Versus_21
Topic Starter
Hello,
I have a computer running Windows 7 and generally use Firefox (version 16 currently) for browsing. Few days ago I been searching for an image and one of the results in Google Images redirected me to a strange website, at which this ad appeared for the first time. I thought this is something site-specific, however later similar adds starting popping up during all my browsing sessions with almost all the websites. Here I attach the screenshot:
[external image: Posted Image]
The dog in the corner is this very ad. Your forum does not have such advertising (I checked on another computer), as well as many other websites visiting which I see similar ads.
I scanned my computer with different malware removal tools including MalWare Bytes, Free Version of Ad-Aware, Norton, Super AntiSpyware. All of them detected certain threats but neither of these threats resolved the issue with the ads.
Also, searching for similar questions I found this thread on your forum - http://forums.whatthetech.com/index.php?showtopic=123243
The case is similar to mine, with the difference that I do not have redirecting of the addresses.
Here are the logs requested:
OTL logfile created on: 02.11.2012 13:47:42 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\George\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000419 | Country: Russia | Language: RUS | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 6,00 Gb Available Physical Memory | 75,21% Memory free
15,96 Gb Paging File | 13,42 Gb Available in Paging File | 84,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,00 Gb Total Space | 32,85 Gb Free Space | 27,15% Space Free | Partition Type: NTFS
Drive D: | 160,20 Gb Total Space | 7,64 Gb Free Space | 4,77% Space Free | Partition Type: NTFS
Drive E: | 650,21 Gb Total Space | 7,02 Gb Free Space | 1,08% Space Free | Partition Type: NTFS
Drive F: | 232,88 Gb Total Space | 11,72 Gb Free Space | 5,03% Space Free | Partition Type: NTFS
Drive G: | 465,75 Gb Total Space | 6,13 Gb Free Space | 1,32% Space Free | Partition Type: NTFS
Drive H: | 465,75 Gb Total Space | 0,96 Gb Free Space | 0,21% Space Free | Partition Type: NTFS
Drive I: | 465,75 Gb Total Space | 0,85 Gb Free Space | 0,18% Space Free | Partition Type: NTFS
Drive J: | 465,75 Gb Total Space | 3,20 Gb Free Space | 0,69% Space Free | Partition Type: NTFS
Computer Name: INTEL-I5 | User Name: George | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
PRC - [2012.10.27 08:04:25 | 000,917,984 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
PRC - [2012.09.20 15:03:16 | 018,941,832 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
PRC - [2012.09.12 14:22:30 | 001,807,560 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
PRC - [2012.08.08 10:17:00 | 000,540,056 | —- | M] (Lavasoft) – C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
PRC - [2012.08.04 14:41:24 | 001,022,352 | —- | M] (BitTorrent, Inc.) – C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
PRC - [2011.09.08 15:38:22 | 003,425,688 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
PRC - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
PRC - [2010.01.22 21:48:02 | 000,638,976 | —- | M] (Drakenscripts.co.cc) – C:\Program Files (x86)\StickyNotes\SNTBHider.exe
PRC - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe
PRC - [2009.12.11 17:24:04 | 001,774,856 | —- | M] (ABBYY (BIT Software)) – C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe
========== Modules (No Company Name) ==========
MOD - [2012.10.27 08:04:10 | 002,295,264 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.09.12 14:22:29 | 009,813,704 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.10.20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012.07.11 20:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2010.09.22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe – (Ad-Aware Service)
SRV - [2012.07.25 18:58:26 | 000,126,976 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe – (Te.Service)
SRV - [2012.07.25 18:13:16 | 000,139,776 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe – (fussvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012.07.09 00:40:10 | 000,104,912 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe – (SBAMSvc)
SRV - [2011.11.24 20:59:24 | 000,008,192 | —- | M] () [Auto | Stopped] – C:\Windows\SysWOW64\srvany.exe – (KMService)
SRV - [2011.09.26 11:17:16 | 009,665,536 | —- | M] () [On_Demand | Stopped] – c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe – (wampmysqld)
SRV - [2011.09.26 11:06:54 | 000,021,504 | —- | M] (Apache Software Foundation) [On_Demand | Stopped] – c:\wamp\bin\apache\Apache2.2.21\bin\httpd.exe – (wampapache)
SRV - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe – (AHDDC2)
SRV - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe – (OS Selector)
SRV - [2010.02.19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.Lingvo.Desktop.14.0)
SRV - [2009.08.24 20:16:12 | 000,544,768 | —- | M] (mst software GmbH, Germany) [On_Demand | Stopped] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe – (DfSdkS)
SRV - [2009.06.10 23:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\SBREDrv.sys – (SBRE)
DRV:64bit: - [2012.09.29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011.12.19 12:44:24 | 000,060,536 | —- | M] (GFI Software) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sbhips.sys – (sbhips)
DRV:64bit: - [2011.11.29 06:59:46 | 000,074,872 | —- | M] (GFI Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\sbapifs.sys – (sbapifs)
DRV:64bit: - [2011.11.15 05:50:14 | 000,125,376 | —- | M] (Power Software Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\scdemu.sys – (SCDEmu)
DRV:64bit: - [2011.11.03 03:01:00 | 000,056,208 | —- | M] (Rovi Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2011.09.08 16:12:20 | 000,143,984 | —- | M] (Tonec Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\idmwfp.sys – (IDMWFP)
DRV:64bit: - [2011.08.17 09:58:26 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys – (UsbserFilt)
DRV:64bit: - [2011.08.17 09:58:22 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys – (upperdev)
DRV:64bit: - [2011.08.17 09:58:20 | 000,027,136 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbox64.sys – (nmwcdc)
DRV:64bit: - [2011.08.17 09:58:16 | 000,019,968 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbx64.sys – (nmwcd)
DRV:64bit: - [2011.07.22 18:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011.07.12 23:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011.06.15 23:07:10 | 000,276,576 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\snapman.sys – (snapman)
DRV:64bit: - [2011.06.04 23:41:47 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2011.04.13 14:04:38 | 000,045,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011.04.08 22:00:20 | 000,047,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010.11.21 05:24:43 | 000,020,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,117,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tsusbhub.sys – (tsusbhub)
DRV:64bit: - [2010.11.21 05:23:48 | 000,088,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Synth3dVsc.sys – (Synth3dVsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,034,816 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010.11.15 18:05:02 | 000,364,520 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmtxhci.sys – (asmtxhci)
DRV:64bit: - [2010.11.15 18:05:00 | 000,121,832 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmthub3.sys – (asmthub3)
DRV:64bit: - [2010.10.26 10:08:08 | 000,406,632 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010.10.19 23:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2007.08.08 12:47:16 | 000,193,312 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0330Vid.sys – (V0330VID)
DRV - [2012.07.24 18:59:11 | 000,036,480 | —- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\npf.sys – (npf)
DRV - [2012.07.13 16:13:14 | 000,070,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys – (VSPerfDrv110)
DRV - [2011.10.26 14:23:40 | 000,101,112 | —- | M] (GFI Software) [Kernel | System | Running] – C:\Windows\SysWOW64\drivers\SBREDrv.sys – (SBRE)
DRV - [2011.07.16 15:29:28 | 000,021,712 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS – (DrvAgent64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9HP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security…;pvid=20.2.0.19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ru.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ru
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 D9 14 86 FF 22 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "korrespondent.net"
FF - prefs.js..extensions.enabledAddons: [removed]:7.3.29
FF - prefs.js..keyword.URL: "http://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=EF15A04EC6049C0776EC1A509245A9D4&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 08:04:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 08:04:08 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]
[2011.06.05 01:11:18 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Extensions
[2012.11.01 11:49:27 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions
[2012.11.01 11:49:28 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2012.03.01 11:04:51 | 000,000,000 | —D | M] (Search Assistant) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{B3834E60-12A8-11E0-A289-939FDFD72085}
[2012.11.01 11:39:29 | 000,000,000 | —D | M] (Lavasoft Search Plugin) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012.10.15 16:55:27 | 000,000,000 | —D | M] (IDM CC) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2012.11.01 06:43:05 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash
[2012.11.01 06:43:05 | 002,042,908 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2011.09.14 21:09:36 | 000,087,923 | R— | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
[2012.10.26 06:39:57 | 002,042,937 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash\[removed]
[2011.06.08 05:55:13 | 000,012,703 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\imdb.xml
[2011.08.04 01:15:27 | 000,009,695 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\lurkmore-ru.xml
[2011.06.08 18:24:35 | 000,001,701 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\rutrackerorg.xml
[2011.06.05 23:50:34 | 000,002,057 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\youtube-video-search.xml
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.27 08:04:26 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.27 15:45:50 | 000,083,456 | —- | M] (LiveVDO ) – C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
[2012.11.01 11:49:30 | 000,000,616 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012.08.30 09:27:08 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.12 19:34:03 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.google.com/
CHR - default_search_provider: blekko (Enabled)
CHR - default_search_provider: search_url = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Google Update (Enabled) = C:\Users\George\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Search Assistant = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfelndikbdcohbdimnhdhhokfljdidgn\2.0.0\
CHR - Extension: vshare plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
CHR - Extension: LiveVDO plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\
O1 HOSTS File: ([2012.10.31 17:42:11 | 000,001,398 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 217.23.13.202 www.google-analytics.com.
O1 - Hosts: 217.23.13.202 ad-emea.doubleclick.net.
O1 - Hosts: 217.23.13.202 www.statcounter.com.
O1 - Hosts: 198.15.104.132 www.google-analytics.com.
O1 - Hosts: 198.15.104.132 ad-emea.doubleclick.net.
O1 - Hosts: 198.15.104.132 www.statcounter.com.
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll File not found
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Lingvo Launcher] C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe (ABBYY (BIT Software))
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\George\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sticky Notes Taskbar Hider.lnk = C:\Program Files (x86)\StickyNotes\SNTBHider.exe (Drakenscripts.co.cc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.2.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD181FDC-6BF9-4094-9BF8-195BA15CE97D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\vs_ultimate.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec64.dll (TechSmith Corporation)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec32.dll (TechSmith Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.11.02 13:47:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:26 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Malwarebytes
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012.11.02 13:16:14 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012.11.02 13:16:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.11.01 18:33:27 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\SUPERAntiSpyware.com
[2012.11.01 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012.11.01 18:08:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2012.11.01 14:42:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2012.11.01 14:23:11 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2012.11.01 13:55:58 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adawarebp
[2012.11.01 12:18:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2012.11.01 12:18:00 | 000,060,536 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\sbhips.sys
[2012.11.01 12:17:59 | 000,045,936 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2012.11.01 12:17:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2012.11.01 12:17:30 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\Downloaded Installations
[2012.11.01 11:44:48 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\LavasoftStatistics
[2012.11.01 11:39:35 | 000,000,000 | —D | C] – C:\ProgramData\blekko toolbars
[2012.11.01 11:39:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\adawaretb
[2012.11.01 11:27:12 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Ad-Aware Antivirus
[2012.11.01 11:03:23 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 10:51:52 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adaware
[2012.11.01 10:51:47 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012.11.01 10:51:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2012.11.01 10:51:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012.11.01 10:51:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012.11.01 09:39:08 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\NPE
[2012.10.31 21:33:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2012.10.31 21:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012.10.31 21:26:05 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2012.10.31 20:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.10.31 20:03:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012.10.29 16:25:01 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012.10.29 12:33:30 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_29
[2012.10.27 20:53:14 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_27
[2012.10.27 08:04:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012.10.25 17:17:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_25
[2012.10.24 12:02:08 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_24
[2012.10.12 00:09:17 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_12
[2012.10.11 16:58:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_11
[2012.10.10 23:36:21 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_10
[2012.10.10 05:00:21 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012.10.10 05:00:21 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012.10.10 05:00:20 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012.10.10 05:00:16 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012.10.10 05:00:16 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012.10.10 05:00:15 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012.10.10 05:00:15 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012.10.10 05:00:15 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012.10.10 05:00:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012.10.10 05:00:15 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012.10.10 05:00:14 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012.10.10 05:00:14 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012.10.10 05:00:14 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012.10.10 05:00:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012.10.10 05:00:09 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012.10.10 05:00:01 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012.10.10 05:00:01 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012.10.10 00:31:29 | 000,000,000 | —D | C] – C:\Users\George\Desktop\bin
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.11.02 13:49:30 | 000,625,664 | —- | M] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:15 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:14:24 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 13:14:24 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 13:13:07 | 001,839,080 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.02 13:13:07 | 000,792,274 | —- | M] () – C:\Windows\SysNative\perfh019.dat
[2012.11.02 13:13:07 | 000,721,924 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012.11.02 13:13:07 | 000,175,684 | —- | M] () – C:\Windows\SysNative\perfc019.dat
[2012.11.02 13:13:07 | 000,147,066 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012.11.02 13:09:21 | 000,233,423 | —- | M] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.02 13:07:09 | 000,001,868 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.11.02 13:06:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012.11.02 13:06:52 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 13:06:00 | 000,000,982 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000UA.job
[2012.11.02 11:57:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-S-1-5-21-1109903177-269762195-694080819-1000.job
[2012.11.02 11:21:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-sys.job
[2012.11.02 10:33:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.02 06:06:01 | 000,000,930 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000Core.job
[2012.11.02 02:00:03 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 15:01:39 | 000,007,618 | —- | M] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2012.10.31 21:28:42 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012.10.31 17:42:11 | 000,001,398 | RHS- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012.10.25 18:14:20 | 017,541,748 | —- | M] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | M] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | M] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:43 | 019,045,148 | —- | M] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | M] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:31 | 000,030,463 | —- | M] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.10 01:07:37 | 000,000,132 | —- | M] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.10.09 21:46:06 | 000,001,456 | —- | M] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.10.09 21:46:05 | 001,320,376 | —- | M] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.09 02:24:23 | 026,055,247 | —- | M] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.08 19:31:35 | 013,416,742 | —- | M] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.05 00:20:02 | 000,086,729 | —- | M] () – C:\Users\George\Desktop\Picture1.png
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.02 13:49:28 | 000,625,664 | —- | C] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:16:15 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:09:19 | 000,233,423 | —- | C] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.01 18:33:35 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.01 18:33:34 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 12:18:12 | 000,001,868 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.10.25 18:14:19 | 017,541,748 | —- | C] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | C] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | C] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:42 | 019,045,148 | —- | C] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | C] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:29 | 000,030,463 | —- | C] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.09 21:46:05 | 001,320,376 | —- | C] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.08 19:26:39 | 013,416,742 | —- | C] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.06 01:36:53 | 026,055,247 | —- | C] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.05 00:20:01 | 000,086,729 | —- | C] () – C:\Users\George\Desktop\Picture1.png
[2012.09.10 21:57:09 | 000,000,021 | —- | C] () – C:\Windows\SurCode.INI
[2012.08.20 11:20:54 | 000,000,010 | —- | C] () – C:\Users\George\Infovis_FILE_HISTORY.cfg
[2012.05.26 06:23:29 | 000,003,584 | —- | C] () – C:\Windows\SysWow64\DrvFltIp.sys
[2012.05.25 11:21:22 | 000,003,584 | —- | C] () – C:\Users\George\AppData\Roaming\DrvFltIp.sys
[2012.05.12 15:51:03 | 000,000,034 | -H– | C] () – C:\Windows\SysWow64\Converter_sysquict.dat
[2012.04.20 03:10:29 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2012.03.10 21:07:36 | 000,000,145 | —- | C] () – C:\Users\George\.appletviewer
[2012.02.21 18:23:30 | 000,000,043 | —- | C] () – C:\Windows\gswin64.ini
[2012.02.01 02:28:27 | 000,000,983 | —- | C] () – C:\Windows\eReg.dat
[2012.01.30 03:49:45 | 000,001,476 | —- | C] () – C:\Users\George\AppData\Local\UserProducts.xml
[2012.01.07 02:04:30 | 000,145,876 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info9.ini
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info7.ini
[2011.12.09 00:00:52 | 001,747,456 | —- | C] () – C:\Windows\SysWow64\re_imageconv.dll
[2011.11.24 21:00:49 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2011.07.14 14:06:11 | 000,000,020 | —- | C] () – C:\Windows\NMCAutorunXP.ini
[2011.07.08 17:28:10 | 000,001,459 | —- | C] () – C:\Users\George\gsview64.ini
[2011.06.24 21:27:30 | 000,001,456 | —- | C] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011.06.11 00:43:23 | 000,000,132 | —- | C] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.06.06 03:55:19 | 000,007,618 | —- | C] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2011.06.05 01:17:10 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011.06.05 01:11:10 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011.06.05 00:26:11 | 001,819,732 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011.06.04 23:31:01 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011.06.04 23:30:56 | 000,021,262 | —- | C] () – C:\Windows\Ascd_tmp.ini
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012.06.09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012.06.09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009.07.14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010.11.21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009.07.14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2011.01.21 19:26:28 | 000,005,858 | —- | M] () MD5=18E3D562E7E80B329AE5309E368FD567 – C:\Windows\PolicyDefinitions\ru-RU\Explorer.adml
[2011.01.21 19:26:28 | 000,005,858 | —- | M] () MD5=18E3D562E7E80B329AE5309E368FD567 – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_c81688edd50b74ab\Explorer.adml
[2010.11.21 09:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2010.11.21 09:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009.06.10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009.06.10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.BMP >
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp
< MD5 for: EXPLORER.DESIGNER.VB >
[2011.12.12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb
[2011.12.12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2010.11.21 09:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010.11.21 09:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2011.01.21 19:25:49 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=55560C826AAF32C42126EE1F5189611F – C:\Windows\ru-RU\explorer.exe.mui
[2011.01.21 19:25:49 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=55560C826AAF32C42126EE1F5189611F – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_ab089078de57cd42\explorer.exe.mui
[2010.11.21 09:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010.11.21 09:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
[2011.01.21 19:25:22 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=C8A97DC216E7986AF093FB639118D404 – C:\Windows\SysWOW64\ru-RU\explorer.exe.mui
[2011.01.21 19:25:22 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=C8A97DC216E7986AF093FB639118D404 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_b55d3acb12b88f3d\explorer.exe.mui
< MD5 for: EXPLORER.EXE.WINDOWS EXPLORER.MICROSOFT CORPORATION.6.1.7601.17567.ICO >
[2012.06.24 07:27:09 | 000,187,373 | —- | M] () MD5=59EF532FA50E1EC27DC50D43DA386BFB – C:\Users\George\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\explorer.exe.Windows Explorer.Microsoft Corporation.6.1.7601.17567.ico
< MD5 for: EXPLORER.EXE-254441E9.PF >
[2012.11.02 13:48:02 | 000,039,902 | —- | M] () MD5=4F24A4D68707A7475BE0FA5DD26AAD70 – C:\Windows\Prefetch\EXPLORER.EXE-254441E9.pf
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012.11.02 13:48:12 | 000,182,486 | —- | M] () MD5=560AD06BC07C0FEF482BAB6495FC31FC – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.GIF >
[2009.08.31 02:59:28 | 000,003,342 | —- | M] () MD5=2C9E121C2DECEF61FED6EA977A30D90F – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif
[2012.06.24 21:45:02 | 000,001,483 | —- | M] () MD5=4ABBABE57F99C84C4154DD289B766E5E – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif
< MD5 for: EXPLORER.PROPERTIES >
[2011.12.02 23:31:21 | 000,000,039 | —- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 – C:\Users\George\.netbeans\7.0\config\Preferences\org\openide\explorer.properties
[2012.08.20 05:21:20 | 000,000,039 | —- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 – C:\Users\George\AppData\Roaming\.gephi\0.8.1\dev\config\Preferences\org\openide\explorer.properties
< MD5 for: EXPLORER.RESX >
[2011.12.12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.resx
[2011.12.12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.resx
< MD5 for: EXPLORER.VB >
[2011.12.12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vb
[2011.12.12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vb
< MD5 for: EXPLORER.VSTEMPLATE >
[2011.12.12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate
[2011.12.12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate
< MD5 for: EXPLORER.WSMODE >
[2012.08.20 05:21:54 | 000,000,476 | —- | M] () MD5=9885B0575BBF4AEC298B13D68EA7D346 – C:\Users\George\AppData\Roaming\.gephi\0.8.1\dev\config\Windows2Local-overview\Modes\explorer.wsmode
[2012.06.30 10:57:43 | 000,000,561 | —- | M] () MD5=E69F93B0A6A6DBEA0D1CF45EBB155EAF – C:\Users\George\.netbeans\7.0\config\Windows2Local\Modes\explorer.wsmode
< MD5 for: EXPLORER.ZIP >
[2009.06.03 20:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2012.06.02 13:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2012.05.18 01:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012.06.29 07:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012.08.24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012.08.24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012.05.18 00:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012.08.24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012.08.24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012.06.02 11:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012.05.18 04:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012.08.24 12:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012.06.29 04:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012.06.02 14:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012.08.24 09:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010.11.21 05:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012.09.29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011.06.04 23:53:53 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012.06.29 03:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012.06.02 10:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010.11.21 05:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012.06.29 01:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011.06.04 23:53:53 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012.05.18 03:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2011.01.21 19:26:32 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=5E222432D3E4D833D6C967FE4FE81C79 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_ru-ru_5464562bc4198720\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=984477F8913BF8CD2F5C12ADC7C0E183 – C:\Program Files\Internet Explorer\ru-RU\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=984477F8913BF8CD2F5C12ADC7C0E183 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_ru-ru_502247c7091bc70d\iexplore.exe.mui
[2011.01.21 19:26:32 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=9A35E917E4B5C27A51B756BAF7D7F815 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_ru-ru_5eb9007df87a491b\iexplore.exe.mui
[2009.07.14 04:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EAEB8DCDDD67C6AF07598D5C2759B24B – C:\Program Files (x86)\Internet Explorer\ru-RU\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EAEB8DCDDD67C6AF07598D5C2759B24B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_ru-ru_5a76f2193d7c8908\iexplore.exe.mui
[2009.07.14 04:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-4B6C9213.PF >
[2012.11.01 21:49:49 | 000,206,646 | —- | M] () MD5=2D7CA11B34DCC48D56AAA42B17EC184B – C:\Windows\Prefetch\IEXPLORE.EXE-4B6C9213.pf
< MD5 for: SERVICES >
[2009.06.10 23:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2012.01.03 15:10:44 | 000,585,874 | —- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009.07.14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009.07.14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2010.11.21 09:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010.11.21 09:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
[2011.01.21 19:25:41 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=EB63EE0FD3C4826F45845C6E83058570 – C:\Windows\SysNative\ru-RU\services.exe.mui
[2011.01.21 19:25:41 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=EB63EE0FD3C4826F45845C6E83058570 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_0f13507290ab300f\services.exe.mui
< MD5 for: SERVICES.H >
[2011.09.26 11:17:40 | 000,001,043 | —- | M] () MD5=EFA6260E75D8055649F88462E3E9E929 – C:\wamp\bin\mysql\mysql5.5.16\include\mysql\services.h
< MD5 for: SERVICES.LNK >
[2009.07.14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009.07.14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009.06.10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009.06.10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2011.01.21 19:25:34 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\SysNative\ru-RU\services.msc
[2011.01.21 19:25:43 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\SysWOW64\ru-RU\services.msc
[2011.01.21 19:25:34 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_4955205e6714ca02\services.msc
[2011.01.21 19:25:43 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_ed3684daaeb758cc\services.msc
[2010.11.21 09:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009.06.10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010.11.21 09:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009.06.10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010.11.21 09:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009.06.10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010.11.21 09:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009.06.10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009.07.13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009.07.13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SETTINGS >
[2012.06.30 10:57:42 | 000,001,622 | —- | M] () MD5=36F72485C04D6C73C4926FD9112339C1 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Components\services.settings
< MD5 for: SERVICES.WSTCGRP >
[2012.06.30 10:57:43 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Groups\InitialLayout\services.wstcgrp
[2012.06.30 10:57:43 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Groups\OpenedProjects\services.wstcgrp
< MD5 for: SERVICES.WSTCREF >
[2012.06.30 10:57:43 | 000,000,223 | —- | M] () MD5=7FDE98E6B2D9881C67AF64D47984210E – C:\Users\George\.netbeans\7.0\config\Windows2Local\Modes\leftSlidingSide\services.wstcref
< MD5 for: WINLOGON.ADML >
[2011.01.21 19:26:27 | 000,013,486 | —- | M] () MD5=0C0FE7ABF455EC3BCBE3EE70EE01E948 – C:\Windows\PolicyDefinitions\ru-RU\WinLogon.adml
[2011.01.21 19:26:27 | 000,013,486 | —- | M] () MD5=0C0FE7ABF455EC3BCBE3EE70EE01E948 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_3a1a1ae34797fc17\WinLogon.adml
[2010.11.21 09:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2010.11.21 09:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009.06.10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009.06.10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.09.29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010.11.21 09:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010.11.21 09:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2011.01.21 19:25:35 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=61620C41698F9B2C6E5A594497B8A735 – C:\Windows\SysNative\ru-RU\winlogon.exe.mui
[2011.01.21 19:25:35 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=61620C41698F9B2C6E5A594497B8A735 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_723faeae6bbaf822\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2010.11.21 09:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010.11.21 09:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
[2011.01.21 19:25:40 | 000,001,080 | —- | M] () MD5=AC3DB6214BE53F6D948067FDFAEA8467 – C:\Windows\SysNative\wbem\ru-RU\winlogon.mfl
[2011.01.21 19:25:40 | 000,001,080 | —- | M] () MD5=AC3DB6214BE53F6D948067FDFAEA8467 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_cdd0ecb18a04ce1d\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009.07.13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009.07.13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2012.11.02 13:06:52 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 13:06:52 | 4275,318,783 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009.07.14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009.07.14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009.07.14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009.07.14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009.06.10 22:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009.07.14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011.06.04 23:56:31 | 000,000,221 | -HS- | M] () – C:\Users\George\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2012.05.29 09:35:38 | 000,001,422 | —- | M] () – C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 1360 bytes -> C:\ProgramData\Microsoft:4xkr54OEiolnkbB3gh0FD6W
@Alternate Data Stream - 1322 bytes -> C:\Users\George\AppData\Local\zwzMyxIsPOk:6wR7NFoi4b5qJsMYjkIeAi8sX7ur
@Alternate Data Stream - 1313 bytes -> C:\ProgramData\Microsoft:VzjVIwISJ0TLQ3v9LvRDbL1cqrbG
@Alternate Data Stream - 1295 bytes -> C:\ProgramData\Microsoft:z2kO985qGpXTXnglXv0KG7z
< End of report >
I have a computer running Windows 7 and generally use Firefox (version 16 currently) for browsing. Few days ago I been searching for an image and one of the results in Google Images redirected me to a strange website, at which this ad appeared for the first time. I thought this is something site-specific, however later similar adds starting popping up during all my browsing sessions with almost all the websites. Here I attach the screenshot:
[external image: Posted Image]
The dog in the corner is this very ad. Your forum does not have such advertising (I checked on another computer), as well as many other websites visiting which I see similar ads.
I scanned my computer with different malware removal tools including MalWare Bytes, Free Version of Ad-Aware, Norton, Super AntiSpyware. All of them detected certain threats but neither of these threats resolved the issue with the ads.
Also, searching for similar questions I found this thread on your forum - http://forums.whatthetech.com/index.php?showtopic=123243
The case is similar to mine, with the difference that I do not have redirecting of the addresses.
Here are the logs requested:
OTL logfile created on: 02.11.2012 13:47:42 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\George\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000419 | Country: Russia | Language: RUS | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 6,00 Gb Available Physical Memory | 75,21% Memory free
15,96 Gb Paging File | 13,42 Gb Available in Paging File | 84,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,00 Gb Total Space | 32,85 Gb Free Space | 27,15% Space Free | Partition Type: NTFS
Drive D: | 160,20 Gb Total Space | 7,64 Gb Free Space | 4,77% Space Free | Partition Type: NTFS
Drive E: | 650,21 Gb Total Space | 7,02 Gb Free Space | 1,08% Space Free | Partition Type: NTFS
Drive F: | 232,88 Gb Total Space | 11,72 Gb Free Space | 5,03% Space Free | Partition Type: NTFS
Drive G: | 465,75 Gb Total Space | 6,13 Gb Free Space | 1,32% Space Free | Partition Type: NTFS
Drive H: | 465,75 Gb Total Space | 0,96 Gb Free Space | 0,21% Space Free | Partition Type: NTFS
Drive I: | 465,75 Gb Total Space | 0,85 Gb Free Space | 0,18% Space Free | Partition Type: NTFS
Drive J: | 465,75 Gb Total Space | 3,20 Gb Free Space | 0,69% Space Free | Partition Type: NTFS
Computer Name: INTEL-I5 | User Name: George | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
PRC - [2012.10.27 08:04:25 | 000,917,984 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
PRC - [2012.09.20 15:03:16 | 018,941,832 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
PRC - [2012.09.12 14:22:30 | 001,807,560 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
PRC - [2012.08.08 10:17:00 | 000,540,056 | —- | M] (Lavasoft) – C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
PRC - [2012.08.04 14:41:24 | 001,022,352 | —- | M] (BitTorrent, Inc.) – C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
PRC - [2011.09.08 15:38:22 | 003,425,688 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
PRC - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
PRC - [2010.01.22 21:48:02 | 000,638,976 | —- | M] (Drakenscripts.co.cc) – C:\Program Files (x86)\StickyNotes\SNTBHider.exe
PRC - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe
PRC - [2009.12.11 17:24:04 | 001,774,856 | —- | M] (ABBYY (BIT Software)) – C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe
========== Modules (No Company Name) ==========
MOD - [2012.10.27 08:04:10 | 002,295,264 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.09.12 14:22:29 | 009,813,704 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.10.20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012.07.11 20:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2010.09.22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2012.09.29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012.09.20 15:03:20 | 001,236,368 | —- | M] (Lavasoft Limited) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe – (Ad-Aware Service)
SRV - [2012.07.25 18:58:26 | 000,126,976 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe – (Te.Service)
SRV - [2012.07.25 18:13:16 | 000,139,776 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe – (fussvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012.07.09 00:40:10 | 000,104,912 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2012.01.03 15:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011.12.19 13:20:06 | 003,289,032 | —- | M] (GFI Software) [Auto | Running] – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe – (SBAMSvc)
SRV - [2011.11.24 20:59:24 | 000,008,192 | —- | M] () [Auto | Stopped] – C:\Windows\SysWOW64\srvany.exe – (KMService)
SRV - [2011.09.26 11:17:16 | 009,665,536 | —- | M] () [On_Demand | Stopped] – c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe – (wampmysqld)
SRV - [2011.09.26 11:06:54 | 000,021,504 | —- | M] (Apache Software Foundation) [On_Demand | Stopped] – c:\wamp\bin\apache\Apache2.2.21\bin\httpd.exe – (wampapache)
SRV - [2011.04.05 10:39:46 | 001,518,976 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe – (AHDDC2)
SRV - [2010.07.01 16:31:36 | 002,153,336 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe – (OS Selector)
SRV - [2010.02.19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009.12.11 17:24:24 | 000,816,392 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files (x86)\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.Lingvo.Desktop.14.0)
SRV - [2009.08.24 20:16:12 | 000,544,768 | —- | M] (mst software GmbH, Germany) [On_Demand | Stopped] – C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe – (DfSdkS)
SRV - [2009.06.10 23:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\SBREDrv.sys – (SBRE)
DRV:64bit: - [2012.09.29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011.12.19 12:44:24 | 000,060,536 | —- | M] (GFI Software) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sbhips.sys – (sbhips)
DRV:64bit: - [2011.11.29 06:59:46 | 000,074,872 | —- | M] (GFI Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\sbapifs.sys – (sbapifs)
DRV:64bit: - [2011.11.15 05:50:14 | 000,125,376 | —- | M] (Power Software Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\scdemu.sys – (SCDEmu)
DRV:64bit: - [2011.11.03 03:01:00 | 000,056,208 | —- | M] (Rovi Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2011.09.08 16:12:20 | 000,143,984 | —- | M] (Tonec Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\idmwfp.sys – (IDMWFP)
DRV:64bit: - [2011.08.17 09:58:26 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys – (UsbserFilt)
DRV:64bit: - [2011.08.17 09:58:22 | 000,009,216 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys – (upperdev)
DRV:64bit: - [2011.08.17 09:58:20 | 000,027,136 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbox64.sys – (nmwcdc)
DRV:64bit: - [2011.08.17 09:58:16 | 000,019,968 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbx64.sys – (nmwcd)
DRV:64bit: - [2011.07.22 18:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011.07.12 23:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011.06.15 23:07:10 | 000,276,576 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\snapman.sys – (snapman)
DRV:64bit: - [2011.06.04 23:41:47 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2011.04.13 14:04:38 | 000,045,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011.04.08 22:00:20 | 000,047,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010.11.21 05:24:43 | 000,020,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,117,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tsusbhub.sys – (tsusbhub)
DRV:64bit: - [2010.11.21 05:23:48 | 000,088,960 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Synth3dVsc.sys – (Synth3dVsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,034,816 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010.11.15 18:05:02 | 000,364,520 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmtxhci.sys – (asmtxhci)
DRV:64bit: - [2010.11.15 18:05:00 | 000,121,832 | —- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\asmthub3.sys – (asmthub3)
DRV:64bit: - [2010.10.26 10:08:08 | 000,406,632 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010.10.19 23:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2007.08.08 12:47:16 | 000,193,312 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0330Vid.sys – (V0330VID)
DRV - [2012.07.24 18:59:11 | 000,036,480 | —- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\npf.sys – (npf)
DRV - [2012.07.13 16:13:14 | 000,070,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys – (VSPerfDrv110)
DRV - [2011.10.26 14:23:40 | 000,101,112 | —- | M] (GFI Software) [Kernel | System | Running] – C:\Windows\SysWOW64\drivers\SBREDrv.sys – (SBRE)
DRV - [2011.07.16 15:29:28 | 000,021,712 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS – (DrvAgent64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9HP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security…;pvid=20.2.0.19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ru.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ru
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 D9 14 86 FF 22 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "korrespondent.net"
FF - prefs.js..extensions.enabledAddons: [removed]:7.3.29
FF - prefs.js..keyword.URL: "http://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=EF15A04EC6049C0776EC1A509245A9D4&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\George\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 08:04:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.01 11:49:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 08:04:08 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\George\AppData\Roaming\IDM\idmmzcc5 [2011.09.10 14:02:43 | 000,000,000 | —D | M]
[2011.06.05 01:11:18 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Extensions
[2012.11.01 11:49:27 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions
[2012.11.01 11:49:28 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2012.03.01 11:04:51 | 000,000,000 | —D | M] (Search Assistant) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{B3834E60-12A8-11E0-A289-939FDFD72085}
[2012.11.01 11:39:29 | 000,000,000 | —D | M] (Lavasoft Search Plugin) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012.10.15 16:55:27 | 000,000,000 | —D | M] (IDM CC) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2012.11.01 06:43:05 | 000,000,000 | —D | M] (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash
[2012.11.01 06:43:05 | 002,042,908 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\[removed]
[2011.09.14 21:09:36 | 000,087,923 | R— | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
[2012.10.26 06:39:57 | 002,042,937 | —- | M] () (No name found) – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\extensions\trash\[removed]
[2011.06.08 05:55:13 | 000,012,703 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\imdb.xml
[2011.08.04 01:15:27 | 000,009,695 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\lurkmore-ru.xml
[2011.06.08 18:24:35 | 000,001,701 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\rutrackerorg.xml
[2011.06.05 23:50:34 | 000,002,057 | —- | M] () – C:\Users\George\AppData\Roaming\Mozilla\Firefox\Profiles\cb334d9p.default\searchplugins\youtube-video-search.xml
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.10.27 08:04:00 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.27 08:04:26 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.27 15:45:50 | 000,083,456 | —- | M] (LiveVDO ) – C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
[2012.11.01 11:49:30 | 000,000,616 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012.08.30 09:27:08 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.12 19:34:03 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.google.com/
CHR - default_search_provider: blekko (Enabled)
CHR - default_search_provider: search_url = http://safesearchr.lavasoft.com/?source=33…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\George\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Google Update (Enabled) = C:\Users\George\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Search Assistant = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfelndikbdcohbdimnhdhhokfljdidgn\2.0.0\
CHR - Extension: vshare plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\
CHR - Extension: LiveVDO plugin = C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\
O1 HOSTS File: ([2012.10.31 17:42:11 | 000,001,398 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 217.23.13.202 www.google-analytics.com.
O1 - Hosts: 217.23.13.202 ad-emea.doubleclick.net.
O1 - Hosts: 217.23.13.202 www.statcounter.com.
O1 - Hosts: 198.15.104.132 www.google-analytics.com.
O1 - Hosts: 198.15.104.132 ad-emea.doubleclick.net.
O1 - Hosts: 198.15.104.132 www.statcounter.com.
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll File not found
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Lingvo Launcher] C:\Program Files (x86)\ABBYY Lingvo x3\LvAgent.exe (ABBYY (BIT Software))
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\George\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sticky Notes Taskbar Hider.lnk = C:\Program Files (x86)\StickyNotes\SNTBHider.exe (Drakenscripts.co.cc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.2.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD181FDC-6BF9-4094-9BF8-195BA15CE97D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\vs_ultimate.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec64.dll (TechSmith Corporation)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec32.dll (TechSmith Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012.11.02 13:47:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:26 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Malwarebytes
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.11.02 13:16:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012.11.02 13:16:14 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012.11.02 13:16:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.11.01 18:33:27 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\SUPERAntiSpyware.com
[2012.11.01 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2012.11.01 18:33:05 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012.11.01 18:08:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2012.11.01 14:42:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2012.11.01 14:23:11 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2012.11.01 13:55:58 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adawarebp
[2012.11.01 12:18:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2012.11.01 12:18:00 | 000,060,536 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\sbhips.sys
[2012.11.01 12:17:59 | 000,045,936 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2012.11.01 12:17:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2012.11.01 12:17:30 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\Downloaded Installations
[2012.11.01 11:44:48 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\LavasoftStatistics
[2012.11.01 11:39:35 | 000,000,000 | —D | C] – C:\ProgramData\blekko toolbars
[2012.11.01 11:39:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\adawaretb
[2012.11.01 11:27:12 | 000,000,000 | —D | C] – C:\Users\George\AppData\Roaming\Ad-Aware Antivirus
[2012.11.01 11:03:23 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 10:51:52 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\adaware
[2012.11.01 10:51:47 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012.11.01 10:51:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2012.11.01 10:51:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012.11.01 10:51:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012.11.01 09:39:08 | 000,000,000 | —D | C] – C:\Users\George\AppData\Local\NPE
[2012.10.31 21:33:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2012.10.31 21:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012.10.31 21:26:05 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2012.10.31 20:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.10.31 20:03:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012.10.29 16:25:01 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012.10.29 12:33:30 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_29
[2012.10.27 20:53:14 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_27
[2012.10.27 08:04:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012.10.25 17:17:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_25
[2012.10.24 12:02:08 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_24
[2012.10.12 00:09:17 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_12
[2012.10.11 16:58:24 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_11
[2012.10.10 23:36:21 | 000,000,000 | —D | C] – C:\Users\George\Desktop\2012_10_10
[2012.10.10 05:00:21 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012.10.10 05:00:21 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012.10.10 05:00:20 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012.10.10 05:00:16 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012.10.10 05:00:16 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012.10.10 05:00:15 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012.10.10 05:00:15 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012.10.10 05:00:15 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012.10.10 05:00:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012.10.10 05:00:15 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012.10.10 05:00:14 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012.10.10 05:00:14 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012.10.10 05:00:14 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012.10.10 05:00:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012.10.10 05:00:14 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:14 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012.10.10 05:00:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012.10.10 05:00:09 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012.10.10 05:00:01 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012.10.10 05:00:01 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012.10.10 00:31:29 | 000,000,000 | —D | C] – C:\Users\George\Desktop\bin
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.11.02 13:49:30 | 000,625,664 | —- | M] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
[2012.11.02 13:16:15 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:14:24 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 13:14:24 | 000,026,576 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.02 13:13:07 | 001,839,080 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.02 13:13:07 | 000,792,274 | —- | M] () – C:\Windows\SysNative\perfh019.dat
[2012.11.02 13:13:07 | 000,721,924 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012.11.02 13:13:07 | 000,175,684 | —- | M] () – C:\Windows\SysNative\perfc019.dat
[2012.11.02 13:13:07 | 000,147,066 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012.11.02 13:09:21 | 000,233,423 | —- | M] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.02 13:07:09 | 000,001,868 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.11.02 13:06:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012.11.02 13:06:52 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 13:06:00 | 000,000,982 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000UA.job
[2012.11.02 11:57:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-S-1-5-21-1109903177-269762195-694080819-1000.job
[2012.11.02 11:21:00 | 000,000,390 | —- | M] () – C:\Windows\tasks\update-sys.job
[2012.11.02 10:33:00 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.02 06:06:01 | 000,000,930 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1109903177-269762195-694080819-1000Core.job
[2012.11.02 02:00:03 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 16:08:06 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012.11.01 15:01:39 | 000,007,618 | —- | M] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2012.10.31 21:28:42 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012.10.31 17:42:11 | 000,001,398 | RHS- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012.10.25 18:14:20 | 017,541,748 | —- | M] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | M] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | M] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:43 | 019,045,148 | —- | M] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | M] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:31 | 000,030,463 | —- | M] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.10 01:07:37 | 000,000,132 | —- | M] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.10.09 21:46:06 | 000,001,456 | —- | M] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.10.09 21:46:05 | 001,320,376 | —- | M] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.09 02:24:23 | 026,055,247 | —- | M] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.08 19:31:35 | 013,416,742 | —- | M] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.05 00:20:02 | 000,086,729 | —- | M] () – C:\Users\George\Desktop\Picture1.png
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.02 13:49:28 | 000,625,664 | —- | C] () – C:\Users\George\Desktop\dds.scr
[2012.11.02 13:16:15 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.02 13:09:19 | 000,233,423 | —- | C] () – C:\Users\George\Desktop\bookmarks-2012-11-02.json
[2012.11.01 18:33:35 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8a2a6511-ce7f-4545-b4a7-11f842f8cbdb.job
[2012.11.01 18:33:34 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 57a291b1-ebd9-4043-9cbe-de77272c297c.job
[2012.11.01 18:33:07 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.11.01 12:18:12 | 000,001,868 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012.10.25 18:14:19 | 017,541,748 | —- | C] () – C:\Users\George\Desktop\Assignment 1,2,3 George 101011.zip
[2012.10.25 13:12:28 | 000,485,225 | —- | C] () – C:\Users\George\Desktop\IMG_2639.jpg
[2012.10.25 13:05:01 | 000,449,736 | —- | C] () – C:\Users\George\Desktop\IMG_2643.jpg
[2012.10.24 12:08:42 | 019,045,148 | —- | C] () – C:\Users\George\Desktop\Assignment 4 George 101011.zip
[2012.10.24 07:18:16 | 000,162,792 | —- | C] () – C:\Users\George\Desktop\IMG_2858.jpg
[2012.10.23 08:28:29 | 000,030,463 | —- | C] () – C:\Users\George\Desktop\getImage.jpg
[2012.10.09 21:46:05 | 001,320,376 | —- | C] () – C:\Users\George\Desktop\Poster-Small.jpg
[2012.10.08 19:26:39 | 013,416,742 | —- | C] () – C:\Users\George\Desktop\tia2011-print.pdf
[2012.10.06 01:36:53 | 026,055,247 | —- | C] () – C:\Users\George\Desktop\Poster.jpg
[2012.10.05 00:20:01 | 000,086,729 | —- | C] () – C:\Users\George\Desktop\Picture1.png
[2012.09.10 21:57:09 | 000,000,021 | —- | C] () – C:\Windows\SurCode.INI
[2012.08.20 11:20:54 | 000,000,010 | —- | C] () – C:\Users\George\Infovis_FILE_HISTORY.cfg
[2012.05.26 06:23:29 | 000,003,584 | —- | C] () – C:\Windows\SysWow64\DrvFltIp.sys
[2012.05.25 11:21:22 | 000,003,584 | —- | C] () – C:\Users\George\AppData\Roaming\DrvFltIp.sys
[2012.05.12 15:51:03 | 000,000,034 | -H– | C] () – C:\Windows\SysWow64\Converter_sysquict.dat
[2012.04.20 03:10:29 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2012.03.10 21:07:36 | 000,000,145 | —- | C] () – C:\Users\George\.appletviewer
[2012.02.21 18:23:30 | 000,000,043 | —- | C] () – C:\Windows\gswin64.ini
[2012.02.01 02:28:27 | 000,000,983 | —- | C] () – C:\Windows\eReg.dat
[2012.01.30 03:49:45 | 000,001,476 | —- | C] () – C:\Users\George\AppData\Local\UserProducts.xml
[2012.01.07 02:04:30 | 000,145,876 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info9.ini
[2011.12.09 00:00:54 | 000,000,019 | —- | C] () – C:\Windows\info7.ini
[2011.12.09 00:00:52 | 001,747,456 | —- | C] () – C:\Windows\SysWow64\re_imageconv.dll
[2011.11.24 21:00:49 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2011.07.14 14:06:11 | 000,000,020 | —- | C] () – C:\Windows\NMCAutorunXP.ini
[2011.07.08 17:28:10 | 000,001,459 | —- | C] () – C:\Users\George\gsview64.ini
[2011.06.24 21:27:30 | 000,001,456 | —- | C] () – C:\Users\George\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011.06.11 00:43:23 | 000,000,132 | —- | C] () – C:\Users\George\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.06.06 03:55:19 | 000,007,618 | —- | C] () – C:\Users\George\AppData\Local\Resmon.ResmonCfg
[2011.06.05 01:17:10 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011.06.05 01:11:10 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011.06.05 00:26:11 | 001,819,732 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011.06.04 23:31:01 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011.06.04 23:30:56 | 000,021,262 | —- | C] () – C:\Windows\Ascd_tmp.ini
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012.06.09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012.06.09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009.07.14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010.11.21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009.07.14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2011.01.21 19:26:28 | 000,005,858 | —- | M] () MD5=18E3D562E7E80B329AE5309E368FD567 – C:\Windows\PolicyDefinitions\ru-RU\Explorer.adml
[2011.01.21 19:26:28 | 000,005,858 | —- | M] () MD5=18E3D562E7E80B329AE5309E368FD567 – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_c81688edd50b74ab\Explorer.adml
[2010.11.21 09:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2010.11.21 09:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009.06.10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009.06.10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.BMP >
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2009.08.31 02:59:28 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2011.12.12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp
< MD5 for: EXPLORER.DESIGNER.VB >
[2011.12.12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb
[2011.12.12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2010.11.21 09:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010.11.21 09:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2011.01.21 19:25:49 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=55560C826AAF32C42126EE1F5189611F – C:\Windows\ru-RU\explorer.exe.mui
[2011.01.21 19:25:49 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=55560C826AAF32C42126EE1F5189611F – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_ab089078de57cd42\explorer.exe.mui
[2010.11.21 09:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010.11.21 09:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
[2011.01.21 19:25:22 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=C8A97DC216E7986AF093FB639118D404 – C:\Windows\SysWOW64\ru-RU\explorer.exe.mui
[2011.01.21 19:25:22 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=C8A97DC216E7986AF093FB639118D404 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_b55d3acb12b88f3d\explorer.exe.mui
< MD5 for: EXPLORER.EXE.WINDOWS EXPLORER.MICROSOFT CORPORATION.6.1.7601.17567.ICO >
[2012.06.24 07:27:09 | 000,187,373 | —- | M] () MD5=59EF532FA50E1EC27DC50D43DA386BFB – C:\Users\George\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\explorer.exe.Windows Explorer.Microsoft Corporation.6.1.7601.17567.ico
< MD5 for: EXPLORER.EXE-254441E9.PF >
[2012.11.02 13:48:02 | 000,039,902 | —- | M] () MD5=4F24A4D68707A7475BE0FA5DD26AAD70 – C:\Windows\Prefetch\EXPLORER.EXE-254441E9.pf
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012.11.02 13:48:12 | 000,182,486 | —- | M] () MD5=560AD06BC07C0FEF482BAB6495FC31FC – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.GIF >
[2009.08.31 02:59:28 | 000,003,342 | —- | M] () MD5=2C9E121C2DECEF61FED6EA977A30D90F – C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif
[2012.06.24 21:45:02 | 000,001,483 | —- | M] () MD5=4ABBABE57F99C84C4154DD289B766E5E – C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif
< MD5 for: EXPLORER.PROPERTIES >
[2011.12.02 23:31:21 | 000,000,039 | —- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 – C:\Users\George\.netbeans\7.0\config\Preferences\org\openide\explorer.properties
[2012.08.20 05:21:20 | 000,000,039 | —- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 – C:\Users\George\AppData\Roaming\.gephi\0.8.1\dev\config\Preferences\org\openide\explorer.properties
< MD5 for: EXPLORER.RESX >
[2011.12.12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.resx
[2011.12.12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.resx
< MD5 for: EXPLORER.VB >
[2011.12.12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vb
[2011.12.12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vb
< MD5 for: EXPLORER.VSTEMPLATE >
[2011.12.12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate
[2011.12.12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate
< MD5 for: EXPLORER.WSMODE >
[2012.08.20 05:21:54 | 000,000,476 | —- | M] () MD5=9885B0575BBF4AEC298B13D68EA7D346 – C:\Users\George\AppData\Roaming\.gephi\0.8.1\dev\config\Windows2Local-overview\Modes\explorer.wsmode
[2012.06.30 10:57:43 | 000,000,561 | —- | M] () MD5=E69F93B0A6A6DBEA0D1CF45EBB155EAF – C:\Users\George\.netbeans\7.0\config\Windows2Local\Modes\explorer.wsmode
< MD5 for: EXPLORER.ZIP >
[2009.06.03 20:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2012.06.02 13:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2012.05.18 01:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012.06.29 07:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012.08.24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012.08.24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012.05.18 00:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012.08.24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012.08.24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012.06.02 11:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012.05.18 04:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012.08.24 12:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012.06.29 04:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012.06.02 14:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012.08.24 09:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010.11.21 05:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012.09.29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011.06.04 23:53:53 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012.06.29 03:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012.06.02 10:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010.11.21 05:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012.06.29 01:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011.06.04 23:53:53 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012.05.18 03:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011.06.04 23:53:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2011.01.21 19:26:32 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=5E222432D3E4D833D6C967FE4FE81C79 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_ru-ru_5464562bc4198720\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=984477F8913BF8CD2F5C12ADC7C0E183 – C:\Program Files\Internet Explorer\ru-RU\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=984477F8913BF8CD2F5C12ADC7C0E183 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_ru-ru_502247c7091bc70d\iexplore.exe.mui
[2011.01.21 19:26:32 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=9A35E917E4B5C27A51B756BAF7D7F815 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_ru-ru_5eb9007df87a491b\iexplore.exe.mui
[2009.07.14 04:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EAEB8DCDDD67C6AF07598D5C2759B24B – C:\Program Files (x86)\Internet Explorer\ru-RU\iexplore.exe.mui
[2011.06.07 19:19:03 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EAEB8DCDDD67C6AF07598D5C2759B24B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_ru-ru_5a76f2193d7c8908\iexplore.exe.mui
[2009.07.14 04:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-4B6C9213.PF >
[2012.11.01 21:49:49 | 000,206,646 | —- | M] () MD5=2D7CA11B34DCC48D56AAA42B17EC184B – C:\Windows\Prefetch\IEXPLORE.EXE-4B6C9213.pf
< MD5 for: SERVICES >
[2009.06.10 23:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2012.01.03 15:10:44 | 000,585,874 | —- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009.07.14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009.07.14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2010.11.21 09:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010.11.21 09:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
[2011.01.21 19:25:41 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=EB63EE0FD3C4826F45845C6E83058570 – C:\Windows\SysNative\ru-RU\services.exe.mui
[2011.01.21 19:25:41 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=EB63EE0FD3C4826F45845C6E83058570 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_0f13507290ab300f\services.exe.mui
< MD5 for: SERVICES.H >
[2011.09.26 11:17:40 | 000,001,043 | —- | M] () MD5=EFA6260E75D8055649F88462E3E9E929 – C:\wamp\bin\mysql\mysql5.5.16\include\mysql\services.h
< MD5 for: SERVICES.LNK >
[2009.07.14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009.07.14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009.06.10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009.06.10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2011.01.21 19:25:34 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\SysNative\ru-RU\services.msc
[2011.01.21 19:25:43 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\SysWOW64\ru-RU\services.msc
[2011.01.21 19:25:34 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_4955205e6714ca02\services.msc
[2011.01.21 19:25:43 | 000,092,790 | —- | M] () MD5=20037594600FF469A209FA3465ECBA8A – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_ed3684daaeb758cc\services.msc
[2010.11.21 09:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009.06.10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010.11.21 09:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009.06.10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010.11.21 09:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009.06.10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010.11.21 09:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009.06.10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009.07.13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009.07.13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SETTINGS >
[2012.06.30 10:57:42 | 000,001,622 | —- | M] () MD5=36F72485C04D6C73C4926FD9112339C1 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Components\services.settings
< MD5 for: SERVICES.WSTCGRP >
[2012.06.30 10:57:43 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Groups\InitialLayout\services.wstcgrp
[2012.06.30 10:57:43 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:\Users\George\.netbeans\7.0\config\Windows2Local\Groups\OpenedProjects\services.wstcgrp
< MD5 for: SERVICES.WSTCREF >
[2012.06.30 10:57:43 | 000,000,223 | —- | M] () MD5=7FDE98E6B2D9881C67AF64D47984210E – C:\Users\George\.netbeans\7.0\config\Windows2Local\Modes\leftSlidingSide\services.wstcref
< MD5 for: WINLOGON.ADML >
[2011.01.21 19:26:27 | 000,013,486 | —- | M] () MD5=0C0FE7ABF455EC3BCBE3EE70EE01E948 – C:\Windows\PolicyDefinitions\ru-RU\WinLogon.adml
[2011.01.21 19:26:27 | 000,013,486 | —- | M] () MD5=0C0FE7ABF455EC3BCBE3EE70EE01E948 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_3a1a1ae34797fc17\WinLogon.adml
[2010.11.21 09:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2010.11.21 09:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009.06.10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009.06.10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.09.29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010.11.21 09:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010.11.21 09:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2011.01.21 19:25:35 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=61620C41698F9B2C6E5A594497B8A735 – C:\Windows\SysNative\ru-RU\winlogon.exe.mui
[2011.01.21 19:25:35 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=61620C41698F9B2C6E5A594497B8A735 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_723faeae6bbaf822\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2010.11.21 09:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010.11.21 09:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
[2011.01.21 19:25:40 | 000,001,080 | —- | M] () MD5=AC3DB6214BE53F6D948067FDFAEA8467 – C:\Windows\SysNative\wbem\ru-RU\winlogon.mfl
[2011.01.21 19:25:40 | 000,001,080 | —- | M] () MD5=AC3DB6214BE53F6D948067FDFAEA8467 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_cdd0ecb18a04ce1d\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009.07.13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009.07.13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2012.11.02 13:06:52 | 2132,746,239 | -HS- | M] () – C:\hiberfil.sys
[2012.11.02 13:06:52 | 4275,318,783 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009.07.14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009.07.14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009.07.14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009.07.14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009.06.10 22:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009.07.14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011.06.04 23:56:31 | 000,000,221 | -HS- | M] () – C:\Users\George\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012.11.02 13:47:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\George\Desktop\HiJackThis.exe
[2012.11.02 13:45:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\George\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2012.05.29 09:35:38 | 000,001,422 | —- | M] () – C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 1360 bytes -> C:\ProgramData\Microsoft:4xkr54OEiolnkbB3gh0FD6W
@Alternate Data Stream - 1322 bytes -> C:\Users\George\AppData\Local\zwzMyxIsPOk:6wR7NFoi4b5qJsMYjkIeAi8sX7ur
@Alternate Data Stream - 1313 bytes -> C:\ProgramData\Microsoft:VzjVIwISJ0TLQ3v9LvRDbL1cqrbG
@Alternate Data Stream - 1295 bytes -> C:\ProgramData\Microsoft:z2kO985qGpXTXnglXv0KG7z
< End of report >