Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Infected with Google Redirect virus!


  • This topic is locked This topic is locked

#1
tudorandrew

tudorandrew

    New Member

  • Member
  • Pip
  • 1 posts
Hello!
So i have been infected with a Google redirect virus and have tried a bunch of things to try and get rid of it, but no matter what i do, its still there, Please help.

I have followed the guide to remove the Google redirect virus which is on this forum but that did help, as per the instructions I used OTM (OTM log.txt log file is attached to this post) then used gooredFix with i dont think did anything ( gooredFix.txt log file is attached to this post) I then used TDSSkiller which found no threats. So this is where i turn to the forum for help.

I have run OLT which has given me the OLT.txt and extras.txt log files (both are attached to this post)
the OLT.txt file has been pasted below.

Thank you very much if you can help me.
i dont know what else to do.
Andrew


OTL logfile created on: 2/06/2011 2:47:02 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Andrew\Downloads
64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

4.00 Gb Total Physical Memory | 2.55 Gb Available Physical Memory | 63.86% Memory free
7.99 Gb Paging File | 6.37 Gb Available in Paging File | 79.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 265.04 Gb Total Space | 187.39 Gb Free Space | 70.70% Space Free | Partition Type: NTFS
Drive D: | 32.95 Gb Total Space | 2.52 Gb Free Space | 7.64% Space Free | Partition Type: NTFS

Computer Name: ANDREW-PC | User Name: Andrew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/02 14:42:05 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Andrew\Downloads\OTL.exe
PRC - [2011/04/08 15:14:00 | 002,218,600 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/03/25 23:26:58 | 000,064,112 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\hqtray.exe
PRC - [2011/03/25 23:26:46 | 000,334,448 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2011/03/25 23:26:28 | 000,404,080 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2011/03/25 23:26:16 | 000,113,264 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
PRC - [2011/03/25 22:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2011/03/17 18:15:46 | 000,382,272 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2011/03/17 18:15:04 | 000,842,048 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe
PRC - [2010/03/23 13:19:32 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe


========== Modules (SafeList) ==========

MOD - [2011/06/02 14:42:05 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Andrew\Downloads\OTL.exe
MOD - [2010/11/20 21:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MOD - [2009/07/14 11:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/11/11 14:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2010/11/11 14:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/14 11:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 11:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/04/08 15:14:00 | 002,218,600 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/03/25 23:26:46 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2011/03/25 23:26:28 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2011/03/25 23:26:16 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2011/03/25 22:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/08/19 13:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010/03/23 13:19:32 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 07:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/05/30 23:13:06 | 000,272,448 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/03/25 23:27:36 | 000,068,720 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2011/03/25 23:27:34 | 000,081,008 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2011/03/25 23:25:46 | 000,031,856 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2011/03/25 23:25:34 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2011/03/25 22:27:36 | 000,038,512 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2011/03/25 20:04:58 | 000,045,104 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2011/03/25 20:04:58 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2011/03/21 13:22:06 | 000,452,200 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/02/18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/11/20 23:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 23:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010/11/20 21:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 19:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010/10/24 21:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010/04/19 19:29:18 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2010/03/23 13:29:46 | 000,304,784 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV:64bit: - [2010/02/08 08:32:00 | 000,014,992 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CVirtA64.sys -- (CVirtA)
DRV:64bit: - [2009/07/14 11:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 11:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 11:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/11 07:01:14 | 001,227,776 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SmSerl64.sys -- (smserial)
DRV:64bit: - [2009/06/11 06:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/11 06:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:64bit: - [2009/06/11 06:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 06:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 06:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 06:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2008/11/16 18:39:44 | 000,157,968 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dne64x.sys -- (DNE)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV - [2010/08/19 13:56:38 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-AU
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 29 49 F8 B5 FD 12 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/16 00:03:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/05/17 14:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andrew\AppData\Roaming\Mozilla\Extensions
[2011/05/15 23:48:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/15 23:48:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) --
[2011/04/15 02:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 18:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/02 14:33:58 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files (x86)\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/02 10:36:52 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Diagnostics
[2011/06/02 10:33:18 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Desktop\redsn0w_win_0.9.6rc16
[2011/06/01 15:08:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kernel Outlook PST Viewer
[2011/06/01 15:08:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kernel Outlook PST Viewer
[2011/05/31 09:46:40 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\Virtual Machines
[2011/05/31 09:33:47 | 000,000,000 | ---D | C] -- C:\windows server 2003
[2011/05/30 23:13:26 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2011/05/30 23:13:06 | 000,272,448 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011/05/30 23:01:59 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\VMware
[2011/05/30 23:01:55 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\VMware
[2011/05/30 22:57:16 | 000,081,008 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmci.sys
[2011/05/30 22:57:14 | 000,068,720 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmx86.sys
[2011/05/30 22:56:53 | 000,334,448 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vmnetdhcp.exe
[2011/05/30 22:56:49 | 000,404,080 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vmnat.exe
[2011/05/30 22:56:49 | 000,030,320 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmnetuserif.sys
[2011/05/30 22:56:46 | 000,968,816 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\vnetlib64.dll
[2011/05/30 22:56:33 | 000,031,856 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\VMkbd.sys
[2011/05/30 22:56:31 | 000,038,512 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\hcmon.sys
[2011/05/30 22:56:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
[2011/05/30 22:56:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\VMware
[2011/05/30 22:56:11 | 000,000,000 | ---D | C] -- C:\ProgramData\VMware
[2011/05/30 22:56:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VMware
[2011/05/30 21:24:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client
[2011/05/30 21:24:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Deterministic Networks
[2011/05/30 21:22:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2011/05/30 14:10:58 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Desktop\QDMS
[2011/05/29 11:34:19 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Desktop\forum
[2011/05/28 10:14:03 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/05/28 10:09:55 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Desktop\GooredFix Backups
[2011/05/28 10:04:48 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/05/27 17:25:46 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/05/27 17:25:46 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\AVG10
[2011/05/27 17:16:47 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2011/05/27 17:16:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2011/05/27 17:10:27 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/05/27 10:58:00 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/05/27 10:04:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EASEUS
[2011/05/25 15:18:16 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2011/05/23 21:17:10 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\TeraCopy
[2011/05/23 21:04:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
[2011/05/23 21:04:26 | 000,000,000 | ---D | C] -- C:\Program Files\TeraCopy
[2011/05/20 17:22:58 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Foxit Software
[2011/05/19 21:09:07 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Desktop\latest
[2011/05/19 12:27:25 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\vlc
[2011/05/17 14:50:20 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Mozilla
[2011/05/17 14:50:20 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Mozilla
[2011/05/17 14:03:41 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\QDMS 2
[2011/05/17 11:51:48 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft Corporation
[2011/05/17 11:27:15 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Xerox
[2011/05/17 11:26:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Xerox
[2011/05/17 10:47:40 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\assembly
[2011/05/17 10:47:38 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Deployment
[2011/05/17 10:47:38 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Apps
[2011/05/16 21:28:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Visual Studio
[2011/05/16 21:18:02 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\TortoiseSVN
[2011/05/16 21:16:39 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\QDMS
[2011/05/16 21:16:10 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Subversion
[2011/05/16 21:15:08 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\TSVNCache
[2011/05/16 21:12:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseSVN
[2011/05/16 21:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\TortoiseSVN
[2011/05/16 21:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\TortoiseOverlays
[2011/05/16 21:01:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco Systems
[2011/05/16 16:19:46 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\Visual Studio 2005
[2011/05/16 16:13:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011/05/16 15:49:44 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011/05/16 15:48:42 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2011/05/16 15:40:24 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\Integration Services Script Component
[2011/05/16 15:39:35 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\Integration Services Script Task
[2011/05/16 15:39:20 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\SQL Server Management Studio
[2011/05/16 15:31:12 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Microsoft_Corporation
[2011/05/16 15:20:15 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\RsFx
[2011/05/16 15:19:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 9.0
[2011/05/16 15:17:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
[2011/05/16 15:12:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2011/05/16 15:12:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
[2011/05/16 15:12:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Sync Framework
[2011/05/16 15:11:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2011/05/16 15:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2011/05/16 15:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011/05/16 15:10:52 | 000,000,000 | ---D | C] -- C:\ProgramData\PreEmptive Solutions
[2011/05/16 15:09:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 3 SDK
[2011/05/16 15:08:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2011/05/16 15:08:14 | 000,000,000 | ---D | C] -- C:\Program Files\IIS
[2011/05/16 15:08:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS
[2011/05/16 15:07:24 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\Visual Studio 2008
[2011/05/16 15:06:53 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\Visual Studio 2010
[2011/05/16 15:03:16 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1033
[2011/05/16 15:02:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft F#
[2011/05/16 15:02:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTML Help Workshop
[2011/05/16 15:02:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010
[2011/05/16 15:02:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0
[2011/05/16 15:02:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules
[2011/05/16 15:00:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 9.0
[2011/05/16 15:00:04 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2011/05/16 15:00:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 10.0
[2011/05/16 15:00:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SDKs
[2011/05/16 15:00:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Help Viewer
[2011/05/16 15:00:04 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1033
[2011/05/16 14:39:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
[2011/05/16 14:39:56 | 000,526,392 | ---- | C] (Duplex Secure Ltd.) -- C:\Windows\SysNative\drivers\sptd.sys
[2011/05/16 14:39:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Pro
[2011/05/16 14:37:24 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\DAEMON Tools Pro
[2011/05/16 14:37:24 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro
[2011/05/16 14:21:33 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\.minecraft
[2011/05/16 13:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/05/16 13:19:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2011/05/16 13:02:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/16 13:01:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2011/05/16 13:01:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/16 13:01:17 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011/05/16 13:01:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2011/05/16 12:59:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011/05/16 12:59:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2011/05/16 12:58:44 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Microsoft Help
[2011/05/16 12:58:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2011/05/16 12:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2011/05/16 12:58:27 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011/05/16 09:18:51 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Skype
[2011/05/16 00:09:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2011/05/16 00:09:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/05/16 00:08:57 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Malwarebytes
[2011/05/16 00:08:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/16 00:08:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/16 00:08:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/05/16 00:08:49 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/05/16 00:08:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/05/16 00:05:02 | 000,000,000 | ---D | C] -- C:\Program Files\Paint.NET
[2011/05/16 00:04:20 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Paint.NET
[2011/05/16 00:03:58 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Apple Computer
[2011/05/16 00:03:58 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Apple Computer
[2011/05/16 00:03:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/16 00:03:48 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2011/05/16 00:03:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/16 00:03:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/05/16 00:03:25 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/16 00:03:25 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/05/16 00:03:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/16 00:02:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/05/16 00:02:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/05/16 00:02:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011/05/16 00:02:25 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Apple
[2011/05/16 00:02:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011/05/16 00:02:10 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/16 00:02:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011/05/16 00:01:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/05/16 00:01:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2011/05/15 23:59:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/05/15 23:59:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2011/05/15 23:58:10 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2011/05/15 23:58:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/15 23:58:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011/05/15 23:50:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2011/05/15 23:50:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxit Software
[2011/05/15 23:50:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/15 23:50:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImgBurn
[2011/05/15 23:49:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/15 23:49:23 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/05/15 23:49:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011/05/15 23:49:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2011/05/15 23:49:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2011/05/15 23:49:03 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\WinRAR
[2011/05/15 23:49:03 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/15 23:49:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/15 23:49:03 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/05/15 23:49:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2011/05/15 23:49:01 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\uTorrent
[2011/05/15 23:48:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011/05/15 23:48:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/05/15 23:48:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011/05/15 23:46:59 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/05/15 23:46:54 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Google
[2011/05/15 23:45:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/05/15 23:33:53 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/05/15 23:33:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2011/05/15 23:33:35 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2011/05/15 23:32:04 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/05/15 23:31:27 | 000,067,176 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/05/15 23:31:27 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/05/15 23:30:37 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011/05/15 23:30:15 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2011/05/15 23:27:48 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2011/05/15 23:27:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2011/05/15 23:27:36 | 000,000,000 | ---D | C] -- C:\Intel
[2011/05/15 23:11:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2011/05/15 23:11:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2011/05/15 23:05:17 | 000,021,992 | ---- | C] (CPUID) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys
[2011/05/15 23:05:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2011/05/15 23:05:16 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2011/05/15 23:04:41 | 000,116,224 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2011/05/15 23:04:24 | 000,093,696 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2011/05/15 22:46:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
[2011/05/15 22:45:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2011/05/15 22:45:05 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2011/05/15 22:44:29 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Macromedia
[2011/05/15 22:44:28 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Adobe
[2011/05/15 22:44:22 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2011/05/15 22:32:55 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2011/05/15 22:32:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2011/05/15 21:59:18 | 000,000,000 | R--D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/15 21:59:18 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Searches
[2011/05/15 21:59:18 | 000,000,000 | R--D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/15 21:59:18 | 000,000,000 | -H-D | C] -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/15 21:59:10 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Identities
[2011/05/15 21:59:08 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Contacts
[2011/05/15 21:59:07 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\VirtualStore
[2011/05/15 21:59:01 | 000,000,000 | --SD | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Videos
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Saved Games
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Pictures
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Music
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Links
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Favorites
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Downloads
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\My Documents
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\Desktop
[2011/05/15 21:59:01 | 000,000,000 | R--D | C] -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\AppData\Local\Temporary Internet Files
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Templates
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Start Menu
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\SendTo
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Recent
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\PrintHood
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\NetHood
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Documents\My Videos
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Documents\My Pictures
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Documents\My Music
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\My Documents
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Local Settings
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\AppData\Local\History
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Cookies
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\Application Data
[2011/05/15 21:59:01 | 000,000,000 | -HSD | C] -- C:\Users\Andrew\AppData\Local\Application Data
[2011/05/15 21:59:01 | 000,000,000 | -H-D | C] -- C:\Users\Andrew\AppData
[2011/05/15 21:59:01 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Temp
[2011/05/15 21:59:01 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Local\Microsoft
[2011/05/15 21:59:01 | 000,000,000 | ---D | C] -- C:\Users\Andrew\AppData\Roaming\Media Center Programs
[2011/05/15 21:58:50 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011/05/15 21:58:20 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011/05/15 21:50:57 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2011/05/15 17:08:44 | 000,000,000 | ---D | C] -- C:\Users\Andrew\Documents\bayside pc repair

========== Files - Modified Within 30 Days ==========

[2011/06/02 14:42:16 | 000,013,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/02 14:42:16 | 000,013,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/02 14:39:27 | 000,873,718 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/02 14:39:27 | 000,731,790 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/06/02 14:39:27 | 000,151,208 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/06/02 14:35:02 | 000,000,316 | -HS- | M] () -- C:\Windows\tasks\nkxr.job
[2011/06/02 14:34:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/02 14:34:51 | 3217,199,104 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/02 14:33:58 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2011/06/02 14:22:16 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-391292659-1930160660-3163114360-1001Core.job
[2011/06/02 14:02:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-391292659-1930160660-3163114360-1001UA.job
[2011/06/02 10:32:00 | 698,558,606 | ---- | M] () -- C:\Users\Andrew\Desktop\iPhone3,1_4.3.3_8J2_Restore.ipsw
[2011/06/01 15:08:40 | 000,001,211 | ---- | M] () -- C:\Users\Andrew\Desktop\Kernel Outlook PST Viewer .lnk
[2011/05/30 23:13:06 | 000,272,448 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011/05/30 22:57:18 | 000,001,015 | ---- | M] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk
[2011/05/30 22:56:23 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/05/30 22:56:21 | 000,878,768 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/30 22:56:21 | 000,002,031 | ---- | M] () -- C:\Users\Public\Desktop\VMware Player.lnk
[2011/05/30 21:24:52 | 000,001,594 | ---- | M] () -- C:\Windows\VPNInstall.MIF
[2011/05/30 21:24:15 | 000,002,653 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk
[2011/05/30 21:22:19 | 000,001,594 | ---- | M] () -- C:\Windows\VPNUnInstall.MIF
[2011/05/29 11:29:34 | 000,000,198 | ---- | M] () -- C:\Users\Andrew\defogger_reenable
[2011/05/28 10:13:37 | 000,013,078 | ---- | M] () -- C:\Users\Andrew\Documents\cc_20110528_101333.reg
[2011/05/27 10:49:38 | 000,131,072 | RHS- | M] () -- C:\Windows\SysWow64\Storpropi.dll
[2011/05/25 15:48:27 | 000,370,693 | ---- | M] () -- C:\Users\Andrew\Documents\Declaration.pdf
[2011/05/16 14:44:20 | 000,414,656 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/16 14:39:58 | 000,526,392 | ---- | M] (Duplex Secure Ltd.) -- C:\Windows\SysNative\drivers\sptd.sys
[2011/05/16 14:39:58 | 000,001,932 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
[2011/05/16 12:15:46 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/16 00:18:26 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_netaapl64_01009.Wdf
[2011/05/16 00:18:19 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/16 00:10:08 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/05/16 00:09:29 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2011/05/16 00:08:53 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/16 00:07:52 | 000,001,176 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2011/05/16 00:03:50 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/16 00:03:06 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/15 23:59:20 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/05/15 23:58:10 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/05/15 23:50:35 | 000,001,254 | ---- | M] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2011/05/15 23:50:35 | 000,001,230 | ---- | M] () -- C:\Users\Public\Desktop\Foxit Reader.lnk
[2011/05/15 23:50:09 | 000,001,865 | ---- | M] () -- C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/15 23:49:24 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/15 23:49:13 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2011/05/15 23:49:03 | 000,000,993 | ---- | M] () -- C:\Users\Public\Desktop\WinRAR.lnk
[2011/05/15 23:49:03 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/05/15 23:48:15 | 000,002,318 | ---- | M] () -- C:\Users\Andrew\Desktop\Google Chrome.lnk
[2011/05/15 23:45:23 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/15 22:55:06 | 000,058,859 | ---- | M] () -- C:\Users\Andrew\Documents\Untitled.wma
[2011/05/15 22:43:32 | 000,001,437 | ---- | M] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/15 22:39:35 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/05/15 22:39:35 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011/05/15 21:53:06 | 000,042,049 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2011/05/15 21:53:06 | 000,042,049 | ---- | M] () -- C:\Windows\SysNative\license.rtf

========== Files Created - No Company Name ==========

[2011/06/02 10:11:31 | 698,558,606 | ---- | C] () -- C:\Users\Andrew\Desktop\iPhone3,1_4.3.3_8J2_Restore.ipsw
[2011/06/01 15:08:40 | 000,001,211 | ---- | C] () -- C:\Users\Andrew\Desktop\Kernel Outlook PST Viewer .lnk
[2011/05/30 22:57:18 | 000,001,015 | ---- | C] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk
[2011/05/30 22:56:23 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/05/30 22:56:21 | 000,002,031 | ---- | C] () -- C:\Users\Public\Desktop\VMware Player.lnk
[2011/05/30 21:24:15 | 000,002,653 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk
[2011/05/30 21:21:25 | 000,001,594 | ---- | C] () -- C:\Windows\VPNUnInstall.MIF
[2011/05/29 11:29:34 | 000,000,198 | ---- | C] () -- C:\Users\Andrew\defogger_reenable
[2011/05/28 10:13:35 | 000,013,078 | ---- | C] () -- C:\Users\Andrew\Documents\cc_20110528_101333.reg
[2011/05/27 10:49:38 | 000,131,072 | RHS- | C] () -- C:\Windows\SysWow64\Storpropi.dll
[2011/05/27 10:49:38 | 000,000,316 | -HS- | C] () -- C:\Windows\tasks\nkxr.job
[2011/05/25 15:48:26 | 000,370,693 | ---- | C] () -- C:\Users\Andrew\Documents\Declaration.pdf
[2011/05/16 21:01:38 | 000,001,594 | ---- | C] () -- C:\Windows\VPNInstall.MIF
[2011/05/16 14:39:58 | 000,001,932 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
[2011/05/16 12:15:46 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/16 00:18:26 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_netaapl64_01009.Wdf
[2011/05/16 00:18:19 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/16 00:10:11 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2011/05/16 00:10:08 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/05/16 00:09:46 | 000,878,768 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/16 00:09:29 | 000,001,897 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/05/16 00:08:53 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/16 00:07:52 | 000,001,188 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2011/05/16 00:07:52 | 000,001,176 | ---- | C] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2011/05/16 00:03:50 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/16 00:03:06 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/16 00:02:22 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/15 23:59:20 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/05/15 23:58:10 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/05/15 23:50:35 | 000,001,254 | ---- | C] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2011/05/15 23:50:35 | 000,001,230 | ---- | C] () -- C:\Users\Public\Desktop\Foxit Reader.lnk
[2011/05/15 23:50:09 | 000,001,877 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/05/15 23:50:09 | 000,001,865 | ---- | C] () -- C:\Users\Public\Desktop\ImgBurn.lnk
[2011/05/15 23:49:24 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/15 23:49:13 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2011/05/15 23:49:03 | 000,000,993 | ---- | C] () -- C:\Users\Public\Desktop\WinRAR.lnk
[2011/05/15 23:49:03 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/05/15 23:47:02 | 000,000,912 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-391292659-1930160660-3163114360-1001UA.job
[2011/05/15 23:47:01 | 000,000,860 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-391292659-1930160660-3163114360-1001Core.job
[2011/05/15 23:47:00 | 000,002,318 | ---- | C] () -- C:\Users\Andrew\Desktop\Google Chrome.lnk
[2011/05/15 23:45:23 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/15 23:45:23 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/15 23:31:26 | 000,007,771 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2011/05/15 23:05:24 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2011/05/15 23:04:09 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2011/05/15 23:04:02 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2011/05/15 23:04:02 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2011/05/15 23:03:54 | 000,146,389 | ---- | C] () -- C:\Windows\SysWow64\printmanagement.msc
[2011/05/15 23:03:54 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2011/05/15 22:55:06 | 000,058,859 | ---- | C] () -- C:\Users\Andrew\Documents\Untitled.wma
[2011/05/15 22:43:32 | 000,001,437 | ---- | C] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/15 22:39:35 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/05/15 22:39:35 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011/05/15 21:59:24 | 000,001,409 | ---- | C] () -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/05/15 21:59:20 | 000,001,443 | ---- | C] () -- C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/15 21:59:01 | 000,000,290 | ---- | C] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/15 21:59:01 | 000,000,272 | ---- | C] () -- C:\Users\Andrew\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/15 21:53:00 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/15 21:52:51 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/15 21:50:23 | 3217,199,104 | -HS- | C] () -- C:\hiberfil.sys
[2009/07/14 15:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 12:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 12:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 10:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 09:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 07:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/17 19:19:32 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\.minecraft
[2011/05/27 17:25:46 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\AVG10
[2011/05/16 14:52:03 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\DAEMON Tools Pro
[2011/05/20 17:22:58 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\Foxit Software
[2011/05/16 21:16:10 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\Subversion
[2011/06/02 14:36:04 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\TeraCopy
[2011/05/28 10:13:56 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\uTorrent
[2011/05/17 11:27:15 | 000,000,000 | ---D | M] -- C:\Users\Andrew\AppData\Roaming\Xerox
[2011/06/02 14:35:02 | 000,000,316 | -HS- | M] () -- C:\Windows\Tasks\nkxr.job
[2009/07/14 15:08:49 | 000,011,990 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Attached Files


  • 0

Advertisements


#2
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hello tudorandrew and welcome to G2G! :)

My nick is maliprog and I'll will be your technical support on this issue. Before we start please read my notes carefully:

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted. Order is crucial in cleaning process.
  • Please DO NOT run any scans or fix on your own without my direction.
  • Please read all of my response through at least once before attempting to follow the procedures described.
  • If there's anything you don't understand or isn't totally clear, please come back to me for clarification.
  • Please do not attach any log files to your replies unless I specifically ask you. Instead please copy and paste so as to include the log in your reply.
  • You must reply within 3 days or your topic will be closed

Please test for redirection after these steps.

Step 1

Please close all running programs and Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    [2011/06/02 14:35:02 | 000,000,316 | -HS- | M] () -- C:\Windows\tasks\nkxr.job
    [2011/05/30 22:56:23 | 000,001,024 | ---- | M] () -- C:\.rnd

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post the fix log it produces in your next reply or you can find it in C:\_OTL\MovedFiles

Step 2

Download aswMBR.exe ( 511KB ) to your desktop.

  • Double click the aswMBR.exe to run it
  • Click the "Scan" button to start scan
  • On completion of the scan click save log, save it to your desktop and post in your next reply

Step 3

Please don't forget to include these items in your reply:

  • OTL fix log
  • aswMBR
It would be helpful if you could post each log in separate post
  • 0

#3
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP