OTL logfile created on: 7/4/2011 4:06:06 PM - Run
OTLPE by OldTimer - Version 3.1.46.0 Folder = X:\Programs\OTLPE
Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 85.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.65 Gb Total Space | 28.72 Gb Free Space | 41.24% Space Free | Partition Type: NTFS
Drive E: | 69.64 Gb Total Space | 65.68 Gb Free Space | 94.32% Space Free | Partition Type: NTFS
Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV - [2011/07/02 00:42:50 | 000,588,672 | ---- | M] (Sysinternals -
www.sysinternals.com) [On_Demand] -- C:\Users\musicmatt\AppData\Local\Temp\PRWXOUZX.exe -- (PRWXOUZX)
SRV - [2011/06/28 17:58:38 | 000,062,928 | R--- | M] () [Auto] -- C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe -- (szserver)
SRV - [2011/06/06 12:55:28 | 000,059,392 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/04/27 15:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] () [Auto] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/09/21 16:09:24 | 000,052,664 | ---- | M] () [Disabled] -- C:\Program Files\Tether\TBService.exe -- (Tether)
SRV - [2009/02/20 09:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/03 02:55:52 | 000,506,416 | ---- | M] (Egis Incorporated) [Disabled] -- C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service)
SRV - [2007/12/20 12:32:04 | 000,131,072 | ---- | M] (Acer Inc.) [Auto] -- C:\Acer\Empowering Technology\eNet\eNet Service.exe -- (eNet Service)
SRV - [2007/12/19 19:09:22 | 000,024,576 | ---- | M] () [Disabled] -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe -- (eSettingsService)
SRV - [2007/11/27 19:54:36 | 000,112,128 | ---- | M] () [Auto] -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService)
SRV - [2007/10/01 17:42:36 | 000,024,576 | ---- | M] (Acer Inc.) [Auto] -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe -- (eLockService)
SRV - [2007/09/20 14:57:28 | 000,167,936 | ---- | M] (acer) [Auto] -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe -- (WMIService)
SRV - [2007/09/10 16:28:18 | 000,057,344 | ---- | M] (Acer Inc.) [Auto] -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService)
SRV - [2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) [Auto] -- C:\Windows\System32\lxdecoms.exe -- (lxde_device)
SRV - [2007/05/29 16:06:44 | 000,099,248 | ---- | M] () [Auto] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdeserv.exe -- (lxdeCATSCustConnectService)
SRV - [2006/10/05 16:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (ute3mty1)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand] -- -- (MEMSWEEP2)
DRV - File not found [Kernel | On_Demand] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - File not found [Kernel | Auto] -- -- (Aspi32)
DRV - [2011/06/29 04:02:44 | 000,070,144 | ---- | M] () [Kernel | On_Demand] -- C:\Users\musicmatt\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys -- (F-Secure Standalone Minifilter)
DRV - [2011/04/27 15:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/18 13:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2010/06/09 17:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2010/05/26 10:45:04 | 000,018,816 | ---- | M] (Sophos Plc) [Kernel | System] -- C:\Windows\System32\SAVRKBootTasks.sys -- (SAVRKBootTasks)
DRV - [2010/05/18 10:53:18 | 000,045,608 | ---- | M] (Tether) [Kernel | On_Demand] -- C:\Windows\System32\drivers\qrkis.sys -- (qrkis)
DRV - [2010/05/12 18:01:06 | 000,059,280 | R--- | M] (iS3, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\SZKGFS.sys -- (szkgfs)
DRV - [2010/04/22 19:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R--- | M] (iS3 Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\SZKG.sys -- (szkg5)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R--- | M] (iS3 Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\is3srv.sys -- (is3srv)
DRV - [2009/11/02 20:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2008/03/10 02:58:40 | 003,533,824 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007/07/03 11:05:20 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15)
DRV - [2007/04/03 14:04:28 | 000,039,680 | ---- | M] (O2Micro ) [Kernel | Boot] -- C:\Windows\System32\drivers\o2media.sys -- (O2MDRDR)
DRV - [2007/04/02 20:11:08 | 000,035,712 | ---- | M] (O2Micro ) [Kernel | Boot] -- C:\Windows\System32\drivers\o2sd.sys -- (O2SDRDR)
DRV - [2007/03/09 18:56:04 | 001,163,616 | ---- | M] (Agere Systems) [Kernel | On_Demand] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/10/30 15:23:12 | 000,007,680 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2006/09/19 17:47:04 | 000,080,744 | ---- | M] (Wasay) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSVD.sys -- (WSVD)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://en.us.acer.yahoo.comIE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\musicmatt_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.searchqu.com/406IE - HKU\musicmatt_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Restore =
http://home.jzip.comIE - HKU\musicmatt_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\musicmatt_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2011/04/12 23:26:27 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.10\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Freecorder Toolbar) - {70dd86e8-b5bc-4e4a-9d5c-b6234c24323c} - C:\Program Files\freecordertoolbar\vmntemplateX.dll ()
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (HiTRUST)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll (DealPly)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {70dd86e8-b5bc-4e4a-9d5c-b6234c24323c} - C:\Program Files\freecordertoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.10\facemoodsTlbr.dll (facemoods.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\musicmatt_ON_C\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKU\musicmatt_ON_C\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.10\facemoodssrv.exe (facemoods.com)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [LTCM Client] C:\Program Files\LTCM Client\ltcmClient.exe (Leader Technologies Inc.)
O4 - HKLM..\Run: [lxdeamon] C:\Program Files\Lexmark 4800 Series\lxdeamon.exe ()
O4 - HKLM..\Run: [lxdemon.exe] C:\Program Files\Lexmark 4800 Series\lxdemon.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKU\musicmatt_ON_C..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - Startup: Error locating startup folders.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\musicmatt_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 205.152.128.23 205.152.37.23
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/07/04 03:58:30 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/07/02 15:51:59 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2011/07/02 02:33:29 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/07/02 02:33:28 | 000,000,000 | ---D | C] -- C:\Program Files\facemoods.com
[2011/07/02 02:33:28 | 000,000,000 | ---D | C] -- C:\Program Files\DealPly
[2011/07/02 02:30:37 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Local\Ilivid Player
[2011/07/02 02:29:35 | 000,000,000 | ---D | C] -- C:\Program Files\iLivid
[2011/07/02 02:29:11 | 000,000,000 | ---D | C] -- C:\Program Files\Windows iLivid Toolbar
[2011/07/02 01:22:52 | 000,018,816 | ---- | C] (Sophos Plc) -- C:\Windows\System32\SAVRKBootTasks.sys
[2011/07/02 00:07:12 | 000,000,000 | --SD | C] -- C:\nchost31914n
[2011/07/02 00:06:29 | 000,000,000 | --SD | C] -- C:\nchost30408n
[2011/06/30 23:13:23 | 000,000,000 | --SD | C] -- C:\nchost26863n
[2011/06/30 22:41:05 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/06/30 18:38:58 | 000,000,000 | --SD | C] -- C:\nchost22291n
[2011/06/30 14:34:33 | 000,000,000 | --SD | C] -- C:\nchost3682n
[2011/06/30 14:20:31 | 000,000,000 | --SD | C] -- C:\nchost17059n
[2011/06/30 14:19:58 | 000,000,000 | --SD | C] -- C:\nchost
[2011/06/30 14:09:25 | 004,130,507 | R--- | C] (Swearware) -- C:\Users\musicmatt\Desktop\nchost.exe
[2011/06/30 13:54:31 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/06/30 13:54:31 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/06/30 13:54:31 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/06/30 13:54:26 | 000,000,000 | --SD | C] -- C:\Commy8405C
[2011/06/30 13:53:57 | 000,000,000 | --SD | C] -- C:\Commy31465C
[2011/06/30 13:53:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/30 13:53:11 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/06/29 22:42:22 | 000,000,000 | --SD | C] -- C:\Commy
[2011/06/29 04:11:19 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\f-secure
[2011/06/29 04:10:39 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure
[2011/06/29 04:08:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2011/06/29 03:20:26 | 000,000,000 | ---D | C] -- C:\Windows\TempBC33A0E8-0AC2-22D1-303C-C46234BCB4E2-Signatures
[2011/06/29 03:19:24 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/29 02:57:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
[2011/06/29 02:56:58 | 000,000,000 | ---D | C] -- C:\Program Files\STOPzilla!
[2011/06/29 02:56:57 | 000,000,000 | ---D | C] -- C:\ProgramData\STOPzilla!
[2011/06/29 02:56:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2011/06/29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/06/29 02:49:00 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/06/29 02:45:03 | 000,015,872 | ---- | C] (VIA Technologies) -- C:\Windows\System32\drivers\1206856434.sys
[2011/06/29 01:47:48 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/06/28 17:58:32 | 000,132,560 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3HTUI5.dll
[2011/06/28 17:58:30 | 000,546,256 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\SZComp5.dll
[2011/06/28 17:58:30 | 000,456,144 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\SZBase5.dll
[2011/06/28 17:58:30 | 000,398,800 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3DBA5.dll
[2011/06/28 17:58:30 | 000,028,624 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3XDat5.dll
[2011/06/28 17:58:30 | 000,022,992 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\SZIO5.dll
[2011/06/28 17:58:28 | 000,390,608 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3UI5.dll
[2011/06/28 17:58:28 | 000,230,864 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3Win325.dll
[2011/06/28 17:58:28 | 000,099,792 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3Svc5.dll
[2011/06/28 17:58:28 | 000,099,792 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3Inet5.dll
[2011/06/28 17:58:28 | 000,067,024 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3Hks5.dll
[2011/06/28 17:58:26 | 000,738,768 | R--- | C] (iS3, Inc.) -- C:\Windows\System32\IS3Base5.dll
[2011/06/24 02:23:41 | 000,000,000 | ---D | C] -- C:\Program Files\WXWarning
[2011/06/24 02:23:20 | 000,000,000 | ---D | C] -- C:\Program Files\WXSpots
[2011/06/22 21:28:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java(7)
[2011/06/22 21:27:30 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/06/22 21:27:29 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/06/22 21:27:29 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/06/22 20:30:37 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\Desktop\camera
[2011/06/22 01:03:24 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\Weather Defender
[2011/06/20 15:40:59 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\FileZilla
[2011/06/20 15:40:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2011/06/20 15:40:38 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2011/06/20 15:38:31 | 000,000,000 | ---D | C] -- C:\Program Files\Scanner Recorder
[2011/06/18 23:22:23 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Local\Apple Computer
[2011/06/18 23:22:11 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\Apple Computer
[2011/06/18 11:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/06/18 03:07:17 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/06/18 03:07:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/06/18 03:07:14 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/06/18 03:07:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/06/16 23:25:08 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Interbank FX Trader 4
[2011/06/16 23:24:51 | 000,000,000 | ---D | C] -- C:\InterbankFX_1-Click
[2011/06/15 20:12:51 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\SpotterNetwork
[2011/06/15 20:07:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spotter Network
[2011/06/15 20:07:48 | 001,355,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvbvm50.dll
[2011/06/15 20:07:48 | 000,132,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Msinet.ocx
[2011/06/15 20:07:42 | 000,368,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbar332.dll
[2011/06/15 20:07:42 | 000,000,000 | ---D | C] -- C:\Program Files\SpotterNetwork
[2011/06/15 20:07:41 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.005
[2011/06/15 20:07:40 | 001,376,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.004
[2011/06/15 20:07:40 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.003
[2011/06/15 20:07:39 | 000,569,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.000
[2011/06/15 20:07:39 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.001
[2011/06/15 20:07:39 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.002
[2011/06/15 01:02:57 | 000,000,000 | ---D | C] -- C:\Users\musicmatt\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/06/15 01:02:52 | 000,000,000 | ---D | C] -- C:\Program Files\TweetDeck
[2011/06/09 14:37:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/06/09 14:37:32 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/06/09 14:37:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/06/05 12:01:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/04/01 15:25:51 | 000,434,176 | ---- | C] ( ) -- C:\Windows\System32\lxdehcp.dll
[2011/01/16 16:17:52 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
[2007/05/29 12:08:10 | 000,320,432 | ---- | C] ( ) -- C:\Windows\System32\lxdeih.exe
[2007/05/29 12:07:58 | 000,598,960 | ---- | C] ( ) -- C:\Windows\System32\lxdecoms.exe
[2007/05/29 12:07:48 | 000,365,488 | ---- | C] ( ) -- C:\Windows\System32\lxdecfg.exe
[2007/05/17 17:08:58 | 000,647,168 | ---- | C] ( ) -- C:\Windows\System32\lxdepmui.dll
[2007/05/17 17:06:40 | 001,200,128 | ---- | C] ( ) -- C:\Windows\System32\lxdeserv.dll
[2007/05/17 17:00:32 | 000,565,248 | ---- | C] ( ) -- C:\Windows\System32\lxdelmpm.dll
[2007/05/17 17:00:32 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxdecomm.dll
[2007/05/17 17:00:32 | 000,356,352 | ---- | C] ( ) -- C:\Windows\System32\lxdeinpa.dll
[2007/05/17 16:59:34 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\lxdehbn3.dll
[2007/05/17 16:57:52 | 000,950,272 | ---- | C] ( ) -- C:\Windows\System32\lxdeusb1.dll
[2007/05/17 16:56:56 | 000,860,160 | ---- | C] ( ) -- C:\Windows\System32\lxdecomc.dll
[2007/05/17 16:52:56 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\lxdeiesc.dll
[2007/05/17 16:51:30 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\lxdeprox.dll
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/07/04 14:53:37 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat
[2011/07/04 14:49:21 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/04 14:49:21 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/04 14:49:21 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/04 14:49:08 | 1877,065,728 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/04 13:01:37 | 000,656,214 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/07/04 13:01:37 | 000,123,536 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/07/04 12:57:36 | 000,000,782 | ---- | M] () -- C:\Users\musicmatt\Desktop\fix.bat
[2011/07/04 12:57:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/04 12:12:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-880227785-1377843364-700853731-1003UA.job
[2011/07/04 05:05:05 | 179,362,107 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/07/03 21:12:00 | 000,000,872 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-880227785-1377843364-700853731-1003Core.job
[2011/07/02 15:53:02 | 000,000,858 | ---- | M] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Virtual DJ Pro.lnk
[2011/07/02 00:06:54 | 004,130,507 | R--- | M] (Swearware) -- C:\Users\musicmatt\Desktop\nchost.exe
[2011/07/02 00:04:17 | 000,000,894 | ---- | M] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/06/29 17:15:30 | 000,000,072 | ---- | M] () -- C:\Users\musicmatt\Desktop\gwrra.sc.t.url
[2011/06/29 17:14:36 | 000,000,072 | ---- | M] () -- C:\Users\musicmatt\Desktop\kf4nxs.url
[2011/06/29 17:13:34 | 000,000,078 | ---- | M] () -- C:\Users\musicmatt\Desktop\whenpigsflypro.url
[2011/06/29 13:21:06 | 000,002,713 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LTCM Client.lnk
[2011/06/29 04:08:28 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2011/06/29 03:30:55 | 000,002,198 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/06/29 03:27:36 | 000,001,772 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/06/29 03:19:24 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/29 03:18:33 | 000,395,608 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/06/29 02:57:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
[2011/06/29 02:45:03 | 000,015,872 | ---- | M] (VIA Technologies) -- C:\Windows\System32\drivers\1206856434.sys
[2011/06/29 01:47:50 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/06/28 17:58:32 | 000,132,560 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3HTUI5.dll
[2011/06/28 17:58:30 | 000,546,256 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\SZComp5.dll
[2011/06/28 17:58:30 | 000,456,144 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\SZBase5.dll
[2011/06/28 17:58:30 | 000,398,800 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3DBA5.dll
[2011/06/28 17:58:30 | 000,028,624 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3XDat5.dll
[2011/06/28 17:58:30 | 000,022,992 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\SZIO5.dll
[2011/06/28 17:58:28 | 000,390,608 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3UI5.dll
[2011/06/28 17:58:28 | 000,230,864 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3Win325.dll
[2011/06/28 17:58:28 | 000,099,792 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3Svc5.dll
[2011/06/28 17:58:28 | 000,099,792 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3Inet5.dll
[2011/06/28 17:58:28 | 000,067,024 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3Hks5.dll
[2011/06/28 17:58:26 | 000,738,768 | R--- | M] (iS3, Inc.) -- C:\Windows\System32\IS3Base5.dll
[2011/06/26 21:44:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GRLevelX
[2011/06/26 02:45:56 | 000,256,000 | ---- | M] () -- C:\Windows\PEV.exe
[2011/06/21 03:07:50 | 000,000,196 | ---- | M] () -- C:\Windows\System32\~.inf
[2011/06/21 03:07:22 | 004,212,452 | ---- | M] () -- C:\Users\musicmatt\Desktop\United_States_Frequency_Allocations_Chart_2003_-_The_Radio_Spectrum.jpg
[2011/06/20 15:40:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2011/06/20 15:38:31 | 000,001,888 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scanner Recorder.lnk
[2011/06/18 11:58:36 | 000,001,804 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/16 23:25:09 | 000,001,499 | ---- | M] () -- C:\Users\musicmatt\Desktop\Interbank FX Trader 4.lnk
[2011/06/16 15:37:26 | 000,000,066 | ---- | M] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chasing the Southeast.url
[2011/06/15 20:08:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spotter Network
[2011/06/15 20:07:56 | 000,001,620 | ---- | M] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spotter Network.lnk
[2011/06/15 01:02:53 | 000,000,738 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweetDeck.lnk
[2011/06/15 01:02:53 | 000,000,726 | ---- | M] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\TweetDeck.lnk
[2011/06/12 05:46:03 | 000,001,356 | ---- | M] () -- C:\Users\musicmatt\AppData\Local\d3d9caps.dat
[2011/06/09 14:37:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/06/06 18:11:35 | 000,000,258 | ---- | M] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/06/05 12:01:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/07/04 12:57:36 | 000,000,782 | ---- | C] () -- C:\Users\musicmatt\Desktop\fix.bat
[2011/07/02 15:53:02 | 000,000,858 | ---- | C] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Virtual DJ Pro.lnk
[2011/06/30 13:54:31 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/06/30 13:54:31 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/06/30 13:54:31 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/06/30 13:54:31 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/06/30 13:54:31 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/06/29 23:06:55 | 1877,065,728 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/29 22:55:57 | 179,362,107 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/06/29 17:15:30 | 000,000,072 | ---- | C] () -- C:\Users\musicmatt\Desktop\gwrra.sc.t.url
[2011/06/29 17:14:18 | 000,000,072 | ---- | C] () -- C:\Users\musicmatt\Desktop\kf4nxs.url
[2011/06/29 17:13:34 | 000,000,078 | ---- | C] () -- C:\Users\musicmatt\Desktop\whenpigsflypro.url
[2011/06/29 03:27:36 | 000,001,772 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/06/21 03:08:03 | 004,212,452 | ---- | C] () -- C:\Users\musicmatt\Desktop\United_States_Frequency_Allocations_Chart_2003_-_The_Radio_Spectrum.jpg
[2011/06/20 15:38:31 | 000,001,888 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scanner Recorder.lnk
[2011/06/18 11:58:36 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/16 23:25:09 | 000,001,499 | ---- | C] () -- C:\Users\musicmatt\Desktop\Interbank FX Trader 4.lnk
[2011/06/16 14:41:49 | 000,000,066 | ---- | C] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chasing the Southeast.url
[2011/06/15 20:07:56 | 000,001,620 | ---- | C] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spotter Network.lnk
[2011/06/15 01:02:53 | 000,000,738 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweetDeck.lnk
[2011/06/15 01:02:53 | 000,000,726 | ---- | C] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\TweetDeck.lnk
[2011/06/06 18:11:35 | 000,000,258 | ---- | C] () -- C:\Users\musicmatt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/06 14:00:10 | 000,246,094 | ---- | C] () -- C:\Users\musicmatt\AppData\Local\census.cache
[2011/05/06 13:59:50 | 000,182,006 | ---- | C] () -- C:\Users\musicmatt\AppData\Local\ars.cache
[2011/05/06 13:48:06 | 000,000,036 | ---- | C] () -- C:\Users\musicmatt\AppData\Local\housecall.guid.cache
[2011/04/24 15:15:00 | 000,098,816 | ---- | C] () -- C:\Windows\System32\FGWVB32.DLL
[2011/04/01 15:25:51 | 000,348,160 | ---- | C] () -- C:\Windows\System32\lxdeinst.dll
[2011/03/29 20:45:53 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011/03/29 19:33:19 | 000,580,096 | ---- | C] () -- C:\Windows\System32\lame.exe
[2011/03/29 19:33:19 | 000,496,640 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2011/03/29 19:33:19 | 000,307,200 | ---- | C] () -- C:\Windows\System32\Mp3Ctrl.dll
[2011/03/29 19:33:19 | 000,131,176 | ---- | C] () -- C:\Windows\System32\mp3gain.exe
[2011/03/29 19:33:19 | 000,086,016 | ---- | C] () -- C:\Windows\System32\akrip32.dll
[2011/03/29 16:56:23 | 000,000,047 | ---- | C] () -- C:\Windows\WinInit.Ini
[2011/03/29 16:24:12 | 000,000,416 | ---- | C] () -- C:\ProgramData\lxde
[2011/03/13 23:05:38 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/01/21 04:51:26 | 000,001,356 | ---- | C] () -- C:\Users\musicmatt\AppData\Local\d3d9caps.dat
[2011/01/19 04:43:58 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/01/19 04:43:57 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/01/18 02:15:50 | 000,669,002 | ---- | C] () -- C:\Windows\unins000.exe
[2011/01/18 02:15:50 | 000,001,103 | ---- | C] () -- C:\Windows\unins000.dat
[2011/01/17 22:23:02 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/01/17 02:56:42 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI
[2011/01/16 23:26:26 | 000,027,648 | ---- | C] () -- C:\Users\musicmatt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/16 23:15:44 | 000,036,864 | ---- | C] () -- C:\Windows\System32\lxf3oem.dll
[2011/01/16 23:15:44 | 000,012,288 | ---- | C] () -- C:\Windows\System32\LXF3PMRC.DLL
[2011/01/16 18:44:22 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2011/01/16 18:44:22 | 000,168,886 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011/01/16 18:44:22 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2011/01/16 18:44:22 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2011/01/16 17:51:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/01/16 17:12:37 | 000,115,267 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2011/01/16 17:12:36 | 000,097,859 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2011/01/16 16:17:52 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
[2011/01/16 16:17:04 | 000,015,656 | ---- | C] () -- C:\Windows\System32\drivers\int15_64.sys
[2011/01/16 16:16:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\NATTraversal.dll
[2009/09/09 19:01:40 | 000,027,675 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat
[2008/03/30 02:41:02 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2008/03/29 23:28:22 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/03/29 23:28:21 | 000,192,816 | ---- | C] () -- C:\Windows\System32\drivers\SynTP.sys
[2008/03/29 23:28:06 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2008/03/29 23:28:06 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2008/03/29 23:28:05 | 000,000,040 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2008/03/29 22:51:04 | 000,001,132 | ---- | C] () -- C:\Windows\RtDefLvl.ini
[2008/03/29 22:51:04 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\RtkHDAud.dat
[2007/05/28 01:02:38 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxdegrd.dll
[2007/05/24 16:24:26 | 000,692,224 | ---- | C] () -- C:\Windows\System32\lxdedrs.dll
[2007/05/22 10:09:42 | 000,065,536 | ---- | C] () -- C:\Windows\System32\lxdecaps.dll
[2007/05/03 18:50:10 | 000,348,160 | ---- | C] () -- C:\Windows\System32\lxdecoin.dll
[2007/04/17 10:17:06 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxdecnv4.dll
[2006/11/02 08:57:28 | 000,067,584 | ---- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,395,608 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,656,214 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,123,536 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/08/01 04:53:18 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxdevs.dll
[2001/12/26 18:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 01:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 18:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
========== LOP Check ========== [2011/06/29 01:15:37 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\.purple
[2011/01/16 16:21:59 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Acer
[2011/03/05 21:12:14 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Audacity
[2011/06/29 02:24:48 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\BitTorrent
[2011/05/06 00:07:35 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\DriverCure
[2011/06/29 04:11:19 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\f-secure
[2011/06/29 02:24:48 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\FileZilla
[2011/04/22 18:53:39 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\GetRightToGo
[2011/06/27 15:00:46 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\GRLevel3
[2011/06/16 22:09:08 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\gtk-2.0
[2011/01/16 16:21:58 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Leadertech
[2011/03/13 23:20:33 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Leawo
[2011/04/25 19:44:24 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Lexmark Productivity Studio
[2011/03/13 23:20:37 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Moyea
[2011/01/18 03:31:26 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\OpenOffice.org
[2011/05/06 00:07:34 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\ParetoLogic
[2011/01/16 22:08:06 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\PCDJ
[2011/01/16 21:21:34 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Shareaza
[2011/05/10 18:19:09 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Sony
[2011/05/10 17:51:02 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Sony Setup
[2011/06/24 02:33:23 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\SpotterNetwork
[2011/04/12 14:47:34 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\SumatraPDF
[2011/04/27 12:38:04 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\TeamViewer
[2011/04/08 10:40:13 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Tether
[2011/06/15 01:02:57 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/05/06 02:00:49 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Uniblue
[2011/06/29 02:24:48 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\uTorrent
[2011/06/24 02:18:26 | 000,000,000 | ---D | M] -- C:\Users\musicmatt\AppData\Roaming\Weather Defender
[2011/05/05 11:59:36 | 000,000,000 | ---D | M] -- C:\ProgramData\Alwil Software
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/07/02 15:51:59 | 000,000,000 | ---D | M] -- C:\ProgramData\boost_interprocess
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2011/04/24 21:53:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Digital Entertainer
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/06/29 04:10:39 | 000,000,000 | ---D | M] -- C:\ProgramData\F-Secure
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011/03/13 23:07:48 | 000,000,000 | ---D | M] -- C:\ProgramData\Leawo
[2011/05/09 12:36:59 | 000,000,000 | ---D | M] -- C:\ProgramData\Lx_cats
[2011/01/17 15:07:30 | 000,000,000 | ---D | M] -- C:\ProgramData\musicmatt
[2011/05/06 00:50:26 | 000,000,000 | ---D | M] -- C:\ProgramData\ParetoLogic
[2011/01/16 22:08:03 | 000,000,000 | ---D | M] -- C:\ProgramData\PCDJ
[2011/05/10 18:19:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/06/29 03:03:48 | 000,000,000 | ---D | M] -- C:\ProgramData\STOPzilla!
[2011/06/27 15:00:46 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2006/11/02 09:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/05/06 02:00:53 | 000,000,000 | ---D | M] -- C:\ProgramData\Uniblue
[2008/03/29 23:11:48 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2011/07/04 14:53:17 | 000,032,646 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < MD5 for: AGRSMSVC.EXE >[2006/10/05 16:10:12 | 000,009,216 | ---- | M] (Agere Systems) MD5=39E435C90C9C4F780FA0ED05CA3C3A1B -- C:\Windows\System32\agrsmsvc.exe
[2006/10/05 16:10:12 | 000,009,216 | ---- | M] (Agere Systems) MD5=39E435C90C9C4F780FA0ED05CA3C3A1B -- C:\Windows\System32\DriverStore\FileRepository\agrmdv32.inf_0ddf652a\agrsmsvc.exe
< MD5 for: ATAPI.SYS >[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\ERDNT\cache\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/20 22:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/20 22:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 05:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
< MD5 for: ATI2EVXX.EXE >[2008/03/10 01:59:02 | 000,655,360 | ---- | M] (ATI Technologies Inc.) MD5=B886D349AFAD502DE4F6EA0C64B1CC4D -- C:\Windows\System32\Ati2evxx.exe
[2008/03/10 01:59:02 | 000,655,360 | ---- | M] (ATI Technologies Inc.) MD5=B886D349AFAD502DE4F6EA0C64B1CC4D -- C:\Windows\System32\DriverStore\FileRepository\cl_61295.inf_f4ec1680\B_60953\Ati2evxx.exe
< MD5 for: DFSC.SYS >[2009/04/11 00:14:12 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=218D8AE46C88E82014F5D73D0236D9B2 -- C:\Windows\winsxs\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.0.6002.18005_none_8985a6e9e33db02a\dfsc.sys
[2011/04/14 10:36:03 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=3A3436F7DFE0E0C58CD5C3B6C9F21634 -- C:\Windows\System32\drivers\dfsc.sys
[2011/04/14 10:36:03 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=3A3436F7DFE0E0C58CD5C3B6C9F21634 -- C:\Windows\winsxs\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.0.6002.18451_none_894b9dbde369cb1f\dfsc.sys
[2011/04/14 10:36:03 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=3A3436F7DFE0E0C58CD5C3B6C9F21634 -- C:\Windows\winsxs\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.0.6002.22625_none_89f9ad5afc6b7999\dfsc.sys
[2008/01/20 22:24:55 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=9E635AE5E8AD93E2B5989E2E23679F97 -- C:\Windows\winsxs\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.0.6001.18000_none_879a2ddde61be4de\dfsc.sys
[2011/04/14 10:24:14 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=A3E9FA213F443AC77C7746119D13FEEC -- C:\Windows\winsxs\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.0.6001.18633_none_877cca5be63173a0\dfsc.sys
[2011/04/13 09:22:40 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=E20FB30D720810646ED24FB7CA9899A2 -- C:\Windows\winsxs\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.0.6001.22899_none_87cb8b40ff7a5041\dfsc.sys
< MD5 for: LXDECOMS.EXE >[2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) MD5=626CF4DB8FF93DF819A6FF479F8086C4 -- C:\Windows\System32\config\systemprofile\{4a452778-f0bb-4a38-940c-1cc99117d899}\i386\lxdecoms.exe
[2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) MD5=626CF4DB8FF93DF819A6FF479F8086C4 -- C:\Windows\System32\config\systemprofile\{f48ced33-c68e-430f-80ed-9a2ea4ef228f}\i386\lxdecoms.exe
[2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) MD5=626CF4DB8FF93DF819A6FF479F8086C4 -- C:\Windows\System32\DriverStore\FileRepository\lxdeprc.inf_7b84dc0b\i386\lxdecoms.exe
[2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) MD5=626CF4DB8FF93DF819A6FF479F8086C4 -- C:\Windows\System32\lxdecoms.exe
[2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) MD5=626CF4DB8FF93DF819A6FF479F8086C4 -- C:\Windows\System32\spool\drivers\w32x86\{2C4DFD08-EF95-4C6A-9F2A-885FB012BA44}\i386\lxdecoms.exe
[2007/05/29 16:07:58 | 000,598,960 | ---- | M] ( ) MD5=626CF4DB8FF93DF819A6FF479F8086C4 -- C:\Windows\System32\spool\drivers\w32x86\{E94154B4-8774-497D-9EEC-81A38EA9F76A}\i386\lxdecoms.exe
< MD5 for: MSCORSVW.EXE >[2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) MD5=31A71C94C8DD415B1C6A90BEE470F727 -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
[2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) MD5=8EE772032E2FE80A924F3B8DD5082194 -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) MD5=8EE772032E2FE80A924F3B8DD5082194 -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6002.18005_none_1fd1ab49e8ca6ebb\mscorsvw.exe
[2008/01/20 22:24:55 | 000,070,144 | ---- | M] (Microsoft Corporation) MD5=A4AF4201BD519971F8F34724F3CA9DBB -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6001.18000_none_1ff6260de878daa7\mscorsvw.exe
[2006/11/02 02:34:11 | 000,059,392 | ---- | M] (Microsoft Corporation) MD5=D3BF342F47996E18490970FCFB8126A8 -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6000.16386_none_2021a451e82131db\mscorsvw.exe
[2008/07/27 14:00:25 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D87ACAED61E417BBA546CED5E7E36D9C -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6000.16720_none_201c2ab5e826014f\mscorsvw.exe
[2008/07/27 13:55:53 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D87ACAED61E417BBA546CED5E7E36D9C -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6000.20883_none_0954415a01c84642\mscorsvw.exe
[2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D87ACAED61E417BBA546CED5E7E36D9C -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6001.18111_none_1ff70f6be8780df0\mscorsvw.exe
[2008/07/27 13:58:33 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D87ACAED61E417BBA546CED5E7E36D9C -- C:\Windows\winsxs\x86_netfx-mscorsvw_exe_b03f5f7f11d50a3a_6.0.6001.22230_none_092b8008021d8703\mscorsvw.exe
< MD5 for: NDIS.SYS >[2009/04/11 02:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\ERDNT\cache\ndis.sys
[2009/04/11 02:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\System32\drivers\ndis.sys
[2009/04/11 02:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2008/01/20 22:23:50 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys
< MD5 for: USERINIT.EXE >[2008/01/20 22:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >[2009/04/11 02:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
========== Alternate Data Streams ========== @Alternate Data Stream - 85 bytes -> C:\ProgramData\Application Data:$SS_DESCRIPTOR_1VPTV9VVMVFBVLVHKV6FYJ6VDVPMF7LBWK96HUTVVVVKVVBVLVV5
@Alternate Data Stream - 85 bytes -> C:\ProgramData:$SS_DESCRIPTOR_1VPTV9VVMVFBVLVHKV6FYJ6VDVPMF7LBWK96HUTVVVVKVVBVLVV5
@Alternate Data Stream - 164 bytes -> C:\ProgramData\TEMP:53829683
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:B63300D1
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:8331D35A
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:EBC2DB92
< End of report >