Amelia123
Topic Starter
I'm infected with something. I guess it is called System Protection Tool or System Tool. I have it disabled for the time-being or so I think.
System Tool Warning
It says something like 20 trojans were found in your system.
Click here to remove threats (Obviously I don't want to open it again to see the little red box it gives me everytime I turn the computer on.)
I inherited the problem, so I believe that this virus has been on here for a very long time. However, it is very hard to get rid of. When I go into my control panel I can not enable Windows Security or firewalls, so please help me out. I don't know what files have been corrupted or deleted.
I have been reading the forum and I used OTS to scan the system. Here is the log:
System Tool Warning
It says something like 20 trojans were found in your system.
Click here to remove threats (Obviously I don't want to open it again to see the little red box it gives me everytime I turn the computer on.)
I inherited the problem, so I believe that this virus has been on here for a very long time. However, it is very hard to get rid of. When I go into my control panel I can not enable Windows Security or firewalls, so please help me out. I don't know what files have been corrupted or deleted.
I have been reading the forum and I used OTS to scan the system. Here is the log:
OTS logfile created on: 5/14/2012 7:32:42 PM - Run 1
OTS by OldTimer - Version 3.1.47.2 Folder = C:UsersOwnerDownloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 189.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 40.00% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 103.09 Gb Total Space | 31.93 Gb Free Space | 30.97% Space Free | Partition Type: NTFS
Drive D: | 8.69 Gb Total Space | 1.27 Gb Free Space | 14.58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-PC
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 360 Days
[Processes - Safe List]
ots.exe -> C:UsersOwnerDownloadsOTS.exe -> [2012/05/14 19:10:14 | 000,646,656 | ---- | M | MD5 = 700B66BC8B579C3CA00DC36E6E48714C] (OldTimer Tools)
firefox.exe -> C:Program FilesMozilla Firefoxfirefox.exe -> [2012/05/04 15:26:19 | 000,924,600 | ---- | M | MD5 = 4F69AABB5D82AA4EF6DFF7871212ADF6] (Mozilla Corporation)
adawareservice.exe -> C:Program FilesAd-Aware AntivirusAdAwareService.exe -> [2012/05/03 18:37:54 | 001,226,096 | ---- | M | MD5 = 09E61047B0CEF21559CFCEDF4F14D216] (Lavasoft Limited)
adaware.exe -> C:Program FilesAd-Aware AntivirusAdAware.exe -> [2012/05/03 18:37:50 | 020,221,792 | ---- | M | MD5 = 54F71FFAE3C44EDE7C9A3050856ABFB2] (Lavasoft Limited)
chrome.exe -> C:Program FilesGoogleChromeApplicationchrome.exe -> [2012/04/27 19:07:02 | 001,224,176 | ---- | M | MD5 = CF220DD7DA87336E697090A25A1B8C99] (Google Inc.)
mbamservice.exe -> C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe -> [2012/04/04 15:56:40 | 000,654,408 | ---- | M | MD5 = BA400ED640BCA1EAE5C727AE17C10207] (Malwarebytes Corporation)
mbamgui.exe -> C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe -> [2012/04/04 15:56:38 | 000,462,408 | ---- | M | MD5 = 1B82BCF0B8F9228B39F75B0DFA079A21] (Malwarebytes Corporation)
sbamsvc.exe -> C:Program FilesAd-Aware AntivirusSBAMSvc.exe -> [2011/12/19 13:20:06 | 003,289,032 | ---- | M | MD5 = BCE943896289A91AD75CC5652620B1C6] (GFI Software)
realsched.exe -> C:Program FilesRealRealPlayerUpdaterealsched.exe -> [2011/11/10 15:42:58 | 000,273,528 | ---- | M | MD5 = 2AA60514B683F15CF484C4A9F21C3425] (RealNetworks, Inc.)
ccsvchst.exe -> C:Program FilesNorton Safe Web LiteEngine2.0.0.16ccSvcHst.exe -> [2011/08/10 13:52:54 | 000,138,760 | R--- | M | MD5 = E127420B7FEB65C7F279EAAC183BBC0E] (Symantec Corporation)
explorer.exe -> C:Windowsexplorer.exe -> [2009/04/10 23:27:36 | 002,926,592 | ---- | M | MD5 = D07D4C3038F3578FFCE1C0237F2A1253] (Microsoft Corporation)
rthdvcpl.exe -> C:WindowsRtHDVCpl.exe -> [2008/01/15 11:26:18 | 004,874,240 | ---- | M | MD5 = 361CD47DC5BD83EE24407903233B0D9A] (Realtek Semiconductor)
finepixviewer.exe -> C:Program FilesFinePixViewerFinePixViewer.exe -> [2008/01/07 19:43:34 | 001,118,208 | ---- | M | MD5 = BC567123913E597F915473EA30461420] (FUJIFILM Corporation)
hpsysdrv.exe -> C:hpsupporthpsysdrv.exe -> [2007/04/18 08:01:34 | 000,065,536 | ---- | M | MD5 = 9A4322EE420D6FACD4D4B1FF6CB856B1] (Hewlett-Packard Company)
osd.exe -> C:Program FilesHewlett-PackardOn-Screen OSD IndicatorOSD.exe -> [2007/02/15 04:59:00 | 000,118,784 | ---- | M | MD5 = B1361669BDC6ED612C35B7C67ADA2240] (OsdMaestro)
[Modules - No Company Name]
mozjs.dll -> C:Program FilesMozilla Firefoxmozjs.dll -> [2012/05/04 15:26:18 | 001,952,696 | ---- | M | MD5 = 97258F0898F8E3F3D154CE1DD71FD50B] ()
ppgooglenaclpluginchrome.dll -> C:Program FilesGoogleChromeApplication18.0.1025.168ppgooglenaclpluginchrome.dll -> [2012/04/27 19:07:01 | 000,444,400 | ---- | M | MD5 = 25A9C83394201574B31CA4EB43D497F4] ()
pdf.dll -> C:Program FilesGoogleChromeApplication18.0.1025.168pdf.dll -> [2012/04/27 19:06:59 | 003,915,248 | ---- | M | MD5 = B5841E70F40BA006DE2B8C7490D05D49] ()
avutil-51.dll -> C:Program FilesGoogleChromeApplication18.0.1025.168avutil-51.dll -> [2012/04/27 19:05:34 | 000,122,880 | ---- | M | MD5 = 8E60F27A0FD98F567E23D38F62BB10DD] ()
avformat-53.dll -> C:Program FilesGoogleChromeApplication18.0.1025.168avformat-53.dll -> [2012/04/27 19:05:33 | 000,220,672 | ---- | M | MD5 = C17C148BB0FE8EBF8433FE68D7D9AE9D] ()
avcodec-53.dll -> C:Program FilesGoogleChromeApplication18.0.1025.168avcodec-53.dll -> [2012/04/27 19:05:32 | 001,747,456 | ---- | M | MD5 = 52431757325B19E67A2EC12FA85A8742] ()
gcswf32.dll -> C:Program FilesGoogleChromeApplication18.0.1025.168gcswf32.dll -> [2012/04/27 18:09:18 | 008,743,584 | ---- | M | MD5 = 0EC672FB962E114339FCD78497827F9A] ()
zlib1.dll -> C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll -> [2011/09/27 07:23:00 | 000,087,912 | ---- | M | MD5 = 2E14406E05789F91C9282AE7CFCA3A07] ()
libxml2.dll -> C:Program FilesCommon FilesAppleApple Application Supportlibxml2.dll -> [2011/09/27 07:22:40 | 001,242,472 | ---- | M | MD5 = 73862FF693168369A90F046E7F227B83] ()
helpercommand.dll -> C:Program FilesFinePixViewerSystemHelperCommand.dll -> [2007/12/21 19:36:08 | 004,689,920 | ---- | M | MD5 = B2A542B5218B0ABA2241A8C1D9D1B61C] ()
openasrun.dll -> C:Program FilesFinePixViewerSystemOpenAsRun.dll -> [2007/11/30 19:58:48 | 000,176,128 | ---- | M | MD5 = E3D9B58A8EB9C80768B6B1E07ECADFF2] ()
servicecustomize.dll -> C:Program FilesFinePixViewerSystemServiceCustomize.dll -> [2006/12/15 21:51:00 | 000,249,856 | ---- | M | MD5 = 8230A26E104B559DF44074E82EBD31D8] ()
wmfsdk.dll -> C:Program FilesFinePixViewerWMFSDK.dll -> [2004/06/19 13:51:00 | 000,114,688 | ---- | M | MD5 = B9181EAA0DCF2F4FA14B897826261AB7] ()
ssleay32.dll -> C:Program FilesFinePixViewerssleay32.dll -> [2001/06/23 23:24:00 | 000,147,456 | ---- | M | MD5 = 28839EADDE7692B2785A65C87743F7F8] ()
libeay32.dll -> C:Program FilesFinePixViewerlibeay32.dll -> [2001/06/23 23:23:00 | 000,708,608 | ---- | M | MD5 = BE2D8DA8FAABF572A4214E1BCA5B40DE] ()
[Win32 Services - Safe List]
(AdwareAlertSrv) AdwareAlert Scanning Engine [Auto | Stopped] -> -> File not found
(AdobeFlashPlayerUpdateSvc) Adobe Flash Player Update Service [On_Demand | Stopped] -> C:WindowsSystem32MacromedFlashFlashPlayerUpdateService.exe -> [2012/05/05 15:40:06 | 000,257,696 | ---- | M | MD5 = 76D5A3D2A50402A0B9B6ED13C4371E79] (Adobe Systems Incorporated)
(MozillaMaintenance) Mozilla Maintenance Service [On_Demand | Stopped] -> C:Program FilesMozilla Maintenance Servicemaintenanceservice.exe -> [2012/05/04 15:26:19 | 000,129,976 | ---- | M | MD5 = 96AA8BA23142CC8E2B30F3CAE0C80254] (Mozilla Foundation)
(Ad-Aware Service) Ad-Aware Service [Auto | Running] -> C:Program FilesAd-Aware AntivirusAdAwareService.exe -> [2012/05/03 18:37:54 | 001,226,096 | ---- | M | MD5 = 09E61047B0CEF21559CFCEDF4F14D216] (Lavasoft Limited)
(MBAMService) MBAMService [Auto | Running] -> C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe -> [2012/04/04 15:56:40 | 000,654,408 | ---- | M | MD5 = BA400ED640BCA1EAE5C727AE17C10207] (Malwarebytes Corporation)
(SBAMSvc) Ad-Aware [Auto | Running] -> C:Program FilesAd-Aware AntivirusSBAMSvc.exe -> [2011/12/19 13:20:06 | 003,289,032 | ---- | M | MD5 = BCE943896289A91AD75CC5652620B1C6] (GFI Software)
(NSL) Norton Safe Web Lite [Unknown | Running] -> C:Program FilesNorton Safe Web LiteEngine2.0.0.16ccSvcHst.exe -> [2011/08/10 13:52:54 | 000,138,760 | R--- | M | MD5 = E127420B7FEB65C7F279EAAC183BBC0E] (Symantec Corporation)
[Driver Services - Safe List]
(MBAMProtector) MBAMProtector [File_System | On_Demand | Running] -> C:WindowsSystem32driversmbam.sys -> [2012/04/04 15:56:40 | 000,022,344 | ---- | M | MD5 = FB097BBC1A18F044BD17BD2FCCF97865] (Malwarebytes Corporation)
(SbFw) SbFw [Kernel | System | Running] -> C:WindowsSystem32driversSbFw.sys -> [2011/12/19 12:44:24 | 000,223,864 | ---- | M | MD5 = BCF3BA30C1CFA2942CF26C31384B37C7] (GFI Software)
(sbhips) sbhips [Kernel | On_Demand | Running] -> C:WindowsSystem32driverssbhips.sys -> [2011/12/19 12:44:24 | 000,093,816 | ---- | M | MD5 = 1AFD7178AB9C4FCE2D332DA7AA474FA6] (GFI Software)
(sbwtis) sbwtis [Kernel | On_Demand | Stopped] -> C:WindowsSystem32driverssbwtis.sys -> [2011/12/19 12:44:24 | 000,072,312 | ---- | M | MD5 = 9BDF801A6C78E3F1E6FA1C5CA90BAA8A] (GFI Software)
(sbapifs) sbapifs [File_System | Auto | Running] -> C:WindowsSystem32driverssbapifs.sys -> [2011/11/29 06:59:52 | 000,077,816 | ---- | M | MD5 = 3FFF8CDA4D2F29CA06F1557E85163C30] (GFI Software)
(SBRE) SBRE [Kernel | System | Running] -> C:WindowsSystem32driversSBREDrv.sys -> [2011/10/26 14:23:40 | 000,101,112 | ---- | M | MD5 = 1FD538C4FEB36B793D2121F20BBDC16F] (GFI Software)
(SBFWIMCLMP) GFI Software Firewall NDIS IM Filter Miniport [Kernel | On_Demand | Running] -> C:WindowsSystem32driversSbFwIm.sys -> [2011/09/29 12:16:18 | 000,094,584 | ---- | M | MD5 = 1DCAD90CC9C0DDC7D060FD97854F8518] (GFI Software)
(SBFWIMCL) GFI Software Firewall NDIS IM Filter Service [Kernel | On_Demand | Stopped] -> C:WindowsSystem32driversSbFwIm.sys -> [2011/09/29 12:16:18 | 000,094,584 | ---- | M | MD5 = 1DCAD90CC9C0DDC7D060FD97854F8518] (GFI Software)
(ccSet_NST) Norton Safe Web Lite Settings Manager [Kernel | System | Running] -> C:Windowssystem32driversNST\0200000.010ccSetx86.sys -> [2011/08/08 16:38:11 | 000,132,744 | R--- | M | MD5 = 2B2F9B4A08190334A9C36446B208BAE9] (Symantec Corporation)
(WUSB54GCv3) Compact Wireless-G USB Network Adapter [Kernel | On_Demand | Stopped] -> C:WindowsSystem32driversWUSB54GCv3.sys -> [2008/12/04 06:17:15 | 000,645,120 | ---- | M | MD5 = 2E812881EC96E80EAE304877ED90206B] (Ralink Technology Corp.)
(HSXHWBS2) HSXHWBS2 [Kernel | On_Demand | Running] -> C:WindowsSystem32driversHSXHWBS2.sys -> [2008/05/08 05:05:18 | 000,266,752 | ---- | M | MD5 = FE440536BD98AF772130DC3A6FE1915F] (Conexant Systems, Inc.)
(HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> C:WindowsSystem32driversHSX_DP.sys -> [2008/05/08 05:03:18 | 000,980,992 | ---- | M | MD5 = 88749FBF8BEB18C90E7D6626C8C1910B] (Conexant Systems, Inc.)
(XAudio) XAudio [Kernel | Auto | Running] -> C:WindowsSystem32driversXAudio.sys -> [2007/10/18 07:36:54 | 000,008,704 | ---- | M | MD5 = DAB33CFA9DD24251AAA389FF36B64D4B] (Conexant Systems, Inc.)
(RTL8169) Realtek 8169 NT Driver [Kernel | On_Demand | Running] -> C:WindowsSystem32driversRtlh86.sys -> [2007/03/05 14:28:00 | 000,076,288 | ---- | M | MD5 = 71B7026D61293C1E91145BDAD11C53BF] (Realtek Corporation )
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE] > -> ->
HKEY_LOCAL_MACHINE: Main"Default_Page_URL" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop ->
HKEY_LOCAL_MACHINE: Main"Start Page" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop ->
< Internet Explorer Settings [HKEY_USERS.DEFAULT] > -> ->
HKEY_USERS.DEFAULT: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERSS-1-5-18] > -> ->
HKEY_USERSS-1-5-18: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERSS-1-5-19] > -> ->
< Internet Explorer Settings [HKEY_USERSS-1-5-20] > -> ->
< Internet Explorer Settings [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> ->
HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000: Main"Start Page" -> http://www.google.com/ ->
HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000: Main"StartPageCache" -> 1 ->
HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:UsersOwnerAppDataRoamingMozillaFireFoxProfiles7tmkfm7m.defaultprefs.j
s ->
extensions.enabledItems -> {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.2 ->
extensions.enabledItems -> {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.7 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINESOFTWAREMozilla
HKLMsoftwaremozillaFirefoxExtensions -> ->
HKLMsoftwaremozillaFirefoxExtensions{ABDE892B-13A8-4d1b-88E6-365A6E755758} -> C:ProgramDataRealRealPlayerBrowserRecordPluginFirefoxExt [C:PROGRAMDATAREALREALPLAYERBROWSERRECORDPLUGINFIREFOXEXT] -> [2011/11/10 15:44:25 | 000,000,000 | ---D | M]
HKLMsoftwaremozillaFirefoxExtensions{203FB6B2-2E1E-4474-863B-4C483ECCE78E} -> C:PROGRAMDATANORTON{92622AAD-05E8-4459-B256-765CE1E929FB}NST_2.0.0.16COFFNST [C:PROGRAMDATANORTON{92622AAD-05E8-4459-B256-765CE1E929FB}NST_2.0.0.16COFFNST] -> [2012/05/14 17:57:07 | 000,000,000 | ---D | M]
HKLMsoftwaremozillaMozilla Firefox 12.0extensions -> ->
HKLMsoftwaremozillaMozilla Firefox 12.0extensionsComponents -> C:Program FilesMozilla Firefoxcomponents [C:PROGRAM FILESMOZILLA FIREFOXCOMPONENTS] -> [2012/05/13 10:49:54 | 000,000,000 | ---D | M]
HKLMsoftwaremozillaMozilla Firefox 12.0extensionsPlugins -> C:Program FilesMozilla Firefoxplugins [C:PROGRAM FILESMOZILLA FIREFOXPLUGINS] -> [2012/04/20 12:52:09 | 000,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:UsersOwnerAppDataRoamingMozillaExtensions -> [2008/08/27 20:02:41 | 000,000,000 | ---D | M]
-> C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles7tmkfm7m.defaultextensi
ons -> [2012/05/13 10:34:05 | 000,000,000 | ---D | M]
Microsoft .NET Framework Assistant -> C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles7tmkfm7m.defaultextensi
ons{20a82645-c095-46ed-80e3-08825760534b} -> [2010/06/23 22:25:46 | 000,000,000 | ---D | M]
Ad-Aware Security Toolbar -> C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles7tmkfm7m.defaultextensi
ons{87934c42-161d-45bc-8cef-ef18abe2a30c} -> [2012/05/13 10:34:01 | 000,000,000 | ---D | M]
-> C:UsersOwnerAppDataRoamingMozillaFirefoxProfiles7tmkfm7m.defaultextensi
onsjid1-yZwVFzbsyfMrqQ@jetpack -> [2012/05/13 10:34:11 | 000,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:Program FilesMozilla Firefoxextensions -> [2010/12/11 18:06:49 | 000,000,000 | ---D | M]
FoxyTunes -> C:Program FilesMozilla Firefoxextensions{463F6CA5-EE3C-4be1-B7E6-7FEE11953374} -> [2008/08/27 20:02:25 | 000,000,000 | ---D | M]
Yahoo! Toolbar -> C:Program FilesMozilla Firefoxextensions{635abd67-4fe9-1b23-4f01-e679fa7484c1} -> [2008/08/27 20:03:03 | 000,000,000 | ---D | M]
< HOSTS File > ([2008/08/29 17:37:55 | 000,262,111 | R--- | M | MD5 = 8A0CC4C9B8418D4FC1CAC21C11FA7873] - 9141 lines) -> C:WindowsSystem32driversetchosts ->
First 25 entries...
Reset Hosts
127.0.0.1 localhost
::1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.1001-search.info
127.0.0.1 1001-search.info
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects ->
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 000,062,080 | ---- | M | Unable to obtain MD5] (Adobe Systems Incorporated)
{3049C3E9-B461-4BC5-8870-4C09146192CA} [HKLM] -> C:ProgramDataRealRealPlayerBrowserRecordPluginIErpbrowserrecordplugin.dll [RealPlayer Download and Record Plugin for Internet Explorer] -> [2011/11/10 15:44:19 | 000,414,416 | ---- | M | MD5 = CC54CD805B70DD0DDAADC00FC38C9994] (RealPlayer)
{6c97a91e-4524-4019-86af-2aa2d567bf5c} [HKLM] -> C:Program FilesadawaretbadawareDx.dll [Ad-Aware Security Toolbar] -> [2012/04/11 13:08:22 | 000,087,440 | ---- | M | MD5 = 6B94578EE59FB048F573B9C8C4149FC7] ()
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:Program FilesJavajre1.6.0_01binssv.dll [SSVHelper Class] -> [2007/04/07 02:56:44 | 000,501,400 | ---- | M | MD5 = CF2AB814CFF79B489402D5D2DD910BF1] (Sun Microsystems, Inc.)
{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} [HKLM] -> C:Program FilesNorton Safe Web LiteEngine2.0.0.16CoIEPlg.dll [Norton Safe Web Lite BHO] -> [2011/10/14 17:49:11 | 000,492,984 | R--- | M | MD5 = 0266D544C8A639A232F883470EF14C20] (Symantec Corporation)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolBar ->
"{30CEEEA2-3742-40e4-85DD-812BF1CBB83D}" [HKLM] -> C:Program FilesNorton Safe Web LiteEngine2.0.0.16CoIEPlg.dll [Norton Safe Web Lite] -> [2011/10/14 17:49:11 | 000,492,984 | R--- | M | MD5 = 0266D544C8A639A232F883470EF14C20] (Symantec Corporation)
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}" [HKLM] -> C:Program FilesadawaretbadawareDx.dll [Ad-Aware Security Toolbar] -> [2012/04/11 13:08:22 | 000,087,440 | ---- | M | MD5 = 6B94578EE59FB048F573B9C8C4149FC7] ()
< Internet Explorer ToolBars [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SoftwareMicrosoftInternet ExplorerToolbar ->
WebBrowser"{30CEEEA2-3742-40E4-85DD-812BF1CBB83D}" [HKLM] -> C:Program FilesNorton Safe Web LiteEngine2.0.0.16CoIEPlg.dll [Norton Safe Web Lite] -> [2011/10/14 17:49:11 | 000,492,984 | R--- | M | MD5 = 0266D544C8A639A232F883470EF14C20] (Symantec Corporation)
< Run [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun ->
"Ad-Aware Antivirus" -> C:Program FilesAd-Aware AntivirusAdAwareLauncher.exe ["C:Program FilesAd-Aware AntivirusAdAwareLauncher" --windows-run] -> [2012/05/03 18:37:52 | 001,771,888 | ---- | M | MD5 = 2301901E6EDDEDB1345007DBF1A4FE2A] (Lavasoft Limited)
"Ad-Aware Browsing Protection" -> C:ProgramDataAd-Aware Browsing Protectionadawarebp.exe ["C:ProgramDataAd-Aware Browsing Protectionadawarebp.exe"] -> [2011/10/21 02:09:36 | 000,198,032 | ---- | M | MD5 = C5F1D82D9CC8979971CC748FCB2EE7CA] (Lavasoft)
"APSDaemon" -> C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe ["C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe"] -> [2011/09/27 07:22:28 | 000,059,240 | ---- | M | MD5 = F7DD2D785280DB73DC9060F80361BEFB] (Apple Inc.)
"HP Health Check Scheduler" -> c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe [c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe] -> [2007/05/24 13:13:16 | 000,071,176 | ---- | M | MD5 = 2D141D455A3F1BDAC97A08006ACD7B4B] (Hewlett-Packard)
"hpsysdrv" -> c:hpsupporthpsysdrv.exe [c:hpsupporthpsysdrv.exe] -> [2007/04/18 08:01:34 | 000,065,536 | ---- | M | MD5 = 9A4322EE420D6FACD4D4B1FF6CB856B1] (Hewlett-Packard Company)
"Malwarebytes' Anti-Malware" -> C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe ["C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe" /starttray] -> [2012/04/04 15:56:38 | 000,462,408 | ---- | M | MD5 = 1B82BCF0B8F9228B39F75B0DFA079A21] (Malwarebytes Corporation)
"OsdMaestro" -> C:Program FilesHewlett-PackardOn-Screen OSD IndicatorOSD.exe ["C:Program FilesHewlett-PackardOn-Screen OSD IndicatorOSD.exe"] -> [2007/02/15 04:59:00 | 000,118,784 | ---- | M | MD5 = B1361669BDC6ED612C35B7C67ADA2240] (OsdMaestro)
"RtHDVCpl" -> C:WindowsRtHDVCpl.exe [RtHDVCpl.exe] -> [2008/01/15 11:26:18 | 004,874,240 | ---- | M | MD5 = 361CD47DC5BD83EE24407903233B0D9A] (Realtek Semiconductor)
"SBC_McciTrayApp" -> [C:Program FilesSBCupdateSST.exe] -> File not found
"TkBellExe" -> c:program filesrealrealplayerUpdaterealsched.exe ["c:program filesrealrealplayerUpdaterealsched.exe" -osboot] -> [2011/11/10 15:42:58 | 000,273,528 | ---- | M | MD5 = 2AA60514B683F15CF484C4A9F21C3425] (RealNetworks, Inc.)
< Run [HKEY_USERSS-1-5-19] > -> HKEY_USERSS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionRun ->
"WindowsWelcomeCenter" -> C:WindowsSystem32oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/10 23:28:23 | 002,153,472 | ---- | M | MD5 = 16FC5B430123238E522B18E63C257AF8] (Microsoft Corporation)
< Run [HKEY_USERSS-1-5-20] > -> HKEY_USERSS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionRun ->
"WindowsWelcomeCenter" -> C:WindowsSystem32oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/10 23:28:23 | 002,153,472 | ---- | M | MD5 = 16FC5B430123238E522B18E63C257AF8] (Microsoft Corporation)
< Run [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionRun ->
"chromium" -> C:Program FilesGoogleChromeApplicationchrome.exe [C:Program FilesGoogleChromeApplicationchrome.exe --no-startup-window] -> [2012/04/27 19:07:02 | 001,224,176 | ---- | M | MD5 = CF220DD7DA87336E697090A25A1B8C99] (Google Inc.)
"System Protection Tools" -> ["C:ProgramData\069f81SP069_8068.exe" /s /d] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer ->
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem ->
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystemUIP
IClipboardExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer ->
HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer
"NoDriveTypeAutoRun" -> [157] -> File not found
< CurrentVersion Policy Settings [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem ->
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerExtensions ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} [HKLM] -> C:Program FilesJavajre1.6.0_01binssv.dll [Menu: Sun Java Console] -> [2007/04/07 02:56:44 | 000,501,400 | ---- | M | MD5 = CF2AB814CFF79B489402D5D2DD910BF1] (Sun Microsystems, Inc.)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerPlugins ->
< Default Prefix > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionURLDefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains ->
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains -> [Key] 4786 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges ->
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS.DEFAULT] > -> HKEY_USERS.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains ->
HKEY_USERS.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains -> [Key] 4786 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS.DEFAULT] > -> HKEY_USERS.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges ->
HKEY_USERS.DEFAULTSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERSS-1-5-18] > -> HKEY_USERSS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains ->
HKEY_USERSS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains -> [Key] 4786 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERSS-1-5-18] > -> HKEY_USERSS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges ->
HKEY_USERSS-1-5-18SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERSS-1-5-19] > -> HKEY_USERSS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains ->
HKEY_USERSS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERSS-1-5-19] > -> HKEY_USERSS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges ->
HKEY_USERSS-1-5-19SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERSS-1-5-20] > -> HKEY_USERSS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains ->
HKEY_USERSS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERSS-1-5-20] > -> HKEY_USERSS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges ->
HKEY_USERSS-1-5-20SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains ->
HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapDomains -> [Key] 4770 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000] > -> HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges ->
HKEY_USERSS-1-5-21-3990776023-3137282466-4049488173-1000SOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsZoneMapRanges -> [Key] 77 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftCode Store DatabaseDistribution Units ->
{44990B00-3C9D-426D-81DF-AAB636FA4345} [HKLM] -> https://www-secure.symantec.com/techsupp/as...abs/tgctlcm.cab [Symantec Configuration Class] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab [Shockwave Flash Object] ->
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] -> http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab [Reg Error: Key error.] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParameters ->
DhcpNameServer -> [removed] [removed] [removed] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParametersAdapters ->
{DC20AA77-DE12-402A-930A-794FF61ECAA1}DhcpNameServer -> [removed] [removed] [removed] (Realtek RTL8101 Family PCI-E Fast Ethernet NIC (NDIS 6.0)) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon ->
*Shell* -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonShell ->
explorer.exe -> C:Windowsexplorer.exe -> [2009/04/10 23:27:36 | 002,926,592 | ---- | M | MD5 = D07D4C3038F3578FFCE1C0237F2A1253] (Microsoft Corporation)
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonUserInit ->
C:Windowssystem32userinit.exe -> C:WindowsSystem32userinit.exe -> [2008/01/19 00:33:33 | 000,025,088 | ---- | M | MD5 = 0E135526E9785D085BCD9AEDE6FBCBF9] (Microsoft Corporation)
*MultiFile Done* -> ->
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFir
ewallPolicyStandardProfileAuthorizedApplicationsList ->
"C:Program FilesEarthLink TotalAccessTaskPanl.exe" -> C:Program FilesEarthLink TotalAccessTaskPanl.exe [C:Program FilesEarthLink TotalAccessTaskPanl.exe:*:Enabled:Earthlink] -> [2006/08/30 05:35:12 | 000,952,088 | ---- | M | MD5 = 306109A57D8110838FD322EF2B953804] (EarthLink, Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesCdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32DRIVERScdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:autoexec.bat [REM Dummy file for NTVDMPATH=%PATH%;C:PROGRA~1COMMON~1MUVEET~1\030625 | ] -> C:autoexec.bat [ NTFS ] -> [2007/08/03 00:50:20 | 000,000,074 | ---- | M | MD5 = C3178889B2A4EA69F90E3FA06C383346] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExplorerMountPoints
2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINESOFTWAREClasses ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 3/14/2010 9:50:06 PM Computer Name = Owner-PC | Source = Application Error | ID = 1000 -> Description = Faulting application FinePixViewer.exe, version 5.5.0.0, time stamp 0x47820254, faulting module FinePixViewer.exe, version 5.5.0.0, time stamp 0x47820254, exception code 0xc0000094, fault offset 0x0002ed43, process id 0x2dc, application start time 0x01cac3e19b3bd500.
Application [ Error ] 3/14/2010 10:32:18 PM Computer Name = Owner-PC | Source = Application Hang | ID = 1002 -> Description = The program Explorer.EXE version 6.0.6001.18164 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel. Process ID: 79c Start Time: 01cac3e064e4c604 Termination Time: 0
Application [ Error ] 3/14/2010 10:34:11 PM Computer Name = Owner-PC | Source = Application Error | ID = 1000 -> Description = Faulting application QuickDCF2.exe, version 1.1.1.0, time stamp 0x45beb544, faulting module ole32.dll, version 6.0.6001.18000, time stamp 0x4791a74c, exception code 0xc0000005, fault offset 0x0003807d, process id 0x5b4, application start time 0x01cac3e06a245ef4.
Application [ Error ] 3/14/2010 11:53:04 PM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
Application [ Error ] 3/14/2010 11:55:19 PM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
Application [ Error ] 3/14/2010 11:57:03 PM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
Application [ Error ] 3/15/2010 12:00:33 AM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
Application [ Error ] 3/15/2010 12:01:31 AM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
Application [ Error ] 3/15/2010 12:03:16 AM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
Application [ Error ] 3/15/2010 12:05:52 AM Computer Name = Owner-PC | Source = VSS | ID = 8194 -> Description =
System [ Error ] 5/14/2012 8:58:27 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7022 -> Description =
System [ Error ] 5/14/2012 8:58:28 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7026 -> Description =
System [ Error ] 5/14/2012 9:01:10 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009 -> Description =
System [ Error ] 5/14/2012 9:02:12 PM Computer Name = Owner-PC | Source = DCOM | ID = 10010 -> Description =
System [ Error ] 5/14/2012 9:02:39 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009 -> Description =
System [ Error ] 5/14/2012 9:02:39 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000 -> Description =
System [ Error ] 5/14/2012 9:13:01 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000 -> Description =
System [ Error ] 5/14/2012 9:13:22 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7022 -> Description =
System [ Error ] 5/14/2012 9:13:51 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000 -> Description =
System [ Error ] 5/14/2012 9:13:52 PM Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000 -> Description =
[Files/Folders - Created Within 360 Days]
Malwarebytes -> C:UsersOwnerAppDataRoamingMalwarebytes -> [2012/05/14 11:47:52 | 000,000,000 | ---D | C]
Malwarebytes -> C:ProgramDataMalwarebytes -> [2012/05/14 11:47:06 | 000,000,000 | ---D | C]
mbam.sys -> C:WindowsSystem32driversmbam.sys -> [2012/05/14 11:47:05 | 000,022,344 | ---- | C | MD5 = FB097BBC1A18F044BD17BD2FCCF97865] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:Program FilesMalwarebytes' Anti-Malware -> [2012/05/14 11:47:05 | 000,000,000 | ---D | C]
adaware -> C:UsersOwnerAppDataLocaladaware -> [2012/05/13 10:59:59 | 000,000,000 | ---D | C]
Ad-Aware Antivirus -> C:ProgramDataMicrosoftWindowsStart MenuProgramsAd-Aware Antivirus -> [2012/05/13 10:58:53 | 000,000,000 | ---D | C]
sbhips.sys -> C:WindowsSystem32driverssbhips.sys -> [2012/05/13 10:56:14 | 000,093,816 | ---- | C | MD5 = 1AFD7178AB9C4FCE2D332DA7AA474FA6] (GFI Software)
SbFwIm.sys -> C:WindowsSystem32driversSbFwIm.sys -> [2012/05/13 10:53:10 | 000,094,584 | ---- | C | MD5 = 1DCAD90CC9C0DDC7D060FD97854F8518] (GFI Software)
SbFw.sys -> C:WindowsSystem32driversSbFw.sys -> [2012/05/13 10:53:09 | 000,223,864 | ---- | C | MD5 = BCF3BA30C1CFA2942CF26C31384B37C7] (GFI Software)
VDD -> C:WindowsSystem32driversVDD -> [2012/05/13 10:53:04 | 000,000,000 | ---D | C]
Ad-Aware Antivirus -> C:Program FilesAd-Aware Antivirus -> [2012/05/13 10:53:00 | 000,000,000 | ---D | C]
adawarebp -> C:UsersOwnerAppDataLocaladawarebp -> [2012/05/13 10:49:51 | 000,000,000 | ---D | C]
Ad-Aware Browsing Protection -> C:ProgramDataAd-Aware Browsing Protection -> [2012/05/13 10:49:47 | 000,000,000 | ---D | C]
Toolbar Cleaner -> C:Program FilesToolbar Cleaner -> [2012/05/13 10:34:15 | 000,000,000 | ---D | C]
adawaretb -> C:Program Filesadawaretb -> [2012/05/13 10:33:36 | 000,000,000 | ---D | C]
Ad-Aware Antivirus -> C:UsersOwnerAppDataRoamingAd-Aware Antivirus -> [2012/05/13 10:31:37 | 000,000,000 | ---D | C]
System Protection Tools -> C:UsersOwnerAppDataRoamingSystem Protection Tools -> [2012/05/12 15:00:24 | 000,000,000 | -HSD | C]
SPOKKIT -> C:ProgramDataSPOKKIT -> [2012/05/12 15:00:18 | 000,000,000 | -HSD | C]
069f81 -> C:ProgramData\069f81 -> [2012/05/12 14:59:52 | 000,000,000 | -HSD | C]
8c44c5e6273895bc008a2a4634 -> C:8c44c5e6273895bc008a2a4634 -> [2012/05/11 17:50:47 | 000,000,000 | ---D | C]
DWrite.dll -> C:WindowsSystem32DWrite.dll -> [2012/05/10 18:56:46 | 001,069,056 | ---- | C | MD5 = CABD1B34BD05C986B4DBC18BC0E947EE] (Microsoft Corporation)
d3d10warp.dll -> C:WindowsSystem32d3d10warp.dll -> [2012/05/10 18:56:45 | 001,172,480 | ---- | C | MD5 = 4A4C71376ECA305D6DEA021F1A44816D] (Microsoft Corporation)
d3d10_1core.dll -> C:WindowsSystem32d3d10_1core.dll -> [2012/05/10 18:56:45 | 000,219,648 | ---- | C | MD5 = A441F5B43EAF4BD4E3ACFBE38841B46B] (Microsoft Corporation)
d2d1.dll -> C:WindowsSystem32d2d1.dll -> [2012/05/10 18:56:44 | 000,683,008 | ---- | C | MD5 = E9B39C81C87E5B790FCE121DA9E02701] (Microsoft Corporation)
d3d10_1.dll -> C:WindowsSystem32d3d10_1.dll -> [2012/05/10 18:56:44 | 000,160,768 | ---- | C | MD5 = 5256383D1D266A9EEFCDB270340C0E5C] (Microsoft Corporation)
ntoskrnl.exe -> C:WindowsSystem32ntoskrnl.exe -> [2012/05/10 18:56:02 | 003,550,080 | ---- | C | MD5 = BA4C485548914034B471EB6FC2B50082] (Microsoft Corporation)
ntkrnlpa.exe -> C:WindowsSystem32ntkrnlpa.exe -> [2012/05/10 18:56:01 | 003,602,816 | ---- | C | MD5 = CAD95AFB7FDDCC490681555C570FBB7D] (Microsoft Corporation)
win32k.sys -> C:WindowsSystem32win32k.sys -> [2012/05/10 18:56:00 | 002,044,928 | ---- | C | MD5 = 98BB495043BD5E98B2E8D2B8239390ED] (Microsoft Corporation)
Mozilla Maintenance Service -> C:Program FilesMozilla Maintenance Service -> [2012/05/04 15:26:24 | 000,000,000 | ---D | C]
Mozilla -> C:ProgramDataMozilla -> [2012/05/04 15:26:24 | 000,000,000 | ---D | C]
mshtml.tlb -> C:WindowsSystem32mshtml.tlb -> [2012/05/02 17:53:30 | 002,382,848 | ---- | C | MD5 = 2CCFBEEA97BB6AF726311437B2DC9265] (Microsoft Corporation)
jscript9.dll -> C:WindowsSystem32jscript9.dll -> [2012/05/02 17:53:27 | 001,799,168 | ---- | C | MD5 = 328E900311D5C31F399730C7CCC8883A] (Microsoft Corporation)
url.dll -> C:WindowsSystem32url.dll -> [2012/05/02 17:53:25 | 000,231,936 | ---- | C | MD5 = 8E35C8E822B6BF11D048C1AA2B076388] (Microsoft Corporation)
ieui.dll -> C:WindowsSystem32ieui.dll -> [2012/05/02 17:53:25 | 000,176,640 | ---- | C | MD5 = CF316FA04D6BD6168223A0E029C6C874] (Microsoft Corporation)
jsproxy.dll -> C:WindowsSystem32jsproxy.dll -> [2012/05/02 17:53:25 | 000,065,024 | ---- | C | MD5 = 327695074718E1BDAC226B2A16F425E2] (Microsoft Corporation)
inetcpl.cpl -> C:WindowsSystem32inetcpl.cpl -> [2012/05/02 17:53:23 | 001,427,456 | ---- | C | MD5 = 8D8BE3DCACEA6C8E52D506E7BAAEA2D4] (Microsoft Corporation)
TDSSKiller.exe -> C:UsersOwnerTDSSKiller.exe -> [2012/05/02 10:00:04 | 002,075,184 | ---- | C | MD5 = 03AEB6909BD8CE8957CA30928DC648C9] (Kaspersky Lab ZAO)
XpsPrint.dll -> C:WindowsSystem32XpsPrint.dll -> [2012/05/01 18:59:54 | 000,876,032 | ---- | C | MD5 = 9F3A1B7FB81A41C7C7AC82B3D07A1091] (Microsoft Corporation)
Windows Portable Devices -> C:Program FilesWindows Portable Devices -> [2012/04/30 15:15:07 | 000,000,000 | ---D | C]
UIAnimation.dll -> C:WindowsSystem32UIAnimation.dll -> [2012/04/30 12:00:43 | 000,092,672 | ---- | C | MD5 = D6BACADF83661F08F9E1515AAE74B03E] (Microsoft Corporation)
UIRibbon.dll -> C:WindowsSystem32UIRibbon.dll -> [2012/04/30 12:00:42 | 003,023,360 | ---- | C | MD5 = 8C459CFAC2FB3DFB693BCFEC32F25407] (Microsoft Corporation)
UIRibbonRes.dll -> C:WindowsSystem32UIRibbonRes.dll -> [2012/04/30 12:00:42 | 001,164,800 | ---- | C | MD5 = 22C2646DD3ED24004F994D0DA9755955] (Microsoft Corporation)
BthMtpContextHandler.dll -> C:WindowsSystem32BthMtpContextHandler.dll -> [2012/04/30 11:59:13 | 000,031,232 | ---- | C | MD5 = 9B9108D3019C18BD6D38B860813E6E52] (Microsoft Corporation)
WPDShextAutoplay.exe -> C:WindowsSystem32WPDShextAutoplay.exe -> [2012/04/30 11:59:13 | 000,030,208 | ---- | C | MD5 = 1D7D7E32A80109D5C3167309265EAC83] (Microsoft Corporation)
PortableDeviceConnectApi.dll -> C:WindowsSystem32PortableDeviceConnectApi.dll -> [2012/04/30 11:59:12 | 000,060,928 | ---- | C | MD5 = B53BD9E63867CD9FD853F666CA172713] (Microsoft Corporation)
wpd_ci.dll -> C:WindowsSystem32wpd_ci.dll -> [2012/04/30 11:59:10 | 000,546,816 | ---- | C | MD5 = 81072240917688254A55C1C568B2377B] (Microsoft Corporation)
WPDSp.dll -> C:WindowsSystem32WPDSp.dll -> [2012/04/30 11:59:10 | 000,350,208 | ---- | C | MD5 = 49456BFE373D90B895795C5A1A13A7C8] (Microsoft Corporation)
PortableDeviceApi.dll -> C:WindowsSystem32PortableDeviceApi.dll -> [2012/04/30 11:59:10 | 000,334,848 | ---- | C | MD5 = 2205A220A264E8C8B86492BF3D112907] (Microsoft Corporation)
WpdMtp.dll -> C:WindowsSystem32WpdMtp.dll -> [2012/04/30 11:59:10 | 000,226,816 | ---- | C | MD5 = A8FB1B20C5ABD1817B7F96251293BFF9] (Microsoft Corporation)
PortableDeviceWMDRM.dll -> C:WindowsSystem32PortableDeviceWMDRM.dll -> [2012/04/30 11:59:10 | 000,196,608 | ---- | C | MD5 = C220FC95DA7AD00AB03C184AFDDC5314] (Microsoft Corporation)
PortableDeviceTypes.dll -> C:WindowsSystem32PortableDeviceTypes.dll -> [2012/04/30 11:59:10 | 000,160,256 | ---- | C | MD5 = 883D02AB5D350BC45E0F60E8CFA97FDC] (Microsoft Corporation)
PortableDeviceClassExtension.dll -> C:WindowsSystem32PortableDeviceClassExtension.dll -> [2012/04/30 11:59:10 | 000,100,864 | ---- | C | MD5 = B2B117BD8D1EA80536CDD91797EF4A0A] (Microsoft Corporation)
WpdMtpUS.dll -> C:WindowsSystem32WpdMtpUS.dll -> [2012/04/30 11:59:10 | 000,061,952 | ---- | C | MD5 = 3501443C148C780E8CE6B5108CE6D95E] (Microsoft Corporation)
WpdConns.dll -> C:WindowsSystem32WpdConns.dll -> [2012/04/30 11:59:10 | 000,033,280 | ---- | C | MD5 = 58E42DDB9F734E8DBDA17E806EF3F64A] (Microsoft Corporation)
msls31.dll -> C:WindowsSystem32msls31.dll -> [2012/04/30 11:49:53 | 000,161,792 | ---- | C | MD5 = 35AAE2E841AA1A949775168E119482C9] (Microsoft Corporation)
msrating.dll -> C:WindowsSystem32msrating.dll -> [2012/04/30 11:49:52 | 000,162,304 | ---- | C | MD5 = 0B8FE658BD033EC8B1F6FBC305CC65E7] (Microsoft Corporation)
iesysprep.dll -> C:WindowsSystem32iesysprep.dll -> [2012/04/30 11:49:52 | 000,086,528 | ---- | C | MD5 = EE0AFCEE88098F754212F9069E80A766] (Microsoft Corporation)
SetIEInstalledDate.exe -> C:WindowsSystem32SetIEInstalledDate.exe -> [2012/04/30 11:49:52 | 000,076,800 | ---- | C | MD5 = 736D1B28224F9DF8008BE8B0DEDFC9EF] (Microsoft Corporation)
RegisterIEPKEYs.exe -> C:WindowsSystem32RegisterIEPKEYs.exe -> [2012/04/30 11:49:52 | 000,074,752 | ---- | C | MD5 = 6B036492120E65C0C367DC31D01088A1] (Microsoft Corporation)
mshtmler.dll -> C:WindowsSystem32mshtmler.dll -> [2012/04/30 11:49:52 | 000,048,640 | ---- | C | MD5 = 76E987D8CF0683337CF165363B6FDFD9] (Microsoft Corporation)
ieapfltr.dat -> C:WindowsSystem32ieapfltr.dat -> [2012/04/30 11:49:51 | 003,695,416 | ---- | C | MD5 = 83F5D4B41BB12CE146786E97F6AAD75E] (Microsoft Corporation)
ieapfltr.dll -> C:WindowsSystem32ieapfltr.dll -> [2012/04/30 11:49:51 | 000,434,176 | ---- | C | MD5 = EE9D715AF1B928982F417238B9914484] (Microsoft Corporation)
html.iec -> C:WindowsSystem32html.iec -> [2012/04/30 11:49:51 | 000,367,104 | ---- | C | MD5 = 09C9E7F477FB225FDB3B6DE8FED0AA9B] (Microsoft Corporation)
dxtmsft.dll -> C:WindowsSystem32dxtmsft.dll -> [2012/04/30 11:49:51 | 000,353,792 | ---- | C | MD5 = 4312DEBDACBE338F0B90E7F08E7672BE] (Microsoft Corporation)
iedkcs32.dll -> C:WindowsSystem32iedkcs32.dll -> [2012/04/30 11:49:51 | 000,353,584 | ---- | C | MD5 = F0FEFB0B5D25A75D478A4317139D937E] (Microsoft Corporation)
dxtrans.dll -> C:WindowsSystem32dxtrans.dll -> [2012/04/30 11:49:51 | 000,223,232 | ---- | C | MD5 = CA493A92DA9880B6F1A89C3DBD54BA5B] (Microsoft Corporation)
wextract.exe -> C:WindowsSystem32wextract.exe -> [2012/04/30 11:49:51 | 000,152,064 | ---- | C | MD5 = 67BC2BA6F94D2D0C51213691FBFEEBB1] (Microsoft Corporation)
inseng.dll -> C:WindowsSystem32inseng.dll -> [2012/04/30 11:49:51 | 000,078,848 | ---- | C | MD5 = 60B4F624BB87A3B21D3EC68F38DA6B61] (Microsoft Corporation)
iesetup.dll -> C:WindowsSystem32iesetup.dll -> [2012/04/30 11:49:51 | 000,074,752 | ---- | C | MD5 = 802B0229D904E28C1EA9A5274AB457FC] (Microsoft Corporation)
ie4uinit.exe -> C:WindowsSystem32ie4uinit.exe -> [2012/04/30 11:49:51 | 000,074,240 | ---- | C | MD5 = C0B8B96D018849FD8CCF15FED84E8782] (Microsoft Corporation)
iernonce.dll -> C:WindowsSystem32iernonce.dll -> [2012/04/30 11:49:51 | 000,031,744 | ---- | C | MD5 = F83865A3007357A5E498EB9E3BED273D] (Microsoft Corporation)
licmgr10.dll -> C:WindowsSystem32licmgr10.dll -> [2012/04/30 11:49:51 | 000,023,552 | ---- | C | MD5 = 6B4701D3D9724812E8C3801E7BF87157] (Microsoft Corporation)
msfeeds.dll -> C:WindowsSystem32msfeeds.dll -> [2012/04/30 11:49:50 | 000,580,608 | ---- | C | MD5 = 7940C04CE581288A3498D57EC4EE47D2] (Microsoft Corporation)
ieaksie.dll -> C:WindowsSystem32ieaksie.dll -> [2012/04/30 11:49:50 | 000,227,840 | ---- | C | MD5 = 49729570B7FD369BBDEC16D7683324A0] (Microsoft Corporation)
ieakui.dll -> C:WindowsSystem32ieakui.dll -> [2012/04/30 11:49:50 | 000,163,840 | ---- | C | MD5 = DB754FF5F6ADBA2A25EC1B6672D1C91E] (Microsoft Corporation)
iexpress.exe -> C:WindowsSystem32iexpress.exe -> [2012/04/30 11:49:50 | 000,150,528 | ---- | C | MD5 = 51AF0A12CD86E22E1A027C38CC021AC6] (Microsoft Corporation)
ieUnatt.exe -> C:WindowsSystem32ieUnatt.exe -> [2012/04/30 11:49:50 | 000,142,848 | ---- | C | MD5 = 46418F422DA88859AECE4C0A1AEB752B] (Microsoft Corporation)
admparse.dll -> C:WindowsSystem32admparse.dll -> [2012/04/30 11:49:50 | 000,101,888 | ---- | C | MD5 = 3F7A8BCF37433A69CEEDE1E6AEE79784] (Microsoft Corporation)
pngfilt.dll -> C:WindowsSystem32pngfilt.dll -> [2012/04/30 11:49:50 | 000,054,272 | ---- | C | MD5 = 04A8B2F67825380BC0C7C46D56776133] (Microsoft Corporation)
ieakeng.dll -> C:WindowsSystem32ieakeng.dll -> [2012/04/30 11:49:49 | 000,130,560 | ---- | C | MD5 = 1E7094AFAD0C369DD6D400C7047E4AB2] (Microsoft Corporation)
iepeers.dll -> C:WindowsSystem32iepeers.dll -> [2012/04/30 11:49:49 | 000,118,784 | ---- | C | MD5 = 90A57CA422923286838AAC7DE2D41B92] (Microsoft Corporation)
IEAdvpack.dll -> C:WindowsSystem32IEAdvpack.dll -> [2012/04/30 11:49:49 | 000,110,592 | ---- | C | MD5 = ED6F6FBBCDEC95483B7351E23F4FCDF6] (Microsoft Corporation)
msfeedsbs.dll -> C:WindowsSystem32msfeedsbs.dll -> [2012/04/30 11:49:49 | 000,041,472 | ---- | C | MD5 = 4B80D1F847C0658977E1E8051A4DE002] (Microsoft Corporation)
imgutil.dll -> C:WindowsSystem32imgutil.dll -> [2012/04/30 11:49:49 | 000,035,840 | ---- | C | MD5 = 68563AC389F92EE79F1C714288BA1DCE] (Microsoft Corporation)
msfeedssync.exe -> C:WindowsSystem32msfeedssync.exe -> [2012/04/30 11:49:49 | 000,010,752 | ---- | C | MD5 = 1D3EE28BA231CBB9600F5D102EAF4EA7] (Microsoft Corporation)
mf.dll -> C:WindowsSystem32mf.dll -> [2012/04/30 11:48:20 | 002,873,344 | ---- | C | MD5 = 67D16247C56C26A4F0D79D1A7F272B8F] (Microsoft Corporation)
MFH264Dec.dll -> C:WindowsSystem32MFH264Dec.dll -> [2012/04/30 11:48:20 | 000,979,456 | ---- | C | MD5 = BC5E45CB2304AFB4D2EF2FD9C41299AF] (Microsoft Corporation)
MFHEAACdec.dll -> C:WindowsSystem32MFHEAACdec.dll -> [2012/04/30 11:48:20 | 000,357,376 | ---- | C | MD5 = 44CEE5264282105A89B650FDB07E40FF] (Microsoft Corporation)
mfmp4src.dll -> C:WindowsSystem32mfmp4src.dll -> [2012/04/30 11:48:20 | 000,302,592 | ---- | C | MD5 = 743B1957729DE905DC44782A957FD284] (Microsoft Corporation)
mfreadwrite.dll -> C:WindowsSystem32mfreadwrite.dll -> [2012/04/30 11:48:20 | 000,261,632 | ---- | C | MD5 = 7BE8835CA7E2975F2E865CEEE8821EB6] (Microsoft Corporation)
mfps.dll -> C:WindowsSystem32mfps.dll -> [2012/04/30 11:48:20 | 000,098,816 | ---- | C | MD5 = B9103A56ACABDED3E87C2A8777B6456C] (Microsoft Corporation)
mfplat.dll -> C:WindowsSystem32mfplat.dll -> [2012/04/30 11:48:19 | 000,209,920 | ---- | C | MD5 = BF142D4F8C61ED3629A9CDD7BA867900] (Microsoft Corporation)
XpsRasterService.dll -> C:WindowsSystem32XpsRasterService.dll -> [2012/04/30 11:48:16 | 000,135,680 | ---- | C | MD5 = 3439DFAD865BF24C3E3DE3BCB2F9C39F] (Microsoft Corporation)
d3d10.dll -> C:WindowsSystem32d3d10.dll -> [2012/04/30 11:48:15 | 001,029,120 | ---- | C | MD5 = 8B02D2ECC7EF6E1F6AF08459E3F741F6] (Microsoft Corporation)
d3d10level9.dll -> C:WindowsSystem32d3d10level9.dll -> [2012/04/30 11:48:15 | 000,486,400 | ---- | C | MD5 = 04802864F51046E93471083A24469ACE] (Microsoft Corporation)
dxgi.dll -> C:WindowsSystem32dxgi.dll -> [2012/04/30 11:48:15 | 000,478,720 | ---- | C | MD5 = AAAE543C535ED596ECAD2AB8761C2C6F] (Microsoft Corporation)
d3d10core.dll -> C:WindowsSystem32d3d10core.dll -> [2012/04/30 11:48:15 | 000,189,952 | ---- | C | MD5 = 9C7094F537782A82B6A29B4A7172E180] (Microsoft Corporation)
cdd.dll -> C:WindowsSystem32cdd.dll -> [2012/04/30 11:48:15 | 000,037,376 | ---- | C | MD5 = CF9F5BBC2740C41DD471278C41B91F5F] (Microsoft Corporation)
printfilterpipelineprxy.dll -> C:WindowsSystem32printfilterpipelineprxy.dll -> [2012/04/30 11:48:15 | 000,026,112 | ---- | C | MD5 = E821547F853BF67CABE187B6FAA5D212] (Microsoft Corporation)
xpsservices.dll -> C:WindowsSystem32xpsservices.dll -> [2012/04/30 11:48:14 | 001,554,432 | ---- | C | MD5 = E607F9C6A2386647B572580CB147C7B3] (Microsoft Corporation)
OpcServices.dll -> C:WindowsSystem32OpcServices.dll -> [2012/04/30 11:48:14 | 000,847,360 | ---- | C | MD5 = A15ED03919107C2A6A3395EE02C7DD47] (Microsoft Corporation)
printfilterpipelinesvc.exe -> C:WindowsSystem32printfilterpipelinesvc.exe -> [2012/04/30 11:48:14 | 000,667,648 | ---- | C | MD5 = DFD714F1A410B32DA258423CF592A96E] (Microsoft Corporation)
d3d11.dll -> C:WindowsSystem32d3d11.dll -> [2012/04/30 11:47:37 | 000,519,680 | ---- | C | MD5 = 6E895BDCB3158E3860A49662332736BA] (Microsoft Corporation)
WMPhoto.dll -> C:WindowsSystem32WMPhoto.dll -> [2012/04/30 11:47:37 | 000,369,664 | ---- | C | MD5 = 8375E2BD58BFB375695135A511EBEE00] (Microsoft Corporation)
PhotoMetadataHandler.dll -> C:WindowsSystem32PhotoMetadataHandler.dll -> [2012/04/30 11:47:37 | 000,321,024 | ---- | C | MD5 = 247609D2CD28A57BC1FE37FDA48AC0DB] (Microsoft Corporation)
dxdiag.exe -> C:WindowsSystem32dxdiag.exe -> [2012/04/30 11:47:37 | 000,252,928 | ---- | C | MD5 = 60BBAF3F5A38D0274B0C46710A218051] (Microsoft Corporation)
dxdiagn.dll -> C:WindowsSystem32dxdiagn.dll -> [2012/04/30 11:47:37 | 000,195,584 | ---- | C | MD5 = D1C47F951EA35073C97EF2E928CF9D6F] (Microsoft Corporation)
WindowsCodecsExt.dll -> C:WindowsSystem32WindowsCodecsExt.dll -> [2012/04/30 11:47:37 | 000,189,440 | ---- | C | MD5 = 012A965F34414458075EF4F0EDC11536] (Microsoft Corporation)
%APPDATA% -> C:WindowsSystem32%APPDATA% -> [2012/04/30 10:52:09 | 000,000,000 | -HSD | C]
psisdecd.dll -> C:WindowsSystem32psisdecd.dll -> [2012/04/29 13:02:04 | 000,293,376 | ---- | C | MD5 = 959A4BC486951267EE6343A431A92B12] (Microsoft Corporation)
psisrndr.ax -> C:WindowsSystem32psisrndr.ax -> [2012/04/29 13:02:03 | 000,217,088 | ---- | C | MD5 = 3A78D48221D32BC99C4B11B112D6EADA] (Microsoft Corporation)
Mpeg2Data.ax -> C:WindowsSystem32Mpeg2Data.ax -> [2012/04/29 13:02:03 | 000,069,632 | ---- | C | MD5 = 1B45ED071775A5E8BF51682EC5B61231] (Microsoft Corporation)
MSDvbNP.ax -> C:WindowsSystem32MSDvbNP.ax -> [2012/04/29 13:02:03 | 000,057,856 | ---- | C | MD5 = D1AE4D2D559C23CE9DE4B3B10A90B901] (Microsoft Corporation)
mciseq.dll -> C:WindowsSystem32mciseq.dll -> [2012/04/29 13:02:03 | 000,023,552 | ---- | C | MD5 = FF8FCDF1913016813AFB966A0F41B299] (Microsoft Corporation)
EncDec.dll -> C:WindowsSystem32EncDec.dll -> [2012/04/29 13:01:49 | 000,429,056 | ---- | C | MD5 = D0F138624B9B49F349C5D3D2341199A1] (Microsoft Corporation)
XpsGdiConverter.dll -> C:WindowsSystem32XpsGdiConverter.dll -> [2012/04/29 13:00:59 | 000,288,768 | ---- | C | MD5 = 1217AEB3DBED42C54ADD826EDDC21660] (Microsoft Corporation)
packager.dll -> C:WindowsSystem32packager.dll -> [2012/04/29 13:00:55 | 000,066,560 | ---- | C | MD5 = A520C77CFFABC96E32818451B60905C7] (Microsoft Corporation)
winsrv.dll -> C:WindowsSystem32winsrv.dll -> [2012/04/29 13:00:54 | 000,376,320 | ---- | C | MD5 = D2293B069E4B63DC17B2F08D45E71124] (Microsoft Corporation)
csrsrv.dll -> C:WindowsSystem32csrsrv.dll -> [2012/04/29 13:00:09 | 000,049,152 | ---- | C | MD5 = 187076DD5D8D4D5D23079D0741195EAD] (Microsoft Corporation)
quartz.dll -> C:WindowsSystem32quartz.dll -> [2012/04/29 13:00:08 | 001,314,816 | ---- | C | MD5 = 5F6359756DBCC901276BC2B62460FA64] (Microsoft Corporation)
qdvd.dll -> C:WindowsSystem32qdvd.dll -> [2012/04/29 13:00:07 | 000,497,152 | ---- | C | MD5 = E1E52D56D266C2741058BA6611970D0C] (Microsoft Corporation)
tzres.dll -> C:WindowsSystem32tzres.dll -> [2012/04/29 13:00:01 | 000,002,048 | ---- | C | MD5 = B96EAA786CAB24AF0890C8B89CEF348C] (Microsoft Corporation)
UIAutomationCore.dll -> C:WindowsSystem32UIAutomationCore.dll -> [2012/04/29 12:59:42 | 000,555,520 | ---- | C | MD5 = CCE5E7C0F8AA13207E777C43F4DA80A3] (Microsoft Corporation)
oleaccrc.dll -> C:WindowsSystem32oleaccrc.dll -> [2012/04/29 12:59:42 | 000,004,096 | ---- | C | MD5 = 7E38DA8C11833B99766A97CEE3F80F07] (Microsoft Corporation)
msshsq.dll -> C:WindowsSystem32msshsq.dll -> [2012/04/29 12:50:56 | 000,231,424 | ---- | C | MD5 = FF41E1AC301F51E16F61AD7C0F45467C] (Microsoft Corporation)
rdpencom.dll -> C:WindowsSystem32rdpencom.dll -> [2012/04/29 12:46:23 | 000,613,376 | ---- | C | MD5 = DE98C769DA2B5F121846C9F3B9493C5A] (Microsoft Corporation)
eu-ES -> C:WindowsSystem32eu-ES -> [2012/04/28 21:24:01 | 000,000,000 | ---D | C]
ca-ES -> C:WindowsSystem32ca-ES -> [2012/04/28 21:24:01 | 000,000,000 | ---D | C]
vi-VN -> C:WindowsSystem32vi-VN -> [2012/04/28 21:24:00 | 000,000,000 | ---D | C]
Apple Computer -> C:ProgramDataApple Computer -> [2012/04/20 12:51:05 | 000,000,000 | ---D | C]
FlashPlayerApp.exe -> C:WindowsSystem32FlashPlayerApp.exe -> [2012/03/29 16:51:55 | 000,419,488 | ---- | C | MD5 = 6C52B933B9ACE73D134752B8C077EDDF] (Adobe Systems Incorporated)
270f7937d9fefa85d1ad39b3b5e731ea -> C:270f7937d9fefa85d1ad39b3b5e731ea -> [2012/01/24 14:07:11 | 000,000,000 | ---D | C]
34c07091c1089e652b9caf82c6 -> C:34c07091c1089e652b9caf82c6 -> [2012/01/21 10:55:57 | 000,000,000 | ---D | C]
ccSetx86.sys -> C:WindowsSystem32driversNST\0200000.010ccSetx86.sys -> [2011/12/19 21:43:42 | 000,132,744 | R--- | C | MD5 = 2B2F9B4A08190334A9C36446B208BAE9] (Symantec Corporation)
NST -> C:WindowsSystem32driversNST -> [2011/12/19 21:43:39 | 000,000,000 | ---D | C]
0200000.010 -> C:WindowsSystem32driversNST\0200000.010 -> [2011/12/19 21:43:39 | 000,000,000 | ---D | C]
apvdd.dll -> C:WindowsSystem32driversVDDapvdd.dll -> [2011/12/19 13:21:22 | 000,011,632 | ---- | C | MD5 = A94FE1FF0C6F4DDEC24109663DC653B9] (GFI Software)
sbbd.exe -> C:WindowsSystem32sbbd.exe -> [2011/12/19 13:21:02 | 000,042,864 | ---- | C | MD5 = 370F5022CC51CCAD5719B980238D68EF] (GFI Software)
sbwtis.sys -> C:WindowsSystem32driverssbwtis.sys -> [2011/12/19 12:44:24 | 000,072,312 | ---- | C | MD5 = 9BDF801A6C78E3F1E6FA1C5CA90BAA8A] (GFI Software)
FLV Player -> C:WindowsFLV Player -> [2011/12/18 12:56:24 | 000,000,000 | ---D | C]
UI_files -> C:UsersOwnerDesktopUI_files -> [2011/12/14 13:48:42 | 000,000,000 | ---D | C]
sbapifs.sys -> C:WindowsSystem32driverssbapifs.sys -> [2011/11/29 06:59:52 | 000,077,816 | ---- | C | MD5 = 3FFF8CDA4D2F29CA06F1557E85163C30] (GFI Software)
eBay -> C:UsersOwnerDocumentseBay -> [2011/11/09 11:29:28 | 000,000,000 | ---D | C]
MSCOMCTL.OCX -> C:WindowsSystem32MSCOMCTL.OCX -> [2011/11/04 06:13:36 | 001,070,352 | ---- | C | MD5 = 03B0224FD1E2D8A6DBC2B18404092F21] (Microsoft Corporation)
FlashPlayerCPLApp.cpl -> C:WindowsSystem32FlashPlayerCPLApp.cpl -> [2011/10/31 11:29:50 | 000,070,304 | ---- | C | MD5 = 2C9341C5E30174AD972AFFED9A10D5E3] (Adobe Systems Incorporated)
Bills -> C:UsersOwnerDocumentsBills -> [2011/10/28 15:04:09 | 000,000,000 | ---D | C]
SBREDrv.sys -> C:WindowsSystem32driversSBREDrv.sys -> [2011/10/26 14:23:40 | 000,101,112 | ---- | C | MD5 = 1FD538C4FEB36B793D2121F20BBDC16F] (GFI Software)
QuickTimeVR.qtx -> C:WindowsSystem32QuickTimeVR.qtx -> [2011/10/24 14:29:02 | 000,094,208 | ---- | C | MD5 = 97A90E7845335C6AB21F9FAD72595563] (Apple Inc.)
QuickTime.qts -> C:WindowsSystem32QuickTime.qts -> [2011/10/24 14:29:02 | 000,069,632 | ---- | C | MD5 = 584F1C20E840CB7E00B2FF40FA6F7544] (Apple Inc.)
1 C:Windows*.tmp files -> C:Windows*.tmp ->
1 C:UsersOwnerAppDataRoaming*.tmp files -> C:UsersOwnerAppDataRoaming*.tmp ->
[Files/Folders - Modified Within 360 Days]
Adobe Flash Player Updater.job -> C:WindowstasksAdobe Flash Player Updater.job -> [2012/05/14 19:40:15 | 000,000,830 | ---- | M | MD5 = 779A61D8B94B56C363C8A32E3FEA06E7] ()
GoogleUpdateTaskMachineUA.job -> C:WindowstasksGoogleUpdateTaskMachineUA.job -> [2012/05/14 19:31:07 | 000,000,884 | ---- | M | MD5 = A1C427A605183C8F93EAFCE79EEBF50E] ()
GoogleUpdateTaskUserS-1-5-21-3990776023-3137282466-4049488173-1000UA.job -> C:WindowstasksGoogleUpdateTaskUserS-1-5-21-3990776023-3137282466-4049488173-1000UA.job -> [2012/05/14 19:11:03 | 000,000,908 | ---- | M | MD5 = 5B1916A010F2A2DC5B2CAA28D255D0DB] ()
Google Chrome.lnk -> C:UsersOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchGoogle Chrome.lnk -> [2012/05/14 17:57:53 | 000,002,255 | ---- | M | MD5 = 2AE3079A8824CDF9FA750C2556443C44] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2012/05/14 17:57:15 | 000,003,568 | -H-- | M | Unable to obtain MD5] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2012/05/14 17:57:15 | 000,003,568 | -H-- | M | Unable to obtain MD5] ()
GoogleUpdateTaskMachineCore.job -> C:WindowstasksGoogleUpdateTaskMachineCore.job -> [2012/05/14 17:57:02 | 000,000,880 | ---- | M | MD5 = 0854BE3FFE7674A96FFDBE5B6EFAB920] ()
bootstat.dat -> C:Windowsbootstat.dat -> [2012/05/14 17:56:19 | 000,067,584 | --S- | M | MD5 = 724FEE542DE615BE7A70BDCB67F8461D] ()
ServiceConfig.xml -> C:WindowsSystem32ServiceConfig.xml -> [2012/05/14 17:53:44 | 000,001,190 | ---- | M | MD5 = E0C72EC18DE4ACF515832F0B4EC9E448] ()
TDSSKiller.exe - Shortcut.lnk -> C:UsersOwnerDesktopTDSSKiller.exe - Shortcut.lnk -> [2012/05/14 17:52:16 | 000,000,518 | ---- | M | MD5 = 4575E0F6923EE84F1D9475830B41916E] ()
TDSSKiller.exe -> C:UsersOwnerTDSSKiller.exe -> [2012/05/14 17:37:40 | 002,075,184 | ---- | M | MD5 = 03AEB6909BD8CE8957CA30928DC648C9] (Kaspersky Lab ZAO)
Malwarebytes Anti-Malware.lnk -> C:UsersPublicDesktopMalwarebytes Anti-Malware.lnk -> [2012/05/14 11:47:07 | 000,000,912 | ---- | M | MD5 = 553B9937C7E85B595C7A651A5BA7E890] ()
perfh009.dat -> C:WindowsSystem32perfh009.dat -> [2012/05/14 11:21:46 | 000,604,264 | ---- | M | MD5 = 576F17F5F9FABB687AEB5BAF38432A08] ()
perfc009.dat -> C:WindowsSystem32perfc009.dat -> [2012/05/14 11:21:46 | 000,103,964 | ---- | M | MD5 = 021BE2CDC108699246845C5370DF4F4B] ()
GoogleUpdateTaskUserS-1-5-21-3990776023-3137282466-4049488173-1000Core.job -> C:WindowstasksGoogleUpdateTaskUserS-1-5-21-3990776023-3137282466-4049488173-1000Core.job -> [2012/05/13 21:11:04 | 000,000,856 | ---- | M | MD5 = B17607888A8A434F2759CE74C727FD7F] ()
FNTCACHE.DAT -> C:WindowsSystem32FNTCACHE.DAT -> [2012/05/11 10:57:08 | 000,344,856 | ---- | M | MD5 = 9ACA567DEFF2C1EF4AFA9FD5A1C07E16] ()
2012_4_19_24_Myk.png -> C:UsersOwnerDocuments2012_4_19_24_Myk.png -> [2012/05/07 21:48:13 | 000,170,050 | ---- | M | MD5 = 9B302F813AF7B004A0E29D7A0850585B] ()
2012_4_9_18_Myk.png -> C:UsersOwnerDocuments2012_4_9_18_Myk.png -> [2012/05/07 21:23:19 | 000,214,136 | ---- | M | MD5 = FD5B01C1B9B53000FDC9E362B29CA813] ()
clp.ashx -> C:UsersOwnerDesktopclp.ashx -> [2012/05/07 13:05:04 | 000,159,831 | ---- | M | MD5 = ED3EB883F2457250F78B7977F759CBF6] ()
FlashPlayerApp.exe -> C:WindowsSystem32FlashPlayerApp.exe -> [2012/05/05 15:40:05 | 000,419,488 | ---- | M | MD5 = 6C52B933B9ACE73D134752B8C077EDDF] (Adobe Systems Incorporated)
FlashPlayerCPLApp.cpl -> C:WindowsSystem32FlashPlayerCPLApp.cpl -> [2012/05/05 15:40:05 | 000,070,304 | ---- | M | MD5 = 2C9341C5E30174AD972AFFED9A10D5E3] (Adobe Systems Incorporated)
MEMORY.DMP -> C:WindowsMEMORY.DMP -> [2012/05/04 13:56:13 | 118,328,543 | ---- | M | MD5 = 27AE34581F8ED67050D6EF95407ED5DC] ()
Google Chrome.lnk -> C:UsersPublicDesktopGoogle Chrome.lnk -> [2012/05/01 18:56:46 | 000,001,977 | ---- | M | MD5 = 3EEC698ED6F2ECB5EC7F8EF7129E840F] ()
Launch Internet Explorer Browser.lnk -> C:UsersOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchLaunch Internet Explorer Browser.lnk -> [2012/04/30 19:40:06 | 000,000,949 | ---- | M | MD5 = 019FA9ABEA764DA2DFD1A882F3782CB3] ()
Msft_User_WpdMtpDr_01_07_00.Wdf -> C:WindowsSystem32driversMsft_User_WpdMtpDr_01_07_00.Wdf -> [2012/04/30 15:14:22 | 000,000,000 | -H-- | M | MD5 = D41D8CD98F00B204E9800998ECF8427E] ()
Msft_User_WpdFs_01_07_00.Wdf -> C:WindowsSystem32driversMsft_User_WpdFs_01_07_00.Wdf -> [2012/04/30 15:14:13 | 000,000,000 | -H-- | M | MD5 = D41D8CD98F00B204E9800998ECF8427E] ()
icrav03.rat -> C:WindowsSystem32icrav03.rat -> [2012/04/30 11:50:10 | 000,008,798 | ---- | M | MD5 = ECD81B99477AB4A93D7838EB40B870D0] ()
ticrf.rat -> C:WindowsSystem32ticrf.rat -> [2012/04/30 11:50:10 | 000,001,988 | ---- | M | MD5 = 6D21D0A95286DCD09E354B612F592EB7] ()
msls31.dll -> C:WindowsSystem32msls31.dll -> [2012/04/30 11:49:53 | 000,161,792 | ---- | M | MD5 = 35AAE2E841AA1A949775168E119482C9] (Microsoft Corporation)
msrating.dll -> C:WindowsSystem32msrating.dll -> [2012/04/30 11:49:52 | 000,162,304 | ---- | M | MD5 = 0B8FE658BD033EC8B1F6FBC305CC65E7] (Microsoft Corporation)
iesysprep.dll -> C:WindowsSystem32iesysprep.dll -> [2012/04/30 11:49:52 | 000,086,528 | ---- | M | MD5 = EE0AFCEE88098F754212F9069E80A766] (Microsoft Corporation)
SetIEInstalledDate.exe -> C:WindowsSystem32SetIEInstalledDate.exe -> [2012/04/30 11:49:52 | 000,076,800 | ---- | M | MD5 = 736D1B28224F9DF8008BE8B0DEDFC9EF] (Microsoft Corporation)
RegisterIEPKEYs.exe -> C:WindowsSystem32RegisterIEPKEYs.exe -> [2012/04/30 11:49:52 | 000,074,752 | ---- | M | MD5 = 6B036492120E65C0C367DC31D01088A1] (Microsoft Corporation)
mshtmler.dll -> C:WindowsSystem32mshtmler.dll -> [2012/04/30 11:49:52 | 000,048,640 | ---- | M | MD5 = 76E987D8CF0683337CF165363B6FDFD9] (Microsoft Corporation)
ieapfltr.dat -> C:WindowsSystem32ieapfltr.dat -> [2012/04/30 11:49:51 | 003,695,416 | ---- | M | MD5 = 83F5D4B41BB12CE146786E97F6AAD75E] (Microsoft Corporation)
ieapfltr.dll -> C:WindowsSystem32ieapfltr.dll -> [2012/04/30 11:49:51 | 000,434,176 | ---- | M | MD5 = EE9D715AF1B928982F417238B9914484] (Microsoft Corporation)
html.iec -> C:WindowsSystem32html.iec -> [2012/04/30 11:49:51 | 000,367,104 | ---- | M | MD5 = 09C9E7F477FB225FDB3B6DE8FED0AA9B] (Microsoft Corporation)
dxtmsft.dll -> C:WindowsSystem32dxtmsft.dll -> [2012/04/30 11:49:51 | 000,353,792 | ---- | M | MD5 = 4312DEBDACBE338F0B90E7F08E7672BE] (Microsoft Corporation)
iedkcs32.dll -> C:WindowsSystem32iedkcs32.dll -> [2012/04/30 11:49:51 | 000,353,584 | ---- | M | MD5 = F0FEFB0B5D25A75D478A4317139D937E] (Microsoft Corporation)
dxtrans.dll -> C:WindowsSystem32dxtrans.dll -> [2012/04/30 11:49:51 | 000,223,232 | ---- | M | MD5 = CA493A92DA9880B6F1A89C3DBD54BA5B] (Microsoft Corporation)
wextract.exe -> C:WindowsSystem32wextract.exe -> [2012/04/30 11:49:51 | 000,152,064 | ---- | M | MD5 = 67BC2BA6F94D2D0C51213691FBFEEBB1] (Microsoft Corporation)
inseng.dll -> C:WindowsSystem32inseng.dll -> [2012/04/30 11:49:51 | 000,078,848 | ---- | M | MD5 = 60B4F624BB87A3B21D3EC68F38DA6B61] (Microsoft Corporation)
iesetup.dll -> C:WindowsSystem32iesetup.dll -> [2012/04/30 11:49:51 | 000,074,752 | ---- | M | MD5 = 802B0229D904E28C1EA9A5274AB457FC] (Microsoft Corporation)
ie4uinit.exe -> C:WindowsSystem32ie4uinit.exe -> [2012/04/30 11:49:51 | 000,074,240 | ---- | M | MD5 = C0B8B96D018849FD8CCF15FED84E8782] (Microsoft Corporation)
ieuinit.inf -> C:WindowsSystem32ieuinit.inf -> [2012/04/30 11:49:51 | 000,072,822 | ---- | M | MD5 = 4B333D3CC96AE66BD754329FD2989EE2] ()
iernonce.dll -> C:WindowsSystem32iernonce.dll -> [2012/04/30 11:49:51 | 000,031,744 | ---- | M | MD5 = F83865A3007357A5E498EB9E3BED273D] (Microsoft Corporation)
licmgr10.dll -> C:WindowsSystem32licmgr10.dll -> [2012/04/30 11:49:51 | 000,023,552 | ---- | M | MD5 = 6B4701D3D9724812E8C3801E7BF87157] (Microsoft Corporation)
msfeeds.dll -> C:WindowsSystem32msfeeds.dll -> [2012/04/30 11:49:50 | 000,580,608 | ---- | M | MD5 = 7940C04CE581288A3498D57EC4EE47D2] (Microsoft Corporation)
ieaksie.dll -> C:WindowsSystem32ieaksie.dll -> [2012/04/30 11:49:50 | 000,227,840 | ---- | M | MD5 = 49729570B7FD369BBDEC16D7683324A0] (Microsoft Corporation)
ieakui.dll -> C:WindowsSystem32ieakui.dll -> [2012/04/30 11:49:50 | 000,163,840 | ---- | M | MD5 = DB754FF5F6ADBA2A25EC1B6672D1C91E] (Microsoft Corporation)
iexpress.exe -> C:WindowsSystem32iexpress.exe -> [2012/04/30 11:49:50 | 000,150,528 | ---- | M | MD5 = 51AF0A12CD86E22E1A027C38CC021AC6] (Microsoft Corporation)
ieUnatt.exe -> C:WindowsSystem32ieUnatt.exe -> [2012/04/30 11:49:50 | 000,142,848 | ---- | M | MD5 = 46418F422DA88859AECE4C0A1AEB752B] (Microsoft Corporation)
admparse.dll -> C:WindowsSystem32admparse.dll -> [2012/04/30 11:49:50 | 000,101,888 | ---- | M | MD5 = 3F7A8BCF37433A69CEEDE1E6AEE79784] (Microsoft Corporation)
pngfilt.dll -> C:WindowsSystem32pngfilt.dll -> [2012/04/30 11:49:50 | 000,054,272 | ---- | M | MD5 = 04A8B2F67825380BC0C7C46D56776133] (Microsoft Corporation)
ieakeng.dll -> C:WindowsSystem32ieakeng.dll -> [2012/04/30 11:49:49 | 000,130,560 | ---- | M | MD5 = 1E7094AFAD0C369DD6D400C7047E4AB2] (Microsoft Corporation)
iepeers.dll -> C:WindowsSystem32iepeers.dll -> [2012/04/30 11:49:49 | 000,118,784 | ---- | M | MD5 = 90A57CA422923286838AAC7DE2D41B92] (Microsoft Corporation)
IEAdvpack.dll -> C:WindowsSystem32IEAdvpack.dll -> [2012/04/30 11:49:49 | 000,110,592 | ---- | M | MD5 = ED6F6FBBCDEC95483B7351E23F4FCDF6] (Microsoft Corporation)
msfeedsbs.dll -> C:WindowsSystem32msfeedsbs.dll -> [2012/04/30 11:49:49 | 000,041,472 | ---- | M | MD5 = 4B80D1F847C0658977E1E8051A4DE002] (Microsoft Corporation)
imgutil.dll -> C:WindowsSystem32imgutil.dll -> [2012/04/30 11:49:49 | 000,035,840 | ---- | M | MD5 = 68563AC389F92EE79F1C714288BA1DCE] (Microsoft Corporation)
msfeedssync.exe -> C:WindowsSystem32msfeedssync.exe -> [2012/04/30 11:49:49 | 000,010,752 | ---- | M | MD5 = 1D3EE28BA231CBB9600F5D102EAF4EA7] (Microsoft Corporation)
mf.dll -> C:WindowsSystem32mf.dll -> [2012/04/30 11:48:20 | 002,873,344 | ---- | M | MD5 = 67D16247C56C26A4F0D79D1A7F272B8F] (Microsoft Corporation)
MFH264Dec.dll -> C:WindowsSystem32MFH264Dec.dll -> [2012/04/30 11:48:20 | 000,979,456 | ---- | M | MD5 = BC5E45CB2304AFB4D2EF2FD9C41299AF] (Microsoft Corporation)
MFHEAACdec.dll -> C:WindowsSystem32MFHEAACdec.dll -> [2012/04/30 11:48:20 | 000,357,376 | ---- | M | MD5 = 44CEE5264282105A89B650FDB07E40FF] (Microsoft Corporation)
mfmp4src.dll -> C:WindowsSystem32mfmp4src.dll -> [2012/04/30 11:48:20 | 000,302,592 | ---- | M | MD5 = 743B1957729DE905DC44782A957FD284] (Microsoft Corporation)
mfreadwrite.dll -> C:WindowsSystem32mfreadwrite.dll -> [2012/04/30 11:48:20 | 000,261,632 | ---- | M | MD5 = 7BE8835CA7E2975F2E865CEEE8821EB6] (Microsoft Corporation)
mfps.dll -> C:WindowsSystem32mfps.dll -> [2012/04/30 11:48:20 | 000,098,816 | ---- | M | MD5 = B9103A56ACABDED3E87C2A8777B6456C] (Microsoft Corporation)
mfplat.dll -> C:WindowsSystem32mfplat.dll -> [2012/04/30 11:48:19 | 000,209,920 | ---- | M | MD5 = BF142D4F8C61ED3629A9CDD7BA867900] (Microsoft Corporation)
XpsRasterService.dll -> C:WindowsSystem32XpsRasterService.dll -> [2012/04/30 11:48:16 | 000,135,680 | ---- | M | MD5 = 3439DFAD865BF24C3E3DE3BCB2F9C39F] (Microsoft Corporation)
d3d10.dll -> C:WindowsSystem32d3d10.dll -> [2012/04/30 11:48:15 | 001,029,120 | ---- | M | MD5 = 8B02D2ECC7EF6E1F6AF08459E3F741F6] (Microsoft Corporation)
d3d10level9.dll -> C:WindowsSystem32d3d10level9.dll -> [2012/04/30 11:48:15 | 000,486,400 | ---- | M | MD5 = 04802864F51046E93471083A24469ACE] (Microsoft Corporation)
dxgi.dll -> C:WindowsSystem32dxgi.dll -> [2012/04/30 11:48:15 | 000,478,720 | ---- | M | MD5 = AAAE543C535ED596ECAD2AB8761C2C6F] (Microsoft Corporation)
d3d10core.dll -> C:WindowsSystem32d3d10core.dll -> [2012/04/30 11:48:15 | 000,189,952 | ---- | M | MD5 = 9C7094F537782A82B6A29B4A7172E180] (Microsoft Corporation)
cdd.dll -> C:WindowsSystem32cdd.dll -> [2012/04/30 11:48:15 | 000,037,376 | ---- | M | MD5 = CF9F5BBC2740C41DD471278C41B91F5F] (Microsoft Corporation)
printfilterpipelineprxy.dll -> C:WindowsSystem32printfilterpipelineprxy.dll -> [2012/04/30 11:48:15 | 000,026,112 | ---- | M | MD5 = E821547F853BF67CABE187B6FAA5D212] (Microsoft Corporation)
xpsservices.dll -> C:WindowsSystem32xpsservices.dll -> [2012/04/30 11:48:14 | 001,554,432 | ---- | M | MD5 = E607F9C6A2386647B572580CB147C7B3] (Microsoft Corporation)
OpcServices.dll -> C:WindowsSystem32OpcServices.dll -> [2012/04/30 11:48:14 | 000,847,360 | ---- | M | MD5 = A15ED03919107C2A6A3395EE02C7DD47] (Microsoft Corporation)
printfilterpipelinesvc.exe -> C:WindowsSystem32printfilterpipelinesvc.exe -> [2012/04/30 11:48:14 | 000,667,648 | ---- | M | MD5 = DFD714F1A410B32DA258423CF592A96E] (Microsoft Corporation)
d3d11.dll -> C:WindowsSystem32d3d11.dll -> [2012/04/30 11:47:37 | 000,519,680 | ---- | M | MD5 = 6E895BDCB3158E3860A49662332736BA] (Microsoft Corporation)
WMPhoto.dll -> C:WindowsSystem32WMPhoto.dll -> [2012/04/30 11:47:37 | 000,369,664 | ---- | M | MD5 = 8375E2BD58BFB375695135A511EBEE00] (Microsoft Corporation)
PhotoMetadataHandler.dll -> C:WindowsSystem32PhotoMetadataHandler.dll -> [2012/04/30 11:47:37 | 000,321,024 | ---- | M | MD5 = 247609D2CD28A57BC1FE37FDA48AC0DB] (Microsoft Corporation)
dxdiag.exe -> C:WindowsSystem32dxdiag.exe -> [2012/04/30 11:47:37 | 000,252,928 | ---- | M | MD5 = 60BBAF3F5A38D0274B0C46710A218051] (Microsoft Corporation)
dxdiagn.dll -> C:WindowsSystem32dxdiagn.dll -> [2012/04/30 11:47:37 | 000,195,584 | ---- | M | MD5 = D1C47F951EA35073C97EF2E928CF9D6F] (Microsoft Corporation)
WindowsCodecsExt.dll -> C:WindowsSystem32WindowsCodecsExt.dll -> [2012/04/30 11:47:37 | 000,189,440 | ---- | M | MD5 = 012A965F34414458075EF4F0EDC11536] (Microsoft Corporation)
dxgkrnl.sys.mui -> C:WindowsSystem32driversen-USdxgkrnl.sys.mui -> [2012/04/30 11:47:37 | 000,004,096 | ---- | M | MD5 = 1AE772003FB59FBD8AE20A09A0341B91] (Microsoft Corporation)
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:UsersOwnerAppDataLocalDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2012/04/29 20:49:05 | 000,043,008 | ---- | M | MD5 = B0FA03B0522B4690DB8B1BAB5EAF823B] ()
QuickTime Player.lnk -> C:UsersPublicDesktopQuickTime Player.lnk -> [2012/04/20 12:51:36 | 000,001,732 | ---- | M | MD5 = B50698B7FAAAC47D2C6AF84BB67EC8E2] ()
Microsoft Office Word 2003.lnk -> C:UsersOwnerDesktopMicrosoft Office Word 2003.lnk -> [2012/04/10 14:12:13 | 000,002,609 | ---- | M | MD5 = CB75F0D5B60BC2900DF067FC43917A9E] ()
IMVU.lnk -> C:UsersOwnerDesktopIMVU.lnk -> [2012/04/10 12:30:13 | 000,001,789 | ---- | M | MD5 = BFA6212E0356B17FFF1C1ECAAD87A225] ()
mbam.sys -> C:WindowsSystem32driversmbam.sys -> [2012/04/04 15:56:40 | 000,022,344 | ---- | M | MD5 = FB097BBC1A18F044BD17BD2FCCF97865] (Malwarebytes Corporation)
ntkrnlpa.exe -> C:WindowsSystem32ntkrnlpa.exe -> [2012/04/03 01:16:12 | 003,602,816 | ---- | M | MD5 = CAD95AFB7FDDCC490681555C570FBB7D] (Microsoft Corporation)
ntoskrnl.exe -> C:WindowsSystem32ntoskrnl.exe -> [2012/04/03 01:16:11 | 003,550,080 | ---- | M | MD5 = BA4C485548914034B471EB6FC2B50082] (Microsoft Corporation)
win32k.sys -> C:WindowsSystem32win32k.sys -> [2012/04/02 06:36:21 | 002,044,928 | ---- | M | MD5 = 98BB495043BD5E98B2E8D2B8239390ED] (Microsoft Corporation)
AprilFools.jpg -> C:UsersOwnerDesktopAprilFools.jpg -> [2012/04/01 12:25:23 | 000,066,765 | ---- | M | MD5 = 12DA86770C533416AE919063CA577DEF] ()
EnterSandman.wps -> C:UsersOwnerDocumentsEnterSandman.wps -> [2012/03/31 17:02:03 | 000,019,456 | ---- | M | MD5 = 585A1AE14D5738268B0C979931339B93] ()
wklnhst.dat -> C:UsersOwnerAppDataRoamingwklnhst.dat -> [2012/03/31 17:02:03 | 000,001,100 | ---- | M | MD5 = 84B5C24FF51E727BF2C54823E10F6A6B] ()
AmeSignature.png -> C:UsersOwnerDocumentsAmeSignature.png -> [2012/03/07 20:08:36 | 000,011,351 | ---- | M | MD5 = D0FBD0BFAFABEA537B603B05BE94D674] ()
2012_STCB_resume.wps -> C:UsersOwnerDocuments2012_STCB_resume.wps -> [2012/03/02 18:34:08 | 000,040,448 | ---- | M | MD5 = 2C5A8FB71E181C1547FF3CA2D84E7E32] ()
d3d10_1core.dll -> C:WindowsSystem32d3d10_1core.dll -> [2012/03/01 07:46:01 | 000,219,648 | ---- | M | MD5 = A441F5B43EAF4BD4E3ACFBE38841B46B] (Microsoft Corporation)
d3d10_1.dll -> C:WindowsSystem32d3d10_1.dll -> [2012/03/01 07:46:01 | 000,160,768 | ---- | M | MD5 = 5256383D1D266A9EEFCDB270340C0E5C] (Microsoft Corporation)
d3d10warp.dll -> C:WindowsSystem32d3d10warp.dll -> [2012/02/29 07:08:47 | 001,172,480 | ---- | M | MD5 = 4A4C71376ECA305D6DEA021F1A44816D] (Microsoft Corporation)
d2d1.dll -> C:WindowsSystem32d2d1.dll -> [2012/02/29 06:44:50 | 000,683,008 | ---- | M | MD5 = E9B39C81C87E5B790FCE121DA9E02701] (Microsoft Corporation)
DWrite.dll -> C:WindowsSystem32DWrite.dll -> [2012/02/29 06:41:40 | 001,069,056 | ---- | M | MD5 = CABD1B34BD05C986B4DBC18BC0E947EE] (Microsoft Corporation)
jscript9.dll -> C:WindowsSystem32jscript9.dll -> [2012/02/27 18:18:55 | 001,799,168 | ---- | M | MD5 = 328E900311D5C31F399730C7CCC8883A] (Microsoft Corporation)
inetcpl.cpl -> C:WindowsSystem32inetcpl.cpl -> [2012/02/27 18:11:21 | 001,427,456 | ---- | M | MD5 = 8D8BE3DCACEA6C8E52D506E7BAAEA2D4] (Microsoft Corporation)
url.dll -> C:WindowsSystem32url.dll -> [2012/02/27 18:09:51 | 000,231,936 | ---- | M | MD5 = 8E35C8E822B6BF11D048C1AA2B076388] (Microsoft Corporation)
jsproxy.dll -> C:WindowsSystem32jsproxy.dll -> [2012/02/27 18:08:15 | 000,065,024 | ---- | M | MD5 = 327695074718E1BDAC226B2A16F425E2] (Microsoft Corporation)
mshtml.tlb -> C:WindowsSystem32mshtml.tlb -> [2012/02/27 18:03:16 | 002,382,848 | ---- | M | MD5 = 2CCFBEEA97BB6AF726311437B2DC9265] (Microsoft Corporation)
ieui.dll -> C:WindowsSystem32ieui.dll -> [2012/02/27 17:59:59 | 000,176,640 | ---- | M | MD5 = CF316FA04D6BD6168223A0E029C6C874] (Microsoft Corporation)
MoneyOrderLetter.wps -> C:UsersOwnerDocumentsMoneyOrderLetter.wps -> [2012/02/23 22:22:01 | 000,096,256 | ---- | M | MD5 = 4E38C8C0D89825788B1D53F26AC0F3A5] ()
MpSigStub.exe -> C:WindowsSystem32MpSigStub.exe -> [2012/02/23 10:18:36 | 000,237,072 | ---- | M | MD5 = D11DBD089AF8B0EE3A5AF739C8BA9189] (Microsoft Corporation)
loraxtrees_lorax_1329961921951_psNL1kFw.png -> C:UsersOwnerDesktoploraxtrees_lorax_1329961921951_psNL1kFw.png -> [2012/02/22 18:52:17 | 000,126,264 | ---- | M | MD5 = 74A9FE9A0454368593674A5ACACDD8F9] ()
2012_SeanTCBurnsResume.rtf -> C:UsersOwnerDocuments2012_SeanTCBurnsResume.rtf -> [2012/02/21 19:37:19 | 000,035,489 | ---- | M | MD5 = 763AB2210E94BAAC68617D69B5E96648] ()
TicketPayment_2_15.png -> C:UsersOwnerDocumentsTicketPayment_2_15.png -> [2012/02/15 15:56:54 | 000,209,782 | ---- | M | MD5 = 8EBF5671BA6CE4FAD669301AA0329C32] ()
Address.wps -> C:UsersOwnerDocumentsAddress.wps -> [2012/02/06 16:45:12 | 000,091,648 | ---- | M | MD5 = 8CE88B12E393E5D417EE087C82F84474] ()
DDAuth.pdf -> C:UsersOwnerDesktopDDAuth.pdf -> [2012/02/06 16:19:25 | 000,013,927 | ---- | M | MD5 = B900EC309AA51659BD2659A261F28D39] ()
TrafSch_4.png -> C:UsersOwnerDocumentsTrafSch_4.png -> [2012/01/22 13:36:27 | 000,204,170 | ---- | M | MD5 = 6A06CF7D12481F6E67607D396FD5DF16] ()
TrafSch_3.png -> C:UsersOwnerDocumentsTrafSch_3.png -> [2012/01/22 13:30:45 | 000,132,294 | ---- | M | MD5 = E237F628A387C4A17CD3F791A6FAA559] ()
TrafSch_2.png -> C:UsersOwnerDocumentsTrafSch_2.png -> [2012/01/22 13:24:24 | 000,166,185 | ---- | M | MD5 = 027423D6BAA4EBD48D76AA16DE1BFD8B] ()
TrafSch_1.png -> C:UsersOwnerDocumentsTrafSch_1.png -> [2012/01/22 13:17:36 | 000,151,068 | ---- | M | MD5 = ABAAD151E7EE3782705D4618AE471E66] ()
LetterTemplate_1.wps -> C:UsersOwnerDocumentsLetterTemplate_1.wps -> [2012/01/18 18:31:18 | 000,094,720 | ---- | M | MD5 = F403D449A50FA39EA021562AEDDB5FF6] ()
FinePixViewer.lnk -> C:UsersOwnerAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupFinePixViewer.lnk -> [2012/01/15 17:03:42 | 000,000,906 | ---- | M | MD5 = E63B172F6A99CC2924ADBB626E6CF5F6] ()
Cookiies.jpg -> C:UsersOwnerDesktopCookiies.jpg -> [2012/01/14 22:32:10 | 000,025,322 | ---- | M | MD5 = 8E5E8B030D2D80C7372F80C28DE06F4B] ()
Sav.jpg -> C:UsersOwnerDesktopSav.jpg -> [2012/01/14 22:31:41 | 000,003,041 | ---- | M | MD5 = 2E7960B4373056B4ABD1875103514906] ()
tagalongs160194.jpg -> C:UsersOwnerDesktoptagalongs160194.jpg -> [2012/01/14 22:19:06 | 000,003,620 | ---- | M | MD5 = 415B5D1E3FA45C6983CEE51011B584BB] ()
trefoils200.JPG -> C:UsersOwnerDesktoptrefoils200.JPG -> [2012/01/14 22:03:07 | 000,008,440 | ---- | M | MD5 = 231EC9B31BE7E5CF5E8C97C53866E698] ()
dosidos200.JPG -> C:UsersOwnerDesktopdosidos200.JPG -> [2012/01/14 22:03:00 | 000,007,662 | ---- | M | MD5 = 110275366F0E6E23796497BAC55B566F] ()
thinmints200.JPG -> C:UsersOwnerDesktopthinmints200.JPG -> [2012/01/14 22:02:36 | 000,005,872 | ---- | M | MD5 = DBAB55B24E0CE43D1E6773BB17120CE6] ()
samoas200.JPG -> C:UsersOwnerDesktopsamoas200.JPG -> [2012/01/14 21:58:47 | 000,010,476 | ---- | M | MD5 = B816DBD14EBCD040F737D2CC6F73E4F3] ()
rdpencom.dll -> C:WindowsSystem32rdpencom.dll -> [2012/01/09 08:54:08 | 000,613,376 | ---- | M | MD5 = DE98C769DA2B5F121846C9F3B9493C5A] (Microsoft Corporation)
Wagoner_E4.jpg -> C:UsersOwnerDocumentsWagoner_E4.jpg -> [2012/01/01 13:53:44 | 000,103,673 | ---- | M | MD5 = 26434039E70EDFE46ED0C75ABCD59D67] ()
config.nt -> C:WindowsSystem32config.nt -> [2011/12/20 12:44:35 | 000,002,577 | ---- | M | MD5 = 01C47C2ECED034EF6F8C1552A97CFF00] ()
Cat.DB -> C:WindowsSystem32driversCat.DB -> [2011/12/20 12:11:49 | 002,288,676 | ---- | M | MD5 = 4699B3B6F230C41BFA6B88DAA0A9C01E] ()
sdasetup.exe.lnk -> C:UsersOwnerDesktopsdasetup.exe.lnk -> [2011/12/20 12:06:12 | 000,001,358 | ---- | M | MD5 = A43B329BB415B3487B679AC8C926E17B] ()
apvdd.dll -> C:WindowsSystem32driversVDDapvdd.dll -> [2011/12/19 13:21:22 | 000,011,632 | ---- | M | MD5 = A94FE1FF0C6F4DDEC24109663DC653B9] (GFI Software)
sbbd.exe -> C:WindowsSystem32sbbd.exe -> [2011/12/19 13:21:02 | 000,042,864 | ---- | M | MD5 = 370F5022CC51CCAD5719B980238D68EF] (GFI Software)
SbFw.sys -> C:WindowsSystem32driversSbFw.sys -> [2011/12/19 12:44:24 | 000,223,864 | ---- | M | MD5 = BCF3BA30C1CFA2942CF26C31384B37C7] (GFI Software)
sbhips.sys -> C:WindowsSystem32driverssbhips.sys -> [2011/12/19 12:44:24 | 000,093,816 | ---- | M | MD5 = 1AFD7178AB9C4FCE2D332DA7AA474FA6] (GFI Software)
sbwtis.sys -> C:WindowsSystem32driverssbwtis.sys -> [2011/12/19 12:44:24 | 000,072,312 | ---- | M | MD5 = 9BDF801A6C78E3F1E6FA1C5CA90BAA8A] (GFI Software)
FLV Player.lnk -> C:UsersPublicDesktopFLV Player.lnk -> [2011/12/18 12:56:25 | 000,001,701 | ---- | M | MD5 = EAD0E5DAD3D0AC4FA198317EEC7C8CF8] ()
IMVU.lnk -> C:UsersOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchIMVU.lnk -> [2011/12/14 14:35:27 | 000,001,789 | ---- | M | MD5 = 88CAB7594A3B0E675510A7B2D2F15D98] ()
UI.htm -> C:UsersOwnerDesktopUI.htm -> [2011/12/14 13:48:42 | 000,042,413 | ---- | M | MD5 = 7376B62C433C987BE682B6E2A2172987] ()
cute.jpg -> C:UsersOwnerDesktopcute.jpg -> [2011/12/14 10:41:14 | 000,036,248 | ---- | M | MD5 = 5DB721FD0F10AC0E6A971C800A4AD673] ()
Snowwhite.jpg -> C:UsersOwnerDesktopSnowwhite.jpg -> [2011/12/07 12:26:47 | 000,078,051 | ---- | M | MD5 = 4CA2BB4F5F9B3D1C9776D143415DD68F] ()
Yes.jpg -> C:UsersOwnerDesktopYes.jpg -> [2011/12/06 15:53:13 | 000,020,479 | ---- | M | MD5 = 3A113FFBCF9CF99E597A78661D1B6ED4] ()
droids.jpg -> C:UsersOwnerDesktopdroids.jpg -> [2011/12/06 15:16:59 | 000,052,775 | ---- | M | MD5 = 2C636C69CDA9A2349CC5C9140F30AFD0] ()
Christi_Xmas.jpg -> C:UsersOwnerDocumentsChristi_Xmas.jpg -> [2011/11/29 20:04:05 | 000,047,712 | ---- | M | MD5 = F1551C9DFE12CEE7A7FCC805291F3690] ()
applications-engineer-resume-sample.jpg -> C:UsersOwnerDocumentsapplications-engineer-resume-sample.jpg -> [2011/11/29 11:08:03 | 000,121,526 | ---- | M | MD5 = CCF2194FABD6FEBEEDABECD6A9599265] ()
engineer2_resume_example.gif -> C:UsersOwnerDocumentsengineer2_resume_example.gif -> [2011/11/29 11:07:33 | 000,034,831 | ---- | M | MD5 = 6BC51FA3C54C7E89172BA55A8D7283EE] ()
sbapifs.sys -> C:WindowsSystem32driverssbapifs.sys -> [2011/11/29 06:59:52 | 000,077,816 | ---- | M | MD5 = 3FFF8CDA4D2F29CA06F1557E85163C30] (GFI Software)
ShowMyPC3105.exe -> C:UsersOwnerDesktopShowMyPC3105.exe -> [2011/11/25 17:07:26 | 002,291,544 | ---- | M | MD5 = B23A50D66334AA2D2263CCA208FA2608] ()
winsrv.dll -> C:WindowsSystem32winsrv.dll -> [2011/11/25 08:59:48 | 000,376,320 | ---- | M | MD5 = D2293B069E4B63DC17B2F08D45E71124] (Microsoft Corporation)
Chewbacca.jpg -> C:UsersOwnerDesktopChewbacca.jpg -> [2011/11/22 14:09:33 | 000,062,607 | ---- | M | MD5 = EED2660D7E9F965D61CBCB96B453E61B] ()
SnowLeopard.png -> C:UsersOwnerDesktopSnowLeopard.png -> [2011/11/19 16:01:42 | 000,256,478 | ---- | M | MD5 = 218313E1C69D8BEEB401BC1F4A2CE729] ()
ChocCake.jpg -> C:UsersOwnerDesktopChocCake.jpg -> [2011/11/19 15:49:46 | 000,021,388 | ---- | M | MD5 = 4C559E04BA76A58AB6C052310AB67A22] ()
foundation.JPG -> C:UsersOwnerDesktopfoundation.JPG -> [2011/11/18 19:35:43 | 000,008,011 | ---- | M | MD5 = D573D3BB1E0966561407C82503DD028A] ()
Freefrenchfries.jpg -> C:UsersOwnerDesktopFreefrenchfries.jpg -> [2011/11/18 17:32:38 | 000,007,548 | ---- | M | MD5 = DA7318A7988A0BFAF09EECCAF07733D6] ()
packager.dll -> C:WindowsSystem32packager.dll -> [2011/11/18 10:47:03 | 000,066,560 | ---- | M | MD5 = A520C77CFFABC96E32818451B60905C7] (Microsoft Corporation)
rmoc3260.dll -> C:WindowsSystem32rmoc3260.dll -> [2011/11/10 15:44:06 | 000,198,832 | ---- | M | MD5 = 1D0316BEB736160D249C4F147261EC70] (RealNetworks, Inc.)
pndx5032.dll -> C:WindowsSystem32pndx5032.dll -> [2011/11/10 15:43:17 | 000,005,632 | ---- | M | MD5 = B74E422BC81236042529DC8A42A18423] (RealNetworks, Inc.)
pndx5016.dll -> C:WindowsSystem32pndx5016.dll -> [2011/11/10 15:43:16 | 000,006,656 | ---- | M | MD5 = 33833B3EDA1B07EBD367FA9B38B23E60] (RealNetworks, Inc.)
pncrt.dll -> C:WindowsSystem32pncrt.dll -> [2011/11/10 15:43:05 | 000,272,896 | ---- | M | MD5 = B4EB68502E52EBDC0B2C55EA3445284C] (Progressive Networks)
tzres.dll -> C:WindowsSystem32tzres.dll -> [2011/11/08 07:42:19 | 000,002,048 | ---- | M | MD5 = B96EAA786CAB24AF0890C8B89CEF348C] (Microsoft Corporation)
Blackout.png -> C:UsersOwnerDesktopBlackout.png -> [2011/11/06 20:27:01 | 000,053,334 | ---- | M | MD5 = 4FADF93EDCD290EDCE71939F31A1D932] ()
MSCOMCTL.OCX -> C:WindowsSystem32MSCOMCTL.OCX -> [2011/11/04 06:13:36 | 001,070,352 | ---- | M | MD5 = 03B0224FD1E2D8A6DBC2B18404092F21] (Microsoft Corporation)
SBREDrv.sys -> C:WindowsSystem32driversSBREDrv.sys -> [2011/10/26 14:23:40 | 000,101,112 | ---- | M | MD5 = 1FD538C4FEB36B793D2121F20BBDC16F] (GFI Software)
csrsrv.dll -> C:WindowsSystem32csrsrv.dll -> [2011/10/25 08:56:04 | 000,049,152 | ---- | M | MD5 = 187076DD5D8D4D5D23079D0741195EAD] (Microsoft Corporation)
QuickTimeVR.qtx -> C:WindowsSystem32QuickTimeVR.qtx -> [2011/10/24 14:29:02 | 000,094,208 | ---- | M | MD5 = 97A90E7845335C6AB21F9FAD72595563] (Apple Inc.)
QuickTime.qts -> C:WindowsSystem32QuickTime.qts -> [2011/10/24 14:29:02 | 000,069,632 | ---- | M | MD5 = 584F1C20E840CB7E00B2FF40FA6F7544] (Apple Inc.)
isolate.ini -> C:WindowsSystem32driversNST\0200000.010isolate.ini -> [2011/10/18 06:18:09 | 000,000,172 | ---- | M | MD5 = 77BF8CEC1E76285A3407050A2D20FA6A] ()
mciseq.dll -> C:WindowsSystem32mciseq.dll -> [2011/10/14 09:00:23 | 000,023,552 | ---- | M | MD5 = FF8FCDF1913016813AFB966A0F41B299] (Microsoft Corporation)
SbFwIm.sys -> C:WindowsSystem32driversSbFwIm.sys -> [2011/09/29 12:16:18 | 000,094,584 | ---- | M | MD5 = 1DCAD90CC9C0DDC7D060FD97854F8518] (GFI Software)
UIAutomationCore.dll -> C:WindowsSystem32UIAutomationCore.dll -> [2011/08/25 09:15:04 | 000,555,520 | ---- | M | MD5 = CCE5E7C0F8AA13207E777C43F4DA80A3] (Microsoft Corporation)
oleaccrc.dll -> C:WindowsSystem32oleaccrc.dll -> [2011/08/25 06:31:01 | 000,004,096 | ---- | M | MD5 = 7E38DA8C11833B99766A97CEE3F80F07] (Microsoft Corporation)
ccSetx86.cat -> C:WindowsSystem32driversNST\0200000.010ccSetx86.cat -> [2011/08/10 11:29:52 | 000,007,510 | R--- | M | MD5 = 7F3FC8E6AD34DB35C91B0658C8343324] ()
ccSetx86.sys -> C:WindowsSystem32driversNST\0200000.010ccSetx86.sys -> [2011/08/08 16:38:11 | 000,132,744 | R--- | M | MD5 = 2B2F9B4A08190334A9C36446B208BAE9] (Symantec Corporation)
ccSetx86.inf -> C:WindowsSystem32driversNST\0200000.010ccSetx86.inf -> [2011/08/08 14:23:20 | 000,000,828 | R--- | M | MD5 = 5F6D49B98EEE4A2B490C59FCE2F37BA6] ()
psisdecd.dll -> C:WindowsSystem32psisdecd.dll -> [2011/07/29 09:01:34 | 000,293,376 | ---- | M | MD5 = 959A4BC486951267EE6343A431A92B12] (Microsoft Corporation)
psisrndr.ax -> C:WindowsSystem32psisrndr.ax -> [2011/07/29 09:01:33 | 000,217,088 | ---- | M | MD5 = 3A78D48221D32BC99C4B11B112D6EADA] (Microsoft Corporation)
MSDvbNP.ax -> C:WindowsSystem32MSDvbNP.ax -> [2011/07/29 09:00:14 | 000,057,856 | ---- | M | MD5 = D1AE4D2D559C23CE9DE4B3B10A90B901] (Microsoft Corporation)
Mpeg2Data.ax -> C:WindowsSystem32Mpeg2Data.ax -> [2011/07/29 09:00:05 | 000,069,632 | ---- | M | MD5 = 1B45ED071775A5E8BF51682EC5B61231] (Microsoft Corporation)
3 C:UsersOwnerAppDataLocalTempLow*.tmp files -> C:UsersOwnerAppDataLocalTempLow*.tmp ->
3 C:UsersOwnerAppDataLocalTempLow*.tmp files -> C:UsersOwnerAppDataLocalTempLow*.tmp ->
1746 C:UsersOwnerAppDataLocalTemp*.tmp files -> C:UsersOwnerAppDataLocalTemp*.tmp ->
1746 C:UsersOwnerAppDataLocalTemp*.tmp files -> C:UsersOwnerAppDataLocalTemp*.tmp ->
1746 C:UsersOwnerAppDataLocalTemp*.tmp files -> C:UsersOwnerAppDataLocalTemp*.tmp ->
1746 C:UsersOwnerAppDataLocalTemp*.tmp files -> C:UsersOwnerAppDataLocalTemp*.tmp ->
1 C:Windows*.tmp files -> C:Windows*.tmp ->
1 C:UsersOwnerAppDataRoaming*.tmp files -> C:UsersOwnerAppDataRoaming*.tmp ->
[Files - No Company Name]
ServiceConfig.xml -> C:WindowsSystem32ServiceConfig.xml -> [2012/05/14 17:53:44 | 000,001,190 | ---- | C | MD5 = E0C72EC18DE4ACF515832F0B4EC9E448] ()
TDSSKiller.exe - Shortcut.lnk -> C:UsersOwnerDesktopTDSSKiller.exe - Shortcut.lnk -> [2012/05/14 17:52:16 | 000,000,518 | ---- | C | MD5 = 4575E0F6923EE84F1D9475830B41916E] ()
Malwarebytes Anti-Malware.lnk -> C:UsersPublicDesktopMalwarebytes Anti-Malware.lnk -> [2012/05/14 11:47:07 | 000,000,912 | ---- | C | MD5 = 553B9937C7E85B595C7A651A5BA7E890] ()
2012_4_19_24_Myk.png -> C:UsersOwnerDocuments2012_4_19_24_Myk.png -> [2012/05/07 21:48:12 | 000,170,050 | ---- | C | MD5 = 9B302F813AF7B004A0E29D7A0850585B] ()
2012_4_9_18_Myk.png -> C:UsersOwnerDocuments2012_4_9_18_Myk.png -> [2012/05/07 21:23:18 | 000,214,136 | ---- | C | MD5 = FD5B01C1B9B53000FDC9E362B29CA813] ()
clp.ashx -> C:UsersOwnerDesktopclp.ashx -> [2012/05/07 13:05:24 | 000,159,831 | ---- | C | MD5 = ED3EB883F2457250F78B7977F759CBF6] ()
Msft_User_WpdMtpDr_01_07_00.Wdf -> C:WindowsSystem32driversMsft_User_WpdMtpDr_01_07_00.Wdf -> [2012/04/30 15:14:22 | 000,000,000 | -H-- | C | MD5 = D41D8CD98F00B204E9800998ECF8427E] ()
Msft_User_WpdFs_01_07_00.Wdf -> C:WindowsSystem32driversMsft_User_WpdFs_01_07_00.Wdf -> [2012/04/30 15:14:13 | 000,000,000 | -H-- | C | MD5 = D41D8CD98F00B204E9800998ECF8427E] ()
ieuinit.inf -> C:WindowsSystem32ieuinit.inf -> [2012/04/30 11:49:51 | 000,072,822 | ---- | C | MD5 = 4B333D3CC96AE66BD754329FD2989EE2] ()
QuickTime Player.lnk -> C:UsersPublicDesktopQuickTime Player.lnk -> [2012/04/20 12:51:36 | 000,001,732 | ---- | C | MD5 = B50698B7FAAAC47D2C6AF84BB67EC8E2] ()
IMVU.lnk -> C:UsersOwnerDesktopIMVU.lnk -> [2012/04/10 12:30:13 | 000,001,789 | ---- | C | MD5 = BFA6212E0356B17FFF1C1ECAAD87A225] ()
AprilFools.jpg -> C:UsersOwnerDesktopAprilFools.jpg -> [2012/04/01 12:25:23 | 000,066,765 | ---- | C | MD5 = 12DA86770C533416AE919063CA577DEF] ()
EnterSandman.wps -> C:UsersOwnerDocumentsEnterSandman.wps -> [2012/03/31 17:02:02 | 000,019,456 | ---- | C | MD5 = 585A1AE14D5738268B0C979931339B93] ()
Adobe Flash Player Updater.job -> C:WindowstasksAdobe Flash Player Updater.job -> [2012/03/29 16:52:05 | 000,000,830 | ---- | C | MD5 = 779A61D8B94B56C363C8A32E3FEA06E7] ()
AmeSignature.png -> C:UsersOwnerDocumentsAmeSignature.png -> [2012/03/07 20:08:35 | 000,011,351 | ---- | C | MD5 = D0FBD0BFAFABEA537B603B05BE94D674] ()
loraxtrees_lorax_1329961921951_psNL1kFw.png -> C:UsersOwnerDesktoploraxtrees_lorax_1329961921951_psNL1kFw.png -> [2012/02/22 18:52:17 | 000,126,264 | ---- | C | MD5 = 74A9FE9A0454368593674A5ACACDD8F9] ()
2012_SeanTCBurnsResume.rtf -> C:UsersOwnerDocuments2012_SeanTCBurnsResume.rtf -> [2012/02/21 19:37:19 | 000,035,489 | ---- | C | MD5 = 763AB2210E94BAAC68617D69B5E96648] ()
TicketPayment_2_15.png -> C:UsersOwnerDocumentsTicketPayment_2_15.png -> [2012/02/15 15:56:53 | 000,209,782 | ---- | C | MD5 = 8EBF5671BA6CE4FAD669301AA0329C32] ()
Address.wps -> C:UsersOwnerDocumentsAddress.wps -> [2012/02/06 16:45:11 | 000,091,648 | ---- | C | MD5 = 8CE88B12E393E5D417EE087C82F84474] ()
DDAuth.pdf -> C:UsersOwnerDesktopDDAuth.pdf -> [2012/02/06 16:19:25 | 000,013,927 | ---- | C | MD5 = B900EC309AA51659BD2659A261F28D39] ()
TrafSch_4.png -> C:UsersOwnerDocumentsTrafSch_4.png -> [2012/01/22 13:36:26 | 000,204,170 | ---- | C | MD5 = 6A06CF7D12481F6E67607D396FD5DF16] ()
TrafSch_3.png -> C:UsersOwnerDocumentsTrafSch_3.png -> [2012/01/22 13:28:35 | 000,132,294 | ---- | C | MD5 = E237F628A387C4A17CD3F791A6FAA559] ()
TrafSch_2.png -> C:UsersOwnerDocumentsTrafSch_2.png -> [2012/01/22 13:21:57 | 000,166,185 | ---- | C | MD5 = 027423D6BAA4EBD48D76AA16DE1BFD8B] ()
TrafSch_1.png -> C:UsersOwnerDocumentsTrafSch_1.png -> [2012/01/22 13:13:58 | 000,151,068 | ---- | C | MD5 = ABAAD151E7EE3782705D4618AE471E66] ()
FinePixViewer.lnk -> C:UsersOwnerAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupFinePixViewer.lnk -> [2012/01/15 17:01:17 | 000,000,906 | ---- | C | MD5 = E63B172F6A99CC2924ADBB626E6CF5F6] ()
Sav.jpg -> C:UsersOwnerDesktopSav.jpg -> [2012/01/14 22:25:52 | 000,003,041 | ---- | C | MD5 = 2E7960B4373056B4ABD1875103514906] ()
Cookiies.jpg -> C:UsersOwnerDesktopCookiies.jpg -> [2012/01/14 22:24:39 | 000,025,322 | ---- | C | MD5 = 8E5E8B030D2D80C7372F80C28DE06F4B] ()
tagalongs160194.jpg -> C:UsersOwnerDesktoptagalongs160194.jpg -> [2012/01/14 22:19:06 | 000,003,620 | ---- | C | MD5 = 415B5D1E3FA45C6983CEE51011B584BB] ()
trefoils200.JPG -> C:UsersOwnerDesktoptrefoils200.JPG -> [2012/01/14 22:03:09 | 000,008,440 | ---- | C | MD5 = 231EC9B31BE7E5CF5E8C97C53866E698] ()
dosidos200.JPG -> C:UsersOwnerDesktopdosidos200.JPG -> [2012/01/14 22:03:02 | 000,007,662 | ---- | C | MD5 = 110275366F0E6E23796497BAC55B566F] ()
thinmints200.JPG -> C:UsersOwnerDesktopthinmints200.JPG -> [2012/01/14 22:02:39 | 000,005,872 | ---- | C | MD5 = DBAB55B24E0CE43D1E6773BB17120CE6] ()
samoas200.JPG -> C:UsersOwnerDesktopsamoas200.JPG -> [2012/01/14 22:02:23 | 000,010,476 | ---- | C | MD5 = B816DBD14EBCD040F737D2CC6F73E4F3] ()
MoneyOrderLetter.wps -> C:UsersOwnerDocumentsMoneyOrderLetter.wps -> [2012/01/12 15:28:23 | 000,096,256 | ---- | C | MD5 = 4E38C8C0D89825788B1D53F26AC0F3A5] ()
LetterTemplate_1.wps -> C:UsersOwnerDocumentsLetterTemplate_1.wps -> [2012/01/12 15:15:34 | 000,094,720 | ---- | C | MD5 = F403D449A50FA39EA021562AEDDB5FF6] ()
Wagoner_E4.jpg -> C:UsersOwnerDocumentsWagoner_E4.jpg -> [2012/01/01 13:53:44 | 000,103,673 | ---- | C | MD5 = 26434039E70EDFE46ED0C75ABCD59D67] ()
Cat.DB -> C:WindowsSystem32driversCat.DB -> [2011/12/20 12:09:00 | 002,288,676 | ---- | C | MD5 = 4699B3B6F230C41BFA6B88DAA0A9C01E] ()
sdasetup.exe.lnk -> C:UsersOwnerDesktopsdasetup.exe.lnk -> [2011/12/20 12:06:12 | 000,001,358 | ---- | C | MD5 = A43B329BB415B3487B679AC8C926E17B] ()
ccSetx86.cat -> C:WindowsSystem32driversNST\0200000.010ccSetx86.cat -> [2011/12/19 21:43:39 | 000,007,510 | R--- | C | MD5 = 7F3FC8E6AD34DB35C91B0658C8343324] ()
ccSetx86.inf -> C:WindowsSystem32driversNST\0200000.010ccSetx86.inf -> [2011/12/19 21:43:39 | 000,000,828 | R--- | C | MD5 = 5F6D49B98EEE4A2B490C59FCE2F37BA6] ()
isolate.ini -> C:WindowsSystem32driversNST\0200000.010isolate.ini -> [2011/12/19 21:43:39 | 000,000,172 | ---- | C | MD5 = 77BF8CEC1E76285A3407050A2D20FA6A] ()
FLV Player.lnk -> C:UsersPublicDesktopFLV Player.lnk -> [2011/12/18 12:56:25 | 000,001,701 | ---- | C | MD5 = EAD0E5DAD3D0AC4FA198317EEC7C8CF8] ()
IMVU.lnk -> C:UsersOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchIMVU.lnk -> [2011/12/14 14:35:27 | 000,001,789 | ---- | C | MD5 = 88CAB7594A3B0E675510A7B2D2F15D98] ()
UI.htm -> C:UsersOwnerDesktopUI.htm -> [2011/12/14 13:48:42 | 000,042,413 | ---- | C | MD5 = 7376B62C433C987BE682B6E2A2172987] ()
cute.jpg -> C:UsersOwnerDesktopcute.jpg -> [2011/12/14 10:41:27 | 000,036,248 | ---- | C | MD5 = 5DB721FD0F10AC0E6A971C800A4AD673] ()
Snowwhite.jpg -> C:UsersOwnerDesktopSnowwhite.jpg -> [2011/12/07 12:26:46 | 000,078,051 | ---- | C | MD5 = 4CA2BB4F5F9B3D1C9776D143415DD68F] ()
Yes.jpg -> C:UsersOwnerDesktopYes.jpg -> [2011/12/06 15:53:21 | 000,020,479 | ---- | C | MD5 = 3A113FFBCF9CF99E597A78661D1B6ED4] ()
droids.jpg -> C:UsersOwnerDesktopdroids.jpg -> [2011/12/06 15:17:11 | 000,052,775 | ---- | C | MD5 = 2C636C69CDA9A2349CC5C9140F30AFD0] ()
Christi_Xmas.jpg -> C:UsersOwnerDocumentsChristi_Xmas.jpg -> [2011/11/29 20:04:05 | 000,047,712 | ---- | C | MD5 = F1551C9DFE12CEE7A7FCC805291F3690] ()
2012_STCB_resume.wps -> C:UsersOwnerDocuments2012_STCB_resume.wps -> [2011/11/29 11:32:19 | 000,040,448 | ---- | C | MD5 = 2C5A8FB71E181C1547FF3CA2D84E7E32] ()
applications-engineer-resume-sample.jpg -> C:UsersOwnerDocumentsapplications-engineer-resume-sample.jpg -> [2011/11/29 11:08:10 | 000,121,526 | ---- | C | MD5 = CCF2194FABD6FEBEEDABECD6A9599265] ()
engineer2_resume_example.gif -> C:UsersOwnerDocumentsengineer2_resume_example.gif -> [2011/11/29 11:07:51 | 000,034,831 | ---- | C | MD5 = 6BC51FA3C54C7E89172BA55A8D7283EE] ()
ShowMyPC3105.exe -> C:UsersOwnerDesktopShowMyPC3105.exe -> [2011/11/25 17:07:16 | 002,291,544 | ---- | C | MD5 = B23A50D66334AA2D2263CCA208FA2608] ()
Chewbacca.jpg -> C:UsersOwnerDesktopChewbacca.jpg -> [2011/11/22 14:09:47 | 000,062,607 | ---- | C | MD5 = EED2660D7E9F965D61CBCB96B453E61B] ()
SnowLeopard.png -> C:UsersOwnerDesktopSnowLeopard.png -> [2011/11/19 16:01:42 | 000,256,478 | ---- | C | MD5 = 218313E1C69D8BEEB401BC1F4A2CE729] ()
ChocCake.jpg -> C:UsersOwnerDesktopChocCake.jpg -> [2011/11/19 15:50:01 | 000,021,388 | ---- | C | MD5 = 4C559E04BA76A58AB6C052310AB67A22] ()
foundation.JPG -> C:UsersOwnerDesktopfoundation.JPG -> [2011/11/18 19:35:42 | 000,008,011 | ---- | C | MD5 = D573D3BB1E0966561407C82503DD028A] ()
Freefrenchfries.jpg -> C:UsersOwnerDesktopFreefrenchfries.jpg -> [2011/11/18 17:32:51 | 000,007,548 | ---- | C | MD5 = DA7318A7988A0BFAF09EECCAF07733D6] ()
Blackout.png -> C:UsersOwnerDesktopBlackout.png -> [2011/11/06 20:27:00 | 000,053,334 | ---- | C | MD5 = 4FADF93EDCD290EDCE71939F31A1D932] ()
{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini -> C:UsersOwnerAppDataLocal{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini -> [2010/11/29 19:12:35 | 000,001,940 | ---- | C | MD5 = 4DBC4C072E7DD16897364E465CD65124] ()
[File - Lop Check]
Ad-Aware Antivirus -> C:UsersOwnerAppDataRoamingAd-Aware Antivirus -> [2012/05/14 11:49:30 | 000,000,000 | ---D | M]
FUJIFILM -> C:UsersOwnerAppDataRoamingFUJIFILM -> [2010/03/14 21:04:05 | 000,000,000 | ---D | M]
Image Zone Express -> C:UsersOwnerAppDataRoamingImage Zone Express -> [2012/02/03 00:44:38 | 000,000,000 | ---D | M]
IMVU -> C:UsersOwnerAppDataRoamingIMVU -> [2012/04/10 13:50:38 | 000,000,000 | ---D | M]
IMVUClient -> C:UsersOwnerAppDataRoamingIMVUClient -> [2012/04/10 12:29:56 | 000,000,000 | ---D | M]
IrfanView -> C:UsersOwnerAppDataRoamingIrfanView -> [2010/02/16 20:59:16 | 000,000,000 | ---D | M]
iScreensaver -> C:UsersOwnerAppDataRoamingiScreensaver -> [2008/03/08 18:17:35 | 000,000,000 | ---D | M]
MSA -> C:UsersOwnerAppDataRoamingMSA -> [2010/12/17 18:33:49 | 000,000,000 | ---D | M]
Opera -> C:UsersOwnerAppDataRoamingOpera -> [2008/11/04 12:56:32 | 000,000,000 | ---D | M]
PeerNetworking -> C:UsersOwnerAppDataRoamingPeerNetworking -> [2009/12/12 12:44:44 | 000,000,000 | ---D | M]
Printer Info Cache -> C:UsersOwnerAppDataRoamingPrinter Info Cache -> [2007/10/30 19:00:32 | 000,000,000 | ---D | M]
Snapfish -> C:UsersOwnerAppDataRoamingSnapfish -> [2007/11/05 10:01:31 | 000,000,000 | ---D | M]
System Protection Tools -> C:UsersOwnerAppDataRoamingSystem Protection Tools -> [2012/05/12 15:02:43 | 000,000,000 | -HSD | M]
Template -> C:UsersOwnerAppDataRoamingTemplate -> [2007/10/30 18:54:27 | 000,000,000 | ---D | M]
TestApp -> C:UsersOwnerAppDataRoamingTestApp -> [2011/12/20 12:06:11 | 000,000,000 | ---D | M]
TrojanHunter -> C:UsersOwnerAppDataRoamingTrojanHunter -> [2008/11/05 21:46:47 | 000,000,000 | ---D | M]
WinBatch -> C:UsersOwnerAppDataRoamingWinBatch -> [2008/07/08 18:42:41 | 000,000,000 | ---D | M]
SCHEDLGU.TXT -> C:WindowsTasksSCHEDLGU.TXT -> [2012/05/14 17:53:20 | 000,032,654 | ---- | M | Unable to obtain MD5] ()
[File - Purity Scan]
[Alternate Data Streams]
@Alternate Data Stream - 109 bytes -> C:ProgramDataTEMP:DFC5A2B2
< End of report >
I forgot to tell you what I have tried:
Malwarebytes (It did find things and thinks that it has found all threats now)
TDSSKiller by Kaspersky (It found nothing)
Ad-aware (I can't remember what it found, but it was not helpful either and Malware Bytes even indicated some unsafe files were in my Ad-aware folder. So, it may have redefined some definitions?)
Please help me. I even made you a nice banner to look at. :lol:
(I don't see an edit button to add these things, so sorry for posting twice)