ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/07 10:16:14 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{150E1CEB-BE26-4800-9A29-036D8F111535}
[2012/05/06 09:05:13 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{B1C17421-765E-43FC-B751-F971CE207370}
[2012/05/06 09:05:01 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{4AFC048E-68AE-4D1C-B124-90F375FB2090}
[2012/05/05 08:29:39 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{F3ACE413-3FCF-4D92-81BB-1F514A9D41BA}
[2012/05/05 08:29:27 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{F6169FFE-F4E6-45BF-969D-5629F9500E32}
[2012/05/05 00:26:12 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{67ADF65A-19A1-429B-918B-A81EDB105CE9}
[2012/05/04 23:43:30 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{FF7730A5-7EEF-4405-8210-87BC632F3330}
[2012/05/04 23:43:18 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{7016AD29-8402-4BFE-9887-C184C395B4BA}
[2012/05/04 20:42:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools
[2012/05/04 20:38:00 | 000,251,528 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012/05/04 20:38:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012/05/04 20:37:39 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012/05/04 20:37:38 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Roaming\TestApp
[2012/05/04 08:26:27 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{4312D6F4-D0E5-4477-8649-F2C65C626853}
[2012/05/04 08:26:16 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{77AFBDA9-0FF0-423D-92F8-2DDB151050F9}
[2012/05/03 18:58:46 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{53623862-72EC-46D1-8D97-7622D8F1A11E}
[2012/05/03 18:58:34 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{09C9D6B7-DC2B-4690-832E-310A92BBD56F}
[2012/05/03 13:07:31 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{BE188C62-402A-4085-9492-BC5C8A409306}
[2012/05/02 23:36:27 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{49BA4033-B6C4-4FCF-8EAF-8DC72797C8CB}
[2012/05/02 23:36:15 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{BCDC91F6-D92A-4308-A379-22B9A797A0C7}
[2012/05/02 23:06:09 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{7C6C1BCA-355E-43B2-AE0F-4A7EF575D08A}
[2012/05/02 23:05:57 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{F9B08B83-C800-4415-9A20-220A6069527E}
[2012/05/02 08:56:23 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{A765C8D1-C4AB-4104-BF0C-17A8E05FBF29}
[2012/05/02 08:56:12 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{E5A544B9-4755-4E84-A6C8-80D56CD31BB0}
[2012/05/01 10:39:06 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{AB5A0EFF-5F9A-4691-AF47-5FF69296243D}
[2012/05/01 10:38:55 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{5FA7BB94-52F3-47EF-83F0-28D08D83126E}
[2012/05/01 09:06:14 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{45C8F973-4DD2-4436-B87C-DDB9D0BB8A41}
[2012/05/01 09:06:02 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{6792A530-5886-4610-AE0A-BDF4FBCFF302}
[2012/04/30 23:24:30 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{490FA1B2-9161-4529-9B9B-4BE240CD0E53}
[2012/04/30 11:03:39 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{B39CBAF8-576E-4372-8166-8F4E14694EE2}
[2012/04/30 11:03:27 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{26683890-F0ED-450E-AB15-CE1F623C125F}
[2012/04/29 22:43:28 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{362B435C-F1C9-45BD-AA8E-326DDD5CCA33}
[2012/04/29 22:43:16 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{0F08837B-F1DF-4F3E-8729-50D09A982B2F}
[2012/04/29 21:51:50 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{D70F67E9-1841-42BC-AFAC-9FB74BB6CD45}
[2012/04/29 09:23:57 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{9AD349A3-4941-4A2D-8CF8-608AE418890D}
[2012/04/29 09:23:45 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{5C99A067-0CA9-4347-95FD-58A4F249CE4A}
[2012/04/28 16:59:16 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{CF85ECC3-624A-40E0-9306-0E6CC84EFDAD}
[2012/04/28 16:59:04 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{91A3EB3F-9606-4AF0-9855-FE570CD20A7D}
[2012/04/28 00:18:31 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{CFA11C0E-CA6A-4AF7-812D-CB86124997E9}
[2012/04/28 00:18:19 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{3B383364-C1F3-478A-AA51-E749F493FAC3}
[2012/04/27 23:46:31 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{4DF77754-1F74-457D-AA75-AC669620C733}
[2012/04/27 08:51:09 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{7DF0EEEA-016D-41C7-AA27-1A06FEBBB329}
[2012/04/27 08:50:58 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{2A2C6E17-ACBC-4499-BA5E-FB4F0890EA6D}
[2012/04/26 18:08:53 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{9CBBA1AC-E2B8-4E84-9C9A-B368F7472B5D}
[2012/04/26 18:08:42 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{3107ED85-5194-445A-90B1-FCE027D01060}
[2012/04/25 22:12:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012/04/25 22:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/04/25 22:11:47 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{4A6C733D-4AE7-41FC-8FB4-F0FC90C2380A}
[2012/04/25 22:11:36 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{2E2B6B76-7B80-43B3-9AA9-9AB2C1EED3F9}
[2012/04/25 08:38:32 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{35656A42-B583-43B5-BF17-D678AA468049}
[2012/04/25 08:38:21 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{9C5D1E71-7FDC-4566-8D5E-8A9D0BC8BD39}
[2012/04/24 23:46:13 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{4F34042B-5D90-428C-902F-1330C8C9B4A6}
[2012/04/24 23:46:02 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{E19C3149-48B1-44C5-AC24-FF32A8138EE4}
[2012/04/24 22:47:30 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{510C81B7-ECAC-47D8-AE6B-AC1BFDC89969}
[2012/04/24 22:47:19 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{650FD129-C19A-4FD7-9BEC-A1FF205F6D4D}
[2012/04/24 08:01:22 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{493D529C-E2E9-4646-BBBE-5D0DB60A67AD}
[2012/04/24 08:01:10 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{9B73EA82-F50D-4DE5-AB0A-68477A5A0958}
[2012/04/23 12:12:33 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{D08F6E1A-87CD-4D50-9898-1D1C821E4835}
[2012/04/23 12:12:21 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{C13C6CC0-957B-4587-8724-DBAA3D3D77C4}
[2012/04/22 23:42:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony Media Go Install
[2012/04/22 23:00:58 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{5C5D3E50-2771-456A-95DE-2213D0BEF832}
[2012/04/22 23:00:46 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{F772081C-8850-401D-9377-2FB9595B983E}
[2012/04/22 09:10:07 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{ED9790E8-ECBB-4968-B855-80D2478EA8C9}
[2012/04/22 09:09:56 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{B8A2ACFA-BC6C-47BA-9E8B-E99D4A15C863}
[2012/04/21 13:54:48 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{7D8749F8-1D73-41C3-8BBF-5BE114C6E002}
[2012/04/21 13:54:35 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{94757264-7740-4C24-A31C-70F42A4F49B4}
[2012/04/21 00:16:44 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{2FE171D6-0063-4618-8D05-C66A31B80153}
[2012/04/21 00:16:32 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{1B279B17-8A41-46DC-B7BF-B79E045C273B}
[2012/04/20 23:52:10 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{85313129-1F65-41A1-987C-DC3204295823}
[2012/04/20 08:51:10 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{6DFAD165-B7A0-45BB-AF2E-349A1F6DC59A}
[2012/04/20 08:50:58 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{4A0FCD91-5B77-4B1E-B974-0B51958CE916}
[2012/04/19 14:33:56 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{E349078A-2D23-4F39-BF8F-2B83163FA8BF}
[2012/04/19 14:33:44 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{0A315724-7819-47BE-9382-9F0F066E9A8C}
[2012/04/19 14:27:42 | 000,000,000 | ---D | C] -- C:\Windows\en
[2012/04/19 14:18:47 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{0D886BE8-6CF5-4BAC-8B7B-3C38CC3BBCD6}
[2012/04/19 14:18:36 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{802BF5F9-31D2-4916-987E-FBFD12F9286D}
[2012/04/19 12:40:41 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{F4DA760C-AC41-41A5-9BEC-3EEA3C865F34}
[2012/04/19 11:52:23 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{D5FAD626-CA93-4129-B8B7-DA270020702A}
[2012/04/19 11:52:12 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{24B134B4-A6F1-47C9-8F87-A9E192F5A2C3}
[2012/04/19 11:46:03 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{747842D2-4CE5-45F0-997C-A29EA57DA43F}
[2012/04/19 11:35:28 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{B614E6F3-9D6E-449E-A20E-F0C661ACB5E8}
[2012/04/19 11:35:16 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{6E0568B8-2179-4837-ABA3-BF76E916B209}
[2012/04/19 00:00:08 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{EC4AE329-63D1-46C4-B076-EBD366579601}
[2012/04/18 23:59:56 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{DD1715CA-99B8-4C26-A874-7C961D35EACE}
[2012/04/18 09:04:59 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{B7789DB8-565B-4789-AA80-8973125E9BB0}
[2012/04/18 09:04:47 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{E426C70D-45E5-4434-B125-E0E5CDEE2664}
[2012/04/17 14:13:22 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{EEDD682B-C0D5-4B2C-A1F6-282E47EFB7DE}
[2012/04/17 14:13:10 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{8D8AF756-B929-4696-92FC-4502B0B9CE0D}
[2012/04/16 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{086D20D8-E1FD-48AA-871D-B371B5992F65}
[2012/04/16 23:10:25 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{C0FAAA7C-BDA6-418B-98FE-B611238ECCE3}
[2012/04/16 10:52:21 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{0181B256-D1BA-4545-97D6-1B9B235B9B95}
[2012/04/16 10:52:10 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{CF2EB3F6-3304-4A42-BBD2-D77756E6982B}
[2012/04/16 09:10:47 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{E41E175D-CF90-4526-865C-E65EF2BC0880}
[2012/04/15 15:00:23 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{C545F619-41A5-403E-93BA-F09787D126FD}
[2012/04/15 15:00:12 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{49BAD8DD-54FC-4F7E-B97C-6139E1F407F2}
[2012/04/14 23:25:35 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{B2B372BE-9E96-4464-BA5D-14170915E940}
[2012/04/14 23:25:23 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{2BD994BB-C748-43D2-B861-65F328228E72}
[2012/04/14 09:24:31 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{A6A5B96E-EDCD-4982-B04B-C7317BDF11E2}
[2012/04/14 09:24:20 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{FE8AF4B3-C147-4F27-8C51-B624AB43364B}
[2012/04/13 23:38:49 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{051E31F7-6D80-444F-8CAE-7FF3ED72F733}
[2012/04/13 23:38:38 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{0B16C0E1-F535-4893-82CE-811A9922ED69}
[2012/04/13 16:19:52 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{E77E7BA8-A299-43AA-9B3D-60222A139BDD}
[2012/04/13 15:56:31 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{FEEAB7AB-F578-442C-B715-C6C30EC2752D}
[2012/04/13 10:28:49 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{16B8E754-8FE9-4DE3-BD91-5383A06710BD}
[2012/04/13 08:43:03 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{2A6FA065-FC79-4838-96F8-9D99AF9A8EEF}
[2012/04/12 13:05:17 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/04/12 13:05:16 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/04/12 13:05:11 | 002,311,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/04/12 13:05:11 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/04/12 13:05:11 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/04/12 13:05:10 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/04/12 13:05:10 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/04/12 13:05:09 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/04/12 13:05:08 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/04/12 13:05:08 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/04/12 13:05:08 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/04/12 13:04:48 | 005,559,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/04/12 13:04:47 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/04/12 13:04:46 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/04/12 13:02:12 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll
[2012/04/12 13:02:12 | 000,023,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fs_rec.sys
[2012/04/12 13:02:09 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2012/04/12 13:00:09 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{1B4E3CF2-A1EC-4431-914A-DEE5170300DC}
[2012/04/12 10:22:59 | 000,000,000 | ---D | C] -- C:\Users\andrew\Documents\Simply Super Software
[2012/04/12 10:22:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2012/04/12 10:22:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2012/04/12 10:22:56 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Roaming\Simply Super Software
[2012/04/12 10:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2012/04/12 09:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Trojan Killer
[2012/04/12 09:36:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GridinSoft Trojan Killer
[2012/04/11 22:13:37 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Roaming\thecleaner
[2012/04/11 22:13:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Cleaner
[2012/04/11 22:13:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Cleaner
[2012/04/11 19:16:02 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Roaming\gizza
[2012/04/11 17:48:15 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{9438B422-07D5-4E38-8C44-F450EBE538D3}
[2012/04/10 23:09:35 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{226659C5-74D4-443E-863C-C7BCA43A3F94}
[2012/04/10 19:34:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2012/04/10 09:07:53 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{3360B13B-8D4A-4DEC-9EC7-8C2AD4E48317}
[2012/04/09 13:13:04 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{DB8C1EF4-BB4E-45E8-8D87-2E291F1443E3}
[2012/04/08 22:44:14 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{BD927A4B-F69A-4CE2-8E6C-AB6B3EF3EA64}
[2012/04/07 23:35:53 | 000,000,000 | ---D | C] -- C:\Users\andrew\AppData\Local\{614FC904-C680-4172-931D-3130AFA42B7F}
[2011/12/04 12:47:17 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe225.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/07 10:52:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/07 10:16:51 | 000,309,358 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/05/07 10:13:48 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2121331011-2378592583-2489391907-1001UA.job
[2012/05/07 10:13:47 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/07 10:13:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/07 08:35:38 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/07 08:35:38 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/07 08:32:50 | 097,345,664 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/05/07 08:28:32 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/07 08:27:42 | 3061,227,520 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/06 18:57:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2121331011-2378592583-2489391907-1001Core.job
[2012/05/06 16:00:19 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\Malwarebytes' Scheduled Update for andrew.job
[2012/05/05 08:52:13 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/05 08:52:13 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/05 08:52:08 | 008,744,608 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2012/05/04 20:38:10 | 001,590,181 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/04/27 18:01:05 | 000,624,914 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/04/12 13:08:08 | 000,784,900 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/12 13:08:08 | 000,652,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/04/12 13:08:08 | 000,121,080 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/04/12 10:22:58 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2012/04/12 09:36:29 | 000,001,149 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Killer.lnk
[2012/04/11 22:13:12 | 000,001,038 | ---- | M] () -- C:\Users\Public\Desktop\The Cleaner 2012.lnk
[2012/04/10 18:01:04 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/04 20:38:03 | 001,590,181 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/04/12 10:22:58 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2012/04/12 10:22:57 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012/04/12 10:22:57 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012/04/12 09:36:29 | 000,001,149 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Killer.lnk
[2012/04/11 22:13:12 | 000,001,038 | ---- | C] () -- C:\Users\Public\Desktop\The Cleaner 2012.lnk
[2012/01/17 15:48:09 | 000,000,017 | ---- | C] () -- C:\Users\andrew\AppData\Local\resmon.resmoncfg
[2011/09/22 21:36:40 | 000,870,544 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/09/22 21:36:40 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2011/09/22 21:36:40 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2011/09/22 21:36:39 | 000,127,896 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/09/22 21:36:39 | 000,051,068 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/04/16 11:56:37 | 000,764,746 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2012/04/25 22:12:33 | 000,125,880 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe
[2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
[2012/04/25 22:12:34 | 000,129,976 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
[2012/04/25 22:12:34 | 000,157,352 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
[2012/04/25 22:12:33 | 000,016,824 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
[2012/04/25 22:12:33 | 000,285,624 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[2012/05/07 08:28:12 | 000,000,018 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\log.txt
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2011/10/19 15:29:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
[2011/12/04 12:45:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
[2011/12/15 22:14:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AVG
[2012/03/13 18:46:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AVG Secure Search
[2012/02/26 17:37:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\BitTorrent
[2012/05/04 20:38:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2011/10/19 16:42:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Conduit
[2011/10/19 15:31:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
[2011/10/19 15:28:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Fujitsu
[2012/01/17 09:58:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2012/04/12 09:56:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GridinSoft Trojan Killer
[2011/10/29 13:58:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iLivid
[2011/12/04 23:49:00 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2011/10/19 15:36:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
[2012/04/12 15:28:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2012/04/25 08:35:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2012/04/10 18:01:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/19 15:26:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2012/02/16 11:31:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
[2011/10/19 15:35:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2011/12/24 14:25:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2012/04/25 22:12:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
[2012/04/25 22:12:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2009/07/14 06:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2011/10/21 12:02:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
[2012/01/02 13:18:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Nero
[2012/05/04 20:57:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PC Tools
[2011/10/19 15:29:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
[2009/07/14 06:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2011/12/04 12:46:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sony
[2011/12/04 23:49:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sony Ericsson
[2012/04/22 23:42:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sony Media Go Install
[2011/10/19 15:30:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Temp
[2012/04/19 12:50:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\The Cleaner
[2012/04/12 10:22:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Trojan Remover
[2009/07/14 05:57:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uninstall Information
[2011/12/03 20:18:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN
[2011/12/22 10:34:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2012/04/19 14:25:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
[2011/12/22 10:34:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2011/12/22 10:34:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2009/07/14 06:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2011/12/22 10:31:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
[2010/11/21 04:31:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2011/12/22 10:34:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
[2011/12/09 12:58:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinRAR
[2012/01/17 09:58:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Yahoo!
[2011/10/21 11:40:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Zynga
< MD5 for: AGP440.SYS >
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: DISK.SYS >
[2009/07/14 02:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\drivers\disk.sys
[2009/07/14 02:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\DriverStore\FileRepository\disk.inf_amd64_neutral_10ce25bbc5a9cc43\disk.sys
[2009/07/14 02:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_55bb738b8ddd8a01\disk.sys
< MD5 for: EXPLORER.EXE >
[2011/02/26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: IASTOR.SYS >
[2010/06/08 09:33:14 | 000,540,696 | ---- | M] (Intel Corporation) MD5=2064090C9FAAD92C090D77E50E735B2E -- C:\Fujitsu\Driver Pool\7\iaStor.sys
[2010/06/08 09:33:14 | 000,540,696 | ---- | M] (Intel Corporation) MD5=2064090C9FAAD92C090D77E50E735B2E -- C:\Windows\SysNative\drivers\iaStor.sys
[2010/06/08 09:33:14 | 000,540,696 | ---- | M] (Intel Corporation) MD5=2064090C9FAAD92C090D77E50E735B2E -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_b2da0d5f1235b4d6\iaStor.sys
[2010/06/08 09:33:14 | 000,540,696 | ---- | M] (Intel Corporation) MD5=2064090C9FAAD92C090D77E50E735B2E -- C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_1170b46175ba2765\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2010/11/21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010/11/21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010/11/21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011/03/11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: USERINIT.EXE >
[2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/04/25 22:12:33 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/04/25 22:12:33 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/04/25 22:12:33 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files (x86)\Mozilla Firefox\firefox.exe [2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/04/16 02:42:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/04/16 02:42:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/04/16 02:42:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2011/04/16 02:42:34 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files (x86)\Internet Explorer\iexplore.exe [2011/04/16 02:42:34 | 000,748,336 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2012/04/25 22:12:33 | 000,866,992 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2012/04/25 22:12:33 | 000,866,992 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2012/04/25 22:12:33 | 000,866,992 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE [2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2012/04/25 22:12:33 | 000,924,600 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2011/04/16 02:42:34 | 000,089,088 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2011/04/16 02:42:34 | 000,089,088 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2011/04/16 02:42:34 | 000,089,088 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2011/04/16 02:42:34 | 000,748,336 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE [2011/04/16 02:42:34 | 000,748,336 | ---- | M] (Microsoft Corporation)
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:CB0AACC9
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report >