C:\Windows\SysNative\slmgr.vbs
  465. [2012/03/21 18:29:46 | 000,002,048 | ---- | M] () -- C:\Windows\SysNative\winver.exe
  466. [2012/03/21 18:29:45 | 002,169,856 | -HS- | M] () -- C:\Windows\SysNative\hale.exe
  467. [2012/03/21 18:20:34 | 000,203,316 | ---- | M] () -- C:\grldr.bak
  468. [2012/03/21 18:03:31 | 000,327,367 | RHS- | M] () -- C:\bootmgr
  469. [2012/03/21 17:42:01 | 001,555,682 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  470. [2012/03/21 17:42:01 | 000,678,120 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
  471. [2012/03/21 17:42:01 | 000,630,324 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  472. [2012/03/21 17:42:01 | 000,132,690 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
  473. [2012/03/21 17:42:01 | 000,110,984 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  474. [2012/03/20 11:36:31 | 004,972,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  475. [2012/03/19 23:52:36 | 000,000,955 | ---- | M] () -- C:\Windows\wininit.ini
  476. [2012/03/19 23:48:46 | 000,001,265 | ---- | M] () -- C:\Users\Gean\Desktop\Ccleaner Business Edition.lnk
  477. [2012/03/14 21:13:31 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
  478. [2012/03/13 20:57:43 | 000,051,270 | ---- | M] () -- C:\Users\Gean\AppData\Roaming\room_v3.dat
  479. [2012/03/13 10:33:53 | 000,001,187 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
  480. [2012/03/01 19:06:02 | 000,545,064 | ---- | M] (BitDefender) -- C:\Windows\SysNative\drivers\avckf.sys
  481. [2012/03/01 19:04:21 | 000,690,872 | ---- | M] (BitDefender) -- C:\Windows\SysNative\drivers\avc3.sys
  482. [2012/02/25 20:51:05 | 000,000,024 | ---- | M] () -- C:\Windows\ATKPF.ini
  483. [2012/02/25 20:05:29 | 000,086,890 | ---- | M] () -- C:\Windows\AsCD_Item_40.jpg
  484. [2012/02/25 19:56:18 | 000,002,617 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
  485. [2012/02/22 19:10:39 | 000,000,014 | ---- | M] () -- C:\Windows\popcinfo.dat
  486. [2012/02/21 18:49:33 | 000,179,084 | ---- | M] () -- C:\Windows\hpdj3500.his
  487. [2012/02/21 18:49:33 | 000,010,115 | ---- | M] () -- C:\Windows\hpdj3500.ini
  489. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  491. [2012/03/21 22:23:56 | 000,205,626 | ---- | C] () -- C:\Users\Gean\Desktop\3.png
  492. [2012/03/21 22:21:29 | 000,205,636 | ---- | C] () -- C:\Users\Gean\Desktop\2.png
  493. [2012/03/21 22:20:49 | 000,205,481 | ---- | C] () -- C:\Users\Gean\Desktop\1.png
  494. [2012/03/21 18:30:56 | 006,465,834 | ---- | C] () -- C:\Windows\SysNative\cwlog.dtl
  495. [2012/03/21 18:29:45 | 002,169,856 | -HS- | C] () -- C:\Windows\SysNative\hale.exe
  496. [2012/03/21 18:20:51 | 000,203,316 | ---- | C] () -- C:\grldr.bak
  497. [2012/03/20 11:34:57 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
  498. [2012/03/20 11:34:52 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
  499. [2012/03/20 11:27:01 | 000,051,867 | ---- | C] () -- C:\Windows\Ultimate.xml
  500. [2012/03/20 00:44:26 | 000,002,062 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
  501. [2012/03/20 00:44:25 | 000,002,617 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
  502. [2012/03/19 23:48:46 | 000,001,265 | ---- | C] () -- C:\Users\Gean\Desktop\Ccleaner Business Edition.lnk
  503. [2012/03/19 23:33:30 | 000,000,955 | ---- | C] () -- C:\Windows\wininit.ini
  504. [2012/03/14 21:36:05 | 000,001,095 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
  505. [2012/03/14 21:35:21 | 000,001,229 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
  506. [2012/03/14 21:33:29 | 000,001,191 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
  507. [2012/03/14 21:33:08 | 000,001,284 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
  508. [2012/03/14 21:32:13 | 000,001,385 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
  509. [2012/03/14 21:32:03 | 000,001,557 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
  510. [2012/03/14 21:13:31 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
  511. [2012/03/12 19:22:40 | 000,001,064 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  512. [2012/03/12 19:22:40 | 000,001,060 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  513. [2012/03/11 14:52:35 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
  514. [2012/03/07 12:50:06 | 000,000,322 | ---- | C] () -- C:\Windows\SysNative\checkdnsid.xml
  515. [2012/03/07 08:33:15 | 000,000,999 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
  516. [2012/03/01 08:34:40 | 000,000,414 | ---- | C] () -- C:\Windows\SysWow64\lame_acm.xml
  517. [2012/03/01 08:34:39 | 004,078,592 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
  518. [2012/03/01 08:34:39 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
  519. [2012/03/01 08:34:39 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
  520. [2012/03/01 08:34:39 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
  521. [2012/03/01 08:34:39 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
  522. [2012/03/01 08:34:37 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
  523. [2012/02/29 17:24:58 | 000,051,270 | ---- | C] () -- C:\Users\Gean\AppData\Roaming\room_v3.dat
  524. [2012/02/26 11:21:51 | 000,007,603 | ---- | C] () -- C:\Users\Gean\AppData\Local\resmon.resmoncfg
  525. [2012/02/25 20:05:29 | 000,086,890 | ---- | C] () -- C:\Windows\AsCD_Item_40.jpg
  526. [2012/02/22 19:10:39 | 000,000,014 | ---- | C] () -- C:\Windows\popcinfo.dat
  527. [2012/02/21 18:45:05 | 000,179,084 | ---- | C] () -- C:\Windows\hpdj3500.his
  528. [2012/02/21 18:45:05 | 000,010,115 | ---- | C] () -- C:\Windows\hpdj3500.ini
  529. [2012/02/20 12:35:08 | 001,565,436 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  530. [2012/02/18 09:53:52 | 001,856,058 | ---- | C] () -- C:\ProgramData\1329562271.bdinstall.bin
  531. [2012/02/18 07:36:24 | 000,021,594 | ---- | C] () -- C:\ProgramData\1329561378.bdinstall.bin
  532. [2012/02/18 07:34:35 | 000,021,594 | ---- | C] () -- C:\ProgramData\1329561266.bdinstall.bin
  533. [2012/02/18 07:33:45 | 000,330,231 | ---- | C] () -- C:\ProgramData\1329560463.bdinstall.bin
  534. [2012/02/18 07:12:19 | 000,000,502 | ---- | C] () -- C:\ProgramData\1329559938.bdinstall.bin
  535. [2012/02/06 12:06:36 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
  536. [2012/02/06 11:28:15 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\acovcnt.exe
  537. [2011/08/31 18:51:16 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
  538. [2011/08/31 18:46:00 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
  539. [2011/08/31 18:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
  540. [2011/07/06 10:29:57 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
  541. [2011/07/06 10:29:52 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
  542. [2011/04/12 01:49:32 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
  544. [color=#E56717]========== Alternate Data Streams ==========[/color]
  546. @Alternate Data Stream - 150 bytes -> C:\ProgramData\Temp:41099CE9
  547. @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:981884E7
  548. @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:52DBE86F
  549. @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:81F83028
  550. @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:3AE22B1A
  551. @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:D20FFA63
  552. @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:5D458568
  553. @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:3E7393FC
  555. < End of report >
