I've come to this forum before and thought my problem was solved but recently found out that someone seems to have accses to where I go online and he uses this info to help harrass me. I also think he might have hacked into my YouTube channel and possibly my Google account despite me having changed passwords and using Keyword Scrambler and Roboform.
From something he posted I suspect that he(and his buddy)also knows that I visited this forum. I'd be very grateful if you guys could help me out.
Thanks xx
I'm using Windows 7, 32- bit Operating system, AMD Athlon( tm) II P320 dual Core Process 2.10 GHz.
Here my OTL scan
OTL logfile created on: 09/02/2015 12:18:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.50 Gb Total Physical Memory | 1.52 Gb Available Physical Memory | 43.43% Memory free
6.99 Gb Paging File | 4.75 Gb Available in Paging File | 67.95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224.73 Gb Total Space | 123.28 Gb Free Space | 54.86% Space Free | Partition Type: NTFS
Drive D: | 628.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 73.36 Gb Total Space | 58.23 Gb Free Space | 79.38% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015/02/09 12:17:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
PRC - [2015/02/08 13:37:42 | 000,232,264 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
PRC - [2015/01/23 11:37:02 | 000,338,032 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2014/12/21 11:21:24 | 000,110,160 | ---- | M] (Siber Systems) -- C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/12/18 17:13:16 | 001,676,344 | ---- | M] (Spotify Ltd) -- C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2014/12/11 11:36:04 | 000,089,864 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
PRC - [2014/12/11 11:34:48 | 000,217,864 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Hp\Common\HpDeviceDetection3.exe
PRC - [2014/12/09 04:45:28 | 039,207,112 | ---- | M] (Dropbox, Inc.) -- C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014/10/29 23:25:46 | 004,673,432 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\User\AppData\Local\Akamai\netsession_win.exe
PRC - [2014/10/29 17:18:30 | 004,826,904 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2014/10/26 15:52:28 | 000,508,744 | ---- | M] (QFX Software Corporation) -- C:\Program Files\KeyScrambler\KeyScrambler.exe
PRC - [2014/08/22 17:54:49 | 000,142,648 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2014/08/01 14:11:23 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/08/01 14:08:43 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/05/17 00:32:48 | 000,919,040 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\bin\cmw_srv.exe
PRC - [2014/05/16 23:34:14 | 000,430,344 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2014/04/09 14:13:04 | 000,279,456 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
PRC - [2014/01/10 06:26:44 | 001,861,968 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2013/11/04 13:42:10 | 001,228,504 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe
PRC - [2013/11/04 13:42:08 | 000,660,184 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe
PRC - [2013/11/04 13:42:08 | 000,565,464 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psi_tray.exe
PRC - [2013/09/24 12:49:26 | 029,395,264 | ---- | M] (SlimWare Utilities, Inc.) -- C:\Program Files\SlimDrivers\SlimDrivers.exe
PRC - [2013/01/11 06:31:55 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2011/10/03 19:59:48 | 000,180,552 | ---- | M] (Solid Documents, LLC) -- C:\Program Files\SolidDocuments\SolidPDFCreator\SPC\SolidPdfService.exe
PRC - [2011/06/05 19:18:33 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/09/20 00:56:14 | 000,380,928 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2010/09/20 00:55:48 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2010/02/05 09:50:20 | 000,907,264 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files\Realtek\Audio\OSD\RtVOsd.exe
PRC - [2010/02/05 09:50:20 | 000,087,968 | ---- | M] (Andrea Electronics Corporation) -- C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
PRC - [2009/07/14 02:14:41 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StikyNot.exe
PRC - [2009/02/07 01:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2005/08/23 20:00:48 | 000,430,080 | ---- | M] (J. Eric Vaughan) -- C:\Program Files\Stay On Top\StayOnTop.exe
PRC - [2000/01/01 01:00:00 | 000,026,112 | ---- | M] (LSI Corporation) -- C:\Program Files\LSI SoftModem\agrsmsvc.exe
========== Modules (No Company Name) ==========
MOD - [2015/02/09 11:57:17 | 000,043,008 | ---- | M] () -- c:\users\user\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfaclmg.dll
MOD - [2015/01/23 11:37:32 | 003,925,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014/10/22 01:22:50 | 000,750,080 | ---- | M] () -- C:\Users\User\AppData\Roaming\Dropbox\bin\libGLESv2.dll
MOD - [2014/10/22 01:22:50 | 000,047,616 | ---- | M] () -- C:\Users\User\AppData\Roaming\Dropbox\bin\libEGL.dll
MOD - [2014/10/22 01:22:48 | 000,863,744 | ---- | M] () -- C:\Users\User\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
MOD - [2014/10/22 01:22:46 | 000,200,704 | ---- | M] () -- C:\Users\User\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
MOD - [2014/08/01 14:08:53 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/08/01 14:08:48 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2014/05/12 10:49:04 | 000,260,608 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_06.dll
MOD - [2014/01/10 06:28:18 | 000,100,688 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2014/01/10 06:26:44 | 001,861,968 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2013/09/05 00:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/10/20 15:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2007/09/21 02:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Perfect World Entertainment\Arc\ArcService.exe -- (ArcService)
SRV - [2015/02/05 20:20:12 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/01/23 11:37:25 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/12/11 11:36:04 | 000,089,864 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2014/12/11 10:30:48 | 000,315,496 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014/11/22 02:55:14 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/08/22 17:54:49 | 000,142,648 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2014/08/01 14:08:43 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014/07/26 16:40:55 | 000,024,576 | ---- | M] (Realtek Semiconductor.) [Auto | Stopped] -- C:\Program Files\Realtek\Audio\SetupAfterRebootService.exe -- (SetupARService)
SRV - [2014/05/17 01:44:24 | 000,078,512 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
SRV - [2014/05/17 00:32:48 | 000,919,040 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\cmw_srv.exe -- (hshld)
SRV - [2014/05/16 23:34:14 | 000,430,344 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2014/04/09 14:12:50 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe -- (McComponentHostService)
SRV - [2013/12/19 00:41:02 | 030,814,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2013/11/04 13:42:10 | 001,228,504 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2013/11/04 13:42:08 | 000,660,184 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2013/07/12 23:34:05 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/11/24 21:49:19 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/10/03 19:59:48 | 000,180,552 | ---- | M] (Solid Documents, LLC) [Auto | Running] -- C:\Program Files\SolidDocuments\SolidPDFCreator\SPC\SolidPdfService.exe -- (SPDFCreatorReadSpool)
SRV - [2010/09/20 00:55:48 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2010/03/16 05:12:19 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/02/05 09:50:20 | 000,087,968 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe -- (AERTFilters)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/02/07 01:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2000/01/01 01:00:00 | 000,026,112 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva409.sys -- (XDva409)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva405.sys -- (XDva405)
DRV - File not found [File_System | On_Demand | Stopped] -- C:\Program Files\Razer\Razer Game Booster\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\RimUsb.sys -- (RimUsb)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\User\AppData\Local\Temp\_MEI20402\drivers\winpmem32.sys -- (pmem)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\User\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Auto | Stopped] -- -- (adfs)
DRV - [2015/02/09 11:56:21 | 000,013,464 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SWDUMon.sys -- (SWDUMon)
DRV - [2014/11/22 01:40:32 | 000,779,536 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsnx.sys -- (aswSnx)
DRV - [2014/08/01 14:11:17 | 000,414,520 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsp.sys -- (aswSP)
DRV - [2014/08/01 14:08:57 | 000,192,352 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014/08/01 14:08:57 | 000,081,768 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014/08/01 14:08:57 | 000,071,944 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswStm.sys -- (aswStm)
DRV - [2014/08/01 14:08:57 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014/08/01 14:08:57 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014/08/01 14:08:57 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2014/05/17 03:33:08 | 000,039,624 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\hssdrv6.sys -- (HssDRV6)
DRV - [2014/05/17 01:41:54 | 000,037,064 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss6.sys -- (taphss6)
DRV - [2013/12/04 22:34:14 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003)
DRV - [2013/11/04 13:42:02 | 000,016,024 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\psi_mf_x86.sys -- (PSI)
DRV - [2013/10/28 01:12:12 | 000,182,680 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013/10/02 01:42:31 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2013/08/25 21:17:26 | 003,234,304 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2013/05/31 15:53:18 | 000,209,016 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\keyscrambler.sys -- (KeyScrambler)
DRV - [2013/05/22 17:49:34 | 000,015,672 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2013/04/03 08:58:16 | 000,083,864 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012/10/23 23:39:46 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012/07/20 11:12:36 | 000,025,088 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcaudrv.sys -- (mcaudrv_simple)
DRV - [2012/07/20 11:11:58 | 000,034,432 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcvidrv.sys -- (ManyCam)
DRV - [2011/07/22 17:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 22:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/03/07 10:20:08 | 000,015,896 | ---- | M] (HandSet Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter_hs.sys -- (massfilter_hs)
DRV - [2010/11/20 04:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 04:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 04:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 01:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 01:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 01:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/09/22 20:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2010/09/20 01:13:18 | 006,380,544 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2010/09/20 01:13:18 | 006,380,544 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2010/09/19 18:20:44 | 000,221,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010/07/27 14:27:41 | 000,035,363 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\windrvNT.sys -- (windrvNT)
DRV - [2010/06/22 03:51:14 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 00:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2000/01/01 01:00:00 | 001,163,328 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2000/01/01 01:00:00 | 000,197,736 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.mystartse...q={searchTerms}
IE - HKCU\..\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}: "URL" = http://www.mystartse...q={searchTerms}
IE - HKCU\..\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}: "URL" = http://www.mystartse...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = [String data over 1000 bytes]
========== FireFox ==========
FF - prefs.js..browser.search.hiddenOneOffs: "mystartsearch"
FF - prefs.js..browser.search.highlightCount: 0
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.searchengine.alias: "mystartsearch"
FF - prefs.js..browser.search.searchengine.desc: "this is my first firefox searchEngine"
FF - prefs.js..browser.search.searchengine.iconURL: "http://www.mystartse...eb/favicon.ico"
FF - prefs.js..browser.search.searchengine.name: "mystartsearch"
FF - prefs.js..browser.search.searchengine.ptid: "smt"
FF - prefs.js..browser.search.searchengine.uid: "ST9320423AS_5VH3ENV8"
FF - prefs.js..browser.search.searchengine.url: "http://www.mystartse...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "mystartsearch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://my.yahoo.com/"
FF - prefs.js..extensions.enabledAddons: personas%40christopher.beard:1.7.3
FF - prefs.js..extensions.enabledAddons: amznUWL2%40amazon.com:1.10
FF - prefs.js..extensions.enabledAddons: doubleclick2reloadtab%40linhph.com:1.0.1
FF - prefs.js..extensions.enabledAddons: firerainbow%40hildebrand.cz:1.5
FF - prefs.js..extensions.enabledAddons: %7B06997db0-c027-4d5f-bd37-b0d9230226ea%7D:0.63
FF - prefs.js..extensions.enabledAddons: %7Baede9b05-c23c-479b-a90e-9146ed62d377%7D:1.2.1
FF - prefs.js..extensions.enabledAddons: duplicate-this-tab%40mozilla.org:1.3
FF - prefs.js..extensions.enabledAddons: passhash%40mozilla.wijjo.com:1.1.7
FF - prefs.js..extensions.enabledAddons: clearrecenthistory%40example.net:1.1.20
FF - prefs.js..extensions.enabledAddons: %7B15a7ef52-8a77-426e-9e17-e21af257d7c8%7D:1.8.5
FF - prefs.js..extensions.enabledAddons: amazononclick%40martin.schreiber:1.2
FF - prefs.js..extensions.enabledAddons: gmail_panel%40alejandrobrizuela.com.ar:1.1.1
FF - prefs.js..extensions.enabledAddons: %7B75CEEE46-9B64-46f8-94BF-54012DE155F0%7D:0.4.14
FF - prefs.js..extensions.enabledAddons: %7B73007fef-a6e0-47d3-b4e7-dfc116ed6f65%7D:1.15
FF - prefs.js..extensions.enabledAddons: %7B3e0e7d2a-070f-4a47-b019-91fe5385ba79%7D:3.6.5
FF - prefs.js..extensions.enabledAddons: simpletimer%40grbradt.org:2.0.3
FF - prefs.js..extensions.enabledAddons: %7BC0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9%7D:0.7.5
FF - prefs.js..extensions.enabledAddons: anttoolbar%40ant.com:2.4.7.27
FF - prefs.js..extensions.enabledAddons: %7BFC5BAC7D-D696-4ba6-B913-CF8F000C33DF%7D:6.0.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0.1
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.5.9
FF - prefs.js..extensions.enabledItems: {7F23E3F4-F72E-4f4f-8761-854C8942708F}:1.2.6
FF - prefs.js..extensions.enabledItems: [email protected]:9.0.2006.53
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.172
FF - prefs.js..extensions.enabledItems: [email protected]:0.3
FF - prefs.js..extensions.enabledItems: [email protected]:3.0.4
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1215155.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/UCPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin: C:\Program Files\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@siber.com/RoboForm: C:\Program Files\Siber Systems\AI RoboForm\chrome\plugin\np-rf-plugin.dll (Siber Systems Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\User\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\thehappycloud.com/HappyCloudPlugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2013/06/29 10:02:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C3949AC2-4B17-43ee-B4F1-D26B9D42404D}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2013/06/29 10:02:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/08/08 08:32:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2014/12/21 11:22:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2015/01/27 15:31:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Pale Moon 24.6.1\extensions\\Components: C:\Program Files\Pale Moon\components [2015/01/13 00:55:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Pale Moon 24.6.1\extensions\\Plugins: C:\Program Files\Pale Moon\plugins [2015/01/13 00:55:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014/04/04 11:36:14 | 000,010,691 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2014/12/21 11:22:03 | 000,000,000 | ---D | M]
[2014/07/21 14:26:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions
[2014/07/21 14:26:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions\[email protected]
[2014/08/05 16:19:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extension-data
[2014/08/05 16:19:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extension-data\[email protected]
[2015/02/09 00:03:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions
[2014/08/05 14:56:28 | 000,000,000 | ---D | M] (Remove Cookies for Site) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\{06997db0-c027-4d5f-bd37-b0d9230226ea}
[2014/12/04 21:58:01 | 000,000,000 | ---D | M] (Lightshot (screenshot tool)) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\{394DCBA4-1F92-4f8e-8EC9-8D2CB90CB69B}
[2015/01/13 20:40:53 | 000,000,000 | ---D | M] (AddThis) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2014/10/15 15:44:27 | 000,000,000 | ---D | M] (New Tab King) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\{FC5BAC7D-D696-4ba6-B913-CF8F000C33DF}
[2014/08/05 14:29:19 | 000,000,000 | ---D | M] (Add to Amazon Wish List Button) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/09 00:03:54 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2014/11/04 11:17:22 | 000,000,000 | ---D | M] (Clear Recent History... +) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/06 11:43:33 | 000,000,000 | ---D | M] (Blur (Formerly DoNotTrackMe)) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2014/08/05 14:56:28 | 000,000,000 | ---D | M] (Double-click To Reload Tab) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2014/08/05 14:56:28 | 000,000,000 | ---D | M] (FireRainbow) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2014/10/12 20:41:28 | 000,000,000 | ---D | M] ("Password Hasher") -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\extensions\[email protected]
[2014/04/08 15:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\jetpack\[email protected]
[2014/04/08 15:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\jetpack\[email protected]\simple-storage
[2014/12/06 14:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\jetpack\[email protected]
[2014/12/06 14:07:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\rcdgk3lo.default\jetpack\[email protected]\simple-storage
[2014/11/29 23:19:07 | 000,010,102 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/08/05 18:03:30 | 000,169,469 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/05 22:45:43 | 002,558,942 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/06 11:53:45 | 001,443,602 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/12/23 19:30:54 | 000,033,116 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/11/26 18:57:22 | 000,516,357 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/04 16:08:26 | 000,328,123 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/01/31 14:26:56 | 000,185,312 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/12/13 22:47:50 | 000,096,404 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/08/05 16:19:40 | 000,144,716 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/12/06 14:02:43 | 000,447,686 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/08/05 16:19:40 | 000,348,260 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/03 23:31:21 | 000,002,736 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/01/07 17:51:11 | 001,183,704 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/01/26 23:09:26 | 000,206,833 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2014/08/05 16:19:40 | 000,012,030 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\[email protected]
[2015/02/06 11:58:43 | 000,086,000 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{023e9ca0-63f3-47b1-bcb2-9badf9d9ef28}.xpi
[2014/11/25 22:58:48 | 000,268,530 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{15a7ef52-8a77-426e-9e17-e21af257d7c8}.xpi
[2014/10/08 12:06:48 | 000,105,141 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi
[2015/02/06 12:00:12 | 000,050,602 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{6BB5760D-F97E-421B-AF5B-8457A90C3CED}.xpi
[2015/01/10 19:23:25 | 000,013,127 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{73007fef-a6e0-47d3-b4e7-dfc116ed6f65}.xpi
[2014/12/25 17:54:00 | 000,030,813 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi
[2015/01/22 21:19:33 | 000,027,016 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{95322c08-05ff-4f3c-85fd-8ceb821988dd}.xpi
[2014/08/05 18:03:30 | 000,002,245 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{aede9b05-c23c-479b-a90e-9146ed62d377}.xpi
[2014/11/13 20:37:04 | 000,129,475 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi
[2015/02/03 17:27:24 | 000,224,629 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9}.xpi
[2014/10/15 17:45:29 | 000,073,612 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi
[2015/01/15 17:53:10 | 000,985,112 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2015/01/10 19:47:15 | 000,004,929 | ---- | M] () -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\searchplugins\google-images.xml
[2013/06/14 21:21:43 | 000,000,910 | ---- | M] () -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\rcdgk3lo.default\searchplugins\yahoo.xml
[2015/02/06 22:33:23 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2015/02/06 22:33:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2015/01/27 15:31:32 | 000,000,000 | ---D | M] (Hotspot Shield Extension) -- C:\Program Files\Mozilla Firefox\browser\extensions\[email protected]
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\40.0.2214.111\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\40.0.2214.111\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\40.0.2214.111\pdf.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 7 U25 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: RealNetworks Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1203133.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.16 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp\6.0.12_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob\7.9.12.2_0\
O1 HOSTS File: ([2014/01/31 13:01:26 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [KeyScrambler] C:\Program Files\KeyScrambler\keyscrambler.exe (QFX Software Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RtkOSD] C:\Program Files\Realtek\Audio\OSD\RtVOsd.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\User\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\User\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKLM..\RunOnce: [NCPluginUpdater] c:\program files\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Save the YouTube video as MP3 - C:\Users\User\AppData\Roaming\Free YouTube to MP3 Converter Studio\Free YouTube to MP3 Converter Studio.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: Customize Menu - file://C:/Program Files/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Fill Forms - file://C:/Program Files/Siber Systems/AI RoboForm/RoboFormComFillForms.html File not found
O8 - Extra context menu item: Save Forms - file://C:/Program Files/Siber Systems/AI RoboForm/RoboFormComSavePass.html File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Show RoboForm Toolbar - file://C:/Program Files/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Show RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5794603A-7296-4361-A208-8D2B25CE0365}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{922811CB-89F2-4B4F-B615-FB20EB03AB4A}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2013/12/18 18:37:08 | 000,000,897 | ---- | M] () - C:\autoupdate.log -- [ NTFS ]
O32 - AutoRun File - [2000/11/02 14:44:46 | 000,000,040 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (bootdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015/02/09 12:17:29 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2015/02/09 12:04:45 | 006,195,168 | ---- | C] (Hewlett-Packard Company ) -- C:\Users\User\Desktop\sp45229.exe
[2015/02/09 12:04:30 | 044,135,360 | ---- | C] (Hewlett-Packard ) -- C:\Users\User\Desktop\sp50718.exe
[2015/02/09 12:04:16 | 133,605,160 | ---- | C] (Hewlett-Packard ) -- C:\Users\User\Desktop\sp49519.exe
[2015/02/09 11:52:43 | 000,345,328 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2015/02/09 11:52:43 | 000,140,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2015/02/09 11:52:42 | 001,640,992 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2015/02/09 11:52:42 | 000,551,456 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2015/02/09 11:52:42 | 000,057,376 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInst.dll
[2015/02/09 11:52:41 | 002,622,496 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll
[2015/02/09 11:52:41 | 000,371,232 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2015/02/09 11:52:41 | 000,357,576 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2015/02/09 11:52:41 | 000,293,584 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2015/02/09 11:52:41 | 000,293,584 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2015/02/09 11:52:41 | 000,168,648 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2015/02/09 11:52:41 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2015/02/09 11:52:41 | 000,062,664 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2015/02/09 11:52:39 | 000,145,760 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2015/02/09 11:52:39 | 000,096,160 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2015/02/09 02:19:23 | 000,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
[2015/02/09 02:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\Hp
[2015/02/06 22:01:47 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2015/02/02 01:08:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\MMFApplications
[2015/02/02 00:57:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Five Nights at Freddy's DEMO
[2015/02/02 00:56:51 | 000,000,000 | ---D | C] -- C:\Program Files\Five Nights at Freddy's DEMO
[2015/01/27 15:31:32 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2015/01/25 17:11:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2015/01/23 20:42:04 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2015/01/18 21:32:41 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\CafePress
[2015/01/18 16:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\paint.net
[2015/01/18 16:49:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\paint.net
[2015/01/18 15:04:40 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Imagina
[2015/01/18 15:01:35 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Planet Imagina
[2015/01/18 14:29:30 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP 2
[2015/01/17 19:57:11 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\FastStone
[2015/01/17 19:56:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
[2015/01/17 19:56:00 | 000,000,000 | ---D | C] -- C:\Program Files\FastStone Image Viewer
[2015/01/14 11:09:05 | 003,971,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2015/01/14 11:09:04 | 003,916,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2015/01/14 11:08:59 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe
[2015/01/13 00:54:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2015/01/12 14:50:48 | 000,000,000 | R--D | C] -- C:\Users\User\Desktop\scrapBYE
[2015/01/12 14:11:48 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\MyPaint
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015/02/09 12:22:56 | 000,020,704 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/02/09 12:22:56 | 000,020,704 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/02/09 12:20:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/02/09 12:17:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2015/02/09 12:07:25 | 133,605,160 | ---- | M] (Hewlett-Packard ) -- C:\Users\User\Desktop\sp49519.exe
[2015/02/09 12:05:21 | 044,135,360 | ---- | M] (Hewlett-Packard ) -- C:\Users\User\Desktop\sp50718.exe
[2015/02/09 12:04:52 | 006,195,168 | ---- | M] (Hewlett-Packard Company ) -- C:\Users\User\Desktop\sp45229.exe
[2015/02/09 11:57:22 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2015/02/09 11:56:21 | 000,013,464 | ---- | M] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2015/02/09 11:54:52 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/02/09 11:54:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/02/09 11:54:28 | 2814,558,208 | -HS- | M] () -- C:\hiberfil.sys
[2015/02/09 11:42:46 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/02/09 11:06:57 | 002,527,296 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2015/02/09 04:08:07 | 000,114,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2015/02/09 00:13:51 | 008,998,130 | ---- | M] () -- C:\Users\User\Desktop\Bryan Ferry - A Hard Rains A-Gonna Fall Official - YouTube.mp4
[2015/02/09 00:11:30 | 011,780,600 | ---- | M] () -- C:\Users\User\Desktop\Dana Fredsti.mp4
[2015/02/08 21:28:35 | 003,049,957 | ---- | M] () -- C:\Users\User\Desktop\2015-02-07 19.05.52.jpg
[2015/02/08 21:26:26 | 000,640,244 | ---- | M] () -- C:\Users\User\Desktop\2015-02-07 19.00.30.jpg
[2015/02/08 20:44:47 | 000,086,016 | -H-- | M] () -- C:\Users\User\Desktop\photothumb.db
[2015/02/08 18:33:06 | 002,728,696 | ---- | M] () -- C:\Users\User\Desktop\2015-02-08 01.10.01.jpg
[2015/02/08 18:31:17 | 003,952,133 | ---- | M] () -- C:\Users\User\Desktop\2015-02-08 01.08.42.jpg
[2015/02/08 13:34:49 | 000,697,506 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2015/02/08 13:34:49 | 000,662,634 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015/02/08 13:34:49 | 000,384,248 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2015/02/08 13:34:49 | 000,149,442 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2015/02/08 13:34:49 | 000,122,470 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015/02/08 13:34:49 | 000,119,918 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2015/02/07 15:05:01 | 008,749,661 | ---- | M] () -- C:\Users\User\Desktop\Bryan Ferry - A Hard Rain's A-Gonna Fall [Official].mp4
[2015/02/06 22:33:26 | 000,001,065 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2015/02/06 22:28:01 | 039,690,816 | ---- | M] () -- C:\Users\User\Desktop\Firefox Setup 35.0.1.exe
[2015/02/05 22:43:47 | 000,002,089 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2015/02/05 20:20:11 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015/02/05 20:20:11 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015/02/05 01:40:59 | 015,795,631 | ---- | M] () -- C:\Users\User\Desktop\Hollywood Undead - Outside (Official Lyric Video).mp4
[2015/02/05 01:32:35 | 020,690,486 | ---- | M] () -- C:\Users\User\Desktop\Jes Ebrahim - Keamanan (Promo MV).mp4
[2015/02/04 22:16:16 | 000,245,131 | ---- | M] () -- C:\Users\User\Desktop\Aldrin_Apollo_11_cropped.jpg
[2015/02/03 17:16:41 | 3869,692,740 | ---- | M] () -- C:\Users\User\Documents\User-PcMediaIDbin.zip
[2015/02/02 00:57:26 | 000,001,095 | ---- | M] () -- C:\Users\User\Desktop\Five Nights at Freddy's DEMO.lnk
[2015/01/28 23:19:31 | 000,303,498 | ---- | M] () -- C:\Users\User\Desktop\14860158820_a7d3ab7cd9_z.jpg
[2015/01/27 01:58:33 | 004,001,425 | ---- | M] () -- C:\Users\User\Desktop\Cintamu Mekar Di Hati - MAY _ HQ Lirik.mp3
[2015/01/27 01:57:44 | 000,001,069 | ---- | M] () -- C:\Users\User\Desktop\Free M4a to MP3 Converter.lnk
[2015/01/26 20:48:40 | 000,002,225 | ---- | M] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/01/26 20:48:40 | 000,001,134 | ---- | M] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2015/01/25 17:10:59 | 000,096,680 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2015/01/25 17:10:50 | 000,272,296 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2015/01/25 17:10:50 | 000,176,552 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2015/01/25 17:10:49 | 000,176,552 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2015/01/19 21:19:27 | 009,498,677 | ---- | M] () -- C:\Users\User\Desktop\14426030064_955dc6e406_o.jpg
[2015/01/18 16:50:29 | 000,001,136 | ---- | M] () -- C:\Users\Public\Desktop\paint.net.lnk
[2015/01/18 15:32:39 | 000,003,045 | ---- | M] () -- C:\Users\User\AppData\Local\recently-used.xbel
[2015/01/18 14:33:53 | 000,001,007 | ---- | M] () -- C:\Users\User\Desktop\GIMP 2.lnk
[2015/01/17 19:56:01 | 000,001,023 | ---- | M] () -- C:\Users\Public\Desktop\FastStone Image Viewer.lnk
[2015/01/14 02:00:47 | 003,473,795 | ---- | M] () -- C:\Users\User\Desktop\David Byrne & Brian Eno - Life is Long.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015/02/09 11:52:48 | 000,000,712 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2015/02/09 00:13:50 | 008,998,130 | ---- | C] () -- C:\Users\User\Desktop\Bryan Ferry - A Hard Rains A-Gonna Fall Official - YouTube.mp4
[2015/02/09 00:11:28 | 011,780,600 | ---- | C] () -- C:\Users\User\Desktop\Dana Fredsti.mp4
[2015/02/08 18:27:52 | 000,640,244 | ---- | C] () -- C:\Users\User\Desktop\2015-02-07 19.00.30.jpg
[2015/02/08 18:27:39 | 002,728,696 | ---- | C] () -- C:\Users\User\Desktop\2015-02-08 01.10.01.jpg
[2015/02/08 18:27:19 | 003,952,133 | ---- | C] () -- C:\Users\User\Desktop\2015-02-08 01.08.42.jpg
[2015/02/08 13:32:28 | 003,049,957 | ---- | C] () -- C:\Users\User\Desktop\2015-02-07 19.05.52.jpg
[2015/02/07 15:04:55 | 008,749,661 | ---- | C] () -- C:\Users\User\Desktop\Bryan Ferry - A Hard Rain's A-Gonna Fall [Official].mp4
[2015/02/06 22:33:26 | 000,001,077 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015/02/06 22:33:26 | 000,001,065 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2015/02/06 22:27:46 | 039,690,816 | ---- | C] () -- C:\Users\User\Desktop\Firefox Setup 35.0.1.exe
[2015/02/05 01:40:47 | 015,795,631 | ---- | C] () -- C:\Users\User\Desktop\Hollywood Undead - Outside (Official Lyric Video).mp4
[2015/02/05 01:31:40 | 020,690,486 | ---- | C] () -- C:\Users\User\Desktop\Jes Ebrahim - Keamanan (Promo MV).mp4
[2015/02/05 00:06:16 | 000,038,777 | ---- | C] () -- C:\Users\User\Desktop\in bread.jpg
[2015/02/04 22:16:14 | 000,245,131 | ---- | C] () -- C:\Users\User\Desktop\Aldrin_Apollo_11_cropped.jpg
[2015/02/03 17:14:23 | 3869,692,740 | ---- | C] () -- C:\Users\User\Documents\User-PcMediaIDbin.zip
[2015/02/02 00:57:26 | 000,001,095 | ---- | C] () -- C:\Users\User\Desktop\Five Nights at Freddy's DEMO.lnk
[2015/01/28 23:08:16 | 000,303,498 | ---- | C] () -- C:\Users\User\Desktop\14860158820_a7d3ab7cd9_z.jpg
[2015/01/27 01:58:21 | 004,001,425 | ---- | C] () -- C:\Users\User\Desktop\Cintamu Mekar Di Hati - MAY _ HQ Lirik.mp3
[2015/01/27 01:57:44 | 000,001,069 | ---- | C] () -- C:\Users\User\Desktop\Free M4a to MP3 Converter.lnk
[2015/01/19 21:19:13 | 009,498,677 | ---- | C] () -- C:\Users\User\Desktop\14426030064_955dc6e406_o.jpg
[2015/01/18 16:50:29 | 000,001,148 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
[2015/01/18 16:50:29 | 000,001,136 | ---- | C] () -- C:\Users\Public\Desktop\paint.net.lnk
[2015/01/18 15:32:39 | 000,003,045 | ---- | C] () -- C:\Users\User\AppData\Local\recently-used.xbel
[2015/01/18 14:33:53 | 000,001,007 | ---- | C] () -- C:\Users\User\Desktop\GIMP 2.lnk
[2015/01/18 14:32:19 | 000,001,007 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2015/01/17 19:56:01 | 000,001,023 | ---- | C] () -- C:\Users\Public\Desktop\FastStone Image Viewer.lnk
[2015/01/14 02:00:39 | 003,473,795 | ---- | C] () -- C:\Users\User\Desktop\David Byrne & Brian Eno - Life is Long.mp3
[2014/11/15 21:33:44 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2014/11/15 21:33:43 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2014/11/15 21:33:43 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2014/08/01 14:10:54 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014/03/22 17:33:37 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\zghsvousb.sys.dump
[2014/03/22 17:33:37 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\zghsnmea.sys.dump
[2014/03/22 17:33:37 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\zghsmdm.sys.dump
[2014/03/22 17:33:37 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\zghsdiag.sys.dump
[2014/03/22 17:33:36 | 000,155,136 | ---- | C] () -- C:\Windows\System32\drivers\WUDFRd.sys.dump
[2014/03/22 17:33:36 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\zghsat.sys.dump
[2014/03/22 17:33:36 | 000,066,560 | ---- | C] () -- C:\Windows\System32\drivers\WUDFPf.sys.dump
[2014/03/22 17:33:36 | 000,016,384 | ---- | C] () -- C:\Windows\System32\drivers\ws2ifsl.sys.dump
[2014/03/22 17:33:36 | 000,014,912 | ---- | C] () -- C:\Windows\System32\drivers\wmilib.sys.dump
[2014/03/22 17:33:35 | 000,043,392 | ---- | C] () -- C:\Windows\System32\drivers\winhv.sys.dump
[2014/03/22 17:33:35 | 000,035,968 | ---- | C] () -- C:\Windows\System32\drivers\winusb.sys.dump
[2014/03/22 17:33:35 | 000,019,008 | ---- | C] () -- C:\Windows\System32\drivers\wimmount.sys.dump
[2014/03/22 17:33:35 | 000,011,264 | ---- | C] () -- C:\Windows\System32\drivers\wmiacpi.sys.dump
[2014/03/22 17:33:35 | 000,009,728 | ---- | C] () -- C:\Windows\System32\drivers\wfplwf.sys.dump
[2014/03/22 17:33:34 | 000,527,064 | ---- | C] () -- C:\Windows\System32\drivers\Wdf01000.sys.dump
[2014/03/22 17:33:34 | 000,047,720 | ---- | C] () -- C:\Windows\System32\drivers\WdfLdr.sys.dump
[2014/03/22 17:33:34 | 000,035,328 | ---- | C] () -- C:\Windows\System32\drivers\watchdog.sys.dump
[2014/03/22 17:33:34 | 000,019,024 | ---- | C] () -- C:\Windows\System32\drivers\wd.sys.dump
[2014/03/22 17:33:33 | 000,063,488 | ---- | C] () -- C:\Windows\System32\drivers\wanarp.sys.dump
[2014/03/22 17:33:33 | 000,021,632 | ---- | C] () -- C:\Windows\System32\drivers\wacompen.sys.dump
[2014/03/22 17:33:33 | 000,014,336 | ---- | C] () -- C:\Windows\System32\drivers\vwifimp.sys.dump
[2014/03/22 17:33:32 | 000,297,040 | ---- | C] () -- C:\Windows\System32\drivers\volmgrx.sys.dump
[2014/03/22 17:33:32 | 000,245,632 | ---- | C] () -- C:\Windows\System32\drivers\volsnap.sys.dump
[2014/03/22 17:33:32 | 000,141,904 | ---- | C] () -- C:\Windows\System32\drivers\vsmraid.sys.dump
[2014/03/22 17:33:32 | 000,048,128 | ---- | C] () -- C:\Windows\System32\drivers\vwififlt.sys.dump
[2014/03/22 17:33:32 | 000,019,968 | ---- | C] () -- C:\Windows\System32\drivers\vwifibus.sys.dump
[2014/03/22 17:33:31 | 000,053,120 | ---- | C] () -- C:\Windows\System32\drivers\volmgr.sys.dump
[2014/03/22 17:33:31 | 000,040,704 | ---- | C] () -- C:\Windows\System32\drivers\vmstorfl.sys.dump
[2014/03/22 17:33:31 | 000,017,920 | ---- | C] () -- C:\Windows\System32\drivers\VMBusHID.sys.dump
[2014/03/22 17:33:31 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\vms3cap.sys.dump
[2014/03/22 17:33:30 | 000,175,360 | ---- | C] () -- C:\Windows\System32\drivers\vmbus.sys.dump
[2014/03/22 17:33:30 | 000,111,616 | ---- | C] () -- C:\Windows\System32\drivers\videoprt.sys.dump
[2014/03/22 17:33:30 | 000,053,328 | ---- | C] () -- C:\Windows\System32\drivers\VIAAGP.SYS.dump
[2014/03/22 17:33:30 | 000,052,736 | ---- | C] () -- C:\Windows\System32\drivers\viac7.sys.dump
[2014/03/22 17:33:30 | 000,016,976 | ---- | C] () -- C:\Windows\System32\drivers\viaide.sys.dump
[2014/03/22 17:33:29 | 000,160,128 | ---- | C] () -- C:\Windows\System32\drivers\vhdmp.sys.dump
[2014/03/22 17:33:29 | 000,032,832 | ---- | C] () -- C:\Windows\System32\drivers\vdrvroot.sys.dump
[2014/03/22 17:33:29 | 000,026,112 | ---- | C] () -- C:\Windows\System32\drivers\vgapnp.sys.dump
[2014/03/22 17:33:29 | 000,025,088 | ---- | C] () -- C:\Windows\System32\drivers\vga.sys.dump
[2014/03/22 17:33:28 | 000,146,816 | ---- | C] () -- C:\Windows\System32\drivers\usbvideo.sys.dump
[2014/03/22 17:33:28 | 000,076,288 | ---- | C] () -- C:\Windows\System32\drivers\USBSTOR.SYS.dump
[2014/03/22 17:33:28 | 000,024,064 | ---- | C] () -- C:\Windows\System32\drivers\usbuhci.sys.dump
[2014/03/22 17:33:27 | 000,284,672 | ---- | C] () -- C:\Windows\System32\drivers\usbport.sys.dump
[2014/03/22 17:33:27 | 000,026,112 | ---- | C] () -- C:\Windows\System32\drivers\usbrpm.sys.dump
[2014/03/22 17:33:27 | 000,020,480 | ---- | C] () -- C:\Windows\System32\drivers\usbohci.sys.dump
[2014/03/22 17:33:27 | 000,019,968 | ---- | C] () -- C:\Windows\System32\drivers\usbprint.sys.dump
[2014/03/22 17:33:26 | 000,258,560 | ---- | C] () -- C:\Windows\System32\drivers\usbhub.sys.dump
[2014/03/22 17:33:26 | 000,086,016 | ---- | C] () -- C:\Windows\System32\drivers\usbcir.sys.dump
[2014/03/22 17:33:26 | 000,043,520 | ---- | C] () -- C:\Windows\System32\drivers\usbehci.sys.dump
[2014/03/22 17:33:26 | 000,006,016 | ---- | C] () -- C:\Windows\System32\drivers\usbd.sys.dump
[2014/03/22 17:33:25 | 000,076,288 | ---- | C] () -- C:\Windows\System32\drivers\usbccgp.sys.dump
[2014/03/22 17:33:25 | 000,043,520 | ---- | C] () -- C:\Windows\System32\drivers\usbaapl.sys.dump
[2014/03/22 17:33:25 | 000,025,856 | ---- | C] () -- C:\Windows\System32\drivers\USBCAMD2.sys.dump
[2014/03/22 17:33:25 | 000,025,856 | ---- | C] () -- C:\Windows\System32\drivers\USBCAMD.sys.dump
[2014/03/22 17:33:25 | 000,015,872 | ---- | C] () -- C:\Windows\System32\drivers\usb8023.sys.dump
[2014/03/22 17:33:24 | 000,246,784 | ---- | C] () -- C:\Windows\System32\drivers\udfs.sys.dump
[2014/03/22 17:33:24 | 000,057,424 | ---- | C] () -- C:\Windows\System32\drivers\ULIAGPKX.SYS.dump
[2014/03/22 17:33:24 | 000,039,936 | ---- | C] () -- C:\Windows\System32\drivers\umbus.sys.dump
[2014/03/22 17:33:24 | 000,008,192 | ---- | C] () -- C:\Windows\System32\drivers\umpass.sys.dump
[2014/03/22 17:33:23 | 000,108,544 | ---- | C] () -- C:\Windows\System32\drivers\tunnel.sys.dump
[2014/03/22 17:33:23 | 000,055,888 | ---- | C] () -- C:\Windows\System32\drivers\UAGP35.SYS.dump
[2014/03/22 17:33:22 | 000,200,976 | ---- | C] () -- C:\Windows\System32\drivers\tmcomm.sys.dump
[2014/03/22 17:33:22 | 000,053,120 | ---- | C] () -- C:\Windows\System32\drivers\termdd.sys.dump
[2014/03/22 17:33:22 | 000,049,664 | ---- | C] () -- C:\Windows\System32\drivers\TsUsbFlt.sys.dump
[2014/03/22 17:33:22 | 000,031,232 | ---- | C] () -- C:\Windows\System32\drivers\tssecsrv.sys.dump
[2014/03/22 17:33:21 | 000,074,752 | ---- | C] () -- C:\Windows\System32\drivers\tdx.sys.dump
[2014/03/22 17:33:21 | 000,035,328 | ---- | C] () -- C:\Windows\System32\drivers\tcpipreg.sys.dump
[2014/03/22 17:33:21 | 000,024,576 | ---- | C] () -- C:\Windows\System32\drivers\tdtcp.sys.dump
[2014/03/22 17:33:21 | 000,021,504 | ---- | C] () -- C:\Windows\System32\drivers\tdi.sys.dump
[2014/03/22 17:33:21 | 000,018,432 | ---- | C] () -- C:\Windows\System32\drivers\tdpipe.sys.dump
[2014/03/22 17:33:20 | 001,294,272 | ---- | C] () -- C:\Windows\System32\drivers\tcpip.sys.dump
[2014/03/22 17:33:20 | 000,037,064 | ---- | C] () -- C:\Windows\System32\drivers\taphss6.sys.dump
[2014/03/22 17:33:19 | 000,299,312 | ---- | C] () -- C:\Windows\System32\drivers\SynTP.sys.dump
[2014/03/22 17:33:19 | 000,032,768 | ---- | C] () -- C:\Windows\System32\drivers\taphss.sys.dump
[2014/03/22 17:33:19 | 000,024,576 | ---- | C] () -- C:\Windows\System32\drivers\tape.sys.dump
[2014/03/22 17:33:18 | 000,013,464 | ---- | C] () -- C:\Windows\System32\drivers\SWDUMon.sys.dump
[2014/03/22 17:33:18 | 000,012,240 | ---- | C] () -- C:\Windows\System32\drivers\swenum.sys.dump
[2014/03/22 17:33:17 | 000,182,680 | ---- | C] () -- C:\Windows\System32\drivers\ssudmdm.sys.dump
[2014/03/22 17:33:17 | 000,148,864 | ---- | C] () -- C:\Windows\System32\drivers\storport.sys.dump
[2014/03/22 17:33:17 | 000,053,632 | ---- | C] () -- C:\Windows\System32\drivers\stream.sys.dump
[2014/03/22 17:33:17 | 000,028,032 | ---- | C] () -- C:\Windows\System32\drivers\storvsc.sys.dump
[2014/03/22 17:33:17 | 000,021,072 | ---- | C] () -- C:\Windows\System32\drivers\stexstor.sys.dump
[2014/03/22 17:33:16 | 000,311,808 | ---- | C] () -- C:\Windows\System32\drivers\srv.sys.dump
[2014/03/22 17:33:16 | 000,310,272 | ---- | C] () -- C:\Windows\System32\drivers\srv2.sys.dump
[2014/03/22 17:33:16 | 000,114,688 | ---- | C] () -- C:\Windows\System32\drivers\srvnet.sys.dump
[2014/03/22 17:33:16 | 000,083,864 | ---- | C] () -- C:\Windows\System32\drivers\ssudbus.sys.dump
[2014/03/22 17:33:15 | 000,405,504 | ---- | C] () -- C:\Windows\System32\drivers\spsys.sys.dump
[2014/03/22 17:33:15 | 000,071,168 | ---- | C] () -- C:\Windows\System32\drivers\smb.sys.dump
[2014/03/22 17:33:15 | 000,017,472 | ---- | C] () -- C:\Windows\System32\drivers\spldr.sys.dump
[2014/03/22 17:33:15 | 000,017,408 | ---- | C] () -- C:\Windows\System32\drivers\smclib.sys.dump
[2014/03/22 17:33:14 | 000,077,888 | ---- | C] () -- C:\Windows\System32\drivers\sisraid4.sys.dump
[2014/03/22 17:33:14 | 000,052,304 | ---- | C] () -- C:\Windows\System32\drivers\SISAGP.SYS.dump
[2014/03/22 17:33:14 | 000,040,016 | ---- | C] () -- C:\Windows\System32\drivers\sisraid2.sys.dump
[2014/03/22 17:33:14 | 000,015,672 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys.dump
[2014/03/22 17:33:13 | 000,013,824 | ---- | C] () -- C:\Windows\System32\drivers\sfloppy.sys.dump
[2014/03/22 17:33:13 | 000,012,800 | ---- | C] () -- C:\Windows\System32\drivers\sffp_sd.sys.dump
[2014/03/22 17:33:13 | 000,012,288 | ---- | C] () -- C:\Windows\System32\drivers\sffp_mmc.sys.dump
[2014/03/22 17:33:12 | 000,083,456 | ---- | C] () -- C:\Windows\System32\drivers\serial.sys.dump
[2014/03/22 17:33:12 | 000,019,968 | ---- | C] () -- C:\Windows\System32\drivers\sermouse.sys.dump
[2014/03/22 17:33:12 | 000,017,920 | ---- | C] () -- C:\Windows\System32\drivers\serenum.sys.dump
[2014/03/22 17:33:12 | 000,011,264 | ---- | C] () -- C:\Windows\System32\drivers\sffdisk.sys.dump
[2014/03/22 17:33:11 | 000,140,160 | ---- | C] () -- C:\Windows\System32\drivers\scsiport.sys.dump
[2014/03/22 17:33:11 | 000,085,376 | ---- | C] () -- C:\Windows\System32\drivers\sbp2port.sys.dump
[2014/03/22 17:33:11 | 000,084,992 | ---- | C] () -- C:\Windows\System32\drivers\sdbus.sys.dump
[2014/03/22 17:33:11 | 000,026,624 | ---- | C] () -- C:\Windows\System32\drivers\scfilter.sys.dump
[2014/03/22 17:33:11 | 000,020,480 | ---- | C] () -- C:\Windows\System32\drivers\secdrv.sys.dump
[2014/03/22 17:33:10 | 002,888,536 | ---- | C] () -- C:\Windows\System32\drivers\RTKVHDA.sys.dump
[2014/03/22 17:33:10 | 000,197,736 | ---- | C] () -- C:\Windows\System32\drivers\RtsUStor.sys.dump
[2014/03/22 17:33:09 | 000,394,856 | ---- | C] () -- C:\Windows\System32\drivers\Rt86win7.sys.dump
[2014/03/22 17:33:09 | 000,060,928 | ---- | C] () -- C:\Windows\System32\drivers\rspndr.sys.dump
[2014/03/22 17:33:09 | 000,033,280 | ---- | C] () -- C:\Windows\System32\drivers\RNDISMP.sys.dump
[2014/03/22 17:33:09 | 000,008,192 | ---- | C] () -- C:\Windows\System32\drivers\rootmdm.sys.dump
[2014/03/22 17:33:08 | 000,117,760 | ---- | C] () -- C:\Windows\System32\drivers\rmcast.sys.dump
[2014/03/22 17:33:07 | 000,183,808 | ---- | C] () -- C:\Windows\System32\drivers\rdpwd.sys.dump
[2014/03/22 17:33:07 | 000,173,440 | ---- | C] () -- C:\Windows\System32\drivers\rdyboost.sys.dump
[2014/03/22 17:33:07 | 000,129,536 | ---- | C] () -- C:\Windows\System32\drivers\rfcomm.sys.dump
[2014/03/22 17:33:07 | 000,027,136 | ---- | C] () -- C:\Windows\System32\drivers\RimSerial.sys.dump
[2014/03/22 17:33:07 | 000,014,848 | ---- | C] () -- C:\Windows\System32\drivers\rdpvideominiport.sys.dump
[2014/03/22 17:33:06 | 000,133,632 | ---- | C] () -- C:\Windows\System32\drivers\rdpdr.sys.dump
[2014/03/22 17:33:06 | 000,018,944 | ---- | C] () -- C:\Windows\System32\drivers\rdpbus.sys.dump
[2014/03/22 17:33:06 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\RDPREFMP.sys.dump
[2014/03/22 17:33:06 | 000,006,656 | ---- | C] () -- C:\Windows\System32\drivers\RDPENCDD.sys.dump
[2014/03/22 17:33:06 | 000,006,656 | ---- | C] () -- C:\Windows\System32\drivers\RDPCDD.sys.dump
[2014/03/22 17:33:05 | 000,242,688 | ---- | C] () -- C:\Windows\System32\drivers\rdbss.sys.dump
[2014/03/22 17:33:05 | 000,078,848 | ---- | C] () -- C:\Windows\System32\drivers\rasl2tp.sys.dump
[2014/03/22 17:33:05 | 000,077,824 | ---- | C] () -- C:\Windows\System32\drivers\raspppoe.sys.dump
[2014/03/22 17:33:05 | 000,075,264 | ---- | C] () -- C:\Windows\System32\drivers\rassstp.sys.dump
[2014/03/22 17:33:05 | 000,073,728 | ---- | C] () -- C:\Windows\System32\drivers\raspptp.sys.dump
[2014/03/22 17:33:04 | 001,383,488 | ---- | C] () -- C:\Windows\System32\drivers\ql2300.sys.dump
[2014/03/22 17:33:04 | 000,106,064 | ---- | C] () -- C:\Windows\System32\drivers\ql40xx.sys.dump
[2014/03/22 17:33:04 | 000,031,744 | ---- | C] () -- C:\Windows\System32\drivers\qwavedrv.sys.dump
[2014/03/22 17:33:04 | 000,011,776 | ---- | C] () -- C:\Windows\System32\drivers\rasacd.sys.dump
[2014/03/22 17:33:03 | 000,052,224 | ---- | C] () -- C:\Windows\System32\drivers\processr.sys.dump
[2014/03/22 17:33:03 | 000,015,544 | ---- | C] () -- C:\Windows\System32\drivers\psi_mf.sys.dump
[2014/03/22 17:33:02 | 000,586,752 | ---- | C] () -- C:\Windows\System32\drivers\PEAuth.sys.dump
[2014/03/22 17:33:02 | 000,180,288 | ---- | C] () -- C:\Windows\System32\drivers\pcmcia.sys.dump
[2014/03/22 17:33:02 | 000,177,152 | ---- | C] () -- C:\Windows\System32\drivers\portcls.sys.dump
[2014/03/22 17:33:02 | 000,043,088 | ---- | C] () -- C:\Windows\System32\drivers\pcw.sys.dump
[2014/03/22 17:33:01 | 000,153,984 | ---- | C] () -- C:\Windows\System32\drivers\pci.sys.dump
[2014/03/22 17:33:01 | 000,056,176 | ---- | C] () -- C:\Windows\System32\drivers\partmgr.sys.dump
[2014/03/22 17:33:01 | 000,042,560 | ---- | C] () -- C:\Windows\System32\drivers\pciidex.sys.dump
[2014/03/22 17:33:01 | 000,012,368 | ---- | C] () -- C:\Windows\System32\drivers\pciide.sys.dump
[2014/03/22 17:33:01 | 000,008,704 | ---- | C] () -- C:\Windows\System32\drivers\parvdm.sys.dump
[2014/03/22 17:33:00 | 000,267,264 | ---- | C] () -- C:\Windows\System32\drivers\nwifi.sys.dump
[2014/03/22 17:33:00 | 000,105,024 | ---- | C] () -- C:\Windows\System32\drivers\NV_AGP.SYS.dump
[2014/03/22 17:33:00 | 000,104,448 | ---- | C] () -- C:\Windows\System32\drivers\pacer.sys.dump
[2014/03/22 17:33:00 | 000,079,360 | ---- | C] () -- C:\Windows\System32\drivers\parport.sys.dump
[2014/03/22 17:33:00 | 000,062,464 | ---- | C] () -- C:\Windows\System32\drivers\ohci1394.sys.dump
[2014/03/22 17:32:59 | 001,211,752 | ---- | C] () -- C:\Windows\System32\drivers\ntfs.sys.dump
[2014/03/22 17:32:59 | 000,143,744 | ---- | C] () -- C:\Windows\System32\drivers\nvstor.sys.dump
[2014/03/22 17:32:59 | 000,117,120 | ---- | C] () -- C:\Windows\System32\drivers\nvraid.sys.dump
[2014/03/22 17:32:59 | 000,004,608 | ---- | C] () -- C:\Windows\System32\drivers\null.sys.dump
[2014/03/22 17:32:58 | 000,044,624 | ---- | C] () -- C:\Windows\System32\drivers\nfrd960.sys.dump
[2014/03/22 17:32:58 | 000,035,328 | ---- | C] () -- C:\Windows\System32\drivers\npfs.sys.dump
[2014/03/22 17:32:58 | 000,016,896 | ---- | C] () -- C:\Windows\System32\drivers\nsiproxy.sys.dump
[2014/03/22 17:32:57 | 000,240,576 | ---- | C] () -- C:\Windows\System32\drivers\netio.sys.dump
[2014/03/22 17:32:57 | 000,187,904 | ---- | C] () -- C:\Windows\System32\drivers\netbt.sys.dump
[2014/03/22 17:32:57 | 000,048,640 | ---- | C] () -- C:\Windows\System32\drivers\ndproxy.sys.dump
[2014/03/22 17:32:57 | 000,036,352 | ---- | C] () -- C:\Windows\System32\drivers\netbios.sys.dump
[2014/03/22 17:32:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\drivers\ndiswan.sys.dump
[2014/03/22 17:32:56 | 000,046,080 | ---- | C] () -- C:\Windows\System32\drivers\ndisuio.sys.dump
[2014/03/22 17:32:56 | 000,027,136 | ---- | C] () -- C:\Windows\System32\drivers\ndiscap.sys.dump
[2014/03/22 17:32:56 | 000,020,992 | ---- | C] () -- C:\Windows\System32\drivers\ndistapi.sys.dump
[2014/03/22 17:32:55 | 000,712,048 | ---- | C] () -- C:\Windows\System32\drivers\ndis.sys.dump
[2014/03/22 17:32:55 | 000,049,728 | ---- | C] () -- C:\Windows\System32\drivers\mup.sys.dump
[2014/03/22 17:32:55 | 000,028,240 | ---- | C] () -- C:\Windows\System32\drivers\mssmbios.sys.dump
[2014/03/22 17:32:55 | 000,012,288 | ---- | C] () -- C:\Windows\System32\drivers\MTConfig.sys.dump
[2014/03/22 17:32:55 | 000,006,144 | ---- | C] () -- C:\Windows\System32\drivers\mstee.sys.dump
[2014/03/22 17:32:54 | 000,233,344 | ---- | C] () -- C:\Windows\System32\drivers\msiscsi.sys.dump
[2014/03/22 17:32:54 | 000,162,896 | ---- | C] () -- C:\Windows\System32\drivers\msrpc.sys.dump
[2014/03/22 17:32:54 | 000,008,320 | ---- | C] () -- C:\Windows\System32\drivers\mskssrv.sys.dump
[2014/03/22 17:32:54 | 000,005,888 | ---- | C] () -- C:\Windows\System32\drivers\mspclock.sys.dump
[2014/03/22 17:32:54 | 000,005,504 | ---- | C] () -- C:\Windows\System32\drivers\mspqm.sys.dump
[2014/03/22 17:32:53 | 000,116,096 | ---- | C] () -- C:\Windows\System32\drivers\msdsm.sys.dump
[2014/03/22 17:32:53 | 000,022,528 | ---- | C] () -- C:\Windows\System32\drivers\msfs.sys.dump
[2014/03/22 17:32:53 | 000,013,888 | ---- | C] () -- C:\Windows\System32\drivers\msisadrv.sys.dump
[2014/03/22 17:32:53 | 000,004,096 | ---- | C] () -- C:\Windows\System32\drivers\mshidkmdf.sys.dump
[2014/03/22 17:32:52 | 000,223,744 | ---- | C] () -- C:\Windows\System32\drivers\mrxsmb10.sys.dump
[2014/03/22 17:32:52 | 000,123,904 | ---- | C] () -- C:\Windows\System32\drivers\mrxsmb.sys.dump
[2014/03/22 17:32:52 | 000,096,768 | ---- | C] () -- C:\Windows\System32\drivers\mrxsmb20.sys.dump
[2014/03/22 17:32:52 | 000,028,032 | ---- | C] () -- C:\Windows\System32\drivers\msahci.sys.dump
[2014/03/22 17:32:51 | 000,130,432 | ---- | C] () -- C:\Windows\System32\drivers\mpio.sys.dump
[2014/03/22 17:32:51 | 000,115,712 | ---- | C] () -- C:\Windows\System32\drivers\mrxdav.sys.dump
[2014/03/22 17:32:51 | 000,078,208 | ---- | C] () -- C:\Windows\System32\drivers\mountmgr.sys.dump
[2014/03/22 17:32:51 | 000,060,416 | ---- | C] () -- C:\Windows\System32\drivers\mpsdrv.sys.dump
[2014/03/22 17:32:51 | 000,026,112 | ---- | C] () -- C:\Windows\System32\drivers\mouhid.sys.dump
[2014/03/22 17:32:50 | 000,235,584 | ---- | C] () -- C:\Windows\System32\drivers\MegaSR.sys.dump
[2014/03/22 17:32:50 | 000,041,552 | ---- | C] () -- C:\Windows\System32\drivers\mouclass.sys.dump
[2014/03/22 17:32:50 | 000,031,744 | ---- | C] () -- C:\Windows\System32\drivers\modem.sys.dump
[2014/03/22 17:32:50 | 000,030,800 | ---- | C] () -- C:\Windows\System32\drivers\megasas.sys.dump
[2014/03/22 17:32:50 | 000,023,552 | ---- | C] () -- C:\Windows\System32\drivers\monitor.sys.dump
[2014/03/22 17:32:50 | 000,012,072 | ---- | C] () -- C:\Windows\System32\drivers\MoborobAssDriver.sys.dump
[2014/03/22 17:32:49 | 000,034,432 | ---- | C] () -- C:\Windows\System32\drivers\mcvidrv.sys.dump
[2014/03/22 17:32:49 | 000,025,088 | ---- | C] () -- C:\Windows\System32\drivers\mcaudrv.sys.dump
[2014/03/22 17:32:49 | 000,022,856 | ---- | C] () -- C:\Windows\System32\drivers\mbam.sys.dump
[2014/03/22 17:32:49 | 000,018,432 | ---- | C] () -- C:\Windows\System32\drivers\mcd.sys.dump
[2014/03/22 17:32:49 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\massfilter_hs.sys.dump
[2014/03/22 17:32:48 | 000,096,848 | ---- | C] () -- C:\Windows\System32\drivers\lsi_scsi.sys.dump
[2014/03/22 17:32:48 | 000,089,168 | ---- | C] () -- C:\Windows\System32\drivers\lsi_sas.sys.dump
[2014/03/22 17:32:48 | 000,086,528 | ---- | C] () -- C:\Windows\System32\drivers\luafv.sys.dump
[2014/03/22 17:32:48 | 000,054,864 | ---- | C] () -- C:\Windows\System32\drivers\lsi_sas2.sys.dump
[2014/03/22 17:32:48 | 000,021,632 | ---- | C] () -- C:\Windows\System32\drivers\ManyCam.sys.dump
[2014/03/22 17:32:47 | 000,136,640 | ---- | C] () -- C:\Windows\System32\drivers\ksecpkg.sys.dump
[2014/03/22 17:32:47 | 000,095,824 | ---- | C] () -- C:\Windows\System32\drivers\lsi_fc.sys.dump
[2014/03/22 17:32:47 | 000,067,520 | ---- | C] () -- C:\Windows\System32\drivers\ksecdd.sys.dump
[2014/03/22 17:32:47 | 000,048,128 | ---- | C] () -- C:\Windows\System32\drivers\lltdio.sys.dump
[2014/03/22 17:32:46 | 000,209,016 | ---- | C] () -- C:\Windows\System32\drivers\keyscrambler.sys.dump
[2014/03/22 17:32:46 | 000,190,976 | ---- | C] () -- C:\Windows\System32\drivers\ks.sys.dump
[2014/03/22 17:32:46 | 000,046,656 | ---- | C] () -- C:\Windows\System32\drivers\isapnp.sys.dump
[2014/03/22 17:32:46 | 000,042,576 | ---- | C] () -- C:\Windows\System32\drivers\kbdclass.sys.dump
[2014/03/22 17:32:46 | 000,028,160 | ---- | C] () -- C:\Windows\System32\drivers\kbdhid.sys.dump
[2014/03/22 17:32:45 | 000,101,888 | ---- | C] () -- C:\Windows\System32\drivers\ipnat.sys.dump
[2014/03/22 17:32:45 | 000,096,768 | ---- | C] () -- C:\Windows\System32\drivers\irda.sys.dump
[2014/03/22 17:32:45 | 000,065,536 | ---- | C] () -- C:\Windows\System32\drivers\IPMIDrv.sys.dump
[2014/03/22 17:32:45 | 000,058,880 | ---- | C] () -- C:\Windows\System32\drivers\ipfltdrv.sys.dump
[2014/03/22 17:32:45 | 000,013,824 | ---- | C] () -- C:\Windows\System32\drivers\irenum.sys.dump
[2014/03/22 17:32:44 | 000,332,160 | ---- | C] () -- C:\Windows\System32\drivers\iaStorV.sys.dump
[2014/03/22 17:32:44 | 000,053,760 | ---- | C] () -- C:\Windows\System32\drivers\intelppm.sys.dump
[2014/03/22 17:32:44 | 000,041,040 | ---- | C] () -- C:\Windows\System32\drivers\iirsp.sys.dump
[2014/03/22 17:32:44 | 000,015,424 | ---- | C] () -- C:\Windows\System32\drivers\intelide.sys.dump
[2014/03/22 17:32:43 | 000,513,536 | ---- | C] () -- C:\Windows\System32\drivers\http.sys.dump
[2014/03/22 17:32:43 | 000,080,896 | ---- | C] () -- C:\Windows\System32\drivers\i8042prt.sys.dump
[2014/03/22 17:32:43 | 000,014,208 | ---- | C] () -- C:\Windows\System32\drivers\hwpolicy.sys.dump
[2014/03/22 17:32:42 | 000,067,152 | ---- | C] () -- C:\Windows\System32\drivers\HpSAMD.sys.dump
[2014/03/22 17:32:42 | 000,039,624 | ---- | C] () -- C:\Windows\System32\drivers\hssdrv6.sys.dump
[2014/03/22 17:32:42 | 000,025,728 | ---- | C] () -- C:\Windows\System32\drivers\hidparse.sys.dump
[2014/03/22 17:32:42 | 000,024,064 | ---- | C] () -- C:\Windows\System32\drivers\hidusb.sys.dump
[2014/03/22 17:32:41 | 000,304,128 | ---- | C] () -- C:\Windows\System32\drivers\HdAudio.sys.dump
[2014/03/22 17:32:41 | 000,091,136 | ---- | C] () -- C:\Windows\System32\drivers\hidbth.sys.dump
[2014/03/22 17:32:41 | 000,055,808 | ---- | C] () -- C:\Windows\System32\drivers\hidclass.sys.dump
[2014/03/22 17:32:41 | 000,037,888 | ---- | C] () -- C:\Windows\System32\drivers\hidir.sys.dump
[2014/03/22 17:32:41 | 000,021,504 | ---- | C] () -- C:\Windows\System32\drivers\hidbatt.sys.dump
[2014/03/22 17:32:40 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\ghsnmea.sys.dump
[2014/03/22 17:32:40 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\ghsmdm.sys.dump
[2014/03/22 17:32:40 | 000,108,544 | ---- | C] () -- C:\Windows\System32\drivers\hdaudbus.sys.dump
[2014/03/22 17:32:40 | 000,026,624 | ---- | C] () -- C:\Windows\System32\drivers\hcw85cir.sys.dump
[2014/03/22 17:32:39 | 000,187,752 | ---- | C] () -- C:\Windows\System32\drivers\FWPKCLNT.SYS.dump
[2014/03/22 17:32:39 | 000,113,432 | ---- | C] () -- C:\Windows\System32\drivers\ghsdiag.sys.dump
[2014/03/22 17:32:39 | 000,057,936 | ---- | C] () -- C:\Windows\System32\drivers\GAGP30KX.SYS.dump
[2014/03/22 17:32:39 | 000,032,408 | ---- | C] () -- C:\Windows\System32\drivers\ghsandroid.sys.dump
[2014/03/22 17:32:39 | 000,026,600 | ---- | C] () -- C:\Windows\System32\drivers\GEARAspiWDM.sys.dump
[2014/03/22 17:32:38 | 000,198,208 | ---- | C] () -- C:\Windows\System32\drivers\fltMgr.sys.dump
[2014/03/22 17:32:38 | 000,196,328 | ---- | C] () -- C:\Windows\System32\drivers\fvevol.sys.dump
[2014/03/22 17:32:38 | 000,046,160 | ---- | C] () -- C:\Windows\System32\drivers\fsdepends.sys.dump
[2014/03/22 17:32:38 | 000,019,824 | ---- | C] () -- C:\Windows\System32\drivers\fs_rec.sys.dump
[2014/03/22 17:32:37 | 000,058,448 | ---- | C] () -- C:\Windows\System32\drivers\fileinfo.sys.dump
[2014/03/22 17:32:37 | 000,028,160 | ---- | C] () -- C:\Windows\System32\drivers\filetrace.sys.dump
[2014/03/22 17:32:37 | 000,025,088 | ---- | C] () -- C:\Windows\System32\drivers\fdc.sys.dump
[2014/03/22 17:32:37 | 000,019,968 | ---- | C] () -- C:\Windows\System32\drivers\flpydisk.sys.dump
[2014/03/22 17:32:36 | 003,100,160 | ---- | C] () -- C:\Windows\System32\drivers\evbdx.sys.dump
[2014/03/22 17:32:36 | 000,148,480 | ---- | C] () -- C:\Windows\System32\drivers\fastfat.sys.dump
[2014/03/22 17:32:36 | 000,142,336 | ---- | C] () -- C:\Windows\System32\drivers\exfat.sys.dump
[2014/03/22 17:32:34 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\errdev.sys.dump
[2014/03/22 17:32:33 | 000,729,024 | ---- | C] () -- C:\Windows\System32\drivers\dxgkrnl.sys.dump
[2014/03/22 17:32:33 | 000,453,712 | ---- | C] () -- C:\Windows\System32\drivers\elxstor.sys.dump
[2014/03/22 17:32:33 | 000,218,984 | ---- | C] () -- C:\Windows\System32\drivers\dxgmms1.sys.dump
[2014/03/22 17:32:33 | 000,076,288 | ---- | C] () -- C:\Windows\System32\drivers\dxg.sys.dump
[2014/03/22 17:32:32 | 000,055,584 | ---- | C] () -- C:\Windows\System32\drivers\dumpfve.sys.dump
[2014/03/22 17:32:32 | 000,026,704 | ---- | C] () -- C:\Windows\System32\drivers\Dumpata.sys.dump
[2014/03/22 17:32:32 | 000,013,312 | ---- | C] () -- C:\Windows\System32\drivers\dxapi.sys.dump
[2014/03/22 17:32:32 | 000,005,120 | ---- | C] () -- C:\Windows\System32\drivers\drmkaud.sys.dump
[2014/03/22 17:32:31 | 000,131,072 | ---- | C] () -- C:\Windows\System32\drivers\Dot4.sys.dump
[2014/03/22 17:32:31 | 000,081,408 | ---- | C] () -- C:\Windows\System32\drivers\drmk.sys.dump
[2014/03/22 17:32:31 | 000,070,720 | ---- | C] () -- C:\Windows\System32\drivers\djsvs.sys.dump
[2014/03/22 17:32:31 | 000,036,864 | ---- | C] () -- C:\Windows\System32\drivers\Dot4usb.sys.dump
[2014/03/22 17:32:31 | 000,027,008 | ---- | C] () -- C:\Windows\System32\drivers\Diskdump.sys.dump
[2014/03/22 17:32:31 | 000,016,384 | ---- | C] () -- C:\Windows\System32\drivers\Dot4Prt.sys.dump
[2014/03/22 17:32:30 | 000,388,096 | ---- | C] () -- C:\Windows\System32\drivers\csc.sys.dump
[2014/03/22 17:32:30 | 000,078,336 | ---- | C] () -- C:\Windows\System32\drivers\dfsc.sys.dump
[2014/03/22 17:32:30 | 000,057,424 | ---- | C] () -- C:\Windows\System32\drivers\disk.sys.dump
[2014/03/22 17:32:30 | 000,032,256 | ---- | C] () -- C:\Windows\System32\drivers\discache.sys.dump
[2014/03/22 17:32:29 | 000,369,848 | ---- | C] () -- C:\Windows\System32\drivers\cng.sys.dump
[2014/03/22 17:32:29 | 000,035,408 | ---- | C] () -- C:\Windows\System32\drivers\crashdmp.sys.dump
[2014/03/22 17:32:29 | 000,031,232 | ---- | C] () -- C:\Windows\System32\drivers\CompositeBus.sys.dump
[2014/03/22 17:32:29 | 000,022,096 | ---- | C] () -- C:\Windows\System32\drivers\crcdisk.sys.dump
[2014/03/22 17:32:29 | 000,019,024 | ---- | C] () -- C:\Windows\System32\drivers\compbatt.sys.dump
[2014/03/22 17:32:28 | 000,140,864 | ---- | C] () -- C:\Windows\System32\drivers\Classpnp.sys.dump
[2014/03/22 17:32:28 | 000,037,888 | ---- | C] () -- C:\Windows\System32\drivers\circlass.sys.dump
[2014/03/22 17:32:28 | 000,015,952 | ---- | C] () -- C:\Windows\System32\drivers\cmdide.sys.dump
[2014/03/22 17:32:28 | 000,014,080 | ---- | C] () -- C:\Windows\System32\drivers\CmBatt.sys.dump
[2014/03/22 17:32:27 | 000,430,080 | ---- | C] () -- C:\Windows\System32\drivers\bxvbdx.sys.dump
[2014/03/22 17:32:27 | 000,108,544 | ---- | C] () -- C:\Windows\System32\drivers\cdrom.sys.dump
[2014/03/22 17:32:27 | 000,070,656 | ---- | C] () -- C:\Windows\System32\drivers\cdfs.sys.dump
[2014/03/22 17:32:26 | 000,393,728 | ---- | C] () -- C:\Windows\System32\drivers\bthport.sys.dump
[2014/03/22 17:32:26 | 000,093,696 | ---- | C] () -- C:\Windows\System32\drivers\bthpan.sys.dump
[2014/03/22 17:32:26 | 000,060,416 | ---- | C] () -- C:\Windows\System32\drivers\BTHUSB.SYS.dump
[2014/03/22 17:32:26 | 000,056,320 | ---- | C] () -- C:\Windows\System32\drivers\bthmodem.sys.dump
[2014/03/22 17:32:25 | 000,062,336 | ---- | C] () -- C:\Windows\System32\drivers\BrSerWdm.sys.dump
[2014/03/22 17:32:25 | 000,034,816 | ---- | C] () -- C:\Windows\System32\drivers\bthenum.sys.dump
[2014/03/22 17:32:25 | 000,012,160 | ---- | C] () -- C:\Windows\System32\drivers\BrUsbMdm.sys.dump
[2014/03/22 17:32:25 | 000,011,904 | ---- | C] () -- C:\Windows\System32\drivers\BrUsbSer.sys.dump
[2014/03/22 17:32:24 | 000,272,128 | ---- | C] () -- C:\Windows\System32\drivers\BrSerId.sys.dump
[2014/03/22 17:32:24 | 000,078,336 | ---- | C] () -- C:\Windows\System32\drivers\bridge.sys.dump
[2014/03/22 17:32:24 | 000,013,568 | ---- | C] () -- C:\Windows\System32\drivers\BrFiltLo.sys.dump
[2014/03/22 17:32:24 | 000,005,248 | ---- | C] () -- C:\Windows\System32\drivers\BrFiltUp.sys.dump
[2014/03/22 17:32:23 | 000,069,632 | ---- | C] () -- C:\Windows\System32\drivers\bowser.sys.dump
[2014/03/22 17:32:23 | 000,035,328 | ---- | C] () -- C:\Windows\System32\drivers\blbdrive.sys.dump
[2014/03/22 17:32:22 | 001,131,008 | ---- | C] () -- C:\Windows\System32\drivers\BCMWL6.SYS.dump
[2014/03/22 17:32:22 | 000,025,168 | ---- | C] () -- C:\Windows\System32\drivers\battc.sys.dump
[2014/03/22 17:32:22 | 000,006,144 | ---- | C] () -- C:\Windows\System32\drivers\beep.sys.dump
[2014/03/22 17:32:21 | 005,342,208 | ---- | C] () -- C:\Windows\System32\drivers\atipmdag.sys.dump
[2014/03/22 17:32:21 | 000,229,888 | ---- | C] () -- C:\Windows\System32\drivers\b57nd60x.sys.dump
[2014/03/22 17:32:21 | 000,056,816 | ---- | C] () -- C:\Windows\System32\drivers\avgntflt.sys.dump
[2014/03/22 17:32:20 | 000,221,696 | ---- | C] () -- C:\Windows\System32\drivers\atikmpag.sys.dump
[2014/03/22 17:32:19 | 006,380,544 | ---- | C] () -- C:\Windows\System32\drivers\atikmdag.sys.dump
[2014/03/22 17:32:19 | 000,077,312 | ---- | C] () -- C:\Windows\System32\drivers\AtihdW73.sys.dump
[2014/03/22 17:32:18 | 003,234,304 | ---- | C] () -- C:\Windows\System32\drivers\athr.sys.dump
[2014/03/22 17:32:17 | 000,133,056 | ---- | C] () -- C:\Windows\System32\drivers\ataport.sys.dump
[2014/03/22 17:32:17 | 000,021,584 | ---- | C] () -- C:\Windows\System32\drivers\atapi.sys.dump
[2014/03/22 17:32:16 | 000,086,608 | ---- | C] () -- C:\Windows\System32\drivers\arcsas.sys.dump
[2014/03/22 17:32:16 | 000,076,368 | ---- | C] () -- C:\Windows\System32\drivers\arc.sys.dump
[2014/03/22 17:32:16 | 000,050,176 | ---- | C] () -- C:\Windows\System32\drivers\appid.sys.dump
[2014/03/22 17:32:16 | 000,017,920 | ---- | C] () -- C:\Windows\System32\drivers\asyncmac.sys.dump
[2014/03/22 17:32:15 | 000,159,312 | ---- | C] () -- C:\Windows\System32\drivers\amdsbs.sys.dump
[2014/03/22 17:32:15 | 000,080,256 | ---- | C] () -- C:\Windows\System32\drivers\amdsata.sys.dump
[2014/03/22 17:32:15 | 000,052,736 | ---- | C] () -- C:\Windows\System32\drivers\amdppm.sys.dump
[2014/03/22 17:32:15 | 000,032,408 | ---- | C] () -- C:\Windows\System32\drivers\androidusb.sys.dump
[2014/03/22 17:32:15 | 000,022,400 | ---- | C] () -- C:\Windows\System32\drivers\amdxata.sys.dump
[2014/03/22 17:32:14 | 001,163,328 | ---- | C] () -- C:\Windows\System32\drivers\AGRSM.sys.dump
[2014/03/22 17:32:14 | 000,055,296 | ---- | C] () -- C:\Windows\System32\drivers\amdk8.sys.dump
[2014/03/22 17:32:14 | 000,053,312 | ---- | C] () -- C:\Windows\System32\drivers\AMDAGP.SYS.dump
[2014/03/22 17:32:14 | 000,014,912 | ---- | C] () -- C:\Windows\System32\drivers\amdide.sys.dump
[2014/03/22 17:32:14 | 000,014,400 | ---- | C] () -- C:\Windows\System32\drivers\aliide.sys.dump
[2014/03/22 17:32:13 | 000,338,944 | ---- | C] () -- C:\Windows\System32\drivers\afd.sys.dump
[2014/03/22 17:32:13 | 000,053,312 | ---- | C] () -- C:\Windows\System32\drivers\AGP440.sys.dump
[2014/03/22 17:32:13 | 000,049,152 | ---- | C] () -- C:\Windows\System32\drivers\agilevpn.sys.dump
[2014/03/22 17:32:12 | 000,422,976 | ---- | C] () -- C:\Windows\System32\drivers\adp94xx.sys.dump
[2014/03/22 17:32:12 | 000,297,552 | ---- | C] () -- C:\Windows\System32\drivers\adpahci.sys.dump
[2014/03/22 17:32:12 | 000,146,512 | ---- | C] () -- C:\Windows\System32\drivers\adpu320.sys.dump
[2014/03/22 17:32:11 | 000,274,304 | ---- | C] () -- C:\Windows\System32\drivers\acpi.sys.dump
[2014/03/22 17:32:11 | 000,010,240 | ---- | C] () -- C:\Windows\System32\drivers\acpipmi.sys.dump
[2014/03/22 17:32:10 | 000,164,864 | ---- | C] () -- C:\Windows\System32\drivers\1394ohci.sys.dump
[2014/03/22 17:32:10 | 000,054,784 | ---- | C] () -- C:\Windows\System32\drivers\1394bus.sys.dump
[2013/12/15 16:58:37 | 000,012,072 | ---- | C] () -- C:\Windows\System32\drivers\MoborobAssDriver.sys
[2013/12/04 22:34:14 | 000,016,304 | ---- | C] () -- C:\Windows\System32\apl003.sys
[2013/12/04 22:34:14 | 000,013,232 | ---- | C] () -- C:\Windows\System32\apf003.sys
[2013/12/04 21:12:51 | 000,003,012 | ---- | C] () -- C:\Windows\System32\client.ini
[2013/11/30 22:27:45 | 000,023,088 | ---- | C] () -- C:\Windows\DCEBoot.exe
[2013/11/30 21:52:11 | 000,362,748 | ---- | C] () -- C:\Users\User\AppData\Local\census.cache
[2013/11/30 21:51:46 | 000,174,615 | ---- | C] () -- C:\Users\User\AppData\Local\ars.cache
[2013/11/26 19:38:07 | 000,000,036 | ---- | C] () -- C:\Users\User\AppData\Local\housecall.guid.cache
[2013/11/20 03:18:07 | 000,119,296 | ---- | C] () -- C:\Windows\System32\zlib.dll
[2013/11/20 03:18:07 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ADsSecurity.dll
[2013/11/20 03:18:07 | 000,036,864 | ---- | C] () -- C:\Windows\System32\dxinputdll.dll
[2013/11/10 15:09:41 | 000,013,464 | ---- | C] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2013/09/18 12:46:53 | 000,192,352 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013/09/18 12:46:52 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2013/08/22 14:45:22 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2013/08/22 14:45:21 | 000,697,506 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2013/08/22 14:45:21 | 000,149,442 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2013/08/22 14:45:21 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2013/08/21 23:29:16 | 000,015,672 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys
[2013/08/18 22:52:21 | 000,000,115 | ---- | C] () -- C:\Users\User\AppData\Roaming\WB.CFG
[2013/08/18 22:52:21 | 000,000,005 | ---- | C] () -- C:\Users\User\AppData\Roaming\WBPU-TTL.DAT
[2012/11/01 20:39:21 | 000,000,043 | ---- | C] () -- C:\Users\User\jagex_cl_runescape_LIVE.dat
[2012/11/01 20:39:21 | 000,000,024 | ---- | C] () -- C:\Users\User\random.dat
[2012/07/16 20:40:29 | 000,027,520 | ---- | C] () -- C:\Users\User\AppData\Local\dt.dat
[2010/12/16 18:20:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/12/16 03:44:17 | 000,636,928 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2012/12/16 03:44:17 | 000,351,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 83 bytes -> C:\Users\User\Desktop\David Byrne & Brian Eno - Life is Long.mp3:com.dropbox.attributes
@Alternate Data Stream - 128 bytes -> C:\Windows\System32\zlib.dll:SummaryInformation
@Alternate Data Stream - 128 bytes -> C:\Windows\System32\zlib.dll:DocumentSummaryInformation
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:5C321E34
< End of report >
Edited by janji, 14 February 2015 - 02:44 PM.