OLT.txt Part 2 of 2
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/30 21:58:24 | 000,000,000 | R--D | C] -- C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/11/30 21:58:24 | 000,000,000 | R--D | C] -- C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/11/30 21:48:41 | 002,560,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll
[2011/11/30 21:48:38 | 000,543,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll
[2011/11/30 20:58:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/11/30 06:06:50 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\AdobeUM
[2011/11/29 23:26:44 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\vlc
[2011/11/29 19:52:29 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2011/11/29 19:52:19 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2011/11/29 19:40:17 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\Apple
[2011/11/27 02:27:06 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Winamp
[2011/11/27 02:23:00 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Roxio
[2011/11/27 02:02:06 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/11/27 02:02:06 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/11/27 02:02:06 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/11/27 01:56:57 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Macromedia
[2011/11/27 01:35:25 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\Adobe
[2011/11/27 01:35:14 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Adobe
[2011/11/27 01:32:07 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\iPodder
[2011/11/27 01:23:56 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Thunderbird
[2011/11/27 01:23:50 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Mozilla
[2011/11/27 01:22:00 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Thunderbird_TEST
[2011/11/27 01:22:00 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\Thunderbird
[2011/11/27 01:02:14 | 000,000,000 | -H-D | C] -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/11/27 00:59:23 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Autodesk
[2011/11/27 00:59:23 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\Autodesk
[2011/11/27 00:20:12 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Mozilla_TEST
[2011/11/27 00:20:12 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\Mozilla
[2011/11/27 00:17:31 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Skype
[2011/11/27 00:17:27 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Roaming\Apple Computer
[2011/11/27 00:17:27 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\Apple Computer
[2011/11/27 00:17:26 | 000,000,000 | R--D | C] -- C:\Users\Kevin\Desktop
[2011/11/27 00:17:24 | 000,000,000 | ---D | C] -- C:\Users\Kevin\AppData\Local\VirtualStore
[2011/11/27 00:17:21 | 000,000,000 | ---D | C] -- C:\ProgramData\VMware
[2011/11/27 00:09:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/27 00:09:13 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/11/27 00:09:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/27 00:07:05 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Avanquest Software
[2011/11/24 00:01:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/16 18:45:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/11/16 18:45:01 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/11/16 18:43:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/16 18:42:53 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/11/09 17:40:29 | 002,341,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
========== Files - Modified Within 30 Days ==========
[2011/12/01 19:59:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/01 19:24:28 | 000,634,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/01 19:24:28 | 000,111,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/01 19:24:13 | 000,006,992 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/01 19:24:13 | 000,006,992 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/01 19:17:19 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/01 19:17:05 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/12/01 19:16:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/01 19:16:47 | 2616,696,832 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/30 22:31:37 | 000,001,126 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/30 20:59:14 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/11/30 19:22:28 | 000,000,512 | ---- | M] () -- C:\Users\Kevin\Desktop\MBR.dat
[2011/11/29 23:18:49 | 000,000,498 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\show desktop - Shortcut.lnk
[2011/11/29 23:13:22 | 000,000,505 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Devices and Printers - Shortcut.lnk
[2011/11/29 23:13:17 | 000,000,104 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Control Panel - Shortcut.lnk
[2011/11/29 19:55:28 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/11/29 19:52:31 | 000,001,030 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/11/27 02:20:18 | 000,000,063 | ---- | M] () -- C:\Users\Kevin\Desktop\Tobuscus's Channel - YouTube.URL
[2011/11/27 01:52:23 | 000,000,120 | ---- | M] () -- C:\Users\Kevin\Desktop\About In Memory Of Michael Christopher Simmons (1991 - 2010).URL
[2011/11/27 01:25:22 | 000,002,044 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2011/11/27 01:03:16 | 000,002,267 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\AutoCAD 2010.lnk
[2011/11/27 01:01:52 | 000,001,990 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\PowerDesk 8.lnk
[2011/11/27 00:18:49 | 000,001,091 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/27 00:18:49 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/24 00:01:25 | 000,002,170 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/11/22 13:26:12 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/22 08:31:16 | 001,489,492 | ---- | M] () -- C:\Users\Kevin\Documents\A0-1.pdf
[2011/11/18 20:55:44 | 025,145,953 | ---- | M] () -- C:\Users\Kevin\Documents\Gift Certificates.pdf
[2011/11/18 20:54:54 | 008,785,316 | ---- | M] () -- C:\Users\Kevin\Documents\Gift Certificates.jpg
[2011/11/16 18:45:26 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/11/16 18:43:55 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/11/16 18:43:55 | 000,001,753 | ---- | M] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/11/16 18:39:46 | 000,001,768 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2011/11/16 18:32:08 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/11/10 20:49:19 | 000,424,464 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/11/03 12:06:56 | 000,064,512 | ---- | M] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
========== Files Created - No Company Name ==========
[2011/12/01 19:17:05 | 000,000,384 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/30 20:58:41 | 000,001,897 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/30 19:22:28 | 000,000,512 | ---- | C] () -- C:\Users\Kevin\Desktop\MBR.dat
[2011/11/29 23:18:49 | 000,000,498 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\show desktop - Shortcut.lnk
[2011/11/29 23:13:22 | 000,000,505 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Devices and Printers - Shortcut.lnk
[2011/11/29 23:13:17 | 000,000,104 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Control Panel - Shortcut.lnk
[2011/11/29 23:08:28 | 000,000,971 | ---- | C] () -- C:\Users\Kevin\Desktop\DVD Shrink 3.2.lnk
[2011/11/29 19:52:31 | 000,001,030 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/11/27 02:22:54 | 000,002,208 | ---- | C] () -- C:\Users\Kevin\Desktop\Roxio Creator 10 CE.lnk
[2011/11/27 02:20:18 | 000,000,063 | ---- | C] () -- C:\Users\Kevin\Desktop\Tobuscus's Channel - YouTube.URL
[2011/11/27 01:53:51 | 000,000,053 | ---- | C] () -- C:\Users\Kevin\Desktop\Randomly ordered wallpapers - Wallbase.net.URL
[2011/11/27 01:53:37 | 001,554,081 | ---- | C] () -- C:\Users\Kevin\Desktop\10_windows7_tips.pdf
[2011/11/27 01:52:23 | 000,000,120 | ---- | C] () -- C:\Users\Kevin\Desktop\About In Memory Of Michael Christopher Simmons (1991 - 2010).URL
[2011/11/27 01:35:10 | 000,002,015 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Photoshop CS2.lnk
[2011/11/27 01:34:30 | 000,002,651 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Project 2007.lnk
[2011/11/27 01:34:07 | 000,002,657 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel.lnk
[2011/11/27 01:34:02 | 000,002,655 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2011/11/27 01:31:57 | 000,000,939 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Juice.lnk
[2011/11/27 01:31:26 | 000,001,753 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/11/27 01:24:52 | 000,002,044 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2011/11/27 01:20:05 | 000,001,126 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/27 01:04:49 | 000,310,168 | ---- | C] () -- C:\Users\Kevin\Documents\Kevin.arg
[2011/11/27 01:03:14 | 000,002,267 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\AutoCAD 2010.lnk
[2011/11/27 01:01:52 | 000,001,990 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\PowerDesk 8.lnk
[2011/11/27 00:19:25 | 000,006,992 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/27 00:19:25 | 000,006,992 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/27 00:18:49 | 000,001,091 | ---- | C] () -- C:\Users\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/27 00:09:16 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/24 00:01:25 | 000,002,170 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/11/22 08:31:16 | 001,489,492 | ---- | C] () -- C:\Users\Kevin\Documents\A0-1.pdf
[2011/11/18 20:55:39 | 025,145,953 | ---- | C] () -- C:\Users\Kevin\Documents\Gift Certificates.pdf
[2011/11/18 20:54:50 | 008,785,316 | ---- | C] () -- C:\Users\Kevin\Documents\Gift Certificates.jpg
[2011/11/16 18:45:26 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/11/16 18:43:55 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/06/30 22:52:04 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/06/10 06:34:52 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011/04/15 21:20:46 | 000,108,544 | ---- | C] () -- C:\Windows\System32\FileMonitor32.dll
[2011/02/27 13:14:30 | 000,000,871 | ---- | C] () -- C:\Windows\QIII.INI
[2010/08/31 18:04:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/08/28 22:23:25 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/08/28 21:46:33 | 000,016,384 | ---- | C] () -- C:\Windows\System32\FileOps.exe
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/13 21:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:33:53 | 000,424,464 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 19:05:48 | 000,634,942 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 19:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 19:05:48 | 000,111,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 19:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 19:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 19:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 16:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 16:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 14:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2008/11/05 13:42:45 | 000,062,400 | ---- | C] () -- C:\Windows\System32\IFC.dll
[2008/11/05 13:41:56 | 000,422,848 | ---- | C] () -- C:\Windows\System32\PPL.dll
[1999/01/22 11:46:58 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2011/11/30 18:23:21 | 000,125,912 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2011/11/30 18:23:19 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2011/11/30 18:23:19 | 000,269,272 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2010/10/06 05:53:54 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2011/01/09 15:28:34 | 000,000,000 | ---D | M] -- C:\Program Files\AnvSoft
[2011/07/18 18:39:00 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/09/24 16:48:43 | 000,000,000 | ---D | M] -- C:\Program Files\Audible
[2010/08/29 16:08:15 | 000,000,000 | ---D | M] -- C:\Program Files\AutoCAD Architecture 2010
[2010/09/07 16:03:33 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk
[2010/08/28 19:45:31 | 000,000,000 | ---D | M] -- C:\Program Files\Avanquest
[2011/04/15 21:16:32 | 000,000,000 | ---D | M] -- C:\Program Files\Avanquest update
[2010/08/30 22:02:06 | 000,000,000 | ---D | M] -- C:\Program Files\Belarc
[2011/10/17 23:06:56 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2011/11/27 01:14:05 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/09/20 12:41:55 | 000,000,000 | ---D | M] -- C:\Program Files\Celestia
[2011/11/26 23:57:45 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2011/05/19 23:26:10 | 000,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Lite
[2011/05/19 23:25:30 | 000,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Toolbar
[2011/04/10 12:21:53 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/10/25 22:17:20 | 000,000,000 | ---D | M] -- C:\Program Files\DVD Decrypter
[2011/07/09 09:26:36 | 000,000,000 | ---D | M] -- C:\Program Files\DVD Maker
[2010/10/26 22:08:27 | 000,000,000 | ---D | M] -- C:\Program Files\DVD Shrink
[2010/12/21 22:56:15 | 000,000,000 | ---D | M] -- C:\Program Files\EASEUS
[2010/11/11 14:29:24 | 000,000,000 | ---D | M] -- C:\Program Files\epson
[2011/05/20 22:33:04 | 000,000,000 | ---D | M] -- C:\Program Files\Flip Video
[2011/11/24 00:01:15 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2011/02/26 20:19:07 | 000,000,000 | ---D | M] -- C:\Program Files\HawkingTech
[2011/05/05 20:16:25 | 000,000,000 | ---D | M] -- C:\Program Files\id Software
[2011/05/05 20:30:31 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2011/11/30 21:30:37 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2011/11/16 18:42:53 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2011/11/16 18:43:54 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2011/11/27 02:02:02 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/08/28 23:07:57 | 000,000,000 | ---D | M] -- C:\Program Files\Juice
[2011/11/29 19:52:19 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2011/11/27 01:14:04 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/22 19:46:57 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2010/12/07 20:50:24 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2010/09/20 13:02:27 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/09/07 16:00:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SDKs
[2011/11/30 20:59:09 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Security Client
[2011/10/12 16:42:02 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2010/09/16 09:55:04 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2010/09/07 16:01:13 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 9.0
[2010/09/20 22:57:25 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2011/11/30 22:39:40 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2011/11/30 18:23:21 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2011/11/09 19:47:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Thunderbird
[2011/02/27 13:16:40 | 000,000,000 | ---D | M] -- C:\Program Files\Mplayer
[2009/07/13 21:52:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/08/28 22:33:09 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2010/08/30 22:33:06 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010/10/26 22:26:02 | 000,000,000 | ---D | M] -- C:\Program Files\Nero
[2011/11/30 21:48:54 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2010/08/29 21:50:45 | 000,000,000 | ---D | M] -- C:\Program Files\Plextor
[2011/02/27 13:14:57 | 000,000,000 | ---D | M] -- C:\Program Files\Quake III Arena
[2011/11/16 18:45:30 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2010/08/30 12:38:56 | 000,000,000 | ---D | M] -- C:\Program Files\Quickview
[2009/07/13 21:52:30 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/10/26 22:20:56 | 000,000,000 | ---D | M] -- C:\Program Files\Roxio
[2011/10/17 23:11:25 | 000,000,000 | ---D | M] -- C:\Program Files\Safari
[2011/10/29 07:34:45 | 000,000,000 | R--D | M] -- C:\Program Files\Skype
[2010/10/11 21:54:07 | 000,000,000 | ---D | M] -- C:\Program Files\SoundSpectrum
[2011/06/13 21:58:14 | 000,000,000 | ---D | M] -- C:\Program Files\Stellarium
[2011/01/19 22:39:45 | 000,000,000 | ---D | M] -- C:\Program Files\TweakNow PowerPack 2010
[2009/07/13 21:53:23 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2011/06/30 21:29:31 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2010/09/24 07:13:18 | 000,000,000 | ---D | M] -- C:\Program Files\VMware
[2011/06/03 20:49:20 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2011/06/03 20:48:30 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp Detect
[2011/02/09 21:27:16 | 000,000,000 | ---D | M] -- C:\Program Files\WinBubble
[2011/07/09 09:26:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2011/07/09 09:26:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Journal
[2011/03/29 23:37:51 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2011/07/09 09:26:36 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2011/07/09 09:26:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/07/13 21:52:30 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2011/07/09 09:26:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Photo Viewer
[2011/07/09 09:26:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Portable Devices
[2011/07/09 09:26:36 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar
[2010/08/29 16:46:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Virtual PC
[2010/08/29 17:22:24 | 000,000,000 | ---D | M] -- C:\Program Files\Windows XP Mode
< MD5 for: AGP440.SYS >
[2009/07/13 18:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009/07/13 18:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009/07/13 18:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009/07/13 18:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/13 18:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/13 18:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009/07/13 18:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009/07/13 18:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
< MD5 for: DISK.SYS >
[2009/07/13 18:20:27 | 000,057,424 | ---- | M] (Microsoft Corporation) MD5=565003F326F99802E68CA78F2A68E9FF -- C:\Windows\System32\drivers\disk.sys
[2009/07/13 18:20:27 | 000,057,424 | ---- | M] (Microsoft Corporation) MD5=565003F326F99802E68CA78F2A68E9FF -- C:\Windows\System32\DriverStore\FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.sys
[2009/07/13 18:20:27 | 000,057,424 | ---- | M] (Microsoft Corporation) MD5=565003F326F99802E68CA78F2A68E9FF -- C:\Windows\winsxs\x86_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_f99cd807d58018cb\disk.sys
< MD5 for: NETLOGON.DLL >
[2010/11/20 05:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010/11/20 05:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011/03/10 22:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011/03/10 22:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/10 22:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011/03/10 22:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011/03/10 22:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011/03/10 22:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2010/11/20 05:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 05:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
[2009/07/13 18:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-02 03:24:34
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/11/30 18:23:19 | 000,713,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/11/30 18:23:19 | 000,713,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/11/30 18:23:19 | 000,713,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/05/12 21:24:31 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/05/12 21:24:31 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/05/12 21:24:31 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/05/12 21:24:32 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/05/12 21:24:32 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/11/30 18:23:19 | 000,713,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/11/30 18:23:19 | 000,713,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/11/30 18:23:19 | 000,713,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/11/30 18:23:20 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/05/12 21:24:31 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/05/12 21:24:31 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/05/12 21:24:31 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/05/12 21:24:32 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/05/12 21:24:32 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011/09/27 14:47:02 | 002,388,848 | ---- | M] (Apple Inc.)
< End of report >