derEitel | 13.03.2012 20:03 | OTL part 2 Code:
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012-03-13 16:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOEFL Official Guide
[2012-03-13 16:56:54 | 000,344,064 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\Tx4ole.ocx
[2012-03-13 16:56:54 | 000,327,680 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\txobj32.dll
[2012-03-13 16:56:54 | 000,159,744 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx_rtf32.dll
[2012-03-13 16:56:54 | 000,114,688 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\txtls32.dll
[2012-03-13 16:56:54 | 000,065,536 | ---- | C] (Larcom and Young) -- C:\Windows\SysWow64\ReSize32.ocx
[2012-03-13 16:56:54 | 000,053,248 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\wndtls32.dll
[2012-03-13 16:56:54 | 000,045,056 | ---- | C] (airJX.com) -- C:\Windows\SysWow64\MPlay.ocx
[2012-03-13 16:56:53 | 000,102,400 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\ic32.dll
[2012-03-13 16:56:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TOEFL Official Guide
[2012-03-13 16:56:47 | 000,000,000 | ---D | C] -- C:\Users\FABI\AppData\Roaming\M-HTOEFL
[2012-03-12 19:50:29 | 002,322,184 | ---- | C] (ESET) -- C:\Users\FABI\Desktop\esetsmartinstaller_enu.exe
[2012-03-10 14:58:51 | 000,000,000 | ---D | C] -- C:\Users\FABI\Desktop\Trojaner
[2012-03-07 18:53:34 | 000,000,000 | ---D | C] -- C:\Users\FABI\AppData\Roaming\Malwarebytes
[2012-03-07 18:53:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012-03-07 18:53:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-03-07 18:53:24 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012-03-07 18:53:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011-08-05 11:56:34 | 001,530,592 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\UIX.dll
[2011-08-05 11:56:34 | 001,288,928 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\UIXcontrols.dll
[2011-08-05 11:56:34 | 001,272,544 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneShell.dll
[2011-08-05 11:56:34 | 001,175,264 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneDBApi.dll
[2011-08-05 11:56:34 | 000,645,856 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\UIX.renderapi.dll
[2011-08-05 11:53:12 | 016,921,312 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneShellResources.dll
[2011-08-05 11:53:12 | 004,020,448 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneSetup.exe
[2011-08-05 11:53:12 | 000,507,104 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneSP.dll
[2011-08-05 11:53:12 | 000,467,680 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneWlanCfgSvc.exe
[2011-08-05 11:53:12 | 000,366,816 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneSrcWrp.dll
[2011-08-05 11:53:12 | 000,306,400 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\WMZuneComm.exe
[2011-08-05 11:53:12 | 000,196,832 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneZMDB.Mobile.dll
[2011-08-05 11:53:12 | 000,157,920 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneZMDB.Library.dll
[2011-08-05 11:53:12 | 000,157,408 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneZMDB.ZuneHD.dll
[2011-08-05 11:53:12 | 000,152,288 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneZMDB.Classic.dll
[2011-08-05 11:53:12 | 000,100,064 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneTaskbar.dll
[2011-08-05 11:53:12 | 000,074,464 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneShellExt.dll
[2011-08-05 11:53:12 | 000,027,872 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\WMZuneTCP2UDP.dll
[2011-08-05 11:53:12 | 000,021,216 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\WMZuneDTPTDNS.dll
[2011-08-05 11:53:12 | 000,018,656 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\WMZuneCommProxyStub.dll
[2011-08-05 11:53:12 | 000,017,632 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneShare.exe
[2011-08-05 11:53:10 | 003,889,376 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneResources.dll
[2011-08-05 11:53:10 | 001,257,184 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneService.dll
[2011-08-05 11:53:10 | 000,916,704 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneQP.dll
[2011-08-05 11:53:10 | 000,683,744 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneSH.dll
[2011-08-05 11:53:10 | 000,514,272 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneSE.dll
[2011-08-05 11:53:10 | 000,155,872 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneSA.dll
[2011-08-05 11:53:06 | 010,061,536 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneNativeLib.dll
[2011-08-05 11:53:06 | 008,277,728 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneNss.exe
[2011-08-05 11:53:06 | 002,110,176 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneEncEng.dll
[2011-08-05 11:53:06 | 001,752,288 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\UIXrender.dll
[2011-08-05 11:53:06 | 001,481,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneCore.dll
[2011-08-05 11:53:06 | 001,184,480 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneH264Dec.dll
[2011-08-05 11:53:06 | 001,161,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneMde.dll
[2011-08-05 11:53:06 | 001,096,928 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneMarketplaceResources.dll
[2011-08-05 11:53:06 | 000,879,328 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneMBR.dll
[2011-08-05 11:53:06 | 000,707,808 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZUNEMP4SDECD.dll
[2011-08-05 11:53:06 | 000,376,544 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneEvr.dll
[2011-08-05 11:53:06 | 000,347,872 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneNssci.dll
[2011-08-05 11:53:06 | 000,223,968 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Zune.exe
[2011-08-05 11:53:06 | 000,218,848 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneHost.exe
[2011-08-05 11:53:06 | 000,212,192 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneDB.dll
[2011-08-05 11:53:06 | 000,163,552 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneLauncher.exe
[2011-08-05 11:53:06 | 000,131,296 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZunePresenter.dll
[2011-08-05 11:53:06 | 000,129,248 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneEffects.dll
[2011-08-05 11:53:06 | 000,121,056 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneAACDec.dll
[2011-08-05 11:53:06 | 000,072,928 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneDXVA2.dll
[2011-08-05 11:53:06 | 000,061,664 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneCfg.dll
[2011-08-05 11:53:06 | 000,056,544 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneConfig.exe
[2011-08-05 11:53:06 | 000,038,624 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZuneEnc.exe
[2011-08-05 11:53:06 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\UIXsup.dll
[2011-08-05 11:53:06 | 000,020,704 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\ZunePS.dll
[2011-08-05 11:31:32 | 000,182,784 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Program Files (x86)\l3codecp.acm
[2011-06-06 12:48:50 | 000,856,576 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\msvcp90.dll
[2011-06-06 12:48:50 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\msvcr90.dll
[2011-06-06 12:48:50 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\msvcm90.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-03-13 19:02:28 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1474680549-846398294-3702337392-1000UA.job
[2012-03-13 19:02:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-03-13 18:02:34 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1474680549-846398294-3702337392-1000UA.job
[2012-03-13 12:51:50 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-03-13 12:51:50 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-03-13 12:47:01 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1474680549-846398294-3702337392-1000Core.job
[2012-03-13 12:43:26 | 3195,293,696 | -HS- | M] () -- C:\hiberfil.sys
[2012-03-12 20:56:03 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1474680549-846398294-3702337392-1000Core.job
[2012-03-12 19:50:35 | 002,322,184 | ---- | M] (ESET) -- C:\Users\FABI\Desktop\esetsmartinstaller_enu.exe
[2012-03-12 19:43:48 | 000,871,102 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012-03-12 19:43:48 | 000,727,544 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012-03-12 19:43:48 | 000,146,570 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012-03-11 19:51:48 | 000,248,141 | ---- | M] () -- C:\Users\FABI\Desktop\13.pdf
[2012-03-10 14:49:11 | 000,000,020 | ---- | M] () -- C:\Users\FABI\defogger_reenable
[2012-03-09 18:34:30 | 000,002,044 | ---- | M] () -- C:\Users\FABI\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012-03-07 13:58:52 | 000,101,524 | ---- | M] () -- C:\Users\FABI\Desktop\424376_10150580414379702_168109079701_9129622_185036658_n.jpg
[2012-02-24 20:17:29 | 000,808,537 | ---- | M] () -- C:\Users\FABI\Desktop\GROEZROCK 49e7f45239f1e015c797b04a2d984f7caf3ccef840acdc4a6cd11cf30aef08c5.pdf
[2012-02-23 18:44:44 | 000,001,437 | ---- | M] () -- C:\Users\FABI\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012-02-22 21:40:57 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012-02-22 21:40:50 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012-02-19 13:38:21 | 004,995,120 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012-02-17 12:13:53 | 000,038,327 | ---- | M] () -- C:\Users\FABI\Desktop\Kalender1112_S2.pdf
[2012-02-17 10:59:05 | 000,002,110 | ---- | M] () -- C:\Users\FABI\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012-02-15 22:37:55 | 000,132,320 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-03-13 16:56:54 | 000,540,672 | ---- | C] () -- C:\Windows\SysWow64\Tx32.dll
[2012-03-13 16:56:53 | 000,000,478 | ---- | C] () -- C:\Windows\SysWow64\ic32.ini
[2012-03-10 14:49:11 | 000,000,020 | ---- | C] () -- C:\Users\FABI\defogger_reenable
[2012-03-07 13:58:27 | 000,101,524 | ---- | C] () -- C:\Users\FABI\Desktop\424376_10150580414379702_168109079701_9129622_185036658_n.jpg
[2012-02-24 20:17:29 | 000,808,537 | ---- | C] () -- C:\Users\FABI\Desktop\GROEZROCK 49e7f45239f1e015c797b04a2d984f7caf3ccef840acdc4a6cd11cf30aef08c5.pdf
[2012-02-22 21:40:57 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012-02-22 21:40:50 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012-02-17 12:13:49 | 000,038,327 | ---- | C] () -- C:\Users\FABI\Desktop\Kalender1112_S2.pdf
[2012-02-14 23:00:22 | 000,248,141 | ---- | C] () -- C:\Users\FABI\Desktop\13.pdf
[2011-12-05 22:04:00 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011-12-05 22:03:52 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011-10-25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011-06-21 22:45:28 | 000,122,484 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_msl.png
[2011-06-21 22:45:28 | 000,122,210 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_ind.png
[2011-06-21 22:45:28 | 000,093,248 | ---- | C] () -- C:\Program Files (x86)\softwaremap_msl.png
[2011-06-21 22:45:28 | 000,092,713 | ---- | C] () -- C:\Program Files (x86)\softwaremap_ind.png
[2011-06-21 22:45:26 | 009,532,452 | ---- | C] () -- C:\Program Files (x86)\Meiryoz.ttc
[2011-06-06 12:50:40 | 000,000,659 | ---- | C] () -- C:\Program Files (x86)\Zune.exe.config
[2011-06-06 12:50:26 | 000,251,333 | ---- | C] () -- C:\Program Files (x86)\softwaremap.png
[2011-06-06 12:50:26 | 000,122,790 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_rus.png
[2011-06-06 12:50:26 | 000,122,620 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_ell.png
[2011-06-06 12:50:26 | 000,122,458 | ---- | C] () -- C:\Program Files (x86)\quickplaymap.png
[2011-06-06 12:50:26 | 000,122,414 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_plk.png
[2011-06-06 12:50:26 | 000,122,134 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_ptb.png
[2011-06-06 12:50:26 | 000,122,068 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_csy.png
[2011-06-06 12:50:26 | 000,122,060 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_jpn.png
[2011-06-06 12:50:26 | 000,122,053 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_nld.png
[2011-06-06 12:50:26 | 000,121,952 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_esp.png
[2011-06-06 12:50:26 | 000,121,837 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_deu.png
[2011-06-06 12:50:26 | 000,121,834 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_hun.png
[2011-06-06 12:50:26 | 000,121,635 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_ptg.png
[2011-06-06 12:50:26 | 000,121,621 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_ita.png
[2011-06-06 12:50:26 | 000,121,558 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_sve.png
[2011-06-06 12:50:26 | 000,121,489 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_dan.png
[2011-06-06 12:50:26 | 000,121,403 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_fra.png
[2011-06-06 12:50:26 | 000,121,358 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_chs.png
[2011-06-06 12:50:26 | 000,121,257 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_fin.png
[2011-06-06 12:50:26 | 000,121,162 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_cht.png
[2011-06-06 12:50:26 | 000,121,155 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_nor.png
[2011-06-06 12:50:26 | 000,120,995 | ---- | C] () -- C:\Program Files (x86)\quickplaymap_kor.png
[2011-06-06 12:50:26 | 000,100,499 | ---- | C] () -- C:\Program Files (x86)\softwaremap_ell.png
[2011-06-06 12:50:26 | 000,099,979 | ---- | C] () -- C:\Program Files (x86)\softwaremap_rus.png
[2011-06-06 12:50:26 | 000,098,663 | ---- | C] () -- C:\Program Files (x86)\softwaremap_plk.png
[2011-06-06 12:50:26 | 000,098,431 | ---- | C] () -- C:\Program Files (x86)\softwaremap_ita.png
[2011-06-06 12:50:26 | 000,098,102 | ---- | C] () -- C:\Program Files (x86)\softwaremap_ptb.png
[2011-06-06 12:50:26 | 000,097,782 | ---- | C] () -- C:\Program Files (x86)\softwaremap_esp.png
[2011-06-06 12:50:26 | 000,097,716 | ---- | C] () -- C:\Program Files (x86)\softwaremap_ptg.png
[2011-06-06 12:50:26 | 000,097,580 | ---- | C] () -- C:\Program Files (x86)\softwaremap_deu.png
[2011-06-06 12:50:26 | 000,097,435 | ---- | C] () -- C:\Program Files (x86)\softwaremap_fra.png
[2011-06-06 12:50:26 | 000,097,298 | ---- | C] () -- C:\Program Files (x86)\softwaremap_csy.png
[2011-06-06 12:50:26 | 000,096,751 | ---- | C] () -- C:\Program Files (x86)\softwaremap_cht.png
[2011-06-06 12:50:26 | 000,096,737 | ---- | C] () -- C:\Program Files (x86)\softwaremap_hun.png
[2011-06-06 12:50:26 | 000,096,603 | ---- | C] () -- C:\Program Files (x86)\softwaremap_jpn.png
[2011-06-06 12:50:26 | 000,096,513 | ---- | C] () -- C:\Program Files (x86)\softwaremap_nld.png
[2011-06-06 12:50:26 | 000,096,441 | ---- | C] () -- C:\Program Files (x86)\softwaremap_fin.png
[2011-06-06 12:50:26 | 000,096,323 | ---- | C] () -- C:\Program Files (x86)\softwaremap_dan.png
[2011-06-06 12:50:26 | 000,095,912 | ---- | C] () -- C:\Program Files (x86)\softwaremap_chs.png
[2011-06-06 12:50:26 | 000,094,750 | ---- | C] () -- C:\Program Files (x86)\softwaremap_nor.png
[2011-06-06 12:50:26 | 000,094,597 | ---- | C] () -- C:\Program Files (x86)\softwaremap_sve.png
[2011-06-06 12:50:26 | 000,093,267 | ---- | C] () -- C:\Program Files (x86)\softwaremap_kor.png
[2011-06-06 12:50:26 | 000,001,922 | ---- | C] () -- C:\Program Files (x86)\TopBar.gif
[2011-06-06 12:50:26 | 000,000,988 | ---- | C] () -- C:\Program Files (x86)\ZuneLogo.gif
[2011-06-06 12:50:26 | 000,000,631 | ---- | C] () -- C:\Program Files (x86)\Background.jpg
[2011-06-06 12:50:26 | 000,000,054 | ---- | C] () -- C:\Program Files (x86)\Arrow.gif
[2011-04-27 13:19:32 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011-04-27 13:19:30 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011-04-27 13:19:30 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011-04-27 13:19:30 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011-04-27 13:19:30 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011-03-17 18:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010-12-08 15:02:29 | 000,000,179 | ---- | C] () -- C:\Users\FABI\AppData\Roaming\Current.prx
[2010-11-16 19:27:06 | 002,506,752 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_new_5-9-08.exe
[2010-09-14 16:57:24 | 000,000,120 | ---- | C] () -- C:\Users\FABI\AppData\Local\Wjetaxubexuyirub.dat
[2010-09-14 16:57:24 | 000,000,000 | ---- | C] () -- C:\Users\FABI\AppData\Local\Xkaqefay.bin
[2010-08-08 13:56:06 | 000,000,132 | ---- | C] () -- C:\Users\FABI\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010-07-01 18:22:23 | 000,000,132 | ---- | C] () -- C:\Users\FABI\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2010-06-25 19:33:54 | 000,867,814 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010-04-28 02:52:48 | 000,001,730 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2010-04-02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
========== LOP Check ==========
[2010-08-07 16:45:04 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\AntMe
[2011-01-14 12:38:58 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Auslogics
[2010-01-11 16:04:45 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Bioshock
[2010-02-14 05:32:28 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Canneverbe Limited
[2010-07-30 12:47:00 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010-09-15 15:08:13 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\com.adobe.ResourceCentral
[2012-01-20 14:34:53 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\com.dailymotion.massuploader
[2010-04-10 04:40:54 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\DAEMON Tools Lite
[2012-01-21 17:36:32 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Dropbox
[2012-01-20 15:29:31 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\DVDVideoSoft
[2012-01-26 20:25:34 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\FileZilla
[2010-01-23 06:18:50 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\FOG Downloader
[2010-04-28 02:43:01 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\GetRightToGo
[2012-03-10 16:47:49 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\ICQ
[2012-03-13 16:56:53 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\M-HTOEFL
[2010-10-16 14:45:53 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Mount&Blade Warband
[2011-08-08 14:45:06 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\MyPhoneExplorer
[2009-12-29 02:59:59 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Notepad++
[2010-07-16 14:16:20 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\PACE Anti-Piracy
[2010-07-27 15:58:44 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\QIP
[2011-06-06 17:41:11 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Samsung
[2011-02-17 22:46:37 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Scan2PDF
[2010-07-16 14:22:16 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011-02-23 12:36:29 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Subversion
[2011-11-09 16:08:01 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\SystemRequirementsLab
[2010-02-11 02:20:37 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Template
[2010-01-07 22:11:50 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Thunderbird
[2011-01-16 14:33:02 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\TuneUp Software
[2010-04-10 05:15:02 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Ubisoft
[2011-10-27 16:30:18 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Unity
[2012-03-12 20:56:03 | 000,000,902 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1474680549-846398294-3702337392-1000Core.job
[2012-03-13 18:02:34 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1474680549-846398294-3702337392-1000UA.job
[2012-01-24 15:18:28 | 000,032,574 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012-03-11 15:57:59 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Adobe
[2010-07-30 12:53:14 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Adobe Mini Bridge CS5
[2010-08-07 16:45:04 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\AntMe
[2011-08-26 15:01:50 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Apple Computer
[2010-01-07 21:39:07 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\ArcSoft
[2009-12-22 08:16:14 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\ATI
[2011-01-14 12:38:58 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Auslogics
[2011-10-24 12:00:00 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Avira
[2010-01-11 16:04:45 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Bioshock
[2010-02-14 05:32:28 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Canneverbe Limited
[2010-07-30 12:47:00 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010-09-15 15:08:13 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\com.adobe.ResourceCentral
[2012-01-20 14:34:53 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\com.dailymotion.massuploader
[2010-04-10 04:40:54 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\DAEMON Tools Lite
[2012-01-21 17:36:32 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Dropbox
[2012-01-20 15:29:31 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\DVDVideoSoft
[2012-01-26 20:25:34 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\FileZilla
[2010-01-23 06:18:50 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\FOG Downloader
[2010-04-28 02:43:01 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\GetRightToGo
[2009-12-22 08:21:59 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Google
[2010-01-17 21:40:13 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Hamachi
[2012-03-10 16:47:49 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\ICQ
[2009-12-22 08:15:39 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Identities
[2010-05-09 18:45:37 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\InstallShield
[2012-03-13 16:56:53 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\M-HTOEFL
[2009-12-22 08:34:58 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Macromedia
[2012-03-07 18:53:34 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Malwarebytes
[2009-08-19 19:30:23 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Media Center Programs
[2011-03-30 21:15:05 | 000,000,000 | --SD | M] -- C:\Users\FABI\AppData\Roaming\Microsoft
[2010-10-16 14:45:53 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Mount&Blade Warband
[2012-03-10 14:48:00 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Mozilla
[2011-08-08 14:45:06 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\MyPhoneExplorer
[2010-02-14 01:24:20 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Nero
[2009-12-29 02:59:59 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Notepad++
[2010-07-16 14:16:20 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\PACE Anti-Piracy
[2010-07-27 15:58:44 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\QIP
[2010-01-04 03:05:35 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Roxio
[2011-06-06 17:41:11 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Samsung
[2011-02-17 22:46:37 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Scan2PDF
[2009-12-28 07:09:03 | 000,000,000 | RH-D | M] -- C:\Users\FABI\AppData\Roaming\SecuROM
[2012-01-07 19:33:38 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Skype
[2011-08-22 18:31:15 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\skypePM
[2009-12-22 08:51:59 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Sony Corporation
[2010-07-16 14:22:16 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011-02-23 12:36:29 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Subversion
[2011-11-09 16:08:01 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\SystemRequirementsLab
[2010-12-18 16:58:54 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\teamspeak2
[2010-02-11 02:20:37 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Template
[2010-01-07 22:11:50 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Thunderbird
[2011-02-23 12:39:08 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\TortoiseSVN
[2011-01-16 14:33:02 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\TuneUp Software
[2010-04-10 05:15:02 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Ubisoft
[2011-10-27 16:30:18 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\Unity
[2011-12-06 21:40:54 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\vlc
[2009-12-24 00:40:55 | 000,000,000 | ---D | M] -- C:\Users\FABI\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2011-08-23 04:34:34 | 024,182,896 | ---- | M] (Dropbox, Inc.) -- C:\Users\FABI\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2011-08-23 04:34:40 | 000,174,784 | ---- | M] (Dropbox, Inc.) -- C:\Users\FABI\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2012-01-20 14:31:32 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\FABI\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010-05-12 19:26:33 | 000,010,134 | R--- | M] () -- C:\Users\FABI\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2011-09-23 13:07:18 | 001,005,512 | ---- | M] (EA Digital Illusions CE AB) -- C:\Users\FABI\AppData\Roaming\Mozilla\Firefox\Profiles\siy2vssi.default\extensions\battlefieldplay4free@ea.com\plugins\BP4FUpdater.exe
[2011-06-30 17:14:52 | 003,154,792 | ---- | M] (Microsoft Corporation) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\NDP40-KB2461678-x64.exe
[2011-06-24 07:54:30 | 000,941,968 | ---- | M] (Samsung) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\Kies.exe
[2011-06-24 07:54:38 | 000,278,928 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
[2011-06-07 03:14:40 | 000,286,720 | ---- | M] (Samsung) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesLogger.exe
[2011-04-27 15:14:54 | 000,034,816 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesMobileDeviceService.exe
[2011-06-24 07:54:36 | 003,373,968 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
[2011-06-07 03:14:06 | 000,140,800 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\ConnectionManager.exe
[2011-06-07 03:14:04 | 000,284,160 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceDataService.exe
[2011-06-09 10:45:38 | 000,660,992 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
[2011-04-27 13:19:58 | 000,107,008 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\HSPConnection.exe
[2011-06-24 07:54:40 | 000,067,472 | ---- | M] (Samsung) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
[2011-06-07 03:13:54 | 000,100,352 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentInstaller.exe
[2011-06-07 03:13:54 | 000,095,232 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentUpdate.exe
[2011-06-24 07:54:44 | 000,131,984 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2011-06-24 07:54:46 | 000,020,880 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
[2011-06-24 07:54:48 | 004,661,464 | ---- | M] () -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
[2011-06-20 02:33:24 | 020,677,600 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2011-06-24 07:54:50 | 000,358,800 | ---- | M] (ml) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\temp\Kies.Update.exe
[2011-09-21 09:43:28 | 000,364,432 | ---- | M] (ml) -- C:\Users\FABI\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
< %SYSTEMDRIVE%\*.exe >
[2007-11-07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: AGP440.SYS >
[2009-07-14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009-07-14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009-07-14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009-07-14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009-07-14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009-07-14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009-07-14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009-07-14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009-07-14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009-07-14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009-07-14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: EVENTLOG.DLL >
[2009-12-20 00:00:00 | 000,037,520 | ---- | M] (perl.org) MD5=2852D57385C4709EAAE2F9DB01AD3672 -- C:\Users\FABI\Documents\xampp\xampp\perl\site\lib\auto\Win32\EventLog\EventLog.dll
< MD5 for: IASTOR.SYS >
[2009-06-05 02:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009-06-05 02:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Windows\SysNative\drivers\iaStor.sys
[2009-06-05 02:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2009-06-05 02:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
< MD5 for: IASTORV.SYS >
[2010-11-20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\drivers\iaStorV.sys
[2010-11-20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010-11-20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2009-07-14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009-07-14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010-11-20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010-11-20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010-11-20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010-11-20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009-07-14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2009-07-14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2010-11-20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\drivers\nvstor.sys
[2010-11-20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010-11-20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009-07-14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009-07-14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010-11-20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010-11-20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010-11-20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010-11-20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: USER32.DLL >
[2010-11-20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010-11-20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009-07-14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009-07-14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010-11-20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010-11-20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
< MD5 for: USERINIT.EXE >
[2010-11-20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010-11-20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009-07-14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009-07-14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010-11-20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010-11-20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WININIT.EXE >
[2009-07-14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009-07-14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009-07-14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009-07-14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >
[2010-11-20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010-11-20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009-07-14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012-01-13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009-10-28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009-10-28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2009-07-14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009-07-14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report > |