Bitcomet is removed. I'm having problems with gmer scan, my laptop crashed while it was scanning and went into a blue screen saying it is preventing my computer being harmed, it said it was dumping something.. I didn't catch what it was and it restarted. my screen was all black after it loaded to windows, so now I started my computer in safe mode and gonna upload the logs from OTC.exe first. I'll try to scan with gmer in safe mode see if it will work.
The following log is OTC.txt
======================
OTL logfile created on: 04/04/2011 10:39:18 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00001009 | Country: 加拿大 | Language: ENC | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 142.09 Gb Total Space | 33.78 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive D: | 143.00 Gb Total Space | 15.02 Gb Free Space | 10.50% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\User\AppData\Local\hke.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\Rezip.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (TeamViewer5) – C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Rezip) – C:\Windows\System32\Rezip.exe ()
SRV - (yksvc) – C:\Windows\System32\ykx32mpcoinst.dll (Marvell)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (dtsoftbus01) – C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (DgiVecp) – C:\Windows\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (SSPORT) – C:\Windows\System32\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (VMC326) – C:\Windows\System32\drivers\VMC326.sys (Vimicro Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (KMDFMEMIO) – C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?br…n&bmod;=smsn
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/redirectdomain?br…N&bmod;=SMSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?br…n&bmod;=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/redirectdomain?br…n&bmod;=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.17
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/25 16:26:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\program files\Mozilla Firefox\components [2011/03/24 18:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\program files\Mozilla Firefox\plugins [2011/03/24 18:33:53 | 000,000,000 | —D | M]
[2009/09/17 13:44:27 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Extensions
[2011/04/04 00:47:37 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\n907lw05.default\extensions
[2010/01/08 18:00:14 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\n907lw05.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2011/04/04 00:47:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/17 05:17:49 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/07 15:12:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/01/25 16:26:52 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2009/07/17 01:40:12 | 000,704,512 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010/07/07 15:11:49 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/16 01:48:29 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010/03/31 14:08:09 | 000,002,310 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\findbook-zh-TW.xml
[2010/03/31 14:08:09 | 000,001,222 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-zh-TW.xml
[2010/03/31 14:08:09 | 000,001,360 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-answer-zh-TW.xml
[2010/03/31 14:08:09 | 000,000,843 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-bid-zh-TW.xml
[2010/03/31 14:08:09 | 000,001,161 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-zh-TW.xml
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] File not found
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [PPS Accelerator] C:\Program Files\PPStream\PPSAP.exe (PPStream Inc)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\User\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: 傳送影像到 Bluetooth 裝置(&B;)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: 傳送頁面到 Bluetooth 裝置(&B;)… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: pps.tv ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: ppstream.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: webscache.com ([]http in Trusted sites)
O16 - DPF: {134607FB-69C2-44ED-8EEC-3D67B5E6CEFE}
http://fgcpatch.funmily.com/fgc/RunupGameActX.ocx (RunupGameActX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://ivenue.webex.com/client/T27L/support/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0b982241-e513-11de-bf97-00242cdc4a53}\Shell - "" = AutoRun
O33 - MountPoints2\{0b982241-e513-11de-bf97-00242cdc4a53}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{11c8d9f1-243e-11df-b3ab-00242cdc4a53}\Shell\AutoRun\command - "" = yq.com
O33 - MountPoints2\{11c8d9f1-243e-11df-b3ab-00242cdc4a53}\Shell\open\Command - "" = yq.com
O33 - MountPoints2\{732a59c0-1aab-11e0-8b23-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{732a59c0-1aab-11e0-8b23-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{83148be7-dae1-11de-be1c-00242cdc4a53}\Shell\1\Command - "" = F:\Recycle.exe
O33 - MountPoints2\{83148be7-dae1-11de-be1c-00242cdc4a53}\Shell\2\Command - "" = F:\Recycle.exe
O33 - MountPoints2\{83148be7-dae1-11de-be1c-00242cdc4a53}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Recycle.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "C:\Users\User\AppData\Local\hke.exe" -a "%1" %* ()
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Users\User\AppData\Local\hke.exe" -a "%1" %* ()
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/04/04 10:37:29 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2011/04/04 00:46:30 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\User\Desktop\HijackThis.exe
[2011/04/03 17:06:26 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/03 17:06:26 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/03 17:06:26 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/03 17:06:26 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/03 17:06:26 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/03 17:06:25 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/03 17:06:25 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/03 17:06:25 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/03 17:06:25 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/03 17:06:25 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/03 17:06:24 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/03 17:06:24 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/03 17:06:24 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/03 17:06:24 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/03 17:06:24 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/03 17:06:24 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/03 17:06:23 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/03 17:03:46 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/04/03 17:03:46 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/04/03 17:03:45 | 000,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/04/03 17:03:45 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2011/04/03 17:03:44 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/04/03 17:03:44 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/04/03 17:03:44 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/04/03 17:03:44 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/04/03 17:03:43 | 000,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/04/03 17:03:43 | 000,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2011/04/03 17:03:43 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/04/03 17:03:43 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/04/03 17:03:43 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/04/03 17:03:43 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/04/03 17:03:42 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/04/03 17:03:42 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/04/03 17:03:41 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/03 17:03:41 | 000,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/03 17:03:41 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/04/03 17:03:40 | 003,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/04/03 17:03:40 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/04/03 17:03:39 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2011/04/03 17:03:39 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/04/03 17:03:39 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/04/03 17:03:39 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2011/03/31 19:18:48 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Tibia
[2011/03/31 18:58:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tibia
[2011/03/31 18:58:04 | 000,000,000 | —D | C] – C:\Program Files\Tibia
[2011/03/24 20:50:06 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FP Solutions 2009
[2011/03/24 20:49:44 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.023
[2011/03/24 20:49:43 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.022
[2011/03/24 20:49:43 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01E
[2011/03/24 20:49:43 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01F
[2011/03/24 20:49:43 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.020
[2011/03/24 20:49:43 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.021
[2011/03/24 20:33:54 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01C
[2011/03/24 20:33:54 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01D
[2011/03/24 20:33:54 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.019
[2011/03/24 20:33:54 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01A
[2011/03/24 20:33:54 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.01B
[2011/03/24 20:33:53 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.018
[2011/03/24 14:05:41 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.016
[2011/03/24 14:05:41 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.012
[2011/03/24 14:05:41 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.017
[2011/03/24 14:05:41 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.013
[2011/03/24 14:05:41 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.014
[2011/03/24 14:05:41 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.015
[2011/03/24 14:05:41 | 000,000,000 | —D | C] – C:\Users\User\FPS2009
[2011/03/24 14:01:13 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.010
[2011/03/24 14:01:13 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00C
[2011/03/24 14:01:13 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.011
[2011/03/24 14:01:13 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00D
[2011/03/24 14:01:13 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00E
[2011/03/24 14:01:13 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00F
[2011/03/24 13:55:20 | 000,000,000 | —D | C] – C:\ProgramData\FPS2009
[2011/03/24 13:55:19 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00B
[2011/03/24 13:55:17 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.00A
[2011/03/24 13:55:17 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.006
[2011/03/24 13:55:17 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.007
[2011/03/24 13:55:17 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.008
[2011/03/24 13:55:17 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.009
[2011/03/24 13:38:48 | 000,000,000 | —D | C] – C:\Users\User\Application Data
[2011/03/24 13:37:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FP Solutions 2009
[2011/03/24 13:36:48 | 000,000,000 | —D | C] – C:\CCH FinancialWorks
[2011/03/24 13:36:47 | 000,368,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbar332.dll
[2011/03/24 13:36:47 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.005
[2011/03/24 13:36:45 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.004
[2011/03/24 13:36:45 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.001
[2011/03/24 13:36:45 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.002
[2011/03/24 13:36:45 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.003
[2011/03/24 13:36:44 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\temp.000
[2011/03/18 16:07:43 | 000,000,000 | —D | C] – C:\Users\User\Documents\OneNote Notebooks
[2011/03/08 12:43:33 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/08 12:43:33 | 000,323,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/08 12:43:33 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/08 12:43:33 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/03/08 12:32:40 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast
[2011/03/08 12:32:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
[2011/03/08 12:32:40 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2011/03/07 15:50:46 | 000,000,000 | —D | C] – C:\Windows\FLV Player
[2011/03/07 15:50:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLV Player
[2011/03/07 15:50:46 | 000,000,000 | —D | C] – C:\Program Files\FLV Player
========== Files Created - No Company Name ==========
[2011/04/04 10:41:30 | 000,301,568 | —- | C] () – C:\Users\User\Desktop\gmer.exe
[2011/04/04 00:35:18 | 000,000,374 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{967B0F62-047B-476C-9458-AEB3A37DC7A8}.job
[2011/04/04 00:27:29 | 3215,572,992 | -HS- | C] () – C:\hiberfil.sys
[2011/04/03 17:06:24 | 000,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/04/03 15:47:32 | 000,008,968 | -HS- | C] () – C:\Users\User\AppData\Local\08a4u2o670p0ms3ur18g20l873t74n
[2011/04/03 15:47:32 | 000,008,968 | -HS- | C] () – C:\ProgramData\08a4u2o670p0ms3ur18g20l873t74n
[2011/04/03 15:47:31 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\vhh.exe
[2011/04/03 15:47:09 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\vpk.exe
[2011/04/03 15:47:04 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\Update.exe
[2011/04/03 15:47:04 | 000,228,990 | -HS- | C] () – C:\Users\User\AppData\Local\hke.exe
[2011/03/29 17:42:39 | 005,201,920 | —- | C] () – C:\Users\User\Desktop\愛在不在 主題曲 愛在一線之差.mp3
[2011/03/27 20:11:25 | 000,000,680 | —- | C] () – C:\Users\User\AppData\Local\d3d9caps.dat
[2011/03/27 14:13:46 | 617,297,023 | —- | C] () – C:\Users\User\Desktop\skgaming_msi_vs_dwi_1.flv
[2011/03/27 14:13:28 | 468,166,547 | —- | C] () – C:\Users\User\Desktop\skgaming_msi_vs_dwi_2.flv
[2011/03/24 20:50:27 | 000,000,776 | —- | C] () – C:\Users\User\Desktop\Annual Review Tool.lnk
[2011/03/24 20:50:26 | 000,000,746 | —- | C] () – C:\Users\User\Desktop\Report Editor.lnk
[2011/03/24 20:50:24 | 000,000,791 | —- | C] () – C:\Users\User\Desktop\Financial Calculators.lnk
[2011/03/24 20:50:23 | 000,000,786 | —- | C] () – C:\Users\User\Desktop\Fact Finder Business.lnk
[2011/03/24 20:50:22 | 000,000,786 | —- | C] () – C:\Users\User\Desktop\Fact Finder Personal.lnk
[2011/03/24 20:50:20 | 000,000,746 | —- | C] () – C:\Users\User\Desktop\FP Solutions Help.lnk
[2011/03/24 20:50:19 | 000,000,896 | —- | C] () – C:\Users\User\Desktop\FP Solutions User Guide.lnk
[2011/03/24 20:50:18 | 000,000,746 | —- | C] () – C:\Users\User\Desktop\FP Solutions.lnk
[2011/03/24 13:40:24 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/03/24 13:40:24 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/03/24 13:35:53 | 000,164,864 | —- | C] () – C:\Program Files\UNWISE.EXE
[2011/03/18 16:07:42 | 000,001,111 | —- | C] () – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/03/17 18:50:48 | 433,798,207 | —- | C] () – C:\Users\User\Desktop\zqxs.dvd.yueyu.rmvb
[2011/03/17 18:32:52 | 000,161,605 | —- | C] () – C:\Users\User\Desktop\IMG00066-20101231-1928.jpg
[2011/03/08 12:32:40 | 000,000,788 | —- | C] () – C:\Users\User\Desktop\SopCast.lnk
[2011/03/07 15:50:46 | 000,001,695 | —- | C] () – C:\Users\Public\Desktop\FLV Player.lnk
[2010/08/09 13:09:01 | 000,479,232 | —- | C] () – C:\Windows\ssndii.exe
[2010/08/09 13:08:08 | 000,022,723 | —- | C] () – C:\Windows\System32\ssp1ml3.dll
[2010/05/24 12:33:00 | 004,670,829 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/05/24 12:33:00 | 001,529,856 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2010/05/24 12:33:00 | 001,447,921 | —- | C] () – C:\Windows\System32\ffmpegmt.dll
[2010/05/24 12:33:00 | 000,877,385 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2010/05/24 12:33:00 | 000,810,113 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/05/24 12:33:00 | 000,336,384 | —- | C] () – C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 12:33:00 | 000,324,096 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 12:33:00 | 000,248,320 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 12:33:00 | 000,216,576 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2010/05/24 12:33:00 | 000,151,552 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2010/05/24 12:33:00 | 000,145,408 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 12:33:00 | 000,139,944 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/05/24 12:33:00 | 000,121,856 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2010/05/24 12:33:00 | 000,116,736 | —- | C] () – C:\Windows\System32\ff_tremor.dll
[2010/05/24 12:33:00 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/24 12:33:00 | 000,100,864 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2010/05/24 12:33:00 | 000,097,792 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2010/05/19 13:59:20 | 000,150,528 | —- | C] () – C:\Windows\System32\mkx.dll
[2010/05/19 13:59:10 | 000,109,568 | —- | C] () – C:\Windows\System32\avi.dll
[2010/05/19 13:59:02 | 000,141,824 | —- | C] () – C:\Windows\System32\mp4.dll
[2010/05/19 13:58:52 | 000,123,392 | —- | C] () – C:\Windows\System32\ogm.dll
[2010/05/19 13:58:24 | 000,113,152 | —- | C] () – C:\Windows\System32\dsmux.exe
[2010/05/19 13:58:18 | 000,154,112 | —- | C] () – C:\Windows\System32\ts.dll
[2010/05/19 13:58:08 | 000,249,856 | —- | C] () – C:\Windows\System32\dxr.dll
[2010/05/19 13:57:42 | 000,097,792 | —- | C] () – C:\Windows\System32\avs.dll
[2010/05/19 13:57:38 | 000,137,728 | —- | C] () – C:\Windows\System32\mkv2vfr.exe
[2010/05/19 13:57:26 | 000,093,184 | —- | C] () – C:\Windows\System32\avss.dll
[2010/05/19 13:57:20 | 000,358,400 | —- | C] () – C:\Windows\System32\gdsmux.exe
[2010/05/19 13:55:40 | 000,080,384 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2010/05/19 13:55:36 | 000,024,576 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2010/04/17 05:20:00 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/26 12:04:54 | 000,041,872 | —- | C] () – C:\Windows\System32\xfcodec.dll
[2009/11/30 16:07:26 | 000,550,418 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2009/11/11 17:04:27 | 000,138,464 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2009/11/11 17:04:26 | 000,022,328 | —- | C] () – C:\Users\User\AppData\Roaming\PnkBstrK.sys
[2009/11/11 17:04:11 | 000,111,928 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/11/11 17:04:08 | 000,682,280 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2009/11/11 17:04:08 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/09/25 08:50:44 | 000,000,534 | —- | C] () – C:\Windows\eReg.dat
[2009/09/23 18:32:16 | 000,145,854 | —- | C] () – C:\Windows\War3Unin.dat
[2009/09/20 06:28:56 | 000,075,776 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/17 13:30:15 | 000,000,378 | —- | C] () – C:\Windows\NJCOM.INI
[2009/08/11 14:21:26 | 000,087,552 | —- | C] () – C:\Windows\System32\ac3config.exe
[2009/07/02 18:55:26 | 000,208,064 | —- | C] () – C:\ProgramData\nvModes.001
[2009/07/02 18:55:13 | 000,208,064 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/06/07 09:24:04 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/06/02 15:43:56 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/06/02 01:14:13 | 000,307,200 | —- | C] () – C:\Windows\SetDisplayResolution.exe
[2009/06/02 00:19:55 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/06/02 00:19:54 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/06/02 00:07:59 | 000,000,135 | R— | C] () – C:\Windows\System32\lngEng.ini
[2009/06/02 00:07:59 | 000,000,117 | —- | C] () – C:\Windows\System32\lngKor.ini
[2009/06/01 23:55:43 | 000,311,296 | —- | C] () – C:\Windows\System32\Rezip.exe
[2009/06/01 23:54:58 | 000,040,960 | —- | C] () – C:\Windows\System32\IhDEV.exe
[2009/06/01 23:54:58 | 000,024,576 | —- | C] () – C:\Windows\System32\IhINF.exe
[2009/06/01 23:54:45 | 000,003,990 | —- | C] () – C:\Windows\HotFixList.ini
[2009/06/01 22:34:09 | 000,381,558 | —- | C] () – C:\Windows\System32\prfh0404.dat
[2009/06/01 22:34:09 | 000,121,430 | —- | C] () – C:\Windows\System32\prfc0404.dat
[2009/06/01 22:34:09 | 000,116,540 | —- | C] () – C:\Windows\System32\prfi0404.dat
[2009/06/01 22:34:09 | 000,030,674 | —- | C] () – C:\Windows\System32\prfd0404.dat
[2009/06/01 22:17:23 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2009/01/10 15:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2008/11/06 08:37:32 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/11 01:45:02 | 000,057,344 | —- | C] () – C:\Windows\System32\BtwNamespaceExt2.dll
[2008/02/09 09:03:07 | 000,024,576 | —- | C] () – C:\Windows\System32\drivers\Marker.exe
[2007/10/13 02:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/04/15 12:24:16 | 000,023,752 | —- | C] () – C:\Windows\System32\providers.bin
[2007/02/26 00:49:12 | 006,139,774 | —- | C] () – C:\Windows\imagine digital freedom.dat
[2007/02/07 20:12:10 | 000,000,021 | —- | C] () – C:\Windows\KwYl.dat
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 001,765,264 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,642,704 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,121,592 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/13 22:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll
========== LOP Check ==========
[2011/01/07 15:19:23 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2010/04/01 10:40:22 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Facebook
[2009/12/18 23:03:36 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\NCH Swift Sound
[2009/10/09 11:04:35 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\NJStar
[2011/03/23 10:02:14 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PPStream
[2009/12/10 00:45:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Research In Motion
[2010/03/11 19:45:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Smilebox
[2011/01/07 15:39:22 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Sports Interactive
[2010/03/01 16:08:42 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TeamViewer
[2011/03/31 19:20:15 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tibia
[2011/04/03 17:17:32 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/04 10:35:35 | 000,000,374 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{967B0F62-047B-476C-9458-AEB3A37DC7A8}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 19:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2008/02/08 02:31:21 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/03/16 02:04:41 | 768,309,223 | —- | M] () – C:\Flyff_Client.exe
[2011/04/04 10:31:29 | 3215,572,992 | -HS- | M] () – C:\hiberfil.sys
[2011/03/24 13:40:24 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/24 13:40:24 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/04/04 10:31:27 | 3529,375,744 | -HS- | M] () – C:\pagefile.sys
[2009/06/01 23:52:19 | 000,001,618 | —- | M] () – C:\RHDSetup.log
[2009/06/02 00:08:00 | 000,000,191 | —- | M] () – C:\Setup.log
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 05:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2007/11/28 06:55:36 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\Windows\System32\spool\prtprocs\w32x86\ssp1mpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2007/02/26 00:49:10 | 001,744,896 | —- | M] (TopThinks, INC.) – C:\Windows\imagine digital freedom.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2011/03/24 20:46:40 | 000,001,527 | —- | M] () – C:\Program Files\INSTALL.LOG
[2001/09/28 17:00:28 | 000,164,864 | —- | M] () – C:\Program Files\UNWISE.EXE
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/09 15:29:43 | 000,000,574 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/03/20 17:07:56 | 000,301,568 | —- | M] () – C:\Users\User\Desktop\gmer.exe
[2011/04/04 00:36:28 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\User\Desktop\HijackThis.exe
[2011/04/04 10:37:29 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-04 00:09:31
< End of report >