This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

OTL scan findings on my PC

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 3/15/2011 7:52:01 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:UsersAhmedDownloadsPrograms
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 37.11 Gb Total Space | 14.23 Gb Free Space | 38.34% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 7.66 Gb Free Space | 39.23% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 97.56 Gb Free Space | 99.90% Space Free | Partition Type: NTFS
Drive F: | 98.11 Gb Total Space | 97.98 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
Drive G: | 19.52 Gb Total Space | 19.52 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive H: | 19.52 Gb Total Space | 19.52 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive I: | 15.92 Gb Total Space | 15.83 Gb Free Space | 99.44% Space Free | Partition Type: NTFS

Computer Name: AHMED-PC | User Name: Ahmed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersAhmedDownloadsProgramsOTL.exe (OldTimer Tools)
PRC - C:Program FilesInternet Download ManagerIDMan.exe (Tonec Inc.)
PRC - C:Program FilesAVAST SoftwareAvastAvastUI.exe (AVAST Software)
PRC - C:Program FilesPaltalk Messengerpaltalk.exe (AVM Software Inc.)
PRC - C:Program FilesYahoo!MessengerYahooMessenger.exe (Yahoo! Inc.)
PRC - C:Program FilesInternet Download ManagerIEMonitor.exe (Tonec Inc.)
PRC - C:Windowsexplorer.exe (Microsoft Corporation)
PRC - C:WindowsSystem32taskhost.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:UsersAhmedDownloadsProgramsOTL.exe (OldTimer Tools)
MOD - C:Program FilesAVAST SoftwareAvastsnxhk.dll (AVAST Software)
MOD - C:Program FilesInternet Download Manageridmmkb.dll (Tonec Inc.)
MOD - C:Program FilesPaltalk Messengerctrlkey.dll ()
MOD - C:Windowswinsxsx86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bdcomctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WatAdminSvc) – C:WindowsSystem32WatWatAdminSvc.exe (Microsoft Corporation)
SRV - (BBSvc) – C:Program FilesMicrosoftBingBarBBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:Program FilesMicrosoftBingBarSeaPort.EXE (Microsoft Corporation)
SRV - (avast! Antivirus) – C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
SRV - (TVersityMediaServer) – C:ProgramDataTVersityMedia ServerMediaServer.exe ()
SRV - (SensrSvc) – C:WindowsSystem32sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:Program FilesYahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:WindowsSystem32driversaswSnx.sys (AVAST Software)
DRV - (aswSP) – C:WindowsSystem32driversaswSP.sys (AVAST Software)
DRV - (aswTdi) – C:WindowsSystem32driversaswTdi.sys (AVAST Software)
DRV - (aswRdr) – C:WindowsSystem32driversaswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:WindowsSystem32driversaswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:WindowsSystem32driversaswFsBlk.sys (AVAST Software)
DRV - (IDMWFP) – C:WindowsSystem32driversidmwfp.sys (Tonec Inc.)
DRV - (WinUsb) – C:WindowsSystem32driverswinusb.sys (Microsoft Corporation)
DRV - (Ph3xIB32) – C:WindowsSystem32driversPh3xIB32.sys (NXP Semiconductors)
DRV - (e1express) Intel® – C:WindowsSystem32driverse1e6032.sys (Intel Corporation)
DRV - (speedfan) – C:Windowssystem32speedfan.sys (Windows ® 2000 DDK provider)
DRV - (giveio) – C:Windowssystem32giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.yahoo.com
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com
IE - HKLM..URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:Program FilesTVersitybartbTVer.dll (Conduit Ltd.)

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2548838
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache = http://www.msn.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache_TIMESTAMP = 1C 60 3E F6 FF DB CB 01 [binary data]
IE - HKCU..URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:Program FilesTVersitybartbTVer.dll (Conduit Ltd.)
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2009/06/11 02:39:37 | 000,000,824 | —- | M]) - C:WindowsSystem32driversetchosts
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:Program FilesInternet Download ManagerIDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O2 - BHO: (TVersitybar Toolbar) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:Program FilesTVersitybartbTVer.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:Program FilesMicrosoftBingBarBingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM..Toolbar: (TVersitybar Toolbar) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:Program FilesTVersitybartbTVer.dll (Conduit Ltd.)
O3 - HKLM..Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:Program FilesMicrosoftBingBarBingExt.dll (Microsoft Corporation.)
O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll ()
O3 - HKLM..Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O3 - HKCU..ToolbarWebBrowser: (TVersitybar Toolbar) - {66BD2442-241B-44CD-8C7A-B51037053CDB} - C:Program FilesTVersitybartbTVer.dll (Conduit Ltd.)
O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)
O4 - HKCU..Run: [IDMan] C:Program FilesInternet Download ManagerIDMan.exe (Tonec Inc.)
O4 - HKCU..Run: [Messenger (Yahoo!)] C:Program FilesYahoo!MessengerYahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..Run: [uTorrent] C:Program FilesuTorrentuTorrent.exe (BitTorrent, Inc.)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 5
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: EnableLUA = 0
O8 - Extra context menu item: Download all links with IDM - C:Program FilesInternet Download ManagerIEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:Program FilesInternet Download ManagerIEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:Program FilesInternet Download ManagerIEExt.htm ()
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:Program FilesPaltalk Messengerpaltalk.exe (AVM Software Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.1
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)
O18 - ProtocolHandlerskype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:WindowsSystem32SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 02:42:20 | 000,000,024 | —- | M] () - C:autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:WindowsSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:WindowsSystem32iccvid.dll (Radius Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/03/15 19:40:00 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{388C4109-687F-4993-B09B-31337FF5ED6C}
[2011/03/15 17:24:45 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{9A629DE6-0CBE-4B92-9E25-8E043CB6C97D}
[2011/03/15 00:29:27 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{6EEB3706-5A1A-4C9D-9838-13993F894ECD}
[2011/03/14 12:25:38 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{A789FDCD-6225-4523-A76F-2516C0A02BF1}
[2011/03/14 12:23:52 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{56317582-FD97-428C-A1E8-6940606927D1}
[2011/03/14 11:21:50 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{CD461D21-451D-4D56-A659-F61C3A4F2C90}
[2011/03/13 17:57:09 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{2D76B631-95A9-4DBC-9368-8B4D5E57A508}
[2011/03/13 05:56:42 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{3B5AEB9D-3592-43C6-B379-D6B553D16697}
[2011/03/13 05:50:28 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{92CB2FCB-D81E-40A8-B56A-C918B2169089}
[2011/03/13 05:40:23 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{C9E1311E-1397-4E5C-8ACE-A76E30DA9BAB}
[2011/03/13 05:35:47 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{E292CE50-DD9D-4CE8-A6AC-8C002641BFA4}
[2011/03/13 03:05:22 | 000,000,000 | —D | C] – C:WindowsSun
[2011/03/12 21:39:18 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramssXe Injected
[2011/03/12 21:39:05 | 000,000,000 | —D | C] – C:Program FilessXe Injected
[2011/03/12 21:30:48 | 000,000,000 | —D | C] – C:Program FilesValve
[2011/03/12 21:30:16 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingWinRAR
[2011/03/12 21:30:16 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsWinRAR
[2011/03/12 21:30:16 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsWinRAR
[2011/03/12 21:30:03 | 000,000,000 | —D | C] – C:Program FilesWinRAR
[2011/03/12 16:54:56 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{B126523A-4694-4EA8-8C10-F73503D5C0E3}
[2011/03/12 04:54:27 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{74313981-333D-45AB-A7CB-760A72F4EB39}
[2011/03/11 16:08:53 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{1E1B18F1-2162-4705-9EAE-F09D538C3E4C}
[2011/03/11 04:08:27 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{AA410385-0241-4531-B2D9-591D14AFF6F2}
[2011/03/11 04:00:45 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{CCC84153-7E50-416E-96A9-271D83801B17}
[2011/03/11 01:12:07 | 000,000,000 | —D | C] – C:WindowsCheckSur
[2011/03/10 16:01:46 | 000,000,000 | —D | C] – C:Program FilesConduit
[2011/03/10 16:01:45 | 000,000,000 | —D | C] – C:Program FilesTVersitybar
[2011/03/10 16:01:26 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsTVersity Media Server
[2011/03/10 16:01:25 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsTVersity Codec Pack
[2011/03/10 16:01:24 | 000,000,000 | —D | C] – C:Program FilesTVersity Codec Pack
[2011/03/10 16:01:16 | 000,000,000 | —D | C] – C:ProgramDataTVersity
[2011/03/10 15:58:34 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{824C4227-02E5-4748-8743-9598BC3B94E2}
[2011/03/10 01:54:36 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{AF337C20-4EC3-4664-B35A-56E338EA0211}
[2011/03/09 22:49:42 | 001,074,176 | —- | C] (Microsoft Corporation) – C:WindowsSystem32DWrite.dll
[2011/03/09 22:49:41 | 000,739,840 | —- | C] (Microsoft Corporation) – C:WindowsSystem32d2d1.dll
[2011/03/09 13:54:10 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{EBCFC053-DE45-42C7-9450-703F91D78FBF}
[2011/03/09 13:54:10 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{CD4DD7CD-3930-4669-A024-3A1A7E713AE2}
[2011/03/08 21:14:19 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{D75234FE-D8D2-4EBD-9156-3959AE701DBA}
[2011/03/08 19:00:20 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{77CD2B52-5E47-4E84-8B0D-8209DE07D817}
[2011/03/08 09:02:01 | 000,000,000 | —D | C] – C:Program FilesMicrosoft.NET
[2011/03/08 06:59:55 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{5BDAB807-7321-4706-A275-2B8C4E7E857B}
[2011/03/08 05:26:23 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsSpeedFan
[2011/03/08 05:26:23 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsSpeedFan
[2011/03/08 05:26:23 | 000,000,000 | —D | C] – C:Program FilesSpeedFan
[2011/03/07 21:20:10 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalDiagnostics
[2011/03/07 20:14:04 | 000,000,000 | —D | C] – C:UsersAhmedDocumentsMy Received Files
[2011/03/07 18:59:29 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{BF06A90A-9618-418E-A710-E49CEF294288}
[2011/03/07 18:17:40 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{1D886AAE-2E06-4D5F-8742-41F4C2ECBB26}
[2011/03/07 18:14:46 | 000,000,000 | —D | C] – C:WindowsSystem32Wat
[2011/03/07 06:59:04 | 000,000,000 | —D | C] – C:WindowsSoftwareDistribution
[2011/03/07 06:57:15 | 000,295,264 | —- | C] (Microsoft Corporation) – C:WindowsSystem32PresentationHost.exe
[2011/03/07 06:57:15 | 000,099,176 | —- | C] (Microsoft Corporation) – C:WindowsSystem32PresentationHostProxy.dll
[2011/03/07 06:57:15 | 000,049,472 | —- | C] (Microsoft Corporation) – C:WindowsSystem32netfxperf.dll
[2011/03/07 06:56:52 | 000,000,000 | —D | C] – C:WindowsPrefetch
[2011/03/07 06:55:18 | 000,000,000 | —D | C] – C:WindowsPanther
[2011/03/07 06:50:18 | 000,190,976 | —- | C] (Microsoft Corporation) – C:WindowsSystem32driversks.sys
[2011/03/07 06:48:56 | 000,000,000 | —D | C] – C:Windows.old
[2011/03/07 06:46:50 | 000,000,000 | -HSD | C] – C:Boot
[2011/03/07 03:49:48 | 000,000,000 | —D | C] – C:ProgramDataSun
[2011/03/07 03:49:48 | 000,000,000 | —D | C] – C:Program FilesCommon FilesJava
[2011/03/07 03:49:22 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSystem32deployJava1.dll
[2011/03/07 03:49:22 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSystem32javaws.exe
[2011/03/07 03:49:22 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSystem32javaw.exe
[2011/03/07 03:49:22 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:WindowsSystem32java.exe
[2011/03/07 03:49:10 | 000,000,000 | —D | C] – C:Program FilesJava
[2011/03/07 03:48:48 | 000,000,000 | —D | C] – C:ProgramDataMcAfee
[2011/03/07 03:21:53 | 000,197,632 | —- | C] (Intel® Corporation) – C:WindowsSystem32ir32_32.dll
[2011/03/07 03:21:53 | 000,082,944 | —- | C] (Radius Inc.) – C:WindowsSystem32iccvid.dll
[2011/03/07 03:21:47 | 002,614,272 | —- | C] (Microsoft Corporation) – C:Windowsexplorer.exe
[2011/03/07 03:21:40 | 000,109,056 | —- | C] (Microsoft Corporation) – C:WindowsSystem32t2embed.dll
[2011/03/07 03:21:30 | 000,002,048 | —- | C] (Microsoft Corporation) – C:WindowsSystem32tzres.dll
[2011/03/07 03:21:23 | 000,641,536 | —- | C] (Microsoft Corporation) – C:WindowsSystem32CPFilters.dll
[2011/03/07 03:21:22 | 000,465,408 | —- | C] (Microsoft Corporation) – C:WindowsSystem32psisdecd.dll
[2011/03/07 03:21:22 | 000,417,792 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msdri.dll
[2011/03/07 03:21:22 | 000,204,288 | —- | C] (Microsoft Corporation) – C:WindowsSystem32MSNP.ax
[2011/03/07 03:21:22 | 000,199,680 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mpg2splt.ax
[2011/03/07 03:21:07 | 002,329,088 | —- | C] (Microsoft Corporation) – C:WindowsSystem32win32k.sys
[2011/03/07 03:21:01 | 000,496,128 | —- | C] (Microsoft Corporation) – C:WindowsSystem32taskschd.dll
[2011/03/07 03:21:01 | 000,351,232 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wmicmiplugin.dll
[2011/03/07 03:21:01 | 000,305,152 | —- | C] (Microsoft Corporation) – C:WindowsSystem32taskcomp.dll
[2011/03/07 03:21:01 | 000,179,712 | —- | C] (Microsoft Corporation) – C:WindowsSystem32schtasks.exe
[2011/03/07 03:20:48 | 001,037,312 | —- | C] (Microsoft Corporation) – C:WindowsSystem32lsasrv.dll
[2011/03/07 03:20:39 | 000,037,376 | —- | C] (Microsoft Corporation) – C:WindowsSystem32rtutils.dll
[2011/03/07 03:20:16 | 000,573,440 | —- | C] (Microsoft Corporation) – C:WindowsSystem32odbc32.dll
[2011/03/07 03:20:04 | 001,320,960 | —- | C] (Microsoft Corporation) – C:WindowsSystem32CertEnroll.dll
[2011/03/07 03:20:03 | 000,507,568 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winload.exe
[2011/03/07 03:20:03 | 000,442,920 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winresume.exe
[2011/03/07 03:19:47 | 000,067,584 | —- | C] (Microsoft Corporation) – C:WindowsSystem32asycfilt.dll
[2011/03/07 03:19:35 | 000,954,752 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mfc40.dll
[2011/03/07 03:19:35 | 000,954,288 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mfc40u.dll
[2011/03/07 03:19:20 | 000,716,800 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jscript.dll
[2011/03/07 03:19:20 | 000,428,032 | —- | C] (Microsoft Corporation) – C:WindowsSystem32vbscript.dll
[2011/03/07 03:19:01 | 012,625,408 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wmploc.DLL
[2011/03/07 03:18:55 | 000,026,504 | —- | C] (Microsoft Corporation) – C:WindowsSystem32driversDiskdump.sys
[2011/03/07 03:18:44 | 000,606,208 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mstime.dll
[2011/03/07 03:18:44 | 000,599,040 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2011/03/07 03:18:44 | 000,381,440 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iedkcs32.dll
[2011/03/07 03:18:44 | 000,185,856 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iepeers.dll
[2011/03/07 03:18:44 | 000,064,512 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeedsbs.dll
[2011/03/07 03:18:43 | 001,638,912 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2011/03/07 03:18:43 | 000,386,048 | —- | C] (Microsoft Corporation) – C:WindowsSystem32html.iec
[2011/03/07 03:18:43 | 000,044,544 | —- | C] (Microsoft Corporation) – C:WindowsSystem32licmgr10.dll
[2011/03/07 03:18:43 | 000,012,800 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeedssync.exe
[2011/03/07 03:18:22 | 001,328,640 | —- | C] (Microsoft Corporation) – C:WindowsSystem32quartz.dll
[2011/03/07 03:18:22 | 000,091,648 | —- | C] (Microsoft Corporation) – C:WindowsSystem32avifil32.dll
[2011/03/07 03:18:22 | 000,084,480 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mciavi32.dll
[2011/03/07 03:18:16 | 000,314,368 | —- | C] (Microsoft Corporation) – C:WindowsSystem32webio.dll
[2011/03/07 03:18:04 | 000,442,880 | —- | C] (Microsoft Corporation) – C:WindowsSystem32XpsPrint.dll
[2011/03/07 03:18:04 | 000,288,256 | —- | C] (Microsoft Corporation) – C:WindowsSystem32XpsGdiConverter.dll
[2011/03/07 03:17:58 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:WindowsSystem32atmfd.dll
[2011/03/07 03:17:58 | 000,070,656 | —- | C] (Microsoft Corporation) – C:WindowsSystem32fontsub.dll
[2011/03/07 03:17:57 | 000,034,304 | —- | C] (Adobe Systems) – C:WindowsSystem32atmlib.dll
[2011/03/07 03:17:35 | 003,957,120 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ntkrnlpa.exe
[2011/03/07 03:17:35 | 003,901,824 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ntoskrnl.exe
[2011/03/07 03:17:26 | 001,170,944 | —- | C] (Microsoft Corporation) – C:WindowsSystem32d3d10warp.dll
[2011/03/07 03:17:25 | 001,495,040 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ExplorerFrame.dll
[2011/03/07 03:17:25 | 000,218,624 | —- | C] (Microsoft Corporation) – C:WindowsSystem32d3d10_1core.dll
[2011/03/07 03:17:25 | 000,161,792 | —- | C] (Microsoft Corporation) – C:WindowsSystem32d3d10_1.dll
[2011/03/07 03:17:25 | 000,135,168 | —- | C] (Microsoft Corporation) – C:WindowsSystem32XpsRasterService.dll
[2011/03/07 03:15:03 | 000,204,288 | —- | C] (Microsoft Corporation) – C:WindowsSystem32upnp.dll
[2011/03/07 03:15:02 | 000,176,640 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2011/03/07 03:15:02 | 000,080,384 | —- | C] (Microsoft Corporation) – C:WindowsSystem32davclnt.dll
[2011/03/07 03:15:02 | 000,051,200 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wscapi.dll
[2011/03/07 03:15:02 | 000,048,128 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2011/03/07 03:15:02 | 000,014,336 | —- | C] (Microsoft Corporation) – C:WindowsSystem32slwga.dll
[2011/03/07 03:14:40 | 000,738,816 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wmpmde.dll
[2011/03/07 03:14:34 | 000,101,760 | —- | C] (Microsoft Corporation) – C:WindowsSystem32consent.exe
[2011/03/07 03:14:22 | 000,369,152 | —- | C] (Microsoft Corporation) – C:WindowsSystem32secproc.dll
[2011/03/07 03:14:22 | 000,365,568 | —- | C] (Microsoft Corporation) – C:WindowsSystem32secproc_isv.dll
[2011/03/07 03:14:22 | 000,324,608 | —- | C] (Microsoft Corporation) – C:WindowsSystem32RMActivate_isv.exe
[2011/03/07 03:14:22 | 000,320,512 | —- | C] (Microsoft Corporation) – C:WindowsSystem32RMActivate.exe
[2011/03/07 03:14:22 | 000,280,064 | —- | C] (Microsoft Corporation) – C:WindowsSystem32RMActivate_ssp.exe
[2011/03/07 03:14:22 | 000,277,504 | —- | C] (Microsoft Corporation) – C:WindowsSystem32RMActivate_ssp_isv.exe
[2011/03/07 03:14:22 | 000,085,504 | —- | C] (Microsoft Corporation) – C:WindowsSystem32secproc_ssp_isv.dll
[2011/03/07 03:14:22 | 000,085,504 | —- | C] (Microsoft Corporation) – C:WindowsSystem32secproc_ssp.dll
[2011/03/07 03:13:47 | 000,219,008 | —- | C] (Microsoft Corporation) – C:WindowsSystem32driversdxgmms1.sys
[2011/03/07 03:13:47 | 000,107,520 | —- | C] (Microsoft Corporation) – C:WindowsSystem32cdd.dll
[2011/03/06 23:44:39 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalYahoo
[2011/03/06 21:18:47 | 000,000,000 | —D | C] – C:ProgramDataYahoo! Companion
[2011/03/06 21:18:47 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingYahoo!
[2011/03/06 21:18:42 | 000,000,000 | —D | C] – C:WindowsSystem32Macromed
[2011/03/06 21:18:28 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsYahoo! Messenger
[2011/03/06 21:18:26 | 000,000,000 | —D | C] – C:ProgramDataYahoo!
[2011/03/06 21:03:07 | 000,000,000 | —D | C] – C:Program FilesYahoo!
[2011/03/06 20:37:25 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsPaltalkScene
[2011/03/06 20:37:23 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingPaltalk
[2011/03/06 20:37:20 | 000,000,000 | —D | C] – C:WindowsPaltalkScene
[2011/03/06 20:37:20 | 000,000,000 | —D | C] – C:Program FilesPaltalk Messenger
[2011/03/06 20:18:41 | 000,019,544 | —- | C] (AVAST Software) – C:WindowsSystem32driversaswFsBlk.sys
[2011/03/06 20:18:41 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsavast! Free Antivirus
[2011/03/06 20:18:40 | 000,301,528 | —- | C] (AVAST Software) – C:WindowsSystem32driversaswSP.sys
[2011/03/06 20:18:39 | 000,371,544 | —- | C] (AVAST Software) – C:WindowsSystem32driversaswSnx.sys
[2011/03/06 20:18:39 | 000,049,240 | —- | C] (AVAST Software) – C:WindowsSystem32driversaswTdi.sys
[2011/03/06 20:18:39 | 000,025,432 | —- | C] (AVAST Software) – C:WindowsSystem32driversaswRdr.sys
[2011/03/06 20:18:37 | 000,053,592 | —- | C] (AVAST Software) – C:WindowsSystem32driversaswMonFlt.sys
[2011/03/06 20:18:10 | 000,190,016 | —- | C] (AVAST Software) – C:WindowsSystem32aswBoot.exe
[2011/03/06 20:18:10 | 000,040,648 | —- | C] (AVAST Software) – C:WindowsavastSS.scr
[2011/03/06 20:18:08 | 000,000,000 | —D | C] – C:ProgramDataAVAST Software
[2011/03/06 20:18:08 | 000,000,000 | —D | C] – C:Program FilesAVAST Software
[2011/03/06 20:11:48 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingIDM
[2011/03/06 20:11:47 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingDMCache
[2011/03/06 20:11:46 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsInternet Download Manager
[2011/03/06 20:11:46 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsInternet Download Manager
[2011/03/06 20:11:45 | 000,000,000 | —D | C] – C:Program FilesInternet Download Manager
[2011/03/06 20:04:57 | 000,000,000 | —D | C] – C:Program FilesuTorrent
[2011/03/06 20:04:28 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoaminguTorrent
[2011/03/06 19:53:20 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocal{1F16BE85-D20F-420E-971E-07541AE255F4}
[2011/03/06 19:53:07 | 000,000,000 | —D | C] – C:UsersAhmedTracing
[2011/03/06 19:50:39 | 000,000,000 | —D | C] – C:Program FilesMicrosoft SQL Server Compact Edition
[2011/03/06 19:50:13 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingskypePM
[2011/03/06 19:49:58 | 000,000,000 | —D | C] – C:WindowsPCHEALTH
[2011/03/06 19:00:23 | 000,398,336 | —- | C] (Intel® Corporation) – C:WindowsSystem32TVWizudlg.exe
[2011/03/06 19:00:23 | 000,000,000 | —D | C] – C:WindowsSystem32Lang
[2011/03/06 19:00:22 | 000,000,000 | —D | C] – C:Program FilesIntel
[2011/03/06 18:58:16 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalElevatedDiagnostics
[2011/03/06 18:55:35 | 000,000,000 | —D | C] – C:Windowsen
[2011/03/06 18:53:10 | 000,000,000 | —D | C] – C:WindowsSystem32RTCOM
[2011/03/06 18:52:49 | 003,804,264 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsSystem32RtkAPO.dll
[2011/03/06 18:52:49 | 002,137,704 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsSystem32RtkPgExt.dll
[2011/03/06 18:52:49 | 001,783,056 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32WavesLib.dll
[2011/03/06 18:52:49 | 001,723,536 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32WavesGUILib.dll
[2011/03/06 18:52:49 | 001,705,816 | —- | C] (Dolby Laboratories) – C:WindowsSystem32R4EEP32A.dll
[2011/03/06 18:52:49 | 001,439,064 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32MaxxAudioRealtek.dll
[2011/03/06 18:52:49 | 001,084,008 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsSystem32RTSndMgr.cpl
[2011/03/06 18:52:49 | 000,783,360 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsSystem32RCoRes.dat
[2011/03/06 18:52:49 | 000,477,800 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsSystem32RtkApoApi.dll
[2011/03/06 18:52:49 | 000,359,768 | —- | C] (Dolby Laboratories, Inc.) – C:WindowsSystem32RTEEP32A.dll
[2011/03/06 18:52:49 | 000,345,328 | —- | C] (SRS Labs, Inc.) – C:WindowsSystem32SRSTSXT.dll
[2011/03/06 18:52:49 | 000,341,848 | —- | C] (Dolby Laboratories) – C:WindowsSystem32R4EED32A.dll
[2011/03/06 18:52:49 | 000,295,768 | —- | C] (Dolby Laboratories, Inc.) – C:WindowsSystem32RP3DHT32.dll
[2011/03/06 18:52:49 | 000,295,768 | —- | C] (Dolby Laboratories, Inc.) – C:WindowsSystem32RP3DAA32.dll
[2011/03/06 18:52:49 | 000,252,760 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32MaxxVolumeSDAPO.dll
[2011/03/06 18:52:49 | 000,214,352 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:WindowsSystem32SFNHK.dll
[2011/03/06 18:52:49 | 000,185,584 | —- | C] (SRS Labs, Inc.) – C:WindowsSystem32SRSTSHD.dll
[2011/03/06 18:52:49 | 000,173,296 | —- | C] (SRS Labs, Inc.) – C:WindowsSystem32SRSHP360.dll
[2011/03/06 18:52:49 | 000,170,840 | —- | C] (Dolby Laboratories, Inc.) – C:WindowsSystem32RTEED32A.dll
[2011/03/06 18:52:49 | 000,140,528 | —- | C] (SRS Labs, Inc.) – C:WindowsSystem32SRSWOW.dll
[2011/03/06 18:52:49 | 000,096,600 | —- | C] (Dolby Laboratories) – C:WindowsSystem32R4EEL32A.dll
[2011/03/06 18:52:49 | 000,081,240 | —- | C] (Dolby Laboratories) – C:WindowsSystem32R4EEA32A.dll
[2011/03/06 18:52:49 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:WindowsSystem32RTEEL32A.dll
[2011/03/06 18:52:49 | 000,074,064 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:WindowsSystem32SFCOM.dll
[2011/03/06 18:52:49 | 000,069,224 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsSystem32RtkCoInst.dll
[2011/03/06 18:52:49 | 000,068,944 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:WindowsSystem32SFAPO.dll
[2011/03/06 18:52:49 | 000,064,856 | —- | C] (Dolby Laboratories, Inc.) – C:WindowsSystem32RTEEG32A.dll
[2011/03/06 18:52:49 | 000,061,784 | —- | C] (Dolby Laboratories) – C:WindowsSystem32R4EEG32A.dll
[2011/03/06 18:52:48 | 001,938,704 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32MaxxAudioEQ.dll
[2011/03/06 18:52:48 | 001,564,736 | —- | C] (Fortemedia Corporation) – C:WindowsSystem32FMAPO.dll
[2011/03/06 18:52:48 | 001,132,648 | —- | C] (DTS) – C:WindowsSystem32DTSS2SpeakerDLL.dll
[2011/03/06 18:52:48 | 000,962,664 | —- | C] (DTS) – C:WindowsSystem32DTSS2HeadphoneDLL.dll
[2011/03/06 18:52:48 | 000,901,224 | —- | C] (DTS) – C:WindowsSystem32DTSBoostDLL.dll
[2011/03/06 18:52:48 | 000,448,616 | —- | C] (DTS) – C:WindowsSystem32DTSBassEnhancementDLL.dll
[2011/03/06 18:52:48 | 000,429,160 | —- | C] (DTS) – C:WindowsSystem32DTSSymmetryDLL.dll
[2011/03/06 18:52:48 | 000,406,120 | —- | C] (DTS) – C:WindowsSystem32DTSVoiceClarityDLL.dll
[2011/03/06 18:52:48 | 000,291,432 | —- | C] (DTS) – C:WindowsSystem32DTSNeoPCDLL.dll
[2011/03/06 18:52:48 | 000,259,928 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32MaxxAudioAPO30.dll
[2011/03/06 18:52:48 | 000,236,648 | —- | C] (DTS) – C:WindowsSystem32DTSGainCompensatorDLL.dll
[2011/03/06 18:52:48 | 000,232,792 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32MaxxAudioAPO20.dll
[2011/03/06 18:52:48 | 000,224,360 | —- | C] (DTS) – C:WindowsSystem32DTSLimiterDLL.dll
[2011/03/06 18:52:48 | 000,132,368 | —- | C] (Waves Audio Ltd.) – C:WindowsSystem32MaxxAudioAPO.dll
[2011/03/06 18:52:48 | 000,107,112 | —- | C] (DTS) – C:WindowsSystem32DTSLFXAPO.dll
[2011/03/06 18:52:48 | 000,107,112 | —- | C] (DTS) – C:WindowsSystem32DTSGFXAPO.dll
[2011/03/06 18:52:48 | 000,106,600 | —- | C] (DTS) – C:WindowsSystem32DTSGFXAPONS.dll
[2011/03/06 18:52:47 | 000,175,200 | —- | C] (Andrea Electronics Corporation) – C:WindowsSystem32AERTACap.dll
[2011/03/06 18:52:47 | 000,096,160 | —- | C] (Andrea Electronics Corporation) – C:WindowsSystem32AERTARen.dll
[2011/03/06 18:52:47 | 000,000,000 | -H-D | C] – C:Program FilesInstallShield Installation Information
[2011/03/06 18:52:47 | 000,000,000 | —D | C] – C:Program FilesRealtek
[2011/03/06 18:52:46 | 000,000,000 | -H-D | C] – C:Program FilesTemp
[2011/03/06 18:52:45 | 001,284,712 | —- | C] (Realtek Semiconductor Corp.) – C:WindowsRtlExUpd.dll
[2011/03/06 18:52:41 | 000,000,000 | —D | C] – C:Program FilesCommon FilesInstallShield
[2011/03/06 18:52:28 | 000,000,000 | —D | C] – C:WindowsSystem32DRVSTORE
[2011/03/06 18:49:46 | 000,000,000 | R–D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsWindows Live
[2011/03/06 18:48:46 | 001,002,008 | —- | C] (Intel Corporation) – C:WindowsSystem32igxpun.exe
[2011/03/06 18:48:46 | 000,000,000 | —D | C] – C:WindowsSystem32x64
[2011/03/06 18:26:58 | 000,222,080 | —- | C] (Microsoft Corporation) – C:WindowsSystem32MpSigStub.exe
[2011/03/06 18:23:35 | 000,000,000 | —D | C] – C:Program FilesWindows Live
[2011/03/06 18:22:51 | 000,000,000 | —D | C] – C:Program FilesMicrosoft
[2011/03/06 18:21:37 | 000,515,416 | —- | C] (Microsoft Corporation) – C:WindowsSystem32XAudio2_5.dll
[2011/03/06 18:21:37 | 000,453,456 | —- | C] (Microsoft Corporation) – C:WindowsSystem32d3dx10_42.dll
[2011/03/06 18:21:37 | 000,069,464 | —- | C] (Microsoft Corporation) – C:WindowsSystem32XAPOFX1_3.dll
[2011/03/06 18:21:24 | 003,426,072 | —- | C] (Microsoft Corporation) – C:WindowsSystem32d3dx9_32.dll
[2011/03/06 18:21:06 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsMicrosoft Silverlight
[2011/03/06 18:20:49 | 000,000,000 | —D | C] – C:Program FilesMicrosoft Silverlight
[2011/03/06 18:19:50 | 002,983,424 | —- | C] (Microsoft Corporation) – C:WindowsSystem32UIRibbon.dll
[2011/03/06 18:19:50 | 001,164,800 | —- | C] (Microsoft Corporation) – C:WindowsSystem32UIRibbonRes.dll
[2011/03/06 18:19:27 | 000,196,608 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mfreadwrite.dll
[2011/03/06 18:19:26 | 003,181,568 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mf.dll
[2011/03/06 18:19:26 | 001,619,456 | —- | C] (Microsoft Corporation) – C:WindowsSystem32WMVDECOD.DLL
[2011/03/06 18:19:26 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsSkype
[2011/03/06 18:19:25 | 000,000,000 | —D | C] – C:Program FilesCommon FilesSkype
[2011/03/06 18:19:24 | 000,000,000 | R–D | C] – C:Program FilesSkype
[2011/03/06 18:19:21 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingSkype
[2011/03/06 18:19:16 | 000,000,000 | -HSD | C] – C:WindowsInstaller
[2011/03/06 18:19:16 | 000,000,000 | —D | C] – C:ProgramDataSkype
[2011/03/06 18:18:21 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalWindows Live
[2011/03/06 18:18:20 | 000,000,000 | —D | C] – C:Program FilesCommon FilesWindows Live
[2011/03/06 18:14:00 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMacromedia
[2011/03/06 18:14:00 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingAdobe
[2011/03/06 18:13:40 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsGoogle Chrome
[2011/03/06 18:12:34 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalGoogle
[2011/03/06 18:12:11 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalDeployment
[2011/03/06 18:12:11 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalApps
[2011/03/06 18:06:49 | 000,000,000 | R–D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
[2011/03/06 18:06:49 | 000,000,000 | R–D | C] – C:UsersAhmedSearches
[2011/03/06 18:06:49 | 000,000,000 | R–D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsAdministrative Tools
[2011/03/06 18:06:49 | 000,000,000 | -H-D | C] – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchUser Pinned
[2011/03/06 18:06:41 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingIdentities
[2011/03/06 18:06:39 | 000,000,000 | R–D | C] – C:UsersAhmedContacts
[2011/03/06 18:06:33 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalVirtualStore
[2011/03/06 18:06:31 | 000,000,000 | –SD | C] – C:UsersAhmedAppDataRoamingMicrosoft
[2011/03/06 18:06:31 | 000,000,000 | R–D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsMaintenance
[2011/03/06 18:06:31 | 000,000,000 | R–D | C] – C:UsersAhmedFavorites
[2011/03/06 18:06:31 | 000,000,000 | R–D | C] – C:UsersAhmedDownloads
[2011/03/06 18:06:31 | 000,000,000 | R–D | C] – C:UsersAhmedMy Documents
[2011/03/06 18:06:31 | 000,000,000 | R–D | C] – C:UsersAhmedDesktop
[2011/03/06 18:06:31 | 000,000,000 | R–D | C] – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsAccessories
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedAppDataLocalTemporary Internet Files
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedTemplates
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedStart Menu
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedSendTo
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedRecent
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedPrintHood
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedNetHood
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedDocumentsMy Videos
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedDocumentsMy Pictures
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedDocumentsMy Music
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedMy Documents
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedLocal Settings
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedAppDataLocalHistory
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedCookies
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedApplication Data
[2011/03/06 18:06:31 | 000,000,000 | -HSD | C] – C:UsersAhmedAppDataLocalApplication Data
[2011/03/06 18:06:31 | 000,000,000 | -H-D | C] – C:UsersAhmedAppData
[2011/03/06 18:06:31 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalTemp
[2011/03/06 18:06:31 | 000,000,000 | —D | C] – C:UsersAhmedAppDataLocalMicrosoft
[2011/03/06 18:06:31 | 000,000,000 | —D | C] – C:UsersAhmedAppDataRoamingMedia Center Programs
[2011/03/06 18:06:30 | 000,000,000 | R–D | C] – C:UsersAhmedVideos
[2011/03/06 18:06:30 | 000,000,000 | R–D | C] – C:UsersAhmedSaved Games
[2011/03/06 18:06:30 | 000,000,000 | R–D | C] – C:UsersAhmedPictures
[2011/03/06 18:06:30 | 000,000,000 | R–D | C] – C:UsersAhmedMusic
[2011/03/06 18:06:30 | 000,000,000 | R–D | C] – C:UsersAhmedLinks
[2011/03/06 18:04:23 | 000,000,000 | -HSD | C] – C:Recovery
[2011/03/06 12:33:16 | 000,000,000 | -HSD | C] – C:Config.Msi
[2011/03/04 09:25:13 | 000,000,000 | -HSD | C] – C:RECYCLER
[2011/03/04 00:57:00 | 000,055,808 | —- | C] (Microsoft Corporation) – C:devcon.exe
[2011/03/04 00:49:55 | 000,000,000 | —D | C] – C:D
[2011/03/04 00:49:47 | 000,000,000 | -HSD | C] – C:System Volume Information
[2011/03/03 20:05:33 | 000,085,768 | —- | C] (Tonec Inc.) – C:WindowsSystem32driversidmwfp.sys

========== Files - Modified Within 30 Days ==========

[2011/03/15 19:46:29 | 000,019,520 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/15 19:46:29 | 000,019,520 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/15 19:39:13 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2011/03/15 19:39:10 | 1589,071,872 | -HS- | M] () – C:hiberfil.sys
[2011/03/15 19:38:01 | 000,000,908 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2706187606-806646636-2821916094-1001UA.job
[2011/03/15 19:38:01 | 000,000,856 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2706187606-806646636-2821916094-1001Core.job
[2011/03/13 00:37:17 | 000,000,056 | -H– | M] () – C:WindowsSystem32ezsidmv.dat
[2011/03/12 21:47:31 | 000,001,820 | —- | M] () – C:UsersPublicDesktopCounter-Strike 1.6.lnk
[2011/03/12 21:39:18 | 000,001,013 | —- | M] () – C:UsersAhmedDesktopsXe Injected.lnk
[2011/03/12 21:31:02 | 000,001,890 | —- | M] () – C:UsersAhmedDesktopCounter Strike 1.6 Non Steam.lnk
[2011/03/12 21:31:02 | 000,001,870 | —- | M] () – C:UsersAhmedDesktopDedicated Server.lnk
[2011/03/12 07:18:29 | 000,002,397 | —- | M] () – C:UsersAhmedDesktopGoogle Chrome.lnk
[2011/03/11 04:37:32 | 000,106,316 | —- | M] () – C:WindowsSystem32perfc009.dat
[2011/03/11 04:37:32 | 000,000,000 | —- | M] () – C:WindowsSystem32perfh009.dat
[2011/03/10 16:01:26 | 000,002,053 | —- | M] () – C:UsersAhmedDesktopTVersity.lnk
[2011/03/08 21:58:14 | 000,000,000 | -H– | M] () – C:WindowsSystem32driversMsft_User_WpdFs_01_09_00.Wdf
[2011/03/08 20:11:06 | 000,000,000 | -H– | M] () – C:WindowsSystem32driversMsft_User_WpdMtpDr_01_09_00.Wdf
[2011/03/08 05:26:24 | 000,000,965 | —- | M] () – C:UsersAhmedDesktopSpeedFan.lnk
[2011/03/08 05:26:23 | 000,000,045 | —- | M] () – C:WindowsSystem32initdebug.nfo
[2011/03/07 18:16:18 | 000,266,808 | —- | M] () – C:WindowsSystem32FNTCACHE.DAT
[2011/03/07 06:59:07 | 000,041,962 | —- | M] () – C:WindowsSystem32license.rtf
[2011/03/07 06:55:06 | 000,008,192 | RHS- | M] () – C:BOOTSECT.BAK
[2011/03/07 06:55:05 | 000,000,355 | RHS- | M] () – C:Boot.ini.saved
[2011/03/07 03:49:13 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:WindowsSystem32javaws.exe
[2011/03/07 03:49:13 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:WindowsSystem32javaw.exe
[2011/03/07 03:49:13 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:WindowsSystem32java.exe
[2011/03/07 03:49:12 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:WindowsSystem32deployJava1.dll
[2011/03/06 21:18:28 | 000,001,131 | —- | M] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchYahoo! Messenger.lnk
[2011/03/06 21:18:28 | 000,001,107 | —- | M] () – C:UsersPublicDesktopYahoo! Messenger.lnk
[2011/03/06 20:37:26 | 000,001,929 | —- | M] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsStartupPalTalk.lnk
[2011/03/06 20:37:26 | 000,001,108 | —- | M] () – C:UsersAhmedDesktopUpgrade to Paltalk Extreme.lnk
[2011/03/06 20:37:25 | 000,001,903 | —- | M] () – C:UsersAhmedDesktopPaltalkScene.lnk
[2011/03/06 20:18:41 | 000,001,994 | —- | M] () – C:UsersPublicDesktopavast! Free Antivirus.lnk
[2011/03/06 20:18:37 | 000,002,577 | —- | M] () – C:WindowsSystem32config.nt
[2011/03/06 20:04:57 | 000,000,937 | —- | M] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchµTorrent.lnk
[2011/03/06 20:04:57 | 000,000,913 | —- | M] () – C:UsersPublicDesktopµTorrent.lnk
[2011/03/06 19:52:16 | 000,001,575 | —- | M] () – C:UsersAhmedDesktopmsnmsgr - Shortcut.lnk
[2011/03/06 18:32:17 | 000,000,020 | —- | M] () – C:Windowst÷ž
[2011/03/06 18:19:26 | 000,002,503 | —- | M] () – C:UsersPublicDesktopSkype.lnk
[2011/03/06 18:11:06 | 000,001,407 | —- | M] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchLaunch Internet Explorer Browser.lnk
[2011/03/06 18:05:31 | 000,206,312 | RHS- | M] () – C:ZJOMU
[2011/03/06 18:05:31 | 000,000,009 | RHS- | M] () – C:wedaolu
[2011/03/04 09:13:14 | 000,000,000 | RHS- | M] () – C:MSDOS.SYS
[2011/03/04 09:13:14 | 000,000,000 | RHS- | M] () – C:IO.SYS
[2011/03/04 09:03:20 | 000,000,211 | -H– | M] () – C:Boot.BAK
[2011/02/23 20:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:WindowsavastSS.scr
[2011/02/23 20:04:17 | 000,190,016 | —- | M] (AVAST Software) – C:WindowsSystem32aswBoot.exe
[2011/02/23 19:56:55 | 000,371,544 | —- | M] (AVAST Software) – C:WindowsSystem32driversaswSnx.sys
[2011/02/23 19:56:45 | 000,301,528 | —- | M] (AVAST Software) – C:WindowsSystem32driversaswSP.sys
[2011/02/23 19:55:49 | 000,049,240 | —- | M] (AVAST Software) – C:WindowsSystem32driversaswTdi.sys
[2011/02/23 19:55:10 | 000,025,432 | —- | M] (AVAST Software) – C:WindowsSystem32driversaswRdr.sys
[2011/02/23 19:55:03 | 000,053,592 | —- | M] (AVAST Software) – C:WindowsSystem32driversaswMonFlt.sys
[2011/02/23 19:54:55 | 000,019,544 | —- | M] (AVAST Software) – C:WindowsSystem32driversaswFsBlk.sys
[2011/02/19 10:32:48 | 001,074,176 | —- | M] (Microsoft Corporation) – C:WindowsSystem32DWrite.dll
[2011/02/19 10:32:35 | 000,739,840 | —- | M] (Microsoft Corporation) – C:WindowsSystem32d2d1.dll

========== Files Created - No Company Name ==========

[2011/03/13 00:37:17 | 000,000,056 | -H– | C] () – C:WindowsSystem32ezsidmv.dat
[2011/03/12 21:47:31 | 000,001,820 | —- | C] () – C:UsersPublicDesktopCounter-Strike 1.6.lnk
[2011/03/12 21:39:18 | 000,001,013 | —- | C] () – C:UsersAhmedDesktopsXe Injected.lnk
[2011/03/12 21:31:02 | 000,001,890 | —- | C] () – C:UsersAhmedDesktopCounter Strike 1.6 Non Steam.lnk
[2011/03/12 21:31:02 | 000,001,870 | —- | C] () – C:UsersAhmedDesktopDedicated Server.lnk
[2011/03/10 16:01:26 | 000,002,053 | —- | C] () – C:UsersAhmedDesktopTVersity.lnk
[2011/03/08 21:58:14 | 000,000,000 | -H– | C] () – C:WindowsSystem32driversMsft_User_WpdFs_01_09_00.Wdf
[2011/03/08 20:11:06 | 000,000,000 | -H– | C] () – C:WindowsSystem32driversMsft_User_WpdMtpDr_01_09_00.Wdf
[2011/03/08 05:26:24 | 000,000,965 | —- | C] () – C:UsersAhmedDesktopSpeedFan.lnk
[2011/03/08 05:26:19 | 000,000,045 | —- | C] () – C:WindowsSystem32initdebug.nfo
[2011/03/07 06:58:57 | 000,001,345 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsMedia Center.lnk
[2011/03/07 06:58:50 | 000,001,326 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsWindows DVD Maker.lnk
[2011/03/07 06:56:15 | 1589,071,872 | -HS- | C] () – C:hiberfil.sys
[2011/03/07 06:55:05 | 000,000,211 | -H– | C] () – C:Boot.BAK
[2011/03/07 06:46:56 | 000,008,192 | RHS- | C] () – C:BOOTSECT.BAK
[2011/03/07 06:46:53 | 000,383,562 | RHS- | C] () – C:bootmgr
[2011/03/06 21:18:28 | 000,001,131 | —- | C] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchYahoo! Messenger.lnk
[2011/03/06 21:18:28 | 000,001,107 | —- | C] () – C:UsersPublicDesktopYahoo! Messenger.lnk
[2011/03/06 20:37:26 | 000,001,929 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsStartupPalTalk.lnk
[2011/03/06 20:37:26 | 000,001,108 | —- | C] () – C:UsersAhmedDesktopUpgrade to Paltalk Extreme.lnk
[2011/03/06 20:37:25 | 000,001,903 | —- | C] () – C:UsersAhmedDesktopPaltalkScene.lnk
[2011/03/06 20:18:41 | 000,001,994 | —- | C] () – C:UsersPublicDesktopavast! Free Antivirus.lnk
[2011/03/06 20:04:57 | 000,000,937 | —- | C] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchµTorrent.lnk
[2011/03/06 20:04:57 | 000,000,913 | —- | C] () – C:UsersPublicDesktopµTorrent.lnk
[2011/03/06 19:52:16 | 000,001,575 | —- | C] () – C:UsersAhmedDesktopmsnmsgr - Shortcut.lnk
[2011/03/06 19:50:54 | 000,001,404 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsWindows Live Mail.lnk
[2011/03/06 19:50:29 | 000,002,432 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsWindows Live Messenger.lnk
[2011/03/06 19:00:23 | 000,140,288 | —- | C] () – C:WindowsSystem32igfxtvcx.dll
[2011/03/06 19:00:23 | 000,121,232 | —- | C] () – C:WindowsSystem32IScrNB.bmp
[2011/03/06 18:49:00 | 000,001,251 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsWindows Live Movie Maker.lnk
[2011/03/06 18:46:07 | 000,001,320 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsWindows Live Photo Gallery.lnk
[2011/03/06 18:32:17 | 000,000,020 | —- | C] () – C:Windowst÷ž
[2011/03/06 18:19:26 | 000,002,503 | —- | C] () – C:UsersPublicDesktopSkype.lnk
[2011/03/06 18:13:41 | 000,002,397 | —- | C] () – C:UsersAhmedDesktopGoogle Chrome.lnk
[2011/03/06 18:12:35 | 000,000,908 | —- | C] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2706187606-806646636-2821916094-1001UA.job
[2011/03/06 18:12:35 | 000,000,856 | —- | C] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2706187606-806646636-2821916094-1001Core.job
[2011/03/06 18:11:06 | 000,001,407 | —- | C] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchLaunch Internet Explorer Browser.lnk
[2011/03/06 18:06:51 | 000,001,413 | —- | C] () – C:UsersAhmedAppDataRoamingMicrosoftWindowsStart MenuProgramsInternet Explorer.lnk
[2011/03/06 18:06:31 | 000,000,290 | —- | C] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchShows Desktop.lnk
[2011/03/06 18:06:31 | 000,000,272 | —- | C] () – C:UsersAhmedApplication DataMicrosoftInternet ExplorerQuick LaunchWindow Switcher.lnk
[2011/03/06 18:05:31 | 000,206,312 | RHS- | C] () – C:ZJOMU
[2011/03/06 18:05:31 | 000,000,009 | RHS- | C] () – C:wedaolu
[2011/03/04 09:13:14 | 000,000,000 | RHS- | C] () – C:MSDOS.SYS
[2011/03/04 09:13:14 | 000,000,000 | RHS- | C] () – C:IO.SYS
[2011/03/04 00:57:00 | 000,246,423 | —- | C] () – C:DPsFnshr.exe
[2011/03/04 00:57:00 | 000,211,039 | —- | C] () – C:DSPdsblr.exe
[2011/03/04 00:57:00 | 000,202,187 | —- | C] () – C:pmtimer.exe
[2011/03/04 00:57:00 | 000,137,728 | —- | C] () – C:mute.exe
[2011/03/04 00:57:00 | 000,020,992 | —- | C] () – C:makePNF.exe
[2011/03/04 00:57:00 | 000,000,630 | —- | C] () – C:DPsFnshr.ini
[2011/03/04 00:57:00 | 000,000,000 | —- | C] () – C:ATICCP.ins
[2011/03/04 00:55:46 | 000,003,107 | —- | C] () – C:DriverPack_Sound_B_wnt5_x86-32.ini
[2011/03/04 00:54:51 | 000,004,048 | —- | C] () – C:DriverPack_Sound_A_wnt5_x86-32.ini
[2011/03/04 00:54:11 | 000,069,211 | —- | C] () – C:DriverPack_MassStorage_wnt5_x86-32.ini
[2011/03/04 00:54:00 | 000,000,764 | —- | C] () – C:DriverPack_LAN_wnt5_x86-32.ini
[2011/03/04 00:53:01 | 000,001,822 | —- | C] () – C:DriverPack_Graphics_C_wnt5_x86-32.ini
[2011/03/04 00:51:55 | 000,001,611 | —- | C] () – C:DriverPack_Graphics_B_wnt5_x86-32.ini
[2011/03/04 00:50:30 | 000,000,961 | —- | C] () – C:DriverPack_Graphics_A_wnt5_x86-32.ini
[2011/03/04 00:50:08 | 000,000,420 | —- | C] () – C:DriverPack_CPU_wnt5_x86-32.ini
[2011/03/04 00:48:58 | 000,000,355 | RHS- | C] () – C:Boot.ini.saved
[2009/07/14 09:57:37 | 000,067,584 | –S- | C] () – C:Windowsbootstat.dat
[2009/07/14 09:33:53 | 000,266,808 | —- | C] () – C:WindowsSystem32FNTCACHE.DAT
[2009/07/14 07:05:48 | 000,291,294 | —- | C] () – C:WindowsSystem32perfi009.dat
[2009/07/14 07:05:48 | 000,106,316 | —- | C] () – C:WindowsSystem32perfc009.dat
[2009/07/14 07:05:48 | 000,031,548 | —- | C] () – C:WindowsSystem32perfd009.dat
[2009/07/14 07:05:48 | 000,000,000 | —- | C] () – C:WindowsSystem32perfh009.dat
[2009/07/14 07:05:05 | 000,000,741 | —- | C] () – C:WindowsSystem32NOISE.DAT
[2009/07/14 07:04:11 | 000,215,943 | —- | C] () – C:WindowsSystem32dssec.dat
[2009/07/14 04:55:01 | 000,043,131 | —- | C] () – C:Windowsmib.bin
[2009/07/14 04:51:43 | 000,073,728 | —- | C] () – C:WindowsSystem32BthpanContextHandler.dll
[2009/07/14 04:42:10 | 000,064,000 | —- | C] () – C:WindowsSystem32BWContextHandler.dll
[2009/06/11 02:26:10 | 000,673,088 | —- | C] () – C:WindowsSystem32mlang.dat
[1996/04/04 00:33:26 | 000,005,248 | —- | C] () – C:WindowsSystem32giveio.sys

========== LOP Check ==========

[2011/03/15 19:38:03 | 000,000,000 | —D | M] – C:UsersAhmedAppDataRoamingDMCache
[2011/03/12 03:50:03 | 000,000,000 | —D | M] – C:UsersAhmedAppDataRoamingIDM
[2011/03/07 00:00:17 | 000,000,000 | —D | M] – C:UsersAhmedAppDataRoamingPaltalk
[2011/03/15 19:42:21 | 000,000,000 | —D | M] – C:UsersAhmedAppDataRoaminguTorrent
[2009/07/14 09:53:46 | 000,026,866 | —- | M] () – C:WindowsTasksSCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%*.* >
[2007/12/16 02:24:22 | 000,000,000 | —- | M] () – C:ATICCP.ins
[2009/06/11 02:42:20 | 000,000,024 | —- | M] () – C:autoexec.bat
[2011/03/04 09:03:20 | 000,000,211 | -H– | M] () – C:Boot.BAK
[2011/03/07 06:55:05 | 000,000,355 | RHS- | M] () – C:Boot.ini.saved
[2009/07/14 06:38:58 | 000,383,562 | RHS- | M] () – C:bootmgr
[2011/03/07 06:55:06 | 000,008,192 | RHS- | M] () – C:BOOTSECT.BAK
[2009/06/11 02:42:20 | 000,000,010 | —- | M] () – C:config.sys
[2007/04/05 17:33:47 | 000,055,808 | —- | M] (Microsoft Corporation) – C:devcon.exe
[2007/05/27 14:08:42 | 000,246,423 | —- | M] () – C:DPsFnshr.exe
[2007/12/16 02:25:39 | 000,000,630 | —- | M] () – C:DPsFnshr.ini
[2007/04/07 23:52:09 | 000,000,420 | —- | M] () – C:DriverPack_CPU_wnt5_x86-32.ini
[2007/09/12 01:15:52 | 000,000,961 | —- | M] () – C:DriverPack_Graphics_A_wnt5_x86-32.ini
[2007/12/04 20:31:36 | 000,001,611 | —- | M] () – C:DriverPack_Graphics_B_wnt5_x86-32.ini
[2007/12/04 20:04:00 | 000,001,822 | —- | M] () – C:DriverPack_Graphics_C_wnt5_x86-32.ini
[2007/06/14 22:51:02 | 000,000,764 | —- | M] () – C:DriverPack_LAN_wnt5_x86-32.ini
[2007/12/13 02:08:48 | 000,069,211 | —- | M] () – C:DriverPack_MassStorage_wnt5_x86-32.ini
[2007/12/04 09:55:34 | 000,004,048 | —- | M] () – C:DriverPack_Sound_A_wnt5_x86-32.ini
[2007/12/04 12:49:11 | 000,003,107 | —- | M] () – C:DriverPack_Sound_B_wnt5_x86-32.ini
[2007/05/27 14:08:45 | 000,211,039 | —- | M] () – C:DSPdsblr.exe
[2011/03/15 19:39:10 | 1589,071,872 | -HS- | M] () – C:hiberfil.sys
[2011/03/04 09:13:14 | 000,000,000 | RHS- | M] () – C:IO.SYS
[2007/04/05 17:33:47 | 000,020,992 | —- | M] () – C:makePNF.exe
[2011/03/04 09:13:14 | 000,000,000 | RHS- | M] () – C:MSDOS.SYS
[2007/04/05 17:33:47 | 000,137,728 | —- | M] () – C:mute.exe
[2004/08/04 09:00:00 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2004/08/04 09:00:00 | 000,250,032 | RHS- | M] () – C:ntldr
[2011/03/15 19:39:12 | 2118,762,496 | -HS- | M] () – C:pagefile.sys
[2007/05/27 14:08:47 | 000,202,187 | —- | M] () – C:pmtimer.exe
[2011/03/06 18:05:31 | 000,000,009 | RHS- | M] () – C:wedaolu
[2011/03/06 18:05:31 | 000,206,312 | RHS- | M] () – C:ZJOMU

< %systemroot%Fonts*.com >
[2009/07/14 09:52:25 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2009/07/14 09:52:25 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2009/07/14 09:52:25 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/07/14 09:52:25 | 000,043,318 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/06/11 02:31:19 | 000,000,065 | —- | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2009/07/14 06:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:WindowsSystem32spoolprtprocsw32x86jnwppr.dll
[2009/07/14 06:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:WindowsSystem32spoolprtprocsw32x86winprint.dll

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2011/02/23 20:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:WindowsavastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:WindowsWLXPGSS.SCR

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >
[2009/07/14 09:41:57 | 000,000,174 | -HS- | M] () – C:Program Filesdesktop.ini

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2011/03/06 18:11:06 | 000,000,221 | -HS- | M] () – C:UsersAhmedAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2011-03-15 12:31:54

< End of report >

OTL Extras logfile created on: 3/15/2011 7:52:01 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:UsersAhmedDownloadsPrograms
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 37.11 Gb Total Space | 14.23 Gb Free Space | 38.34% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 7.66 Gb Free Space | 39.23% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 97.56 Gb Free Space | 99.90% Space Free | Partition Type: NTFS
Drive F: | 98.11 Gb Total Space | 97.98 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
Drive G: | 19.52 Gb Total Space | 19.52 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive H: | 19.52 Gb Total Space | 19.52 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive I: | 15.92 Gb Total Space | 15.83 Gb Free Space | 99.44% Space Free | Partition Type: NTFS

Computer Name: AHMED-PC | User Name: Ahmed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSystem32control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:Windowswinhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%system32mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [TVersity] – "C:ProgramDataTVersityMedia ServerGUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcVol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A29549FD-65F3-440C-A552-6B8114CF319D}" = Skype Toolbars
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"avast" = avast! Free Antivirus
"HDMI" = Intel® Graphics Media Accelerator Driver
"Internet Download Manager" = Internet Download Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PalTalk8.2" = PaltalkScene
"SpeedFan" = SpeedFan (remove only)
"sXe Injected" = sXe Injected
"TVersity Codec Pack" = TVersity Codec Pack 1.4
"TVersity Media Server" = TVersity Media Server 1.9.3
"TVersitybar Toolbar" = TVersitybar Toolbar
"TVWiz" = Intel® TV Wizard
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


I've been seeing some Java infections lately.

Go here and follow the instructions to clear your Java Cache
http://www.java.com/en/download/help/plugin_cache.xml


Next:
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.


  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI