O1 HOSTS File: ([2006/09/18 13:41:30 | 000,000,736 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\SBLAHCASEY\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVGTOOLBAR) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Inc. )
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Zango) - {E1BACF55-35E1-4E47-9247-2D48660E5545} - C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (AVGTOOLBAR) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Inc. )
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Zango) - {E1BACF55-35E1-4E47-9247-2D48660E5545} - C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVGTOOLBAR) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Inc. )
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [35529024] C:\ProgramData\35529024\35529024.exe File not found
O4 - HKLM..\Run: [61881832] C:\ProgramData\61881832\61881832.exe ()
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BearShare] C:\Program Files\BearShare\BearShare.exe File not found
O4 - HKLM..\Run: [CTFMON] C:\Windows\Temp\_ex-08.exe ()
O4 - HKLM..\Run: [DLCXCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL ()
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [lxdcamon] C:\Program Files\Lexmark 1300 Series\lxdcamon.exe ()
O4 - HKLM..\Run: [lxdcmon.exe] C:\Program Files\Lexmark 1300 Series\lxdcmon.exe File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe File not found
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [notepad] C:\Windows\System32\notepad.DLL (Microsoft)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [Rgebecebe] C:\Users\Case\AppData\Local\uyejoyexa.DLL ()
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [LosAlamos] C:\Windows\System32\sshnas21.DLL ()
O4 - HKCU..\Run: [notepad] C:\Windows\System32\config\systemprofile\ntload.dll (Microsoft)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [RTHDBPL] C:\Users\Case\AppData\Roaming\SystemProc\lsass.exe ( )
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\SBLAHCASEY\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TOSCDSPD] File not found
O4 - HKCU..\Run: [TOY5KNQ8OC] C:\Users\Case\AppData\Local\Temp\Ddq.exe ()
O4 - HKCU..\Run: [WeatherDPA] C:\Program Files\Zango\bin\10.1.181.0\Weather.exe File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Yxiviri] C:\Users\Case\AppData\Local\d2nPLAlp.DLL (
www.madshi.net)O4 - Startup: C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk = C:\Users\Case\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe File not found
O4 - Startup: C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.dll (Microsoft)
O4 - Startup: C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sismkw32.exe (TWX Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SBLAHCASEY\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: comcast.net ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: runescape.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([games] http in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([games] https in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1288.0816.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1288.0816.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img29.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img29.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 13:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{077b3d4f-9af4-11dd-a1e8-001a92faec1a}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe -- File not found
O33 - MountPoints2\{a5cdeafd-ae9f-11dc-bbeb-001a92faec1a}\Shell\AutoRun\command - "" = WD_Windows_Tools\setup.exe
O33 - MountPoints2\{bf953760-4b6d-11dd-b47a-001a92faec1a}\Shell - "" = AutoRun
O33 - MountPoints2\{bf953760-4b6d-11dd-b47a-001a92faec1a}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\F\Shell\AutoRun\command - "" = WD_Windows_Tools\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/02/28 15:47:34 | 000,549,888 | ---- | C] (OldTimer Tools) -- C:\Users\Case\Desktop\OTL.exe
[2010/02/28 13:55:20 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Local\{A72EF5FF-A3A0-4F22-9C40-CE50AC223818}
[2010/02/28 13:52:13 | 000,000,000 | ---D | C] -- C:\ProgramData\61881832
[2010/02/28 00:39:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/02/28 00:39:07 | 000,000,000 | ---D | C] -- C:\Program Files\SBLAHCASEY
[2010/02/26 00:43:48 | 000,000,000 | -HSD | C] -- C:\Users\Case\AppData\Roaming\SystemProc
[2010/02/24 21:07:55 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Local\Threat Expert
[2010/02/23 19:14:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/02/23 19:13:24 | 000,473,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2010/02/23 19:13:24 | 000,472,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2010/02/23 19:13:23 | 000,523,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2010/02/23 19:13:23 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2010/02/23 19:13:23 | 000,435,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2010/02/23 19:13:22 | 000,431,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/02/23 19:13:22 | 000,312,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2010/02/23 19:13:22 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2010/02/23 19:13:22 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2010/02/21 22:47:22 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Local\Blizzard Entertainment
[2010/02/21 20:46:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2010/02/21 16:47:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard
[2010/02/21 14:40:45 | 000,000,000 | ---D | C] -- C:\Program Files\World of Warcraft
[2010/02/21 14:40:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2010/02/21 12:55:57 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2010/02/21 12:55:56 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2010/02/21 12:55:56 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2010/02/21 12:55:49 | 000,233,136 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2010/02/21 12:55:49 | 000,098,600 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/02/21 12:55:37 | 000,207,792 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2010/02/21 12:55:37 | 000,087,784 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/02/21 12:55:31 | 000,070,408 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2010/02/21 12:55:26 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/02/21 12:55:26 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Roaming\PC Tools
[2010/02/21 12:55:26 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/02/21 12:55:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/02/21 12:01:02 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Local\bkbfwi
[2010/02/21 11:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\World of Warcraft.temp
[2010/02/21 11:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment.temp
[2010/02/20 17:15:25 | 000,000,000 | ---D | C] -- C:\Users\Case\Documents\My Received Files
[2010/02/20 14:10:50 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Roaming\Malwarebytes
[2010/02/20 14:10:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/20 14:10:34 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/02/20 14:10:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/02/20 14:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/20 13:36:28 | 000,055,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2010/02/20 00:23:43 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Software
[2010/02/20 00:22:19 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Swift Sound
[2010/02/20 00:21:49 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Swift Sound
[2010/02/20 00:21:48 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Roaming\NCH Swift Sound
[2010/02/20 00:11:45 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Roaming\AVS4YOU
[2010/02/20 00:07:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVSMedia
[2010/02/20 00:07:46 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\GdiPlus.dll
[2010/02/20 00:07:38 | 000,000,000 | ---D | C] -- C:\Program Files\AVS4YOU
[2010/02/15 11:15:58 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Roaming\Vivox
[2010/02/12 03:20:17 | 000,097,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
[2010/02/12 03:20:16 | 000,105,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2010/02/12 03:20:14 | 000,622,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
[2010/02/12 03:20:14 | 000,037,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl
[2010/02/12 03:20:13 | 000,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010/02/12 03:20:13 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
[2010/02/12 03:20:07 | 000,781,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll
[2010/02/12 03:20:02 | 000,326,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010/02/10 14:39:56 | 003,467,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010/02/10 14:39:50 | 003,502,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010/02/10 14:39:34 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tcpipcfg.dll
[2010/02/10 14:39:34 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiougc.exe
[2010/02/10 14:39:25 | 001,327,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2010/02/10 14:39:23 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvfw32.dll
[2010/02/10 14:39:23 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2010/02/10 14:39:23 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2010/02/10 14:39:23 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avicap32.dll
[2010/01/30 02:26:51 | 000,000,000 | ---D | C] -- C:\Users\Case\AppData\Roaming\e frontier
[2010/01/30 02:25:24 | 000,000,000 | ---D | C] -- C:\Program Files\e frontier
[2008/08/02 22:07:21 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxbcinpa.dll
[2008/08/02 22:07:21 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXBChcp.dll
[2008/08/02 22:07:20 | 000,995,328 | ---- | C] ( ) -- C:\Windows\System32\lxbcusb1.dll
[2008/08/02 22:07:20 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxbciesc.dll
[2008/08/02 22:07:19 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxbcserv.dll
[2008/08/02 22:07:19 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxbcprox.dll
[2008/08/02 22:07:18 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxbcpmui.dll
[2008/08/02 22:07:18 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxbclmpm.dll
[2008/08/02 22:07:18 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxbcpplc.dll
[2008/08/02 22:07:10 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxbchbn3.dll
[2008/08/02 22:07:08 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxbccomm.dll
[2008/08/02 22:07:07 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxbccomc.dll
[2008/02/07 04:29:48 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXDChcp.dll
[2008/02/07 04:29:47 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxdcinpa.dll
[2008/02/07 04:29:47 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxdciesc.dll
[2008/02/07 04:29:46 | 001,232,896 | ---- | C] ( ) -- C:\Windows\System32\lxdcserv.dll
[2008/02/07 04:29:46 | 000,999,424 | ---- | C] ( ) -- C:\Windows\System32\lxdcusb1.dll
[2008/02/07 04:29:46 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxdcprox.dll
[2008/02/07 04:29:46 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxdcpplc.dll
[2008/02/07 04:29:45 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxdcpmui.dll
[2008/02/07 04:29:45 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxdclmpm.dll
[2008/02/07 04:29:43 | 000,700,416 | ---- | C] ( ) -- C:\Windows\System32\lxdchbn3.dll
[2008/02/07 04:29:41 | 000,425,984 | ---- | C] ( ) -- C:\Windows\System32\lxdccomm.dll
[2008/02/07 04:29:40 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxdccomc.dll
[2007/09/06 15:52:10 | 000,047,104 | ---- | C] (
www.madshi.net) -- C:\Users\Case\AppData\Local\d2nPLAlp.dll
[2006/10/11 17:01:40 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\dlcxpmui.dll
[2006/10/11 16:59:56 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\dlcxserv.dll
[2006/10/11 16:54:10 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\dlcxcomm.dll
[2006/10/11 16:52:34 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\dlcxlmpm.dll
[2006/10/11 16:51:16 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\dlcxiesc.dll
[2006/10/11 16:48:58 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\dlcxpplc.dll
[2006/10/11 16:48:14 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\dlcxcomc.dll
[2006/10/11 16:47:42 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\dlcxprox.dll
[2006/10/11 16:41:42 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\dlcxinpa.dll
[2006/10/11 16:41:04 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\dlcxusb1.dll
[2006/10/11 16:37:14 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\dlcxhbn3.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/02/28 16:06:33 | 004,980,736 | -HS- | M] () -- C:\Users\Case\NTUSER.DAT
[2010/02/28 16:04:06 | 000,009,736 | -HS- | M] () -- C:\Users\Case\AppData\Local\UYxp8qC
[2010/02/28 16:02:43 | 000,792,064 | ---- | M] () -- C:\Windows\System32\drivers\oelyhf.sys
[2010/02/28 16:02:41 | 000,000,238 | -H-- | M] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/02/28 15:53:55 | 000,003,584 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/28 15:53:55 | 000,003,584 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/28 15:47:36 | 000,549,888 | ---- | M] (OldTimer Tools) -- C:\Users\Case\Desktop\OTL.exe
[2010/02/28 15:32:18 | 000,000,282 | -H-- | M] () -- C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[2010/02/28 15:30:08 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/02/28 15:24:43 | 000,000,760 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2010/02/28 13:55:23 | 000,000,120 | ---- | M] () -- C:\Users\Case\AppData\Local\Mmokanede.dat
[2010/02/28 13:55:21 | 000,000,000 | ---- | M] () -- C:\Users\Case\AppData\Local\Lsexivewava.bin
[2010/02/28 13:51:20 | 000,000,024 | ---- | M] () -- C:\Users\Case\AppData\Roaming\glchvt.dat
[2010/02/28 13:51:12 | 000,000,004 | ---- | M] () -- C:\Users\Case\AppData\Roaming\avdrn.dat
[2010/02/28 12:27:10 | 000,155,136 | ---- | M] () -- C:\Windows\msa.exe
[2010/02/28 12:27:08 | 000,189,440 | ---- | M] () -- C:\Windows\System32\sshnas21.dll
[2010/02/28 10:21:30 | 000,267,997 | ---- | M] () -- C:\Users\Case\Desktop\wp_Hatsune_Miku_Easter_1024x768.jpg
[2010/02/28 09:53:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/02/28 00:50:45 | 176,519,017 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/02/28 00:39:35 | 000,000,961 | ---- | M] () -- C:\Users\Case\Desktop\Spybot - Search & Destroy.lnk
[2010/02/27 12:08:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2010/02/27 12:08:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2010/02/27 11:57:08 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2010/02/27 11:57:07 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2010/02/27 11:52:37 | 003,424,470 | -H-- | M] () -- C:\Users\Case\AppData\Local\IconCache.db
[2010/02/27 11:51:32 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2010/02/27 11:51:31 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2010/02/26 22:11:46 | 000,000,813 | -HS- | M] () -- C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk
[2010/02/25 20:29:04 | 000,197,632 | -HS- | M] () -- C:\Users\Case\AppData\Local\av.exe
[2010/02/25 20:29:04 | 000,000,008 | ---- | M] () -- C:\ProgramData\mswintmp.dat
[2010/02/25 18:40:48 | 000,010,908 | -HS- | M] () -- C:\Users\Case\AppData\Local\7EgpN4
[2010/02/25 17:16:12 | 000,009,704 | ---- | M] () -- C:\Users\Case\Desktop\Untitled.jpg
[2010/02/25 16:17:45 | 000,009,820 | -HS- | M] () -- C:\Users\Case\AppData\Local\BnDHfux
[2010/02/24 16:47:45 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2010/02/24 16:47:44 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2010/02/24 03:32:38 | 000,097,424 | ---- | M] () -- C:\Users\Case\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/24 03:24:43 | 000,341,376 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/02/23 15:43:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2010/02/23 15:43:50 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2010/02/22 16:31:58 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2010/02/22 16:31:58 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2010/02/22 03:18:24 | 079,020,032 | ---- | M] () -- C:\Windows\ocsetup_install_NetFx3.etl
[2010/02/22 03:18:22 | 002,654,208 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/02/22 03:18:22 | 000,016,384 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/02/21 19:58:38 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2010/02/21 19:58:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2010/02/21 16:45:42 | 000,215,552 | ---- | M] () -- C:\Users\Case\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/21 15:23:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2010/02/21 15:23:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2010/02/21 12:55:35 | 000,001,770 | ---- | M] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/02/21 12:39:12 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2010/02/21 12:39:11 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2010/02/21 12:29:57 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2010/02/21 12:29:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2010/02/21 04:01:38 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2010/02/21 04:01:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2010/02/21 00:09:17 | 056,007,005 | ---- | M] () -- C:\Users\Case\Desktop\Movie_0001.wmv
[2010/02/20 23:34:30 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2010/02/20 23:34:30 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2010/02/20 23:22:11 | 578,071,552 | ---- | M] () -- C:\Users\Case\Desktop\Movie.avi
[2010/02/20 22:49:48 | 566,158,336 | ---- | M] () -- C:\Users\Case\Desktop\Finished.avi
[2010/02/20 19:23:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2010/02/20 19:23:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2010/02/20 14:10:43 | 000,000,829 | ---- | M] () -- C:\Users\Public\Desktop\case.lnk
[2010/02/20 11:47:13 | 000,000,835 | ---- | M] () -- C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk
[2010/02/20 03:48:53 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2010/02/20 03:48:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2010/02/20 00:21:55 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/02/19 03:44:39 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2010/02/19 03:44:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2010/02/18 20:39:17 | 001,453,170 | ---- | M] () -- C:\Users\Case\Desktop\Untitled-1.jpg
[2010/02/18 20:19:09 | 000,416,804 | ---- | M] () -- C:\Users\Case\Desktop\IMG00195.jpg
[2010/02/18 03:44:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2010/02/18 03:44:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2010/02/17 03:48:46 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2010/02/17 03:48:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2010/02/15 03:43:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2010/02/15 03:43:19 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2010/02/14 03:44:44 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2010/02/14 03:44:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2010/02/13 03:45:59 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2010/02/13 03:45:59 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2010/01/30 04:14:20 | 009,521,152 | ---- | M] () -- C:\Users\Case\Desktop\ichiko-01-magic-of-love.mp3
[2010/01/30 02:36:51 | 000,066,188 | ---- | M] () -- C:\Users\Case\Desktop\012910193422.jpeg
[2010/01/30 02:26:02 | 000,003,120 | ---- | M] () -- C:\Windows\System32\6ffdbcaf-f6c1-42d3-a4a9-c7957224a70b.dll
[2010/01/30 02:26:01 | 000,003,120 | ---- | M] () -- C:\Windows\2afbd66b-251d-4389-8ddb-6f8a3f253f1f.ocx
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/02/28 13:52:36 | 000,792,064 | ---- | C] () -- C:\Windows\System32\drivers\oelyhf.sys
[2010/02/28 13:51:20 | 000,000,024 | ---- | C] () -- C:\Users\Case\AppData\Roaming\glchvt.dat
[2010/02/28 13:51:12 | 000,000,004 | ---- | C] () -- C:\Users\Case\AppData\Roaming\avdrn.dat
[2010/02/28 12:28:02 | 000,155,136 | ---- | C] () -- C:\Windows\msa.exe
[2010/02/28 12:27:30 | 000,000,238 | -H-- | C] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/02/28 12:27:08 | 000,189,440 | ---- | C] () -- C:\Windows\System32\sshnas21.dll
[2010/02/28 00:39:35 | 000,000,961 | ---- | C] () -- C:\Users\Case\Desktop\Spybot - Search & Destroy.lnk
[2010/02/25 20:29:07 | 000,009,740 | -HS- | C] () -- C:\Users\Case\AppData\Local\UYxp8qC
[2010/02/25 20:29:04 | 000,197,632 | -HS- | C] () -- C:\Users\Case\AppData\Local\av.exe
[2010/02/25 20:29:04 | 000,000,008 | ---- | C] () -- C:\ProgramData\mswintmp.dat
[2010/02/25 19:19:00 | 000,000,282 | -H-- | C] () -- C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[2010/02/25 17:40:38 | 000,010,908 | -HS- | C] () -- C:\Users\Case\AppData\Local\7EgpN4
[2010/02/25 17:16:11 | 000,009,704 | ---- | C] () -- C:\Users\Case\Desktop\Untitled.jpg
[2010/02/25 02:17:02 | 000,009,820 | -HS- | C] () -- C:\Users\Case\AppData\Local\BnDHfux
[2010/02/21 21:12:17 | 000,267,997 | ---- | C] () -- C:\Users\Case\Desktop\wp_Hatsune_Miku_Easter_1024x768.jpg
[2010/02/21 14:40:45 | 000,000,760 | ---- | C] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2010/02/21 12:55:57 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2010/02/21 12:55:57 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2010/02/21 12:55:57 | 000,000,880 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2010/02/21 12:55:57 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2010/02/21 12:55:56 | 001,152,444 | ---- | C] () -- C:\Windows\UDB.zip
[2010/02/21 12:55:49 | 000,007,387 | ---- | C] () -- C:\Windows\System32\drivers\pctgntdi.cat
[2010/02/21 12:55:38 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctcore.cat
[2010/02/21 12:55:37 | 000,007,412 | ---- | C] () -- C:\Windows\System32\drivers\PCTAppEvent.cat
[2010/02/21 12:55:35 | 000,001,770 | ---- | C] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/02/21 12:55:31 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplsg.cat
[2010/02/21 00:02:59 | 056,007,005 | ---- | C] () -- C:\Users\Case\Desktop\Movie_0001.wmv
[2010/02/20 23:20:09 | 578,071,552 | ---- | C] () -- C:\Users\Case\Desktop\Movie.avi
[2010/02/20 22:25:17 | 566,158,336 | ---- | C] () -- C:\Users\Case\Desktop\Finished.avi
[2010/02/20 17:10:55 | 176,519,017 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/02/20 14:10:43 | 000,000,829 | ---- | C] () -- C:\Users\Public\Desktop\case.lnk
[2010/02/20 13:21:11 | 000,000,120 | ---- | C] () -- C:\Users\Case\AppData\Local\Mmokanede.dat
[2010/02/20 13:21:11 | 000,000,000 | ---- | C] () -- C:\Users\Case\AppData\Local\Lsexivewava.bin
[2010/02/20 00:21:55 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/02/18 20:19:07 | 000,416,804 | ---- | C] () -- C:\Users\Case\Desktop\IMG00195.jpg
[2010/02/15 11:14:15 | 000,000,835 | ---- | C] () -- C:\Users\Case\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk
[2010/01/30 04:14:18 | 009,521,152 | ---- | C] () -- C:\Users\Case\Desktop\ichiko-01-magic-of-love.mp3
[2010/01/30 02:36:51 | 000,066,188 | ---- | C] () -- C:\Users\Case\Desktop\012910193422.jpeg
[2010/01/30 02:26:02 | 000,003,120 | ---- | C] () -- C:\Windows\System32\6ffdbcaf-f6c1-42d3-a4a9-c7957224a70b.dll
[2010/01/30 02:26:01 | 000,003,120 | ---- | C] () -- C:\Windows\2afbd66b-251d-4389-8ddb-6f8a3f253f1f.ocx
[2009/12/27 17:50:33 | 000,055,808 | ---- | C] () -- C:\Windows\System32\zlib1.dll
[2009/12/26 19:24:09 | 000,000,056 | RHS- | C] () -- C:\Windows\System32\D72CD155C2.sys
[2009/12/26 19:24:04 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2009/08/16 02:57:42 | 000,000,552 | ---- | C] () -- C:\Users\Case\AppData\Local\d3d8caps.dat
[2009/07/08 11:45:17 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/05/22 17:08:24 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2009/01/27 13:21:16 | 000,000,000 | ---- | C] () -- C:\Windows\Game.INI
[2009/01/20 12:35:19 | 000,000,283 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008/10/28 23:42:40 | 000,000,004 | ---- | C] () -- C:\Users\Case\AppData\Roaming\998058
[2008/10/28 23:42:39 | 000,870,128 | ---- | C] () -- C:\Users\Case\AppData\Roaming\mcs.rma
[2008/09/19 13:57:34 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008/09/19 13:55:10 | 000,000,416 | ---- | C] () -- C:\Windows\System32\dtu100.dll.manifest
[2008/09/19 13:55:10 | 000,000,416 | ---- | C] () -- C:\Windows\System32\dpl100.dll.manifest
[2008/09/19 13:54:18 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008/08/19 11:07:38 | 000,000,680 | ---- | C] () -- C:\Users\Case\AppData\Local\d3d9caps.dat
[2008/08/02 22:16:03 | 000,000,142 | ---- | C] () -- C:\Windows\Lexstat.ini
[2008/08/02 22:07:21 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXBCinst.dll
[2008/08/02 22:07:20 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxbcutil.dll
[2008/07/05 20:30:19 | 000,000,028 | ---- | C] () -- C:\Windows\Robota.INI
[2008/07/05 20:19:59 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2008/07/05 20:16:14 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2008/07/05 20:09:17 | 000,006,211 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2008/07/04 22:18:52 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008/07/04 22:18:52 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2008/06/26 13:06:25 | 000,000,736 | ---- | C] () -- C:\ProgramData\lxdc
[2008/04/01 20:03:34 | 000,000,194 | ---- | C] () -- C:\Windows\frontpg.ini
[2008/04/01 19:37:44 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/03/23 10:45:29 | 000,000,113 | ---- | C] () -- C:\Windows\CyData.ini
[2008/03/23 01:32:19 | 000,000,024 | ---- | C] () -- C:\Windows\data.ini
[2008/03/22 22:01:39 | 000,053,248 | ---- | C] () -- C:\Windows\System32\zlib.dll
[2008/03/22 15:57:49 | 000,036,864 | ---- | C] () -- C:\Windows\System32\vbDABL.dll
[2008/03/22 15:57:47 | 000,031,232 | ---- | C] () -- C:\Windows\System32\alphablt.dll
[2008/03/22 15:57:44 | 000,221,184 | ---- | C] () -- C:\Windows\System32\COMSocketServer.dll
[2008/03/22 15:57:43 | 000,454,656 | ---- | C] () -- C:\Windows\System32\PaintX.dll
[2008/03/22 11:07:28 | 000,032,768 | ---- | C] () -- C:\Windows\System32\MD5.dll
[2008/02/07 04:36:42 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxdccoin.dll
[2008/02/07 04:31:56 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxdcrwrd.ini
[2008/02/07 04:29:48 | 000,286,720 | ---- | C] () -- C:\Windows\System32\LXDCinst.dll
[2008/02/07 04:29:43 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxdcgrd.dll
[2008/01/12 23:56:49 | 000,014,385 | ---- | C] () -- C:\Windows\Tw561a.ini
[2008/01/12 23:56:47 | 000,000,081 | ---- | C] () -- C:\Windows\Setup8a.ini
[2007/11/03 21:21:17 | 000,024,206 | ---- | C] () -- C:\Users\Case\AppData\Roaming\UserTile.png
[2007/10/31 07:54:28 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1364.dll
[2007/09/08 10:47:21 | 000,001,080 | ---- | C] () -- C:\Users\Case\AppData\Roaming\wklnhst.dat
[2007/09/06 15:52:10 | 000,165,376 | ---- | C] () -- C:\Users\Case\AppData\Local\uyejoyexa.dll
[2007/09/04 18:40:50 | 000,000,067 | ---- | C] () -- C:\Windows\swupdate.INI
[2007/09/03 14:53:25 | 000,215,552 | ---- | C] () -- C:\Users\Case\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007/07/22 17:39:26 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007/05/10 09:33:54 | 000,524,288 | -HS- | C] () -- C:\ProgramData\ntuser.dat{c94a5114-ff1a-11db-ae27-001a92a80021}.TMContainer00000000000000000002.regtrans-ms
[2007/05/10 09:33:54 | 000,524,288 | -HS- | C] () -- C:\ProgramData\ntuser.dat{c94a5114-ff1a-11db-ae27-001a92a80021}.TMContainer00000000000000000001.regtrans-ms
[2007/05/10 09:33:54 | 000,065,536 | -HS- | C] () -- C:\ProgramData\ntuser.dat{c94a5114-ff1a-11db-ae27-001a92a80021}.TM.blf
[2007/05/10 09:33:53 | 000,524,288 | -HS- | C] () -- C:\ProgramData\ntuser.dat{c94a5104-ff1a-11db-ae27-001a92a80021}.TMContainer00000000000000000002.regtrans-ms
[2007/05/10 09:33:53 | 000,524,288 | -HS- | C] () -- C:\ProgramData\ntuser.dat{c94a5104-ff1a-11db-ae27-001a92a80021}.TMContainer00000000000000000001.regtrans-ms
[2007/05/10 09:33:52 | 000,262,144 | ---- | C] () -- C:\ProgramData\ntuser.dat
[2007/05/10 09:33:52 | 000,065,536 | -HS- | C] () -- C:\ProgramData\ntuser.dat{c94a5104-ff1a-11db-ae27-001a92a80021}.TM.blf
[2007/05/10 09:33:52 | 000,005,120 | -H-- | C] () -- C:\ProgramData\ntuser.dat.LOG1
[2007/05/10 09:33:52 | 000,000,000 | -H-- | C] () -- C:\ProgramData\ntuser.dat.LOG2
[2007/05/10 09:29:33 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2007/05/10 09:29:33 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2007/05/10 09:29:33 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2007/05/10 09:29:33 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2007/05/10 09:29:33 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2007/05/10 09:29:33 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2007/05/10 08:59:33 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2007/05/10 08:35:32 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2007/05/10 08:35:32 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2007/05/10 08:35:32 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2007/05/10 08:35:32 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2007/04/10 13:46:48 | 000,015,498 | ---- | C] () -- C:\Windows\VX3000.ini
[2007/03/30 11:27:34 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1244.dll
[2007/02/22 17:32:00 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxbccoin.dll
[2006/11/02 04:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/01 23:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/10/28 09:31:44 | 000,344,064 | ---- | C] () -- C:\Windows\System32\dlcxcoin.dll
[2006/10/20 19:07:32 | 000,106,496 | ---- | C] () -- C:\Windows\System32\dlcxinsr.dll
[2006/10/20 19:06:44 | 000,036,864 | ---- | C] () -- C:\Windows\System32\dlcxcur.dll
[2006/10/20 19:03:28 | 000,139,264 | ---- | C] () -- C:\Windows\System32\dlcxjswr.dll
[2006/10/20 18:57:40 | 000,176,128 | ---- | C] () -- C:\Windows\System32\dlcxinsb.dll
[2006/10/20 18:56:52 | 000,086,016 | ---- | C] () -- C:\Windows\System32\dlcxcub.dll
[2006/10/20 18:55:28 | 000,073,728 | ---- | C] () -- C:\Windows\System32\dlcxcu.dll
[2006/10/20 18:54:42 | 000,176,128 | ---- | C] () -- C:\Windows\System32\dlcxins.dll
[2006/10/20 18:48:38 | 000,454,656 | ---- | C] () -- C:\Windows\System32\dlcxutil.dll
[2006/10/20 18:46:42 | 000,188,416 | ---- | C] () -- C:\Windows\System32\dlcxgrd.dll
[2006/09/22 06:42:38 | 000,065,536 | ---- | C] () -- C:\Windows\System32\dlcxcaps.dll
[2006/09/06 05:13:14 | 000,073,728 | ---- | C] () -- C:\Windows\System32\dlcxcfg.dll
[2006/08/08 14:58:04 | 000,692,224 | ---- | C] () -- C:\Windows\System32\dlcxdrs.dll
[2006/05/17 18:47:12 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxdcvs.dll
[2006/04/24 14:09:58 | 000,040,960 | ---- | C] () -- C:\Windows\System32\dlcxvs.dll
[2006/03/19 18:03:04 | 000,061,440 | ---- | C] () -- C:\Windows\System32\dlcxcnv4.dll
[2006/03/09 09:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/10/25 13:51:14 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxbcvs.dll
[2005/08/30 00:00:00 | 000,781,312 | ---- | C] () -- C:\Windows\System32\RGSS102J.dll
[2005/08/30 00:00:00 | 000,778,752 | ---- | C] () -- C:\Windows\System32\RGSS102E.dll
[2005/08/30 00:00:00 | 000,771,584 | ---- | C] () -- C:\Windows\System32\RGSS100J.dll
[1998/06/09 23:00:00 | 000,015,120 | ---- | C] () -- C:\Windows\System32\REPUTIL.DLL
========== Alternate Data Streams ========== @Alternate Data Stream - 64 bytes -> C:\Users\Case\Documents\Willis.wav:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Case\Documents\background.wav:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Case\Documents\Ad.wav:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Case\Desktop\Finished.avi:TOC.WMV
@Alternate Data Stream - 159 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86
< End of report >