O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (&Google Web Accelerator Helper) - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O2 - BHO: (Enhanced search Toolbar) - {abb88e4e-75f4-4fdc-8f42-d101484c4b3f} - C:\Program Files\Enhanced_search\tbEnha.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Enhanced search Toolbar) - {abb88e4e-75f4-4fdc-8f42-d101484c4b3f} - C:\Program Files\Enhanced_search\tbEnha.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Enhanced search Toolbar) - {ABB88E4E-75F4-4FDC-8F42-D101484C4B3F} - C:\Program Files\Enhanced_search\tbEnha.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe File not found
O4 - HKLM..\Run: [cfFncEnabler.exe] File not found
O4 - HKLM..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe (TOSHIBA Corporation.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - AppInit_DLLs: (c:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - c:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 08:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe - (Orbitdownloader.com)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk - C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe - ()
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TOSHIBA Face Recognition Watcher.lnk - C:\PROGRA~1\Toshiba\SMARTF~1\SMARTF~1.EXE - File not found
MsConfig - StartUpFolder: C:^Users^valued customer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^gueinywcf.lnk - - File not found
MsConfig - StartUpReg:
Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
avgnt - hkey= - key= - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe File not found
MsConfig - StartUpReg:
DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
MsConfig - StartUpReg:
FingerPrintNotifer - hkey= - key= - C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
MsConfig - StartUpReg:
Google Desktop Search - hkey= - key= - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
MsConfig - StartUpReg:
Google Update - hkey= - key= - C:\Users\valued customer\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig - StartUpReg:
Internet Security Services - hkey= - key= - c:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe File not found
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg:
MsnMsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig - StartUpReg:
OxigenClientAdmin - hkey= - key= - C:\Program Files\Oxigen\bin\Oxigen.exe ()
MsConfig - StartUpReg:
OxigenTrayIcon - hkey= - key= - C:\Program Files\Oxigen\bin\OxiTray.exe ()
MsConfig - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg:
RoboForm - hkey= - key= - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe File not found
MsConfig - StartUpReg:
Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe File not found
MsConfig - StartUpReg:
SpeedBitVideoAccelerator - hkey= - key= - C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
MsConfig - StartUpReg:
StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig - StartUpReg:
TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
MsConfig - StartUpReg:
TrackerChecker2 - hkey= - key= - C:\Program Files\Tracker Checker 2\Tracker Checker 2.exe ()
MsConfig - StartUpReg:
Windows Defender - hkey= - key= - File not found
MsConfig - State: "startup" - 2
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (
www.helixcommunity.org)
========== Files/Folders - Created Within 30 Days ========== [2 C:\Windows\*.tmp files]
[2009/10/27 21:36:52 | 00,000,000 | ---D | C] -- C:\ProgramData\Agnitum
[2009/10/17 17:33:43 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/10/27 15:50:19 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\ATI
[2009/10/27 21:08:35 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\BitTorrent
[2009/10/25 22:25:25 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\GrabPro
[2009/10/25 21:33:05 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Macromedia
[2009/10/17 17:33:48 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
[2009/10/25 21:42:14 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Mozilla
[2009/10/25 22:23:04 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Orbit
[2009/10/19 19:08:02 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\WinRAR
[2009/10/11 22:03:26 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Yahoo!
[2009/10/25 21:55:02 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Local\Adobe
[2009/10/27 15:50:19 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Local\ATI
[2009/10/25 21:42:14 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Local\Mozilla
[2009/10/25 22:23:45 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\AppData\Local\Toshiba
[2009/10/27 21:37:12 | 00,000,000 | ---D | C] -- C:\Program Files\Agnitum
[2009/10/17 17:33:43 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/18 15:13:19 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/10/29 18:12:09 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Windows\system32\config\systemprofile\Desktop\OTL.exe
[2009/10/29 07:38:52 | 00,000,000 | ---D | C] -- C:\Microsoft
[2009/10/28 17:35:24 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009/10/27 21:41:04 | 00,704,384 | ---- | C] (Agnitum Ltd.) -- C:\Windows\System32\drivers\SandBox.sys
[2009/10/27 21:40:23 | 00,307,224 | ---- | C] (Agnitum Ltd.) -- C:\Windows\System32\drivers\afwcore.sys
[2009/10/27 21:37:46 | 00,029,208 | ---- | C] (Agnitum Ltd.) -- C:\Windows\System32\drivers\afw.sys
[2009/10/27 16:09:54 | 00,312,344 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\iaStor.sys
[2009/10/27 16:09:54 | 00,028,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\msahci.sys
[2009/10/26 22:21:10 | 00,000,000 | ---D | C] -- C:\Sun
[2009/10/26 19:21:58 | 00,195,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2009/10/26 15:44:37 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\Documents\Bluetooth
[2009/10/25 22:28:59 | 00,052,368 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/10/25 22:28:59 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/10/25 22:28:57 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/10/25 22:28:57 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/10/25 22:28:57 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/10/25 22:28:26 | 01,279,968 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/10/25 22:28:26 | 00,053,328 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/10/25 22:28:00 | 00,000,000 | ---D | C] -- C:\Windows\system32\config\systemprofile\Desktop\New Folder
[2009/10/25 21:50:55 | 00,213,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2009/10/25 21:50:51 | 00,604,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2009/10/25 21:50:42 | 03,584,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/10/25 21:50:41 | 00,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/10/25 21:50:40 | 00,833,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/10/25 21:50:39 | 01,174,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/10/25 21:50:36 | 06,069,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/10/25 21:50:34 | 00,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2009/10/25 21:50:34 | 00,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/10/25 21:50:33 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/10/25 21:50:33 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/10/25 21:50:32 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2009/10/25 21:50:31 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2009/10/25 21:50:31 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/10/25 21:50:30 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/10/25 21:50:30 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2009/10/25 21:50:30 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/10/25 21:50:29 | 01,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/10/25 21:50:21 | 03,597,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2009/10/25 21:50:20 | 03,546,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009/10/25 21:49:52 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll
[2009/10/25 21:49:50 | 00,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys
[2009/10/25 21:42:52 | 00,308,160 | ---- | C] (ALWIL Software) -- C:\Windows\system32\config\systemprofile\Documents\avast_home_setup.exe
[2009/10/21 17:17:28 | 00,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2009/10/21 17:17:28 | 00,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2009/10/21 17:17:28 | 00,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2009/10/21 17:17:28 | 00,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2009/10/21 17:17:22 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/10/21 17:16:59 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/10/17 17:33:44 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/10/17 17:33:43 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/05/10 15:59:32 | 00,389,120 | ---- | C] (Henrik Rydgård Inc.) -- C:\Program Files\DaShRelease.exe
========== Files - Modified Within 30 Days ========== [2 C:\Windows\*.tmp files]
[2009/10/29 18:11:44 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Windows\system32\config\systemprofile\Desktop\OTL.exe
[2009/10/29 17:46:09 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/29 17:46:09 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/29 17:26:00 | 00,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-21628702-580910898-2647980920-1000UA.job
[2009/10/29 17:24:00 | 00,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/29 15:53:05 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/10/29 15:53:05 | 00,600,378 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/10/29 15:53:05 | 00,105,852 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/10/29 15:47:54 | 00,001,649 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
[2009/10/29 15:46:35 | 00,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2009/10/29 15:46:35 | 00,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/29 15:46:25 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/29 15:46:01 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/29 07:50:33 | 03,122,188 | -H-- | M] () -- C:\Windows\system32\config\systemprofile\AppData\Local\IconCache.db
[2009/10/27 21:08:39 | 00,000,751 | ---- | M] () -- C:\Windows\system32\config\systemprofile\Desktop\BitTorrent.lnk
[2009/10/27 15:49:24 | 03,436,844 | R--- | M] () -- C:\Windows\system32\config\systemprofile\Desktop\ComboFix.exe
[2009/10/26 22:26:00 | 00,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-21628702-580910898-2647980920-1000Core.job
[2009/10/26 20:22:50 | 00,000,725 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/10/26 20:01:18 | 00,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/10/26 19:28:17 | 00,073,621 | ---- | M] () -- C:\Windows\system32\config\systemprofile\Desktop\Brisbane Lions LOGO.jpg
[2009/10/26 17:28:13 | 00,001,630 | ---- | M] () -- C:\Windows\system32\config\systemprofile\Desktop\Media Center.lnk
[2009/10/26 15:42:54 | 00,000,000 | ---- | M] () -- C:\rasphone.pbk
[2009/10/26 15:42:12 | 00,067,528 | ---- | M] () -- C:\Windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/10/25 22:34:42 | 01,620,272 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/10/25 22:28:59 | 00,001,816 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/10/25 22:28:56 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/10/25 22:27:22 | 00,001,752 | ---- | M] () -- C:\Windows\System32\rasphone.pbk
[2009/10/25 22:23:56 | 00,000,821 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
[2009/10/25 21:52:26 | 00,000,600 | ---- | M] () -- C:\Windows\PUTTY.RND
[2009/10/25 21:49:12 | 00,001,649 | ---- | M] () -- C:\Windows\system32\config\systemprofile\Desktop\CCleaner.lnk
[2009/10/25 21:43:03 | 00,308,160 | ---- | M] (ALWIL Software) -- C:\Windows\system32\config\systemprofile\Documents\avast_home_setup.exe
[2009/10/25 21:42:18 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/10/25 19:49:42 | 00,003,900 | ---- | M] () -- C:\Windows\System32\gasfkylog.dat
[2009/10/25 06:11:34 | 00,077,312 | ---- | M] () -- C:\Windows\MBR.exe
[2009/10/24 14:00:38 | 00,001,356 | ---- | M] () -- C:\Windows\system32\config\systemprofile\AppData\Local\d3d9caps.dat
[2009/10/15 18:53:28 | 00,021,052 | ---- | M] () -- C:\Windows\System32\SIntfNT.dll
[2009/10/15 18:53:28 | 00,015,144 | ---- | M] () -- C:\Windows\System32\SIntf32.dll
[2009/10/15 18:53:28 | 00,012,067 | ---- | M] () -- C:\Windows\System32\SIntf16.dll
[2009/10/11 08:10:09 | 00,236,544 | ---- | M] () -- C:\Windows\PEV.exe
[2009/10/03 05:01:57 | 25,198,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe
[2009/10/01 10:29:14 | 00,195,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
========== Files - No Company Name ==========[2009/10/27 21:37:48 | 00,000,049 | ---- | C] () -- C:\Windows\transp.gif
[2009/10/27 21:08:39 | 00,000,751 | ---- | C] () -- C:\Windows\system32\config\systemprofile\Desktop\BitTorrent.lnk
[2009/10/27 15:59:27 | 00,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2009/10/27 15:49:59 | 03,436,844 | R--- | C] () -- C:\Windows\system32\config\systemprofile\Desktop\ComboFix.exe
[2009/10/26 20:22:50 | 00,000,725 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2009/10/26 20:01:18 | 00,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/10/26 19:28:15 | 00,073,621 | ---- | C] () -- C:\Windows\system32\config\systemprofile\Desktop\Brisbane Lions LOGO.jpg
[2009/10/26 17:28:13 | 00,001,630 | ---- | C] () -- C:\Windows\system32\config\systemprofile\Desktop\Media Center.lnk
[2009/10/26 15:42:54 | 00,000,000 | ---- | C] () -- C:\rasphone.pbk
[2009/10/25 22:30:54 | 03,122,188 | -H-- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Local\IconCache.db
[2009/10/25 22:28:59 | 00,001,816 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/10/25 22:28:26 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/10/25 22:27:22 | 00,001,752 | ---- | C] () -- C:\Windows\System32\rasphone.pbk
[2009/10/25 21:52:26 | 00,000,600 | ---- | C] () -- C:\Windows\PUTTY.RND
[2009/10/25 21:49:12 | 00,001,649 | ---- | C] () -- C:\Windows\system32\config\systemprofile\Desktop\CCleaner.lnk
[2009/10/25 21:42:18 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/10/25 13:49:40 | 00,003,900 | ---- | C] () -- C:\Windows\System32\gasfkylog.dat
[2009/10/21 17:17:28 | 00,236,544 | ---- | C] () -- C:\Windows\PEV.exe
[2009/10/21 17:17:28 | 00,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2009/10/21 17:17:28 | 00,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2009/10/21 17:17:28 | 00,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2009/10/15 18:53:28 | 00,021,052 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2009/10/15 18:53:28 | 00,015,144 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2009/10/15 18:53:28 | 00,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2009/07/18 10:25:57 | 00,721,904 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/07/03 18:46:02 | 00,000,024 | ---- | C] () -- C:\Windows\cdplayer.ini
[2009/07/02 18:08:44 | 00,000,000 | ---- | C] () -- C:\Windows\AudioDVD.INI
[2009/06/05 17:15:53 | 01,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2009/05/18 19:37:54 | 00,921,600 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll
[2009/05/18 19:37:54 | 00,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2009/05/18 19:37:54 | 00,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2009/05/18 19:37:54 | 00,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2009/05/13 20:35:08 | 00,395,776 | ---- | C] () -- C:\Windows\System32\libmplayer.dll
[2009/05/13 20:35:08 | 00,262,144 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2009/05/13 20:35:08 | 00,112,640 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2009/05/13 20:35:07 | 02,255,360 | ---- | C] () -- C:\Windows\System32\libavcodec.dll
[2009/05/10 14:01:56 | 00,171,008 | ---- | C] () -- C:\Program Files\ePSXe.exe
[2009/05/05 10:59:44 | 00,000,050 | ---- | C] () -- C:\Windows\MegaManager.INI
[2009/05/02 12:40:03 | 00,168,448 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/05/02 12:40:01 | 00,795,648 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/05/02 12:40:00 | 03,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2009/05/02 12:40:00 | 00,130,048 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/04/29 21:59:49 | 00,000,000 | ---- | C] () -- C:\Windows\LiveBilliardsDemo.INI
[2009/04/09 10:56:57 | 00,000,568 | ---- | C] () -- C:\Windows\ss4200utility.ini
[2009/04/07 14:29:46 | 00,000,098 | ---- | C] () -- C:\Windows\WirelessFTP.INI
[2009/03/29 14:48:10 | 00,000,204 | ---- | C] () -- C:\Windows\struct~.ini
[2009/03/15 18:42:22 | 00,192,512 | ---- | C] () -- C:\Windows\System32\ssresources.dll
[2009/03/15 18:42:22 | 00,020,481 | ---- | C] () -- C:\Windows\System32\SystemsHook.dll
[2009/02/04 20:50:32 | 00,024,576 | ---- | C] () -- C:\Windows\System32\nsis_loader.dll
[2008/12/31 17:04:42 | 00,691,560 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2008/12/09 22:24:28 | 00,000,000 | ---- | C] () -- C:\Windows\tosOBEX.INI
[2008/12/08 20:41:54 | 00,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008/12/01 15:32:56 | 00,000,006 | -HS- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Roaming\desktop.ini
[2008/11/22 16:12:55 | 00,001,151 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008/10/23 02:58:00 | 25,089,272 | ---- | C] () -- C:\Windows\System32\TrueAccessCoInst.dll
[2008/10/22 01:32:02 | 00,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/10/22 01:32:02 | 00,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/10/22 01:32:02 | 00,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/10/22 01:32:02 | 00,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/10/22 01:32:02 | 00,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/10/22 01:32:02 | 00,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/10/22 00:20:23 | 00,067,528 | ---- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/05/06 16:08:19 | 01,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/05/06 16:07:54 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/05/06 15:32:46 | 00,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/03/29 03:41:32 | 00,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008/02/29 15:14:04 | 00,223,744 | ---- | C] () -- C:\Windows\System32\b4fm.dll
[2007/12/24 01:02:16 | 00,126,976 | ---- | C] () -- C:\Windows\gdf.dll
[2007/12/22 10:46:32 | 00,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2007/07/11 02:10:12 | 00,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2006/11/03 00:02:10 | 00,001,356 | ---- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Local\d3d9caps.dat
[2006/11/03 00:01:48 | 00,000,006 | -HS- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Local\desktop.ini
[2006/11/02 23:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 23:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 21:23:31 | 00,000,442 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 21:23:31 | 00,000,179 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 18:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/09/13 22:06:10 | 00,045,056 | ---- | C] () -- C:\Windows\System32\gtapi.dll
[2005/07/23 15:30:18 | 00,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
========== LOP Check ========== [2009/10/29 15:46:35 | 00,000,882 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/29 17:24:00 | 00,000,886 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2009/10/26 22:26:00 | 00,000,896 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-21628702-580910898-2647980920-1000Core.job
[2009/10/29 17:26:00 | 00,000,948 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-21628702-580910898-2647980920-1000UA.job
[2009/10/29 15:46:25 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/10/29 15:43:53 | 00,032,538 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %PROGRAMFILES%\*. >[2009/10/27 21:37:12 | 00,000,000 | R--D | M] -- C:\Program Files
[2009/01/11 10:46:45 | 00,000,000 | ---D | M] -- C:\Program Files\3 Mobile
[2009/05/01 22:04:38 | 00,000,000 | ---D | M] -- C:\Program Files\Acoustica Mixcraft 4
[2009/08/30 14:51:25 | 00,000,000 | ---D | M] -- C:\Program Files\Acoustica Shared Effects
[2009/06/02 16:58:02 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/10/27 21:37:12 | 00,000,000 | ---D | M] -- C:\Program Files\Agnitum
[2009/05/13 23:32:00 | 00,000,000 | ---D | M] -- C:\Program Files\All Sound Recorder XP 210
[2009/04/19 15:37:31 | 00,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2009/08/30 14:48:21 | 00,000,000 | ---D | M] -- C:\Program Files\Antares Audio Technologies
[2008/12/16 16:35:06 | 00,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2009/04/06 17:58:21 | 00,000,000 | ---D | M] -- C:\Program Files\ASIO4ALL v2
[2008/10/22 01:09:04 | 00,000,000 | ---D | M] -- C:\Program Files\ATI
[2008/10/22 01:10:30 | 00,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2009/08/27 17:14:48 | 00,000,000 | ---D | M] -- C:\Program Files\Audacity
[2009/06/16 18:02:38 | 00,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2009/06/21 11:01:29 | 00,000,000 | ---D | M] -- C:\Program Files\Babylon
[2008/12/07 10:34:32 | 00,000,000 | ---D | M] -- C:\Program Files\BitComet
[2009/04/11 13:44:11 | 00,000,000 | ---D | M] -- C:\Program Files\BitDefender
[2008/12/01 13:37:30 | 00,000,000 | ---D | M] -- C:\Program Files\BitTorrent
[2009/06/15 22:18:07 | 00,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2008/12/08 20:19:01 | 00,000,000 | ---D | M] -- C:\Program Files\Camtech
[2009/01/01 17:39:37 | 00,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2009/07/20 21:06:00 | 00,000,000 | ---D | M] -- C:\Program Files\Chat Republic Games
[2009/07/20 22:56:49 | 00,000,000 | ---D | M] -- C:\Program Files\Cheat Engine
[2009/07/11 00:11:04 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files
[2008/12/06 12:51:49 | 00,000,000 | ---D | M] -- C:\Program Files\Conduit
[2009/05/27 17:25:29 | 00,000,000 | ---D | M] -- C:\Program Files\Counter-Strike 1.6
[2008/12/19 12:19:37 | 00,000,000 | ---D | M] -- C:\Program Files\Crazy-World
[2009/07/18 10:45:11 | 00,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Lite
[2009/07/18 10:44:37 | 00,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Pro
[2009/07/18 10:45:11 | 00,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Toolbar
[2009/05/15 14:04:37 | 00,000,000 | ---D | M] -- C:\Program Files\DAP Premium
[2009/04/21 18:23:48 | 00,000,000 | ---D | M] -- C:\Program Files\Defraggler
[2009/06/26 18:58:31 | 00,000,000 | ---D | M] -- C:\Program Files\DivX
[2008/12/01 13:37:27 | 00,000,000 | ---D | M] -- C:\Program Files\DNA
[2009/05/05 11:05:42 | 00,000,000 | ---D | M] -- C:\Program Files\DOSBox-0.72
[2009/06/25 14:06:57 | 00,000,000 | ---D | M] -- C:\Program Files\Enhanced_search
[2009/01/22 13:12:30 | 00,000,000 | ---D | M] -- C:\Program Files\FlashGet Network
[2009/08/15 12:03:04 | 00,000,000 | ---D | M] -- C:\Program Files\Footy Fanatic FX
[2009/10/11 22:02:35 | 00,000,000 | ---D | M] -- C:\Program Files\Freebies Hack Engine
[2008/12/03 19:07:16 | 00,000,000 | ---D | M] -- C:\Program Files\'Full Speed' Internet Booster + Performance Tests
[2009/10/27 16:26:47 | 00,000,000 | ---D | M] -- C:\Program Files\Google
[2009/01/10 21:10:44 | 00,000,000 | ---D | M] -- C:\Program Files\Google Earth Pro 4.2
[2009/03/28 12:57:17 | 00,000,000 | ---D | M] -- C:\Program Files\Google Hacks
[2009/07/19 00:23:28 | 00,000,000 | ---D | M] -- C:\Program Files\Graboid
[2009/07/04 12:00:49 | 00,000,000 | ---D | M] -- C:\Program Files\GRETECH
[2009/07/18 10:47:43 | 00,000,000 | ---D | M] -- C:\Program Files\Hasbro Interactive
[2008/11/22 16:17:50 | 00,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2008/12/06 19:10:50 | 00,000,000 | ---D | M] -- C:\Program Files\HP
[2008/12/16 18:11:05 | 00,000,000 | ---D | M] -- C:\Program Files\HyCam2
[2009/04/06 17:58:23 | 00,000,000 | ---D | M] -- C:\Program Files\Image-Line
[2009/05/05 11:00:02 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2008/10/22 00:16:12 | 00,000,000 | ---D | M] -- C:\Program Files\Intel
[2009/10/28 17:57:53 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2008/10/22 01:32:02 | 00,000,000 | ---D | M] -- C:\Program Files\InterVideo
[2009/06/15 22:18:39 | 00,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/06/15 22:19:00 | 00,000,000 | ---D | M] -- C:\Program Files\iTunes
[2008/12/23 13:39:13 | 00,000,000 | ---D | M] -- C:\Program Files\iWin.com
[2009/10/21 17:10:57 | 00,000,000 | ---D | M] -- C:\Program Files\Java
[2009/08/12 19:12:50 | 00,000,000 | ---D | M] -- C:\Program Files\K-Lite Codec Pack
[2009/06/08 13:28:22 | 00,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/04/15 15:52:13 | 00,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2008/12/09 17:46:37 | 00,000,000 | ---D | M] -- C:\Program Files\LimeWire Accelerator 4.10
[2009/07/21 18:25:42 | 00,000,000 | ---D | M] -- C:\Program Files\MagicISO
[2009/01/05 23:20:14 | 00,000,000 | ---D | M] -- C:\Program Files\Makayama Interactive
[2009/10/17 17:33:47 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/12/20 22:00:52 | 00,000,000 | ---D | M] -- C:\Program Files\Media Manager
[2009/05/16 19:55:59 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger Plus! Live
[2009/03/20 17:32:12 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2006/11/02 23:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2009/04/04 12:45:50 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009/09/11 23:31:12 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2009/10/25 22:10:05 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2009/03/18 15:40:27 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2008/01/21 13:35:17 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009/10/29 17:59:59 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2006/11/02 23:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2008/12/13 12:31:23 | 00,000,000 | ---D | M] -- C:\Program Files\MSECache
[2008/05/06 16:20:42 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009/08/28 12:24:00 | 00,000,000 | ---D | M] -- C:\Program Files\NaturalSoft
[2009/03/29 17:01:09 | 00,000,000 | ---D | M] -- C:\Program Files\Nero 9
[2009/10/26 20:22:51 | 00,000,000 | ---D | M] -- C:\Program Files\Opera
[2009/10/29 15:59:53 | 00,000,000 | ---D | M] -- C:\Program Files\Orbitdownloader
[2008/12/22 19:17:56 | 00,000,000 | ---D | M] -- C:\Program Files\Outsim
[2009/04/08 18:12:30 | 00,000,000 | ---D | M] -- C:\Program Files\Oxigen
[2009/04/08 18:10:38 | 00,000,000 | ---D | M] -- C:\Program Files\OxigenInstall
[2009/05/10 16:27:57 | 00,000,000 | ---D | M] -- C:\Program Files\Pcsx2
[2009/03/26 08:25:08 | 00,000,000 | ---D | M] -- C:\Program Files\Play89
[2009/03/23 17:03:02 | 00,000,000 | ---D | M] -- C:\Program Files\Pool Station
[2009/06/15 22:17:36 | 00,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/04/24 21:23:26 | 00,000,000 | ---D | M] -- C:\Program Files\Real
[2008/10/22 01:06:40 | 00,000,000 | ---D | M] -- C:\Program Files\Realtek
[2009/06/16 18:02:34 | 00,000,000 | ---D | M] -- C:\Program Files\Red Kawa
[2006/11/02 23:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2009/04/05 11:50:16 | 00,000,000 | ---D | M] -- C:\Program Files\Safari
[2009/07/10 23:45:27 | 00,000,000 | ---D | M] -- C:\Program Files\SharpHacker's Registration Hack
[2009/03/29 14:24:13 | 00,000,000 | ---D | M] -- C:\Program Files\SopCast
[2009/04/21 19:56:46 | 00,000,000 | ---D | M] -- C:\Program Files\SpeedBit Video Accelerator
[2008/12/13 08:26:07 | 00,000,000 | ---D | M] -- C:\Program Files\Super DVD Creator 8.0
[2008/10/22 00:18:38 | 00,000,000 | ---D | M] -- C:\Program Files\Synaptics
[2008/12/22 20:02:04 | 00,000,000 | ---D | M] -- C:\Program Files\TOSHIBA
[2009/07/10 12:55:08 | 00,000,000 | ---D | M] -- C:\Program Files\Tracker Checker 2
[2009/10/18 15:13:19 | 00,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2008/12/21 12:26:46 | 00,000,000 | ---D | M] -- C:\Program Files\TrueSuite Access Manager
[2009/04/05 10:53:19 | 00,000,000 | ---D | M] -- C:\Program Files\TVUPlayer
[2008/10/22 01:29:21 | 00,000,000 | ---D | M] -- C:\Program Files\Ulead Systems
[2009/10/29 16:24:30 | 00,000,000 | ---D | M] -- C:\Program Files\UltraStar Deluxe
[2006/11/03 00:01:55 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/06/16 23:03:01 | 00,000,000 | ---D | M] -- C:\Program Files\Unity
[2009/04/06 10:37:54 | 00,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2009/03/29 15:27:09 | 00,000,000 | ---D | M] -- C:\Program Files\uusee
[2008/12/08 21:44:52 | 00,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2009/03/21 08:34:00 | 00,000,000 | ---D | M] -- C:\Program Files\VoiceSync
[2009/08/24 19:08:25 | 00,000,000 | ---D | M] -- C:\Program Files\VSO
[2009/08/30 14:48:21 | 00,000,000 | ---D | M] -- C:\Program Files\VstPlugins
[2008/12/22 20:01:15 | 00,000,000 | ---D | M] -- C:\Program Files\Winamp
[2008/01/21 13:35:18 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Calendar
[2008/01/21 13:35:15 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Collaboration
[2008/01/21 13:35:09 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2008/01/21 13:35:14 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Journal
[2009/03/20 17:34:09 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2009/03/20 17:31:54 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2008/01/21 13:35:16 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2008/10/22 01:31:47 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Components
[2009/08/15 18:38:43 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/12/31 10:50:58 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Mobile Device Handbook
[2006/11/02 23:37:34 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2008/01/21 13:35:14 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Photo Gallery
[2008/01/21 13:35:17 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar
[2008/12/09 18:19:40 | 00,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2009/03/23 16:27:02 | 00,000,000 | ---D | M] -- C:\Program Files\XAimer
[2009/10/11 22:03:26 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2009/01/24 13:42:57 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo! Games
========== Alternate Data Streams ========== @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:AC6124CA
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:13EDD51B
< End of report >