Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Quality Control


  • Please log in to reply

#1
BenKosem

BenKosem

    New Member

  • Member
  • Pip
  • 1 posts
Hi all,

I purchased a laptop just over a week ago.
It came with a lot of bloatware installed, and I have done my best to clean out the crap.
I am posting my OTL here to see if someone might notice something undesirable that I haven't, and to stay on top of things as more of a preventative maintenance.
So there aren't any emergencies here (as far as I am aware).

Anti-Malware/maintenance programs I have ran since I got this laptop:

MalwareBytes
CCleaner
AntiVir
SUPERAntiSpyware Free Edition
TFC
pretty sure I ran Ad-Aware too before I uninstalled it

EDIT: One more thing, the "16000+ more lines" in the hosts file section are addresses I manually added that block adds and such.

Thanks for your time

OTL logfile created on: 6/6/2011 2:30:37 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\b.home\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 53.05% Memory free
7.61 Gb Paging File | 5.49 Gb Available in Paging File | 72.14% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254.14 Gb Total Space | 184.81 Gb Free Space | 72.72% Space Free | Partition Type: NTFS
Drive D: | 29.00 Gb Total Space | 27.86 Gb Free Space | 96.07% Space Free | Partition Type: NTFS

Computer Name: BHOME-PC | User Name: b.home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/06 14:30:05 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\b.home\Desktop\OTL.exe
PRC - [2011/06/04 03:01:11 | 000,941,936 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\opera.exe
PRC - [2011/06/04 02:38:49 | 001,496,528 | ---- | M] (TrueCrypt Foundation) -- C:\Program Files\TrueCrypt\TrueCrypt.exe
PRC - [2011/06/03 14:29:16 | 004,771,184 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\BitTorrent\BitTorrent.exe
PRC - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/04/11 17:45:30 | 000,107,520 | ---- | M] () -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
PRC - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/28 16:15:29 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/03/03 13:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/03 13:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/12/09 01:48:26 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/12/09 01:48:24 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe


========== Modules (SafeList) ==========

MOD - [2011/06/06 14:30:05 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\b.home\Desktop\OTL.exe
MOD - [2011/04/10 12:04:38 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/05/04 10:55:09 | 000,128,384 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2010/11/30 13:27:58 | 000,336,824 | ---- | M] (arvato digital services llc) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2_x64)
SRV:64bit: - [2010/09/22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/06/06 03:12:41 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 13:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/12/09 01:48:26 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2009/12/09 01:48:24 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/06/04 02:38:49 | 000,230,352 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:64bit: - [2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/04/10 12:21:41 | 000,107,912 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/04/10 12:21:41 | 000,027,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/04/01 17:07:59 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/04/01 17:07:59 | 000,083,120 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011/01/15 09:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010/12/16 15:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010/10/12 22:20:02 | 000,736,896 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010/08/07 01:07:16 | 001,326,928 | ---- | M] (Bison Electronics. Inc. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BisonC07.sys -- (Cam5607)
DRV:64bit: - [2010/06/18 06:34:58 | 004,170,304 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/06/10 04:43:20 | 001,380,400 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/03/31 00:47:08 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/03/11 20:23:16 | 000,242,720 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/03/03 12:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/02/26 01:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010/02/17 11:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2010/02/17 11:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2010/02/02 15:38:30 | 000,271,872 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2009/10/18 17:40:50 | 000,028,176 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2009/09/16 21:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®
DRV:64bit: - [2009/08/20 09:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 13:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 13:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:64bit: - [2009/06/10 13:34:36 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2011/06/03 20:28:58 | 000,617,588 | ---- | M]) - C:\Windows\SysNative\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 16297 more lines...
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.69.150 68.87.85.102
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/06 14:30:05 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\b.home\Desktop\OTL.exe
[2011/06/06 03:37:25 | 000,000,000 | ---D | C] -- C:\windows\Minidump
[2011/06/06 03:12:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2011/06/06 03:12:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Rosetta Stone
[2011/06/05 22:48:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Corel
[2011/06/05 22:48:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Protexis
[2011/06/05 22:47:03 | 000,000,000 | ---D | C] -- C:\Program Files\Corel
[2011/06/05 22:29:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Protexis64
[2011/06/05 22:29:27 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Corel
[2011/06/05 22:26:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Corel
[2011/06/05 22:24:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Corel Painter 12
[2011/06/05 18:03:40 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/06/05 18:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TweetDeck
[2011/06/05 14:33:50 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\WebcamMax
[2011/06/05 03:01:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2011/06/05 03:00:35 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\OpenOffice.org
[2011/06/05 02:55:51 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
[2011/06/05 02:54:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice.org 3
[2011/06/05 02:54:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011/06/05 02:54:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/06/05 02:54:24 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\deployJava1.dll
[2011/06/05 02:54:24 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\javaws.exe
[2011/06/05 02:54:24 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\javaw.exe
[2011/06/05 02:54:24 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\java.exe
[2011/06/05 02:54:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011/06/05 02:41:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2011/06/05 02:41:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elaborate Bytes
[2011/06/05 02:30:51 | 000,000,000 | ---D | C] -- C:\Users\b.home\Documents\Books
[2011/06/05 02:10:23 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Wat
[2011/06/05 02:10:22 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Wat
[2011/06/05 02:08:06 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\b.home\Desktop\TFC.exe
[2011/06/05 02:02:44 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dfshim.dll
[2011/06/05 02:02:44 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dfshim.dll
[2011/06/05 02:02:44 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\PresentationHost.exe
[2011/06/05 02:02:44 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PresentationHost.exe
[2011/06/05 02:02:44 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\PresentationHostProxy.dll
[2011/06/05 02:02:44 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PresentationHostProxy.dll
[2011/06/05 02:02:44 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netfxperf.dll
[2011/06/05 02:02:44 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\netfxperf.dll
[2011/06/05 02:02:19 | 000,000,000 | ---D | C] -- C:\windows\pss
[2011/06/05 01:57:41 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\SUPERAntiSpyware.com
[2011/06/05 01:57:41 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/06/05 01:57:36 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2011/06/05 01:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/06/05 01:57:33 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/06/05 01:52:28 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/06/05 01:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/06/05 01:52:25 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/06/05 01:45:05 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\WinRAR
[2011/06/05 01:45:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2011/06/04 17:32:46 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/04 12:13:02 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\poqexec.exe
[2011/06/04 12:13:02 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\poqexec.exe
[2011/06/04 12:13:01 | 002,870,272 | ---- | C] (Microsoft Corporation) -- C:\windows\explorer.exe
[2011/06/04 12:13:01 | 002,614,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\explorer.exe
[2011/06/04 12:12:53 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\sbe.dll
[2011/06/04 12:12:53 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\CPFilters.dll
[2011/06/04 12:12:53 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\EncDec.dll
[2011/06/04 12:12:53 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CPFilters.dll
[2011/06/04 12:12:53 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\EncDec.dll
[2011/06/04 12:12:52 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\sbe.dll
[2011/06/04 12:12:52 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mpg2splt.ax
[2011/06/04 12:12:51 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mpg2splt.ax
[2011/06/04 12:12:49 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\XpsGdiConverter.dll
[2011/06/04 12:12:49 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XpsGdiConverter.dll
[2011/06/04 12:12:47 | 005,509,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe
[2011/06/04 12:12:46 | 003,957,632 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntkrnlpa.exe
[2011/06/04 12:12:46 | 003,901,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntoskrnl.exe
[2011/06/04 12:12:43 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2011/06/04 12:12:42 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2011/06/04 12:12:42 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\vbscript.dll
[2011/06/04 12:12:41 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\upnp.dll
[2011/06/04 12:12:41 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\upnp.dll
[2011/06/04 12:12:40 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\davclnt.dll
[2011/06/04 12:12:39 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\davclnt.dll
[2011/06/04 12:12:39 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wscapi.dll
[2011/06/04 12:12:39 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wscapi.dll
[2011/06/04 12:12:39 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\slwga.dll
[2011/06/04 12:12:39 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\slwga.dll
[2011/06/04 12:12:35 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\XpsPrint.dll
[2011/06/04 12:12:35 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XpsPrint.dll
[2011/06/04 12:12:33 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mfc42u.dll
[2011/06/04 12:12:32 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mfc42.dll
[2011/06/04 12:12:32 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfc42u.dll
[2011/06/04 12:12:32 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfc42.dll
[2011/06/04 12:12:23 | 000,367,104 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\SysNative\atmfd.dll
[2011/06/04 12:12:23 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\SysWow64\atmfd.dll
[2011/06/04 12:12:23 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\windows\SysNative\atmlib.dll
[2011/06/04 12:12:23 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\windows\SysWow64\atmlib.dll
[2011/06/04 12:12:10 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msfeeds.dll
[2011/06/04 12:12:10 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iepeers.dll
[2011/06/04 12:12:09 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2011/06/04 12:12:09 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iepeers.dll
[2011/06/04 12:12:09 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2011/06/04 12:12:09 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2011/06/04 12:12:09 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2011/06/04 12:12:09 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2011/06/04 12:12:09 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\licmgr10.dll
[2011/06/04 12:12:09 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\licmgr10.dll
[2011/06/04 12:12:08 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\html.iec
[2011/06/04 12:12:08 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\html.iec
[2011/06/04 12:12:08 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msfeedssync.exe
[2011/06/04 12:12:08 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeedssync.exe
[2011/06/04 12:12:02 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winsrv.dll
[2011/06/04 12:12:02 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\Diskdump.sys
[2011/06/04 12:12:01 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dnsapi.dll
[2011/06/04 12:12:01 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dnscacheugc.exe
[2011/06/04 12:12:01 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dnscacheugc.exe
[2011/06/04 12:11:56 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\prevhost.exe
[2011/06/04 12:11:56 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\prevhost.exe
[2011/06/04 12:11:54 | 001,739,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntdll.dll
[2011/06/04 12:11:53 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mstscax.dll
[2011/06/04 12:11:52 | 002,690,560 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mstscax.dll
[2011/06/04 12:11:52 | 001,097,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mstsc.exe
[2011/06/04 12:11:52 | 001,034,240 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mstsc.exe
[2011/06/04 12:11:51 | 000,640,896 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winload.efi
[2011/06/04 12:11:51 | 000,603,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winload.exe
[2011/06/04 12:11:51 | 000,556,928 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winresume.efi
[2011/06/04 12:11:51 | 000,518,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winresume.exe
[2011/06/04 12:11:51 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\kdusb.dll
[2011/06/04 12:11:51 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\kd1394.dll
[2011/06/04 12:11:51 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\kdcom.dll
[2011/06/04 12:11:50 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\FXSCOVER.exe
[2011/06/04 12:11:49 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\odbc32.dll
[2011/06/04 12:11:48 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\odbc32.dll
[2011/06/04 03:02:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe 2
[2011/06/04 03:01:12 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Opera
[2011/06/04 03:01:12 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Opera
[2011/06/04 03:01:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2011/06/04 03:00:42 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\vlc
[2011/06/04 02:56:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/06/04 02:55:58 | 000,116,568 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avipbb.sys
[2011/06/04 02:55:58 | 000,083,120 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avgntflt.sys
[2011/06/04 02:55:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/06/04 02:55:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2011/06/04 02:53:04 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Malwarebytes
[2011/06/04 02:52:13 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2011/06/04 02:52:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/04 02:52:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/04 02:52:10 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2011/06/04 02:52:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/04 02:38:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt
[2011/06/04 02:38:49 | 000,230,352 | ---- | C] (TrueCrypt Foundation) -- C:\windows\SysNative\drivers\truecrypt.sys
[2011/06/04 02:38:42 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt
[2011/06/04 02:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 5.0
[2011/06/04 02:37:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxit Software
[2011/06/04 02:33:57 | 000,049,752 | ---- | C] (Sunbelt Software) -- C:\windows\SysNative\drivers\SBREDrv.sys
[2011/06/04 02:32:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/06/04 02:32:25 | 000,000,000 | ---D | C] -- C:\windows\SysNative\DRVSTORE
[2011/06/04 02:32:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2011/06/04 02:32:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2011/06/04 02:32:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2011/06/04 02:09:16 | 002,934,112 | ---- | C] (TODO: <公司名>) -- C:\windows\DeleteVF.exe
[2011/06/04 02:06:08 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011/06/04 02:03:31 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Macromedia
[2011/06/04 02:03:31 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Adobe
[2011/06/04 01:59:53 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/06/04 01:59:41 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\PackageAware
[2011/06/04 01:59:28 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Google
[2011/06/04 01:58:53 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Apps
[2011/06/04 01:58:52 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Deployment
[2011/06/04 01:53:40 | 000,000,000 | ---D | C] -- C:\Users\b.home\My Others
[2011/06/04 01:52:46 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Mozilla
[2011/06/04 01:47:41 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Intel Corporation
[2011/06/04 01:46:58 | 000,000,000 | R--D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/06/04 01:46:58 | 000,000,000 | R--D | C] -- C:\Users\b.home\Searches
[2011/06/04 01:46:58 | 000,000,000 | R--D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/06/04 01:46:58 | 000,000,000 | -H-D | C] -- C:\Users\b.home\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/06/04 01:46:38 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Identities
[2011/06/04 01:46:35 | 000,000,000 | R--D | C] -- C:\Users\b.home\Contacts
[2011/06/04 01:46:34 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\VirtualStore
[2011/06/04 01:46:18 | 000,000,000 | --SD | C] -- C:\Users\b.home\AppData\Roaming\Microsoft
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Videos
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Saved Games
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Pictures
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Music
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Links
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Favorites
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Downloads
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\My Documents
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\Desktop
[2011/06/04 01:46:18 | 000,000,000 | R--D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\AppData\Local\Temporary Internet Files
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Templates
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Start Menu
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\SendTo
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Recent
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\PrintHood
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\NetHood
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Documents\My Videos
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Documents\My Pictures
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Documents\My Music
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\My Documents
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Local Settings
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\AppData\Local\History
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Cookies
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\Application Data
[2011/06/04 01:46:18 | 000,000,000 | -HSD | C] -- C:\Users\b.home\AppData\Local\Application Data
[2011/06/04 01:46:18 | 000,000,000 | -H-D | C] -- C:\Users\b.home\AppData
[2011/06/04 01:46:18 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Temp
[2011/06/04 01:46:18 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Microsoft
[2011/06/04 01:46:18 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Media Center Programs
[2011/06/04 01:42:39 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011/06/03 23:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/06/03 23:57:33 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/06/03 23:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC
[2011/06/03 23:49:43 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\mIRC
[2011/06/03 23:49:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\mIRC
[2011/06/03 23:34:56 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Miranda
[2011/06/03 22:17:36 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2011/06/03 20:45:26 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/06/03 20:45:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/06/03 20:34:05 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Local\Adobe
[2011/06/03 16:15:01 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/03 16:00:32 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Avira
[2011/06/03 14:47:41 | 000,000,000 | R--D | C] -- C:\Users\b.home\Dropbox
[2011/06/03 14:44:45 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2011/06/03 14:44:16 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\Dropbox
[2011/06/03 14:29:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrent
[2011/06/03 14:28:47 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\BitTorrent
[2011/06/03 12:43:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KVIrc
[2011/06/03 12:36:05 | 000,000,000 | ---D | C] -- C:\Program Files\Mine
[2011/06/03 12:26:46 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\TrueCrypt
[2011/06/03 12:13:41 | 000,000,000 | ---D | C] -- C:\Users\b.home\AppData\Roaming\KeePass

========== Files - Modified Within 30 Days ==========

[2011/06/06 14:30:05 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\b.home\Desktop\OTL.exe
[2011/06/06 14:04:00 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1836834686-2587307601-3739489574-1000UA.job
[2011/06/06 11:47:26 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/06/06 04:12:06 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 04:12:06 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 04:08:45 | 000,726,316 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2011/06/06 04:08:45 | 000,624,178 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2011/06/06 04:08:45 | 000,106,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2011/06/06 04:04:15 | 3063,033,856 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/06 02:04:00 | 000,000,860 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1836834686-2587307601-3739489574-1000Core.job
[2011/06/05 22:36:38 | 004,853,024 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2011/06/05 02:54:14 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\javaws.exe
[2011/06/05 02:54:14 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\javaw.exe
[2011/06/05 02:54:14 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\java.exe
[2011/06/05 02:54:13 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\SysWow64\deployJava1.dll
[2011/06/05 02:12:06 | 000,000,408 | ---- | M] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job
[2011/06/05 02:08:06 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\b.home\Desktop\TFC.exe
[2011/06/04 02:38:49 | 000,230,352 | ---- | M] (TrueCrypt Foundation) -- C:\windows\SysNative\drivers\truecrypt.sys
[2011/06/04 02:33:57 | 000,049,752 | ---- | M] (Sunbelt Software) -- C:\windows\SysNative\drivers\SBREDrv.sys
[2011/06/04 01:55:17 | 000,001,441 | ---- | M] () -- C:\Users\b.home\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/04 01:42:56 | 000,000,235 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/06/03 20:28:58 | 000,617,588 | ---- | M] () -- C:\windows\SysNative\drivers\etc\HOSTS
[2011/06/03 18:40:44 | 000,039,252 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2011/06/03 18:40:44 | 000,039,252 | ---- | M] () -- C:\windows\SysNative\license.rtf
[2011/06/03 16:15:01 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2011/06/05 22:48:11 | 000,001,990 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel Painter 12.lnk
[2011/06/05 18:03:37 | 000,000,893 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweetDeck.lnk
[2011/06/05 02:12:06 | 000,000,408 | ---- | C] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job
[2011/06/04 03:01:11 | 000,001,845 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2011/06/04 01:59:33 | 000,000,912 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1836834686-2587307601-3739489574-1000UA.job
[2011/06/04 01:59:33 | 000,000,860 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1836834686-2587307601-3739489574-1000Core.job
[2011/06/04 01:55:17 | 000,001,441 | ---- | C] () -- C:\Users\b.home\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/04 01:47:16 | 000,001,413 | ---- | C] () -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/06/04 01:47:09 | 000,001,447 | ---- | C] () -- C:\Users\b.home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/06/04 01:46:18 | 000,000,290 | ---- | C] () -- C:\Users\b.home\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/06/04 01:46:18 | 000,000,272 | ---- | C] () -- C:\Users\b.home\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/06/03 20:47:24 | 000,001,093 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
[2011/06/03 20:46:50 | 000,001,227 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2011/06/03 20:45:09 | 000,001,189 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2011/06/03 20:44:53 | 000,001,282 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2011/06/03 20:43:47 | 000,001,383 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2011/06/03 20:43:42 | 000,001,555 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2011/06/03 20:43:16 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/04/10 21:48:02 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin
[2011/04/10 21:48:02 | 000,000,512 | ---- | C] () -- C:\windows\current.bin
[2011/04/10 21:30:48 | 002,110,816 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/04/10 21:30:48 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/04/10 21:30:32 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/04/10 21:24:02 | 000,000,235 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/04/10 21:04:10 | 000,015,190 | ---- | C] () -- C:\windows\M3000Twn.ini
[2011/04/10 20:52:35 | 000,870,560 | ---- | C] () -- C:\windows\SysWow64\igkrng575.bin
[2011/04/10 20:52:35 | 000,208,896 | ---- | C] () -- C:\windows\SysWow64\iglhsip32.dll
[2011/04/10 20:52:35 | 000,143,360 | ---- | C] () -- C:\windows\SysWow64\iglhcp32.dll
[2011/04/10 20:52:32 | 000,127,868 | ---- | C] () -- C:\windows\SysWow64\igcompkrng575.bin
[2011/04/10 20:52:32 | 000,104,636 | ---- | C] () -- C:\windows\SysWow64\igfcg575m.bin
[2009/07/13 22:38:36 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:59:36 | 000,982,196 | ---- | C] () -- C:\windows\SysWow64\igkrng500.bin
[2009/07/13 14:59:36 | 000,139,824 | ---- | C] () -- C:\windows\SysWow64\igfcg500.bin
[2009/07/13 14:59:36 | 000,097,448 | ---- | C] () -- C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 14:59:35 | 000,417,344 | ---- | C] () -- C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 14:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat

< End of report >


Edited by BenKosem, 06 June 2011 - 03:48 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP