Hi folks, my webhost says I may have a keylogger.
I'm getting a crazy amount of undelivered mail bouncebacks from emails I never sent. I've changed my email passwords twice and notified my host company. I don't see any malicious software on my email host account server. My host company says I may have a key logger virus / trojan.
Malwarebytes found one issue and removed it, posted below. Search & Destroy found only two browser ad tracking cookies.
I then ran OTL. I've posted the two text files below.
I forgot to mention that I ran Malwarebytes Anti-Rootkit. No issues found.
And since posting, I've run TrendMicro Housecall and Rootkit Buster. No issues found.
I've also installed RUBotted.
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
C:\Users\Test IE9\Downloads\SoftonicDownloader_for_ietester.exe (PUP.Optional.Softonic.A) -> Quarantined and deleted successfully.
OTL logfile created on: 2/24/2014 2:36:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marc\Desktop\virus
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.79 Gb Available Physical Memory | 62.40% Memory free
5.73 Gb Paging File | 4.43 Gb Available in Paging File | 77.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.43 Gb Total Space | 73.70 Gb Free Space | 33.13% Space Free | Partition Type: NTFS
Computer Name: KIDSCOMPUTER | User Name: Marc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Marc\Desktop\virus\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) -- C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (TMachInfo) -- C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) -- C:\Program Files (x86)\Toshiba\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION)
SRV - (ConfigFree Gadget Service) -- C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ConfigFree Service) -- C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
========== Driver Services (SafeList) ==========
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Lbd) -- C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8187B) -- C:\Windows\SysNative\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (LPCFilter) -- C:\Windows\SysNative\drivers\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV:64bit: - (tdcmdpst) -- C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (tos_sps64) -- C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (MSHUSBVideo) -- C:\Windows\SysNative\drivers\nx6000.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (TVALZ) -- C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) -- C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (adfs) -- C:\windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (WDC_SAM) -- C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (PAC207) -- C:\Windows\SysNative\drivers\PFC027.SYS (PixArt Imaging Inc.)
DRV - (Lavasoft Kernexplorer) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (adfs) -- C:\windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {000B8AEA-AB2A-4863-92EB-3FEEEAA2D56A}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9A30A3F8-4AD7-4964-8087-ADA2EC0FF187}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\..\SearchScopes,DefaultScope = {9A30A3F8-4AD7-4964-8087-ADA2EC0FF187}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledAddons: fiddlerhook%40fiddler2.com:2.2.9.8
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.1
FF - prefs.js..extensions.enabledItems: flashbug@coursevector.com:1.7.0
FF - prefs.js..extensions.enabledItems: fiddlerhook@fiddler2.com:2.2.9.8
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fiddlerhook@fiddler2.com: C:\Program Files (x86)\Fiddler2\FiddlerHook [2014/01/15 22:15:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014/01/29 08:05:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/02/22 14:22:08 | 000,000,000 | ---D | M]
[2011/01/06 13:49:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marc\AppData\Roaming\mozilla\Extensions
[2011/01/07 09:34:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marc\AppData\Roaming\mozilla\Firefox\Profiles\floebvbu.default\extensions
[2011/01/06 13:51:21 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Marc\AppData\Roaming\mozilla\Firefox\Profiles\floebvbu.default\extensions\firebug@software.joehewitt.com
[2011/01/06 13:51:20 | 000,000,000 | ---D | M] (Flashbug) -- C:\Users\Marc\AppData\Roaming\mozilla\Firefox\Profiles\floebvbu.default\extensions\flashbug@coursevector.com
[2011/01/06 13:51:20 | 000,000,000 | ---D | M] ("FlashFirebug") -- C:\Users\Marc\AppData\Roaming\mozilla\Firefox\Profiles\floebvbu.default\extensions\flashfirebug@o-minds.com
[2014/01/05 14:06:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/02/23 20:34:08 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/01/15 22:15:28 | 000,000,000 | ---D | M] (FiddlerHook) -- C:\PROGRAM FILES (X86)\FIDDLER2\FIDDLERHOOK
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
CHR - Extension: Google Wallet = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2014/01/13 15:52:16 | 000,434,935 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 74.217.239.152 staging-laprairieswitzerland.com
O1 - Hosts: 74.217.239.151 staging-laprairieswitzerland.ch
O1 - Hosts: 74.217.239.151 staging-laprairie.de
O1 - Hosts: 74.217.239.151 staging-laprairie.es
O1 - Hosts: 74.217.239.151 staging-la-prairie.fr
O1 - Hosts: 74.217.239.151 staging-la-prairie.it
O1 - Hosts: 74.217.239.151 staging-laprairie.at
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 14962 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O9:64bit: - Extra Button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik)
O9:64bit: - Extra 'Tools' menuitem : Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik)
O9 - Extra Button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik)
O9 - Extra 'Tools' menuitem : Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4AAC1865-70C9-4D56-A74C-C1609AA0102E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C6E97FB-BE6A-439D-8FF9-BF34FAFFBEF1}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{bc5a4196-ef4f-11de-bd94-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bc5a4196-ef4f-11de-bd94-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE
O33 - MountPoints2\{bc5a4196-ef4f-11de-bd94-806e6f6e6963}\Shell\configure\command - "" = D:\SETUP.EXE
O33 - MountPoints2\{bc5a4196-ef4f-11de-bd94-806e6f6e6963}\Shell\install\command - "" = D:\SETUP.EXE
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2014/02/24 13:35:24 | 000,000,000 | ---D | C] -- C:\Users\Marc\Desktop\virus
[2014/02/23 20:34:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014/02/23 20:34:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2014/02/21 16:59:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/02/21 16:59:05 | 000,119,000 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/02/21 16:58:23 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbamchameleon.sys
[2014/02/21 16:58:13 | 000,000,000 | ---D | C] -- C:\Users\Marc\Desktop\mbar
[2014/02/21 14:06:22 | 000,204,496 | ---- | C] (Malwarebytes) -- C:\Users\Marc\Desktop\startuplite-setup-1.07.exe
[2014/02/21 14:04:07 | 012,589,848 | ---- | C] (Malwarebytes Corp.) -- C:\Users\Marc\Desktop\mbar-1.07.0.1009.exe
[2014/01/31 13:12:17 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\RegisterIEPKEYs.exe
[2014/01/31 13:12:16 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2014/01/31 13:12:16 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msrating.dll
[2014/01/31 13:12:16 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieakeng.dll
[2014/01/31 13:12:16 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iepeers.dll
[2014/01/31 13:12:16 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\IEAdvpack.dll
[2014/01/31 13:12:16 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msfeedssync.exe
[2014/01/31 13:12:15 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dat
[2014/01/31 13:12:15 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dll
[2014/01/31 13:12:15 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\html.iec
[2014/01/31 13:12:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2014/01/31 13:12:15 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iesysprep.dll
[2014/01/31 13:12:15 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\SetIEInstalledDate.exe
[2014/01/31 13:12:15 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ie4uinit.exe
[2014/01/31 13:12:15 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\tdc.ocx
[2014/01/31 13:12:15 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmler.dll
[2014/01/31 13:12:15 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iernonce.dll
[2014/01/31 13:12:14 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl
[2014/01/31 13:12:14 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll
[2014/01/31 13:12:14 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iesetup.dll
[2014/01/31 13:12:14 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\icardie.dll
[2014/01/31 13:12:14 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\licmgr10.dll
[2014/01/31 13:12:13 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wextract.exe
[2014/01/31 13:12:13 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iexpress.exe
[2014/01/31 13:12:13 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieUnatt.exe
[2014/01/31 13:12:13 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inseng.dll
[2014/01/31 13:12:13 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2014/01/31 13:12:13 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\pngfilt.dll
[2014/01/31 13:12:12 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieaksie.dll
[2014/01/31 13:12:12 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieakui.dll
[2014/01/31 13:12:12 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\occache.dll
[2014/01/31 13:12:12 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\admparse.dll
[2014/01/31 13:12:11 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\RegisterIEPKEYs.exe
[2014/01/31 13:12:10 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msls31.dll
[2014/01/31 13:12:10 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msrating.dll
[2014/01/31 13:12:09 | 002,334,720 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2014/01/31 13:12:09 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2014/01/31 13:12:09 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieaksie.dll
[2014/01/31 13:12:09 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieUnatt.exe
[2014/01/31 13:12:09 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieakui.dll
[2014/01/31 13:12:09 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\occache.dll
[2014/01/31 13:12:09 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iepeers.dll
[2014/01/31 13:12:09 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\admparse.dll
[2014/01/31 13:12:09 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\pngfilt.dll
[2014/01/31 13:12:09 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\imgutil.dll
[2014/01/31 13:12:09 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshta.exe
[2014/01/31 13:12:08 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieakeng.dll
[2014/01/31 13:12:08 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\IEAdvpack.dll
[2014/01/31 13:12:08 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iesysprep.dll
[2014/01/31 13:12:08 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\SetIEInstalledDate.exe
[2014/01/31 13:12:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmler.dll
[2014/01/31 13:12:08 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeedssync.exe
[2014/01/31 13:12:07 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2014/01/31 13:12:07 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\tdc.ocx
[2014/01/31 13:12:06 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieapfltr.dat
[2014/01/31 13:12:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieapfltr.dll
[2014/01/31 13:12:06 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dxtmsft.dll
[2014/01/31 13:12:06 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\html.iec
[2014/01/31 13:12:06 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dxtrans.dll
[2014/01/31 13:12:06 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ie4uinit.exe
[2014/01/31 13:12:06 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\icardie.dll
[2014/01/31 13:12:06 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iernonce.dll
[2014/01/31 13:12:05 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl
[2014/01/31 13:12:05 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2014/01/31 13:12:05 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\vbscript.dll
[2014/01/31 13:12:05 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll
[2014/01/31 13:12:05 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iexpress.exe
[2014/01/31 13:12:05 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wextract.exe
[2014/01/31 13:12:05 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inseng.dll
[2014/01/31 13:12:05 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2014/01/31 13:12:05 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iesetup.dll
[2014/01/31 13:12:05 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\licmgr10.dll
[2014/01/31 13:10:33 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WMVDECOD.DLL
[2014/01/31 13:10:33 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WMVDECOD.DLL
[2014/01/31 13:10:32 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ExplorerFrame.dll
[2014/01/31 13:10:32 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\d3d10warp.dll
[2014/01/31 13:10:32 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ExplorerFrame.dll
[2014/01/31 13:10:32 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\XpsPrint.dll
[2014/01/31 13:10:32 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\XpsGdiConverter.dll
[2014/01/31 13:10:32 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\d3d10_1core.dll
[2014/01/31 13:10:32 | 000,265,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\dxgmms1.sys
[2014/01/31 13:10:32 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\d3d10_1.dll
[2014/01/31 13:10:32 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cdd.dll
[2014/01/31 13:10:31 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\DWrite.dll
[2014/01/31 13:10:31 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\d2d1.dll
[2014/01/31 13:10:31 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XpsPrint.dll
[2014/01/31 13:10:31 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XpsGdiConverter.dll
[2014/01/31 13:10:31 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\XpsRasterService.dll
[2014/01/31 13:10:31 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XpsRasterService.dll
[2014/01/31 13:10:30 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mf.dll
[2014/01/31 13:10:30 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mf.dll
[2014/01/31 13:10:30 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mfreadwrite.dll
[2014/01/31 13:10:30 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mfps.dll
[2014/01/31 13:10:30 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfreadwrite.dll
[2014/01/27 05:41:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014/01/27 05:41:22 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\windows\SysNative\drivers\GEARAspiWDM.sys
[2014/01/27 05:40:21 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/01/27 05:40:20 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014/01/27 05:40:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2014/01/27 05:40:20 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2014/01/27 05:33:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2014/01/27 05:33:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2009/02/13 10:02:52 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\Program Files\devcon_amd64.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/02/24 14:07:05 | 000,016,304 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/02/24 14:07:05 | 000,016,304 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/02/24 14:04:35 | 000,000,898 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/02/24 14:00:22 | 000,000,894 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/02/24 13:58:21 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2014/02/24 13:58:16 | 2309,660,672 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/24 13:52:01 | 000,000,598 | ---- | M] () -- C:\windows\tasks\G2MUpdateTask-S-1-5-21-3357349812-2239403225-1323811888-1004.job
[2014/02/24 09:44:29 | 000,781,586 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2014/02/24 09:44:29 | 000,661,918 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2014/02/24 09:44:29 | 000,121,714 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2014/02/23 07:37:48 | 005,063,088 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2014/02/21 16:59:05 | 000,119,000 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/02/21 16:58:23 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbamchameleon.sys
[2014/02/21 14:06:22 | 000,204,496 | ---- | M] (Malwarebytes) -- C:\Users\Marc\Desktop\startuplite-setup-1.07.exe
[2014/02/21 14:04:08 | 012,589,848 | ---- | M] (Malwarebytes Corp.) -- C:\Users\Marc\Desktop\mbar-1.07.0.1009.exe
[2014/02/10 20:22:54 | 000,001,449 | ---- | M] () -- C:\Users\Marc\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/02/04 21:30:53 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe
[2014/02/04 21:30:53 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/01/31 13:12:17 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\msrating.dll
[2014/01/31 13:12:17 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\RegisterIEPKEYs.exe
[2014/01/31 13:12:16 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2014/01/31 13:12:16 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieakeng.dll
[2014/01/31 13:12:16 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\iepeers.dll
[2014/01/31 13:12:16 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\IEAdvpack.dll
[2014/01/31 13:12:16 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\SetIEInstalledDate.exe
[2014/01/31 13:12:16 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\msfeedssync.exe
[2014/01/31 13:12:15 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dat
[2014/01/31 13:12:15 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dll
[2014/01/31 13:12:15 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\html.iec
[2014/01/31 13:12:15 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2014/01/31 13:12:15 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\iesysprep.dll
[2014/01/31 13:12:15 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ie4uinit.exe
[2014/01/31 13:12:15 | 000,072,822 | ---- | M] () -- C:\windows\SysWow64\ieuinit.inf
[2014/01/31 13:12:15 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\tdc.ocx
[2014/01/31 13:12:15 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmler.dll
[2014/01/31 13:12:15 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\iernonce.dll
[2014/01/31 13:12:14 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl
[2014/01/31 13:12:14 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll
[2014/01/31 13:12:14 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\inseng.dll
[2014/01/31 13:12:14 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\iesetup.dll
[2014/01/31 13:12:14 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\icardie.dll
[2014/01/31 13:12:14 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\licmgr10.dll
[2014/01/31 13:12:13 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\wextract.exe
[2014/01/31 13:12:13 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\iexpress.exe
[2014/01/31 13:12:13 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieUnatt.exe
[2014/01/31 13:12:13 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\occache.dll
[2014/01/31 13:12:13 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2014/01/31 13:12:13 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\pngfilt.dll
[2014/01/31 13:12:12 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieaksie.dll
[2014/01/31 13:12:12 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieakui.dll
[2014/01/31 13:12:12 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\admparse.dll
[2014/01/31 13:12:11 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\RegisterIEPKEYs.exe
[2014/01/31 13:12:10 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\msls31.dll
[2014/01/31 13:12:10 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\msrating.dll
[2014/01/31 13:12:09 | 002,334,720 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2014/01/31 13:12:09 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2014/01/31 13:12:09 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieaksie.dll
[2014/01/31 13:12:09 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieUnatt.exe
[2014/01/31 13:12:09 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieakui.dll
[2014/01/31 13:12:09 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\occache.dll
[2014/01/31 13:12:09 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\iepeers.dll
[2014/01/31 13:12:09 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\admparse.dll
[2014/01/31 13:12:09 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\pngfilt.dll
[2014/01/31 13:12:09 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\imgutil.dll
[2014/01/31 13:12:09 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mshta.exe
[2014/01/31 13:12:08 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieakeng.dll
[2014/01/31 13:12:08 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\IEAdvpack.dll
[2014/01/31 13:12:08 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\iesysprep.dll
[2014/01/31 13:12:08 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\SetIEInstalledDate.exe
[2014/01/31 13:12:08 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mshtmler.dll
[2014/01/31 13:12:08 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\msfeedssync.exe
[2014/01/31 13:12:07 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2014/01/31 13:12:07 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\tdc.ocx
[2014/01/31 13:12:06 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieapfltr.dat
[2014/01/31 13:12:06 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieapfltr.dll
[2014/01/31 13:12:06 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\dxtmsft.dll
[2014/01/31 13:12:06 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\html.iec
[2014/01/31 13:12:06 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\dxtrans.dll
[2014/01/31 13:12:06 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ie4uinit.exe
[2014/01/31 13:12:06 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\icardie.dll
[2014/01/31 13:12:06 | 000,072,822 | ---- | M] () -- C:\windows\SysNative\ieuinit.inf
[2014/01/31 13:12:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\iernonce.dll
[2014/01/31 13:12:05 | 001,494,528 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl
[2014/01/31 13:12:05 | 000,729,088 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2014/01/31 13:12:05 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\vbscript.dll
[2014/01/31 13:12:05 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\url.dll
[2014/01/31 13:12:05 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\iexpress.exe
[2014/01/31 13:12:05 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wextract.exe
[2014/01/31 13:12:05 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\inseng.dll
[2014/01/31 13:12:05 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2014/01/31 13:12:05 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\iesetup.dll
[2014/01/31 13:12:05 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\licmgr10.dll
[2014/01/31 13:10:33 | 001,888,256 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\WMVDECOD.DLL
[2014/01/31 13:10:33 | 001,619,456 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\WMVDECOD.DLL
[2014/01/31 13:10:32 | 001,863,680 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ExplorerFrame.dll
[2014/01/31 13:10:32 | 001,837,568 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\d3d10warp.dll
[2014/01/31 13:10:32 | 001,495,040 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ExplorerFrame.dll
[2014/01/31 13:10:32 | 000,662,528 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\XpsPrint.dll
[2014/01/31 13:10:32 | 000,470,016 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\XpsGdiConverter.dll
[2014/01/31 13:10:32 | 000,320,512 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\d3d10_1core.dll
[2014/01/31 13:10:32 | 000,265,088 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\drivers\dxgmms1.sys
[2014/01/31 13:10:32 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\d3d10_1.dll
[2014/01/31 13:10:32 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\cdd.dll
[2014/01/31 13:10:31 | 003,181,568 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\mf.dll
[2014/01/31 13:10:31 | 001,540,608 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\DWrite.dll
[2014/01/31 13:10:31 | 000,902,656 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\d2d1.dll
[2014/01/31 13:10:31 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\XpsPrint.dll
[2014/01/31 13:10:31 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\XpsGdiConverter.dll
[2014/01/31 13:10:31 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\XpsRasterService.dll
[2014/01/31 13:10:31 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\XpsRasterService.dll
[2014/01/31 13:10:30 | 004,068,864 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mf.dll
[2014/01/31 13:10:30 | 000,257,024 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mfreadwrite.dll
[2014/01/31 13:10:30 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mfps.dll
[2014/01/31 13:10:30 | 000,196,608 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\mfreadwrite.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/02/10 20:22:54 | 000,001,421 | ---- | C] () -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2014/02/04 20:19:40 | 000,001,542 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
[2014/02/04 14:41:25 | 000,000,598 | ---- | C] () -- C:\windows\tasks\G2MUpdateTask-S-1-5-21-3357349812-2239403225-1323811888-1004.job
[2014/01/31 13:12:14 | 000,072,822 | ---- | C] () -- C:\windows\SysWow64\ieuinit.inf
[2014/01/31 13:12:05 | 000,072,822 | ---- | C] () -- C:\windows\SysNative\ieuinit.inf
[2013/12/30 23:10:35 | 000,000,192 | ---- | C] () -- C:\windows\QUICKEN.INI
[2013/12/27 10:41:19 | 000,007,616 | ---- | C] () -- C:\Users\Marc\AppData\Local\Resmon.ResmonCfg
[2012/10/27 14:08:58 | 000,000,257 | ---- | C] () -- C:\windows\Brpfx04a.ini
[2012/10/27 14:08:58 | 000,000,094 | ---- | C] () -- C:\windows\brpcfx.ini
[2012/10/27 14:03:07 | 000,106,496 | ---- | C] () -- C:\windows\SysWow64\BrMuSNMP.dll
[2012/10/27 14:03:07 | 000,000,066 | ---- | C] () -- C:\windows\Brfaxrx.ini
[2012/10/27 14:03:06 | 000,000,000 | ---- | C] () -- C:\windows\brdfxspd.dat
[2012/10/27 13:54:21 | 000,000,419 | ---- | C] () -- C:\windows\BRWMARK.INI
[2012/10/27 13:54:21 | 000,000,027 | ---- | C] () -- C:\windows\BRPP2KA.INI
[2012/10/27 13:54:02 | 000,000,000 | ---- | C] () -- C:\Program Files (x86)\error.dat
[2012/10/27 13:54:02 | 000,000,000 | ---- | C] () -- C:\windows\brmx2001.ini
[2012/10/27 13:52:59 | 000,000,080 | ---- | C] () -- C:\windows\Brownie.ini
[2011/04/21 12:53:46 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/01/06 13:51:22 | 000,001,291 | ---- | C] () -- C:\Users\Marc\mm.cfg
[2010/12/09 09:45:33 | 000,000,632 | RHS- | C] () -- C:\Users\Marc\ntuser.pol
[2010/03/29 14:29:42 | 000,000,268 | ---- | C] () -- C:\Users\Marc\AppData\Roaming\wklnhst.dat
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010/07/27 09:59:11 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010/07/27 09:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/13 20:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/02/03 14:29:50 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\.minecraft
[2013/01/19 21:06:38 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\Broderbund
[2011/11/17 00:46:49 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014/01/17 08:23:06 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\Scooter Software
[2011/04/21 04:30:27 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\Subversion
[2010/03/29 14:29:44 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\Template
[2010/03/29 14:34:03 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\Toshiba
[2010/03/25 10:24:32 | 000,000,000 | ---D | M] -- C:\Users\Marc\AppData\Roaming\WinBatch
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | ---- | M] () MD5=7A4C7F3CB156543113596988479CAFCE -- C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | ---- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 -- C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2009/07/13 20:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 -- C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-254441E9.PF >
[2014/02/24 12:45:13 | 000,027,344 | ---- | M] () MD5=E9B0B55EDF509B96492C45807D10CC4C -- C:\Windows\Prefetch\EXPLORER.EXE-254441E9.pf
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2014/02/24 12:45:22 | 000,153,358 | ---- | M] () MD5=E5685335BEA0F36522E452551AF9A4D1 -- C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: IEXPLORE.EXE >
[2014/01/31 13:12:11 | 000,763,632 | ---- | M] (Microsoft Corporation) MD5=140325733F0DFB82A6A600CE301478EE -- C:\Program Files\Internet Explorer\iexplore.exe
[2014/01/31 13:12:11 | 000,763,632 | ---- | M] (Microsoft Corporation) MD5=140325733F0DFB82A6A600CE301478EE -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16526_none_0d599df380650659\iexplore.exe
[2010/09/07 23:36:39 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | ---- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2014/01/31 13:12:17 | 000,757,488 | ---- | M] (Microsoft Corporation) MD5=43E6F2A7FB182F2D7CB0CE5B8F1005CF -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2014/01/31 13:12:17 | 000,757,488 | ---- | M] (Microsoft Corporation) MD5=43E6F2A7FB182F2D7CB0CE5B8F1005CF -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16526_none_17ae4845b4c5c854\iexplore.exe
[2010/09/08 00:37:57 | 000,696,592 | ---- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2010/09/08 00:49:01 | 000,696,592 | ---- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2010/09/07 23:31:24 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2011/02/24 00:45:11 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 -- C:\Windows\SoftwareDistribution\Download\4dcf2c50f89fe861f87e27d41beac164\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2011/02/24 01:29:19 | 000,696,592 | ---- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 -- C:\Windows\SoftwareDistribution\Download\4dcf2c50f89fe861f87e27d41beac164\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2013/04/04 13:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011/02/24 00:32:52 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 -- C:\Windows\SoftwareDistribution\Download\4dcf2c50f89fe861f87e27d41beac164\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2011/02/24 01:32:09 | 000,696,592 | ---- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 -- C:\Windows\SoftwareDistribution\Download\4dcf2c50f89fe861f87e27d41beac164\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | ---- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
< MD5 for: IEXPLORE.EXE.4524.DMP >
[2012/05/23 11:33:03 | 002,744,797 | ---- | M] () MD5=2D1DBA906D31D608223B125A10AA0AE3 -- C:\Users\Mom\AppData\Local\CrashDumps\iexplore.exe.4524.dmp
< MD5 for: IEXPLORE.EXE.768.DMP >
[2011/05/31 22:17:24 | 002,474,565 | ---- | M] () MD5=7662FCC4936EF24372533E21574D5FDF -- C:\Users\Development\AppData\Local\CrashDumps\iexplore.exe.768.dmp
< MD5 for: IEXPLORE.EXE.MUI >
[2014/01/31 13:12:12 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2014/01/31 13:12:12 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2014/01/31 13:12:18 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F -- C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2014/01/31 13:12:18 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
< MD5 for: IEXPLORE.LOG >
[2013/04/03 11:00:57 | 000,000,620 | ---- | M] () MD5=5EC66FD42B829C5DC1C09692AB6DAEFB -- C:\Users\Cole\AppData\Local\Temp\Low\iexplore.log
[2013/05/25 18:42:44 | 000,000,775 | ---- | M] () MD5=7BF7948F413F4EAC503F21B4456E227E -- C:\Users\Kids\AppData\Local\Temp\Low\iexplore.log
< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.AIP >
[2012/03/29 20:35:50 | 000,297,104 | ---- | M] (Adobe Systems Incorporated) MD5=8311BFD3FD21EB8089259C491406A7B0 -- C:\Program Files\Adobe\Adobe Illustrator CS6 (64 Bit)\Plug-ins\Extensions\Services.aip
< MD5 for: SERVICES.AS >
[2011/11/21 14:15:44 | 000,003,458 | ---- | M] () MD5=1C4E2DB4EFACD90A5F9B92DDE9D51233 -- C:\Users\Development\Documents\Business\```Work\Luxurious Animals\Lunchables\trunk\src\lux\communications\Services.as
[2012/09/26 23:48:14 | 000,003,476 | ---- | M] () MD5=564C39A19C61B50FE77E5C62B335687F -- C:\Users\Development\Documents\development svn\terzi interactive\games\Run Zombie\branches\genesis\src\com\runzombie\communications\Services.as
< MD5 for: SERVICES.AS.SVN-BASE >
[2011/11/21 14:15:44 | 000,003,458 | R--- | M] () MD5=1C4E2DB4EFACD90A5F9B92DDE9D51233 -- C:\$Recycle.Bin\S-1-5-21-3357349812-2239403225-1323811888-1004\$R17C064.svn\text-base\Services.as.svn-base
< MD5 for: SERVICES.ASFX >
[2011/09/05 12:05:06 | 000,001,888 | ---- | M] () MD5=14A44E8C50067E903D81B951B0F20EC6 -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\Services\Services.asfx
[2011/09/05 12:05:06 | 000,001,831 | ---- | M] () MD5=FE3CE5C3CCD3DF6B436B0DA535E36744 -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\fr_FR\Services\Services.asfx
< MD5 for: SERVICES.CFG >
[2011/09/05 12:05:06 | 000,584,808 | ---- | M] () MD5=B3B25937514C772FD2490108B91CE17F -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Services\Services.cfg
[2010/10/25 15:13:46 | 000,032,633 | R--- | M] () MD5=EA1C35DD541D60819D55482130BD585D -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA3301004F7706000000000050\10.0.0\services.cfg
< MD5 for: SERVICES.CNF >
[2008/06/30 14:17:00 | 000,000,002 | ---- | M] () MD5=A55822426A5330C04625A41D264C190B -- C:\Users\Development\Documents\Business\```Work\Kichiwawa\Kichiwawa Backup 2008-10-29\Website Kichiwawa Backup 01\_vti_pvt\services.cnf
[2008/06/30 14:17:00 | 000,000,002 | ---- | M] () MD5=A55822426A5330C04625A41D264C190B -- C:\Users\Development\Documents\Business\```Work\Kichiwawa\Kichiwawa Backup 2008-10-29\Website Kichiwawa Backup 02\_vti_pvt\services.cnf
[2008/06/30 14:17:00 | 000,000,002 | ---- | M] () MD5=A55822426A5330C04625A41D264C190B -- C:\Users\Development\Documents\Business\```Work\Kichiwawa\Kichiwawa Backup 2008-10-29\Website Kichiwawa Backup 03\_vti_pvt\services.cnf
[2008/06/30 14:17:00 | 000,000,002 | ---- | M] () MD5=A55822426A5330C04625A41D264C190B -- C:\Users\Development\Documents\Business\```Work\Kichiwawa\Kichiwawa Backup 2008-10-29\Website Kichiwawa Backup 04\_vti_pvt\services.cnf
< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.HTML >
[2014/01/04 09:02:34 | 000,003,702 | ---- | M] () MD5=6A70764DF110A7C538E1C328CBF92CEE -- C:\Users\Development\Documents\development svn\terzi interactive\clients\Epicure of Design\Regal Blu\website\trunk\deploy\services.html
< MD5 for: SERVICES.ISML >
[2013/10/21 09:39:28 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\$Recycle.Bin\S-1-5-21-3357349812-2239403225-1323811888-1004\$R2BGH5S\LaPrairie\Website\trunk\demandware 02\int_cybersource\cartridge\templates\default\services\services.isml
[2013/10/21 09:39:28 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\$Recycle.Bin\S-1-5-21-3357349812-2239403225-1323811888-1004\$R2BGH5S\LaPrairie\Website\trunk\demandware\int_cybersource\cartridge\templates\default\services\services.isml
[2013/09/11 16:51:32 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\Users\Development\Documents\Business\```Work\International Technology Solutions\La Prairie\Website\Eclipse\LPWebsite - Copy v02\int_cybersource\cartridge\templates\default\services\services.isml
[2013/09/11 16:51:32 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\Users\Development\Documents\Business\```Work\International Technology Solutions\La Prairie\Website\Eclipse\LPWebsite - Copy v03 2013-10-16 my version\int_cybersource\cartridge\templates\default\services\services.isml
[2013/10/21 09:22:56 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\Users\Development\Documents\Business\```Work\International Technology Solutions\La Prairie\Website\Eclipse\LPWebsite - Copy v06\int_cybersource\cartridge\templates\default\services\services.isml
[2013/10/21 09:39:28 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\Users\Development\Documents\development svn\terzi interactive\clients\International Technology Solutions\LaPrairie\Website\trunk\demandware 02\int_cybersource\cartridge\templates\default\services\services.isml
[2013/10/21 09:39:28 | 000,000,366 | ---- | M] () MD5=82008CF95961CDDF10B547E78D6A2F31 -- C:\Users\Development\Documents\development svn\terzi interactive\clients\International Technology Solutions\LaPrairie\Website\trunk\demandware\int_cybersource\cartridge\templates\default\services\services.isml
< MD5 for: SERVICES.JPG >
[2013/12/19 08:26:49 | 000,191,700 | ---- | M] () MD5=E527FB8488F2B27D6BCD3EFEDA886A3B -- C:\Users\Development\Documents\development svn\terzi interactive\clients\Epicure of Design\Regal Blu\website\trunk\deploy\images\services.jpg
< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2011/06/09 23:28:19 | 000,000,487 | ---- | M] () MD5=209FFC891CC922AE7F9FC7CA3E75A29F -- C:\Users\Development\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5435WMNH\mochiads.com\services.mochiads.com.sol
< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PNG >
[2013/12/19 08:27:19 | 000,186,369 | ---- | M] () MD5=E4D5891CEE0EB5135D51F7C3A3590D2B -- C:\Users\Development\Documents\development svn\terzi interactive\clients\Epicure of Design\Regal Blu\website\trunk\deploy\images\services.png
< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SBS >
[2013/07/16 12:21:30 | 000,034,818 | ---- | M] () MD5=E2ACBC77020C8D5CE97CA61D0D859A44 -- C:\Program Files (x86)\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: SERVICES.WSDL >
[2013/12/23 02:22:40 | 000,055,856 | ---- | M] () MD5=D26F7BEAD65817702D53F18C4BE111F0 -- C:\Program Files (x86)\Klok2\Services.wsdl
< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | ---- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | ---- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2009/07/13 20:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013/04/04 13:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\windows\SysNative\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2009/07/13 21:29:52 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 -- C:\windows\SysNative\en-US\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2014/02/24 06:58:16 | 000,040,304 | ---- | M] () MD5=0C64404CA2093F7A0655F7B46C2927C8 -- C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf
< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2014/02/24 13:58:15 | 000,180,764 | ---- | M] () -- C:\aaw7boot.log
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/11/30 23:07:20 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2014/02/24 13:58:16 | 2309,660,672 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/24 13:58:17 | 3079,548,928 | -HS- | M] () -- C:\pagefile.sys
[2011/04/21 09:06:52 | 000,061,960 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_21.04.2011_10.06.15_log.txt
[2011/04/21 09:08:53 | 000,061,960 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_21.04.2011_10.08.03_log.txt
[2011/04/21 09:09:51 | 000,002,246 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_21.04.2011_10.09.26_log.txt
[2011/04/22 18:12:43 | 000,062,694 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_22.04.2011_19.11.56_log.txt
[2011/05/22 14:06:26 | 000,000,414 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_22.05.2011_15.06.20_log.txt
[2011/04/23 17:28:00 | 000,062,694 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_23.04.2011_18.27.12_log.txt
[2011/04/24 01:18:54 | 000,062,694 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_24.04.2011_02.17.31_log.txt
[2011/04/24 02:09:55 | 000,063,472 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_24.04.2011_03.08.51_log.txt
[2011/04/24 10:01:54 | 000,026,774 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_24.04.2011_11.01.35_log.txt
[2011/04/24 18:20:47 | 000,063,472 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_24.04.2011_19.17.16_log.txt
[2011/04/24 21:18:49 | 000,063,472 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_24.04.2011_22.18.14_log.txt
[2011/05/22 14:08:08 | 000,063,716 | ---- | M] () -- C:\TDSSKiller.2.5.1.0_22.05.2011_15.07.22_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 15:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
[2012/10/27 13:54:02 | 000,000,000 | ---- | M] () -- C:\Program Files (x86)\error.dat
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is CeeDrive
Volume Serial Number is 3AD6-C62D
Directory of C:\
07/14/2009 12:08 AM <JUNCTION> Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\ProgramData]
07/14/2009 12:08 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM <JUNCTION> Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM <SYMLINKD> All Users [C:\ProgramData]
07/14/2009 12:08 AM <JUNCTION> Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\ProgramData]
07/14/2009 12:08 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM <JUNCTION> Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cole
01/16/2013 12:57 PM <JUNCTION> Application Data [C:\Users\Cole\AppData\Roaming]
01/16/2013 12:57 PM <JUNCTION> Cookies [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\Cookies]
01/16/2013 12:57 PM <JUNCTION> Local Settings [C:\Users\Cole\AppData\Local]
01/16/2013 12:57 PM <JUNCTION> My Documents [C:\Users\Cole\Documents]
01/16/2013 12:57 PM <JUNCTION> NetHood [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/16/2013 12:57 PM <JUNCTION> PrintHood [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/16/2013 12:57 PM <JUNCTION> Recent [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\Recent]
01/16/2013 12:57 PM <JUNCTION> SendTo [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\SendTo]
01/16/2013 12:57 PM <JUNCTION> Start Menu [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\Start Menu]
01/16/2013 12:57 PM <JUNCTION> Templates [C:\Users\Cole\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cole\AppData\Local
01/16/2013 12:57 PM <JUNCTION> Application Data [C:\Users\Cole\AppData\Local]
01/16/2013 12:57 PM <JUNCTION> History [C:\Users\Cole\AppData\Local\Microsoft\Windows\History]
01/16/2013 12:57 PM <JUNCTION> Temporary Internet Files [C:\Users\Cole\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Cole\Documents
01/16/2013 12:57 PM <JUNCTION> My Music [C:\Users\Cole\Music]
01/16/2013 12:57 PM <JUNCTION> My Pictures [C:\Users\Cole\Pictures]
01/16/2013 12:57 PM <JUNCTION> My Videos [C:\Users\Cole\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM <JUNCTION> Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM <JUNCTION> Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM <JUNCTION> My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM <JUNCTION> NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM <JUNCTION> PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM <JUNCTION> Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM <JUNCTION> SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM <JUNCTION> Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM <JUNCTION> Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM <JUNCTION> History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM <JUNCTION> Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM <JUNCTION> My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM <JUNCTION> My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM <JUNCTION> My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Development
04/20/2011 08:15 PM <JUNCTION> Application Data [C:\Users\Development\AppData\Roaming]
04/20/2011 08:15 PM <JUNCTION> Cookies [C:\Users\Development\AppData\Roaming\Microsoft\Windows\Cookies]
04/20/2011 08:15 PM <JUNCTION> Local Settings [C:\Users\Development\AppData\Local]
04/20/2011 08:15 PM <JUNCTION> My Documents [C:\Users\Development\Documents]
04/20/2011 08:15 PM <JUNCTION> NetHood [C:\Users\Development\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/20/2011 08:15 PM <JUNCTION> PrintHood [C:\Users\Development\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/20/2011 08:15 PM <JUNCTION> Recent [C:\Users\Development\AppData\Roaming\Microsoft\Windows\Recent]
04/20/2011 08:15 PM <JUNCTION> SendTo [C:\Users\Development\AppData\Roaming\Microsoft\Windows\SendTo]
04/20/2011 08:15 PM <JUNCTION> Start Menu [C:\Users\Development\AppData\Roaming\Microsoft\Windows\Start Menu]
04/20/2011 08:15 PM <JUNCTION> Templates [C:\Users\Development\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Development\AppData\Local
04/20/2011 08:15 PM <JUNCTION> Application Data [C:\Users\Development\AppData\Local]
04/20/2011 08:15 PM <JUNCTION> History [C:\Users\Development\AppData\Local\Microsoft\Windows\History]
04/20/2011 08:15 PM <JUNCTION> Temporary Internet Files [C:\Users\Development\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Development\AppData\LocalLow
05/20/2011 11:59 PM <JUNCTION> PlayReady [C:\ProgramData\Microsoft\PlayReady]
0 File(s) 0 bytes
Directory of C:\Users\Development\Documents
04/20/2011 08:15 PM <JUNCTION> My Music [C:\Users\Development\Music]
04/20/2011 08:15 PM <JUNCTION> My Pictures [C:\Users\Development\Pictures]
04/20/2011 08:15 PM <JUNCTION> My Videos [C:\Users\Development\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Kids
12/09/2010 10:01 AM <JUNCTION> Application Data [C:\Users\Kids\AppData\Roaming]
12/09/2010 10:01 AM <JUNCTION> Cookies [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Cookies]
12/09/2010 10:01 AM <JUNCTION> Local Settings [C:\Users\Kids\AppData\Local]
12/09/2010 10:01 AM <JUNCTION> My Documents [C:\Users\Kids\Documents]
12/09/2010 10:01 AM <JUNCTION> NetHood [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/09/2010 10:01 AM <JUNCTION> PrintHood [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/09/2010 10:01 AM <JUNCTION> Recent [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Recent]
12/09/2010 10:01 AM <JUNCTION> SendTo [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\SendTo]
12/09/2010 10:01 AM <JUNCTION> Start Menu [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Start Menu]
12/09/2010 10:01 AM <JUNCTION> Templates [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Kids\AppData\Local
12/09/2010 10:01 AM <JUNCTION> Application Data [C:\Users\Kids\AppData\Local]
12/09/2010 10:01 AM <JUNCTION> History [C:\Users\Kids\AppData\Local\Microsoft\Windows\History]
12/09/2010 10:01 AM <JUNCTION> Temporary Internet Files [C:\Users\Kids\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Kids\AppData\LocalLow
08/31/2012 02:04 PM <JUNCTION> PlayReady [C:\ProgramData\Microsoft\PlayReady]
0 File(s) 0 bytes
Directory of C:\Users\Kids\Documents
12/09/2010 10:01 AM <JUNCTION> My Music [C:\Users\Kids\Music]
12/09/2010 10:01 AM <JUNCTION> My Pictures [C:\Users\Kids\Pictures]
12/09/2010 10:01 AM <JUNCTION> My Videos [C:\Users\Kids\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Marc
03/25/2010 10:23 AM <JUNCTION> Application Data [C:\Users\Marc\AppData\Roaming]
03/25/2010 10:23 AM <JUNCTION> Cookies [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Cookies]
03/25/2010 10:23 AM <JUNCTION> Local Settings [C:\Users\Marc\AppData\Local]
03/25/2010 10:23 AM <JUNCTION> My Documents [C:\Users\Marc\Documents]
03/25/2010 10:23 AM <JUNCTION> NetHood [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/25/2010 10:23 AM <JUNCTION> PrintHood [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/25/2010 10:23 AM <JUNCTION> Recent [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Recent]
03/25/2010 10:23 AM <JUNCTION> SendTo [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\SendTo]
03/25/2010 10:23 AM <JUNCTION> Start Menu [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu]
03/25/2010 10:23 AM <JUNCTION> Templates [C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Marc\AppData\Local
03/25/2010 10:23 AM <JUNCTION> Application Data [C:\Users\Marc\AppData\Local]
03/25/2010 10:23 AM <JUNCTION> History [C:\Users\Marc\AppData\Local\Microsoft\Windows\History]
03/25/2010 10:23 AM <JUNCTION> Temporary Internet Files [C:\Users\Marc\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Marc\Documents
03/25/2010 10:23 AM <JUNCTION> My Music [C:\Users\Marc\Music]
03/25/2010 10:23 AM <JUNCTION> My Pictures [C:\Users\Marc\Pictures]
03/25/2010 10:23 AM <JUNCTION> My Videos [C:\Users\Marc\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Mom
10/27/2011 01:00 PM <JUNCTION> Application Data [C:\Users\Mom\AppData\Roaming]
10/27/2011 01:00 PM <JUNCTION> Cookies [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Cookies]
10/27/2011 01:00 PM <JUNCTION> Local Settings [C:\Users\Mom\AppData\Local]
10/27/2011 01:00 PM <JUNCTION> My Documents [C:\Users\Mom\Documents]
10/27/2011 01:00 PM <JUNCTION> NetHood [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
10/27/2011 01:00 PM <JUNCTION> PrintHood [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
10/27/2011 01:00 PM <JUNCTION> Recent [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Recent]
10/27/2011 01:00 PM <JUNCTION> SendTo [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\SendTo]
10/27/2011 01:00 PM <JUNCTION> Start Menu [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu]
10/27/2011 01:00 PM <JUNCTION> Templates [C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Mom\AppData\Local
10/27/2011 01:00 PM <JUNCTION> Application Data [C:\Users\Mom\AppData\Local]
10/27/2011 01:00 PM <JUNCTION> History [C:\Users\Mom\AppData\Local\Microsoft\Windows\History]
10/27/2011 01:00 PM <JUNCTION> Temporary Internet Files [C:\Users\Mom\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Mom\Documents
10/27/2011 01:00 PM <JUNCTION> My Music [C:\Users\Mom\Music]
10/27/2011 01:00 PM <JUNCTION> My Pictures [C:\Users\Mom\Pictures]
10/27/2011 01:00 PM <JUNCTION> My Videos [C:\Users\Mom\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM <JUNCTION> My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM <JUNCTION> My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM <JUNCTION> My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Safety
08/24/2013 10:42 PM <JUNCTION> Application Data [C:\Users\Safety\AppData\Roaming]
08/24/2013 10:42 PM <JUNCTION> Cookies [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\Cookies]
08/24/2013 10:42 PM <JUNCTION> Local Settings [C:\Users\Safety\AppData\Local]
08/24/2013 10:42 PM <JUNCTION> My Documents [C:\Users\Safety\Documents]
08/24/2013 10:42 PM <JUNCTION> NetHood [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/24/2013 10:42 PM <JUNCTION> PrintHood [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/24/2013 10:42 PM <JUNCTION> Recent [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\Recent]
08/24/2013 10:42 PM <JUNCTION> SendTo [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\SendTo]
08/24/2013 10:42 PM <JUNCTION> Start Menu [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\Start Menu]
08/24/2013 10:42 PM <JUNCTION> Templates [C:\Users\Safety\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Safety\AppData\Local
08/24/2013 10:42 PM <JUNCTION> Application Data [C:\Users\Safety\AppData\Local]
08/24/2013 10:42 PM <JUNCTION> History [C:\Users\Safety\AppData\Local\Microsoft\Windows\History]
08/24/2013 10:42 PM <JUNCTION> Temporary Internet Files [C:\Users\Safety\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Safety\Documents
08/24/2013 10:42 PM <JUNCTION> My Music [C:\Users\Safety\Music]
08/24/2013 10:42 PM <JUNCTION> My Pictures [C:\Users\Safety\Pictures]
08/24/2013 10:42 PM <JUNCTION> My Videos [C:\Users\Safety\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Test IE10
01/31/2014 01:02 PM <JUNCTION> Application Data [C:\Users\Test IE10\AppData\Roaming]
01/31/2014 01:02 PM <JUNCTION> Cookies [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\Cookies]
01/31/2014 01:02 PM <JUNCTION> Local Settings [C:\Users\Test IE10\AppData\Local]
01/31/2014 01:02 PM <JUNCTION> My Documents [C:\Users\Test IE10\Documents]
01/31/2014 01:02 PM <JUNCTION> NetHood [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/31/2014 01:02 PM <JUNCTION> PrintHood [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/31/2014 01:02 PM <JUNCTION> Recent [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\Recent]
01/31/2014 01:02 PM <JUNCTION> SendTo [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\SendTo]
01/31/2014 01:02 PM <JUNCTION> Start Menu [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\Start Menu]
01/31/2014 01:02 PM <JUNCTION> Templates [C:\Users\Test IE10\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Test IE10\AppData\Local
01/31/2014 01:02 PM <JUNCTION> Application Data [C:\Users\Test IE10\AppData\Local]
01/31/2014 01:02 PM <JUNCTION> History [C:\Users\Test IE10\AppData\Local\Microsoft\Windows\History]
01/31/2014 01:02 PM <JUNCTION> Temporary Internet Files [C:\Users\Test IE10\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Test IE10\Documents
01/31/2014 01:02 PM <JUNCTION> My Music [C:\Users\Test IE10\Music]
01/31/2014 01:02 PM <JUNCTION> My Pictures [C:\Users\Test IE10\Pictures]
01/31/2014 01:02 PM <JUNCTION> My Videos [C:\Users\Test IE10\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Test IE9
01/31/2014 01:00 PM <JUNCTION> Application Data [C:\Users\Test IE9\AppData\Roaming]
01/31/2014 01:00 PM <JUNCTION> Cookies [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\Cookies]
01/31/2014 01:00 PM <JUNCTION> Local Settings [C:\Users\Test IE9\AppData\Local]
01/31/2014 01:00 PM <JUNCTION> My Documents [C:\Users\Test IE9\Documents]
01/31/2014 01:00 PM <JUNCTION> NetHood [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/31/2014 01:00 PM <JUNCTION> PrintHood [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/31/2014 01:00 PM <JUNCTION> Recent [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\Recent]
01/31/2014 01:00 PM <JUNCTION> SendTo [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\SendTo]
01/31/2014 01:00 PM <JUNCTION> Start Menu [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\Start Menu]
01/31/2014 01:00 PM <JUNCTION> Templates [C:\Users\Test IE9\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Test IE9\AppData\Local
01/31/2014 01:00 PM <JUNCTION> Application Data [C:\Users\Test IE9\AppData\Local]
01/31/2014 01:00 PM <JUNCTION> History [C:\Users\Test IE9\AppData\Local\Microsoft\Windows\History]
01/31/2014 01:00 PM <JUNCTION> Temporary Internet Files [C:\Users\Test IE9\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Test IE9\Documents
01/31/2014 01:00 PM <JUNCTION> My Music [C:\Users\Test IE9\Music]
01/31/2014 01:00 PM <JUNCTION> My Pictures [C:\Users\Test IE9\Pictures]
01/31/2014 01:00 PM <JUNCTION> My Videos [C:\Users\Test IE9\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Tommy
05/26/2013 09:03 AM <JUNCTION> Application Data [C:\Users\Tommy\AppData\Roaming]
05/26/2013 09:03 AM <JUNCTION> Cookies [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Cookies]
05/26/2013 09:03 AM <JUNCTION> Local Settings [C:\Users\Tommy\AppData\Local]
05/26/2013 09:03 AM <JUNCTION> My Documents [C:\Users\Tommy\Documents]
05/26/2013 09:03 AM <JUNCTION> NetHood [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
05/26/2013 09:03 AM <JUNCTION> PrintHood [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
05/26/2013 09:03 AM <JUNCTION> Recent [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Recent]
05/26/2013 09:03 AM <JUNCTION> SendTo [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\SendTo]
05/26/2013 09:03 AM <JUNCTION> Start Menu [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu]
05/26/2013 09:03 AM <JUNCTION> Templates [C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Tommy\AppData\Local
05/26/2013 09:03 AM <JUNCTION> Application Data [C:\Users\Tommy\AppData\Local]
05/26/2013 09:03 AM <JUNCTION> History [C:\Users\Tommy\AppData\Local\Microsoft\Windows\History]
05/26/2013 09:03 AM <JUNCTION> Temporary Internet Files [C:\Users\Tommy\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Tommy\Documents
05/26/2013 09:03 AM <JUNCTION> My Music [C:\Users\Tommy\Music]
05/26/2013 09:03 AM <JUNCTION> My Pictures [C:\Users\Tommy\Pictures]
05/26/2013 09:03 AM <JUNCTION> My Videos [C:\Users\Tommy\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
12/22/2009 06:33 PM <JUNCTION> Application Data [C:\windows\system32\config\systemprofile\AppData\Roaming]
12/22/2009 06:33 PM <JUNCTION> Cookies [C:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
12/22/2009 06:33 PM <JUNCTION> Local Settings [C:\windows\system32\config\systemprofile\AppData\Local]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
12/22/2009 06:33 PM <JUNCTION> Application Data [C:\windows\system32\config\systemprofile\AppData\Local]
12/22/2009 06:33 PM <JUNCTION> History [C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
12/22/2009 06:33 PM <JUNCTION> Temporary Internet Files [C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile
12/22/2009 06:33 PM <JUNCTION> Application Data [C:\windows\system32\config\systemprofile\AppData\Roaming]
12/22/2009 06:33 PM <JUNCTION> Cookies [C:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
12/22/2009 06:33 PM <JUNCTION> Local Settings [C:\windows\system32\config\systemprofile\AppData\Local]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
12/22/2009 06:33 PM <JUNCTION> Application Data [C:\windows\system32\config\systemprofile\AppData\Local]
12/22/2009 06:33 PM <JUNCTION> History [C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
12/22/2009 06:33 PM <JUNCTION> Temporary Internet Files [C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
192 Dir(s) 79,031,418,880 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2014/02/10 20:22:54 | 000,000,221 | -HS- | M] () -- C:\Users\Marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2014/02/21 14:04:08 | 012,589,848 | ---- | M] (Malwarebytes Corp.) -- C:\Users\Marc\Desktop\mbar-1.07.0.1009.exe
[2014/02/21 14:06:22 | 000,204,496 | ---- | M] (Malwarebytes) -- C:\Users\Marc\Desktop\startuplite-setup-1.07.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >