My computer has been infected by a virus, and although I still can use my computer, I'm worried that it might be a keylogger. Any help would be appreciated.
I'm currently doing my first year of computer sciences at university, and having an infected computer is quite inconvenient when you need it almost every day to program.
Symptoms:
Now and then some search results in google get redirected to web advertisements. This seems to be happening randomly, although I noticed that the browser first gets redirected to tealtimes.com before going to the actual advert.
Even more worrying: Microsoft Security Essentials has been turned off, and I am unable to start it. That is, when I run MSE, the main window and the tray icon pop up for a tenth of a second and then close themselves.
Possible Source:
The entire mess started when I clicked the fist link in this search query. It linked to a gouvernmental website, so I wasn't very carefull, because I trusted it to be safe and because I had visited the main page plenty of times before. I still don't think the site is to blaim because now the link as well as the webpage load fine. However, when I opened the website yesterday, a rar file opened containing a program with the name (translated into English): conservatory_mechelen_abscences.exe. Now I realize that this happens to be the exact same name as the search query. Anyway, having seen too much programming code, I assumed that it was some kind of database program for abscences and - stupid as I was - I ran the program.
Things I Tried:
When I felt somerhing was not right, I immediately killed the initial process in task manager (located in AppData/Temp/$RarXyz$). But it seemed that the damage was already done, because MSE wouldn't respond anymore.
I managed to start MSE in safe mode and I ran a full scan. I had to terminate the scan because it was too late in the evening, but still the scan returned a single virus. As far as I can tell the virus was successfully removed. However, when enabling MSE an error code appeared (which I can post here if you want).
When I exited safe mode MSE still wouldn't run, and then I noticed that some links in google got redirected. I followed the step on this page because the sympoms matched mine, but to no avail.
And that is how I got here in the first place, so, again, any help within the next few days with this frustrating problem would be awesome.
OTL QuickScan Results:
OTL logfile created on: 14/02/2012 18:47:47 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = D:\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy
7,90 Gb Total Physical Memory | 5,35 Gb Available Physical Memory | 67,71% Memory free
15,79 Gb Paging File | 13,04 Gb Available in Paging File | 82,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 446,13 Gb Total Space | 274,45 Gb Free Space | 61,52% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 190,04 Gb Free Space | 40,80% Space Free | Partition Type: NTFS
Computer Name: XPS | User Name: Sam | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/14 08:21:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe
PRC - [2012/02/12 18:51:27 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/02/03 20:56:05 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/01/19 12:47:20 | 003,027,840 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012/01/18 19:54:06 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\Sam\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/01/03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/10/15 09:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/09/16 14:39:24 | 000,115,048 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2011/08/02 08:33:22 | 002,998,592 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
PRC - [2011/01/12 17:00:42 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/01/12 17:00:38 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/12/20 18:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/12/20 18:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/11/03 11:01:34 | 000,983,104 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2010/11/03 11:01:20 | 001,298,496 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2010/11/03 10:53:28 | 000,897,088 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2010/11/03 10:53:06 | 000,979,008 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/12 18:51:27 | 001,911,768 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/12/31 11:26:10 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\b41e38edbd6dfe20997f6ea7c080aceb\System.Web.ni.dll
MOD - [2011/12/31 11:26:04 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b559a471eef00081f0b5c2719d1d9623\System.Runtime.Remoting.ni.dll
MOD - [2011/11/14 07:49:04 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/04 15:54:16 | 000,930,304 | ---- | M] () -- C:\Users\Sam\AppData\Roaming\Mozilla\Firefox\Profiles\xqhe8rpc.default\extensions\[email protected]\platform\WINNT_x86-msvc\components\lpxpcom.dll
MOD - [2011/10/14 08:48:50 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\b40ad47b1338dd50c41d2c5571819a09\IAStorCommon.ni.dll
MOD - [2011/10/14 08:48:49 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\356136d6f23fe3cde33dc96fbda2df0a\IAStorUtil.ni.dll
MOD - [2011/10/13 08:09:23 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/10/13 08:09:18 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/10/13 08:09:09 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/10/13 08:09:05 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/13 08:09:03 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/13 08:09:02 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/13 08:08:59 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/11/13 00:33:28 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_nl_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009/06/10 23:10:44 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_nl_b77a5c561934e089\System.Runtime.Remoting.resources.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/10/20 18:33:22 | 000,135,440 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV:64bit: - [2011/10/19 14:25:00 | 000,661,504 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011/06/10 22:46:54 | 002,044,688 | ---- | M] (Blue Coat Systems, Inc.) [Auto | Running] -- C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe -- (bckwfs)
SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/11/29 15:00:56 | 000,149,504 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2009/11/17 18:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/02/14 08:26:45 | 000,481,064 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/02/03 20:56:05 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/01/19 12:47:20 | 003,027,840 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/01/03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/10/15 09:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/01/12 17:00:42 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/12/20 18:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010/12/20 18:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/11/03 11:01:34 | 000,983,104 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2010/11/03 11:01:20 | 001,298,496 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2010/11/03 10:53:28 | 000,897,088 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010/10/22 12:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/03/22 09:17:24 | 000,276,584 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/11/06 13:24:54 | 000,282,728 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe -- (UpdateCenterService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/12/16 16:53:01 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2011/12/07 18:22:48 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2011/10/31 15:57:50 | 008,615,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel®
DRV:64bit: - [2011/10/19 14:19:08 | 000,195,072 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011/10/19 14:19:08 | 000,195,072 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011/10/15 09:53:00 | 000,249,152 | ---- | M] (NVIDIA Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\nvkflt.sys -- (nvkflt)
DRV:64bit: - [2011/10/15 09:53:00 | 000,028,992 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2011/09/16 14:10:50 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2011/09/16 14:10:24 | 000,014,944 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\radpms.sys -- (radpms)
DRV:64bit: - [2011/09/16 14:10:24 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2011/09/13 16:14:44 | 000,212,992 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011/09/13 16:14:42 | 000,095,744 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011/08/24 00:03:02 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/08/23 21:57:24 | 000,565,352 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/08/17 12:58:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2011/08/17 12:58:22 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2011/08/17 12:58:20 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2011/08/17 12:58:16 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2011/08/01 15:59:06 | 000,052,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV:64bit: - [2011/08/01 15:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2011/07/19 14:39:56 | 012,287,456 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/07/08 00:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/06/10 22:46:04 | 000,107,280 | ---- | M] (Blue Coat Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bckd.sys -- (bckd)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2011/04/07 12:33:42 | 000,014,544 | ---- | M] (MaxiVista) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mvvideodemo.sys -- (mvvideodemo)
DRV:64bit: - [2011/04/07 12:33:40 | 000,015,568 | ---- | M] (MaxiVista) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mvCmdemo.SYS -- (mvCmdemo)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/16 17:53:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2011/01/12 16:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/11/29 15:00:04 | 000,016,120 | ---- | M] (Intel® Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010/11/21 04:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 04:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 04:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 04:23:48 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010/11/21 04:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/04 04:07:06 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2010/11/04 02:31:44 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2010/10/19 17:12:58 | 000,274,432 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2010/10/19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/10/15 07:28:18 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2010/09/23 16:44:48 | 001,394,224 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/07/02 02:46:56 | 000,029,288 | ---- | M] (Quanta Computer) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\qicflt.sys -- (qicflt)
DRV:64bit: - [2010/06/11 02:14:42 | 001,799,808 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVer7231_x64.sys -- (AVer7231_x64)
DRV:64bit: - [2009/09/15 14:59:30 | 000,042,088 | ---- | M] (NVIDIA Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvoclk64.sys -- (nvoclk64)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/09 02:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "chrome://speeddial/content/speeddial.xul"
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@spoon.net/Spoon Plugin 3.32: C:\Users\Sam\AppData\Local\Spoon\3.32.1.5\npMozillaSpoonPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Sam\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/02/12 18:51:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_7.0 [2012/01/07 01:43:45 | 000,000,000 | ---D | M]
[2011/10/16 17:07:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sam\AppData\Roaming\mozilla\Extensions
[2011/10/16 17:07:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sam\AppData\Roaming\mozilla\Extensions\[email protected]
[2012/02/14 08:27:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sam\AppData\Roaming\mozilla\Firefox\Profiles\xqhe8rpc.default\extensions
[2012/01/06 16:22:01 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Sam\AppData\Roaming\mozilla\Firefox\Profiles\xqhe8rpc.default\extensions\[email protected]
[2012/01/31 14:08:01 | 000,000,000 | ---D | M] (rein) -- C:\Users\Sam\AppData\Roaming\mozilla\Firefox\Profiles\xqhe8rpc.default\extensions\[email protected]
[2011/11/18 12:42:21 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Sam\AppData\Roaming\mozilla\Firefox\Profiles\xqhe8rpc.default\extensions\[email protected]
[2012/01/03 17:28:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\{097D3191-E6FA-4728-9826-B533D755359D}.XPI
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\{64161300-E22B-11DB-8314-0800200C9A66}.XPI
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\{A7C6CF7F-112C-4500-A7EA-39801A327E5F}.XPI
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\{C45C406E-AB73-11D8-BE73-000A95BE3B12}.XPI
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\{D47A9F51-8281-43FA-F450-F28EF8735E9A}.XPI
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\SAM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XQHE8RPC.DEFAULT\EXTENSIONS\[email protected]
[2012/02/12 18:51:27 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/01/03 17:28:25 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/03 17:28:25 | 000,001,892 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bolcom-nl.xml
[2012/01/03 17:28:25 | 000,004,558 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\marktplaats-nl.xml
[2012/01/03 17:28:25 | 000,001,049 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-nl.xml
O1 HOSTS File: ([2012/02/14 16:43:13 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" File not found
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Sam\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.2.0)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7FEA4FC0-2D32-498F-8308-3FA5AF02E877}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C303EEE4-A7FA-4C58-8D90-BFF878F38DA9}: DhcpNameServer = 195.130.131.11 195.130.130.11
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/14 16:41:25 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/02/14 08:30:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/02/14 08:30:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/02/14 08:30:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/02/14 08:30:39 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/02/14 08:30:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/14 08:02:46 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\QuickScan
[2012/02/14 07:56:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/02/14 07:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/02/13 11:23:52 | 000,000,000 | ---D | C] -- C:\Users\Sam\www
[2012/02/12 21:21:58 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\TeamViewer
[2012/02/10 22:05:45 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AutoHotkey
[2012/02/10 18:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
[2012/02/10 18:19:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AutoHotkey
[2012/02/10 11:38:03 | 000,035,112 | ---- | C] (TeamViewer GmbH) -- C:\Windows\SysNative\drivers\teamviewervpn.sys
[2012/02/10 11:37:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2012/02/08 15:15:43 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\Creative Boxes
[2012/02/08 14:20:02 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\Sun
[2012/02/08 14:04:04 | 000,000,000 | ---D | C] -- C:\Users\Sam\.netbeans-derby
[2012/02/08 10:31:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio
[2012/02/08 10:31:07 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2012/02/08 10:30:34 | 002,604,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2012/02/08 10:30:33 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2012/02/08 10:30:33 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2012/02/08 10:30:32 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2012/02/08 10:30:32 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2012/02/08 10:30:23 | 000,376,936 | ---- | C] (Realtek Semiconductor) -- C:\Windows\SysNative\RtkGuiCompLib.dll
[2012/02/08 10:30:21 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2012/02/08 10:30:21 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2012/02/08 10:30:20 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2012/02/08 10:30:20 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2012/02/08 10:30:18 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2012/02/08 10:30:18 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2012/02/08 10:30:10 | 003,768,152 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek.dll
[2012/02/08 10:30:10 | 000,702,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek2.dll
[2012/02/08 10:30:10 | 000,334,680 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2012/02/08 10:30:09 | 002,132,824 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2012/02/08 10:30:09 | 000,341,336 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
[2012/02/08 10:30:09 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2012/02/08 10:29:52 | 002,085,440 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2012/02/08 10:29:51 | 000,693,352 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2012/02/08 10:29:50 | 000,712,296 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2012/02/08 10:29:49 | 001,756,264 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2012/02/08 10:29:48 | 001,568,360 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2012/02/08 10:29:46 | 000,491,112 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2012/02/08 10:29:44 | 000,432,744 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
[2012/02/08 10:29:43 | 000,242,792 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
[2012/02/08 10:29:42 | 000,241,768 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
[2012/02/08 10:29:41 | 000,242,792 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
[2012/02/08 10:29:38 | 000,428,648 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2012/02/08 10:29:35 | 001,486,952 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
[2012/02/08 10:29:35 | 000,728,680 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2012/02/08 10:27:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2012/02/08 10:06:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JMicron
[2012/02/07 20:32:44 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2012/02/07 19:21:08 | 000,015,568 | ---- | C] (MaxiVista) -- C:\Windows\SysNative\drivers\mvCmdemo.SYS
[2012/02/07 19:20:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MaxiVista Demo Server
[2012/02/07 19:20:22 | 000,039,120 | ---- | C] (Maxivsta) -- C:\Windows\SysNative\mvvideodemo.dll
[2012/02/07 19:20:22 | 000,014,544 | ---- | C] (MaxiVista) -- C:\Windows\SysNative\drivers\mvvideodemo.sys
[2012/02/07 19:20:21 | 000,000,000 | ---D | C] -- C:\Program Files\MaxiVista Demo Server
[2012/02/07 17:56:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse
[2012/02/07 17:56:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft IntelliPoint
[2012/02/03 20:56:03 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\PunkBuster
[2012/02/01 00:37:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell
[2012/02/01 00:37:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Dell
[2012/01/30 23:52:53 | 000,000,000 | ---D | C] -- C:\Users\Sam\AppData\Roaming\VOS
[2012/01/30 16:53:02 | 000,000,000 | ---D | C] -- C:\.netbeans
[2012/01/28 14:54:35 | 000,000,000 | ---D | C] -- C:\MyGame
========== Files - Modified Within 30 Days ==========
[2012/02/14 17:32:22 | 003,181,004 | ---- | M] () -- C:\Users\Sam\Desktop\t.nfo
[2012/02/14 17:19:09 | 000,000,428 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
[2012/02/14 16:51:49 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/14 16:51:49 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/14 16:50:43 | 001,678,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/14 16:50:43 | 000,748,464 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2012/02/14 16:50:43 | 000,657,218 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/02/14 16:50:43 | 000,154,538 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2012/02/14 16:50:43 | 000,122,990 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/02/14 16:44:30 | 000,000,300 | ---- | M] () -- C:\Windows\tasks\ojefuwb.job
[2012/02/14 16:44:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/14 16:44:17 | 2064,252,927 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/14 16:43:13 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012/02/14 08:10:37 | 000,007,642 | ---- | M] () -- C:\Users\Sam\AppData\Local\resmon.resmoncfg
[2012/02/14 08:06:25 | 000,000,036 | ---- | M] () -- C:\Users\Sam\AppData\Local\housecall.guid.cache
[2012/02/14 07:57:13 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/02/14 07:56:58 | 001,700,724 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/13 18:39:02 | 000,102,400 | RHS- | M] () -- C:\Windows\SysWow64\Dism8.dll
[2012/02/12 18:50:54 | 000,001,130 | ---- | M] () -- C:\Users\Sam\Desktop\Team Server RC.lnk
[2012/02/11 10:26:59 | 004,904,008 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/11 00:58:36 | 000,001,582 | ---- | M] () -- C:\Users\Sam\Desktop\Team Server Final.lnk
[2012/02/10 18:45:05 | 000,001,351 | ---- | M] () -- D:\Documents\AutoHotkey.ahk
[2012/02/10 11:38:09 | 000,001,134 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/02/08 10:31:14 | 000,074,452 | ---- | M] () -- C:\Windows\SysNative\drivers\RTWAVES30.dat
[2012/02/08 10:28:38 | 000,018,980 | ---- | M] () -- C:\Windows\SysNative\results.xml
[2012/02/07 19:24:32 | 000,000,003 | ---- | M] () -- C:\Windows\SysNative\OutN64proc64.dll
[2012/02/07 19:24:32 | 000,000,001 | ---- | M] () -- C:\Windows\SysNative\InN64proc64.dll
[2012/02/04 20:55:14 | 000,000,951 | ---- | M] () -- C:\Users\Public\Desktop\Pidgin.lnk
[2012/02/03 20:56:06 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/02/03 20:56:05 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/02/01 11:28:47 | 000,001,014 | ---- | M] () -- C:\Users\Sam\Desktop\Dropbox.lnk
[2012/02/01 11:28:47 | 000,000,994 | ---- | M] () -- C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/01/29 13:16:40 | 000,000,478 | ---- | M] () -- C:\project.ini
[2012/01/27 13:38:30 | 000,000,830 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ==========
[2012/02/14 17:32:20 | 003,181,004 | ---- | C] () -- C:\Users\Sam\Desktop\t.nfo
[2012/02/14 08:30:46 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/14 08:30:46 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/14 08:30:46 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/02/14 08:30:46 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/02/14 08:30:46 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/02/14 08:06:25 | 000,000,036 | ---- | C] () -- C:\Users\Sam\AppData\Local\housecall.guid.cache
[2012/02/14 07:56:55 | 000,001,905 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/02/13 23:37:15 | 000,007,642 | ---- | C] () -- C:\Users\Sam\AppData\Local\resmon.resmoncfg
[2012/02/13 18:39:02 | 000,102,400 | RHS- | C] () -- C:\Windows\SysWow64\Dism8.dll
[2012/02/13 18:39:02 | 000,000,300 | ---- | C] () -- C:\Windows\tasks\ojefuwb.job
[2012/02/12 18:50:54 | 000,001,130 | ---- | C] () -- C:\Users\Sam\Desktop\Team Server RC.lnk
[2012/02/11 10:25:53 | 004,904,008 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/11 00:58:36 | 000,001,582 | ---- | C] () -- C:\Users\Sam\Desktop\Team Server Final.lnk
[2012/02/10 18:45:05 | 000,001,351 | ---- | C] () -- D:\Documents\AutoHotkey.ahk
[2012/02/10 11:38:09 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012/02/10 11:38:09 | 000,001,134 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/02/07 19:24:32 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\OutN64proc64.dll
[2012/02/07 19:24:32 | 000,000,001 | ---- | C] () -- C:\Windows\SysNative\InN64proc64.dll
[2012/02/03 20:56:06 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/02/03 20:56:04 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/01/29 13:16:40 | 000,000,478 | ---- | C] () -- C:\project.ini
[2012/01/08 21:51:41 | 000,000,131 | ---- | C] () -- C:\Users\Sam\AppData\Roaming\CairoAppConfig.xml
[2012/01/08 21:50:38 | 000,000,210 | ---- | C] () -- C:\Users\Sam\AppData\Roaming\CairoStacksConfig.xml
[2011/12/25 23:37:00 | 000,000,600 | ---- | C] () -- C:\Users\Sam\AppData\Local\PUTTY.RND
[2011/12/25 18:31:36 | 000,016,410 | ---- | C] () -- C:\Windows\UN900119.INI
[2011/12/24 13:29:52 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/12/24 13:29:51 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011/12/24 13:29:50 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/11/04 17:19:00 | 000,117,332 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/10/15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/10/06 21:35:13 | 000,000,132 | ---- | C] () -- C:\Users\Sam\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/09/17 20:08:29 | 000,062,299 | ---- | C] () -- C:\Windows\hpqins01.dat
[2011/09/16 18:03:19 | 000,208,000 | ---- | C] () -- C:\Windows\hpoins31.dat
[2011/09/16 18:03:19 | 000,000,873 | ---- | C] () -- C:\Windows\hpomdl31.dat
[2011/08/28 19:00:45 | 000,050,688 | ---- | C] () -- C:\Users\Sam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/25 22:46:24 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/08/25 22:46:24 | 000,000,023 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2011/08/23 18:30:21 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2011/08/23 18:30:21 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_8a.bin
[2011/08/23 18:30:21 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_2B0f1461_ca.bin
[2011/08/23 18:30:21 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2011/08/23 18:30:21 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_0B0f1461_ca.bin
[2011/08/23 18:30:21 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2011/08/23 18:30:21 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2011/08/23 18:30:21 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
[2011/08/23 18:16:47 | 001,700,724 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/23 17:42:31 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/08/23 17:42:30 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/12/01 22:17:08 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\.minecraft
[2012/02/04 23:04:06 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\.purple
[2011/10/23 00:01:09 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/02/07 20:07:23 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\DAEMON Tools Lite
[2012/02/14 17:41:01 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Dropbox
[2011/09/05 18:52:54 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\gtk-2.0
[2011/09/01 12:48:40 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Image-Line
[2011/10/23 00:17:28 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\LolClient
[2012/02/12 23:22:25 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\MediaMonkey
[2011/08/28 13:44:25 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\My Battle for Middle-earth™ II Files
[2011/08/25 21:35:54 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
[2012/01/07 02:15:40 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Nokia
[2012/01/07 01:39:35 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Nokia Ovi Suite
[2012/01/07 02:15:40 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Nokia Suite
[2012/02/07 20:07:22 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Notepad++
[2011/08/28 18:50:41 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\PC Suite
[2011/10/16 17:07:28 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Prism
[2012/02/03 20:56:03 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\PunkBuster
[2012/02/14 08:02:52 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\QuickScan
[2012/02/11 00:47:09 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Racket
[2011/08/28 00:23:42 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\SPORE
[2011/08/23 17:31:56 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\SystemRequirementsLab
[2012/02/12 21:21:58 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\TeamViewer
[2011/08/29 11:44:25 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\The Creative Assembly
[2011/08/28 19:31:26 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\Ubisoft
[2012/01/30 23:52:53 | 000,000,000 | ---D | M] -- C:\Users\Sam\AppData\Roaming\VOS
[2012/02/14 16:44:30 | 000,000,300 | ---- | M] () -- C:\Windows\Tasks\ojefuwb.job
[2011/12/20 09:59:00 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Edited by Sam Vervaeck, 18 February 2012 - 08:15 AM.