Thanks Gringo
Here is the OTL.txt log....
OTL logfile created on: 04/02/2012 14:51:46 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Dan\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
5.99 Gb Total Physical Memory | 4.54 Gb Available Physical Memory | 75.74% Memory free
11.98 Gb Paging File | 9.37 Gb Available in Paging File | 78.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.64 Gb Total Space | 38.30 Gb Free Space | 27.43% Space Free | Partition Type: NTFS
Drive D: | 1397.26 Gb Total Space | 435.45 Gb Free Space | 31.16% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive F: | 14.83 Gb Total Space | 4.86 Gb Free Space | 32.77% Space Free | Partition Type: FAT32
Drive I: | 15.26 Gb Total Space | 9.13 Gb Free Space | 59.80% Space Free | Partition Type: FAT32
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\Dan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Pantone\huey\hueyTray.exe (Pantone & GretagMacbeth)
========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Bridge CS5\libmysqld.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Symlib.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
MOD - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\zlib1.dll ()
========== Win32 Services (SafeList) ========== SRV:
64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV:
64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:
64bit: - (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:
64bit: - (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:
64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:
64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:
64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:
64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:
64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:
64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:
64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:
64bit: - (AthDfu) -- C:\Windows\SysNative\drivers\AthDfu.sys (Windows ® Codename Longhorn DDK provider)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (scsiscan) -- C:\Windows\SysNative\drivers\scsiscan.sys (Microsoft Corporation)
DRV:
64bit: - (ROOTMODEM) -- C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:
64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:
64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (RimVSerPort) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:
64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1380508786-221943138-798723109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKU\S-1-5-21-1380508786-221943138-798723109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-1380508786-221943138-798723109-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 BC D1 5E F3 CD CB 01 [binary data]
IE - HKU\S-1-5-21-1380508786-221943138-798723109-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/"FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/" FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/31 18:17:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/10 13:33:37 | 000,000,000 | ---D | M]
[2012/01/31 11:56:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
[2012/01/31 11:57:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\p08irgxz.default\extensions
[2012/01/30 19:51:42 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\p08irgxz.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012/01/30 19:42:19 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\p08irgxz.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012/01/30 19:39:03 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\p08irgxz.default\extensions\ffxtlbr@babylon.com
[2012/01/30 19:42:18 | 000,003,915 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\p08irgxz.default\searchplugins\sweetim.xml
[2012/01/31 18:17:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/29 16:13:13 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/29 14:08:59 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/30 19:38:00 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/01/29 13:50:55 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/29 14:08:59 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/29 14:08:59 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/01/29 14:08:59 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012/02/03 13:53:06 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1380508786-221943138-798723109-1000\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\ASUS Bluetooth Suite\BtvStack.exe ()
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-1380508786-221943138-798723109-1000..\Run: [AdobeBridge] C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe (Adobe Systems, Inc.)
O4 - HKU\S-1-5-21-1380508786-221943138-798723109-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1380508786-221943138-798723109-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1380508786-221943138-798723109-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4DEFDE4-DDD1-45A9-AB68-5F5CC382EE45}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4DEFDE4-DDD1-45A9-AB68-5F5CC382EE45}: NameServer = 8.8.8.8,8.8.4.4
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28:
64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012/02/04 14:49:35 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Dan\Desktop\OTL.exe
[2012/02/03 16:36:57 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\Ben Pindar portraits
[2012/02/03 16:31:50 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\Insider Exporter of the Month Round Table at Ernst and Young, Leeds
[2012/02/03 14:41:38 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{ED8B5956-DFB8-4EF2-80B3-37B7586018F7}
[2012/02/03 14:41:26 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{BFD85848-2273-4BA0-BA1A-AF6487D906B9}
[2012/02/03 13:55:38 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/02/03 13:53:08 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/02/03 13:44:07 | 004,395,020 | R--- | C] (Swearware) -- C:\Users\Dan\Desktop\ComboFix.exe
[2012/02/02 12:21:02 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{CC72BD76-CDF0-4B11-9431-531B5771C9D2}
[2012/02/02 12:20:51 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{642704C7-FE9E-4457-9E6D-39C9F1E305AA}
[2012/02/02 12:05:13 | 000,607,017 | ---- | C] (Swearware) -- C:\Users\Dan\Desktop\dds.pif
[2012/02/02 12:05:04 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Dan\Desktop\dds.com
[2012/02/02 12:04:35 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Dan\Desktop\dds.scr
[2012/02/01 17:02:58 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{9642FF32-ED5D-4AD0-B593-FDF2F3A0AFA4}
[2012/02/01 17:02:46 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{EBD9801A-C99D-44BB-B1DD-AA2908D3BC31}
[2012/02/01 15:14:41 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\Samaritans Feel Good Friday launch, in Headingley
[2012/01/31 18:28:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012/01/31 18:28:11 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/01/31 17:17:04 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\GooredFix Backups
[2012/01/31 16:56:49 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\SUPERAntiSpyware.com
[2012/01/31 16:56:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/01/31 16:56:22 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012/01/31 16:56:22 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012/01/31 09:42:21 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{98707F08-094F-4249-8E26-D41DAFD067B5}
[2012/01/31 09:40:25 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{B5CC27BF-5649-43A7-8F97-47390A707464}
[2012/01/31 00:21:44 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/01/31 00:14:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\PACE Anti-Piracy
[2012/01/31 00:14:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\PACE Anti-Piracy
[2012/01/31 00:14:23 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy
[2012/01/31 00:14:22 | 000,000,000 | ---D | C] -- C:\Users\Dan\Documents\Adobe
[2012/01/31 00:10:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Story
[2012/01/31 00:10:33 | 000,055,280 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\PxHlpa64.sys
[2012/01/31 00:10:33 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys
[2012/01/31 00:10:33 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys
[2012/01/31 00:10:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2012/01/31 00:10:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2012/01/31 00:10:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2012/01/31 00:03:34 | 000,000,000 | ---D | C] -- C:\Users\Dan\Tracing
[2012/01/31 00:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2012/01/30 21:12:11 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{1DB2E695-1F1B-451D-A9D0-94F6BB20CF5E}
[2012/01/30 21:12:00 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{D171093D-959B-48E8-9D70-92AEC1C80F52}
[2012/01/30 09:55:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\rats
[2012/01/30 09:51:26 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\The Burgess Premier Small Animal Show, in Harrogate
[2012/01/30 09:50:27 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\Asda easter products feature in Wetherby
[2012/01/30 09:11:35 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{4DE4A5AD-AA3D-4CBD-B4A0-3397D5A22DBB}
[2012/01/30 09:11:24 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{6431F847-3B03-4221-B360-24B6EA3A5CB4}
[2012/01/29 16:09:11 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{B2341582-020F-4894-B479-CDD9B099E07B}
[2012/01/29 16:09:00 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{E174EB6F-D20F-45ED-9CB5-51F7B3BC44BF}
[2012/01/28 22:24:53 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{5E236467-70B0-440D-A549-AE6C240AA521}
[2012/01/28 22:24:41 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{2D205CF6-AF42-4DE0-A47F-3CEF04D7D590}
[2012/01/27 13:55:22 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\Lovell's Vivo Northshore development, in Stockton
[2012/01/27 12:01:03 | 000,000,000 | ---D | C] -- C:\Users\Dan\Desktop\INVOICES 2012
[2012/01/27 11:46:28 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{C72568F5-8965-4DE4-BBAD-3621AA439D60}
[2012/01/27 11:46:17 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{09740E94-6C88-401B-9B56-255E332334DF}
[2012/01/26 02:45:28 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{063EC967-D825-4691-8ECD-160D823E01F2}
[2012/01/26 02:45:17 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{73002CD2-C9C3-40E1-9142-508118E36FA9}
[2012/01/25 11:36:07 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{5323A0C4-B437-4B18-9B1B-B046FF4B7EEE}
[2012/01/25 11:35:56 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{FE9DC19A-F324-4255-951F-5709129CF343}
[2012/01/24 14:38:18 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{12707C56-E668-4A94-BA99-9703BEB9FD53}
[2012/01/24 14:38:07 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{38BD2F15-E907-4D1E-8616-8FCD0EFCF9FA}
[2012/01/23 15:12:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{1A951799-ECB7-41C7-9821-162223A44896}
[2012/01/23 15:12:10 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{AC781FB8-113E-411F-B216-9E15522F457E}
[2012/01/22 09:10:01 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{A04EF896-0672-4F49-8507-CD2ABD4D4AE9}
[2012/01/22 09:09:49 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{792C5274-9EB2-42A4-A752-6FF5B3336FE7}
[2012/01/20 09:04:48 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{BF3FDD44-0A68-49F7-8AFA-1C30D16B684D}
[2012/01/20 09:04:36 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{88F1040D-FEBC-480C-9264-2AFF6E870167}
[2012/01/19 14:09:14 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{7FA7F6D1-30DE-4A43-A05C-2683DB572DDA}
[2012/01/19 14:09:01 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{5C4A2C91-42FA-4579-92BA-2B70E6157723}
[2012/01/18 14:01:57 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{CFF106F8-9D4E-4B0E-BB8D-CCB02E698BC5}
[2012/01/18 14:01:46 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{8C3406EB-FA22-49AF-8AE1-189DF28C8D2F}
[2012/01/17 10:08:18 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{BED13A9B-C8CB-4F68-8CFA-CD17DF5FF36E}
[2012/01/17 10:08:07 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{226AAB53-18B9-4FC9-A658-4DC3919B09D9}
[2012/01/16 09:45:58 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{34F66A3D-BD58-4794-ADEA-7F28E9861B66}
[2012/01/16 09:45:44 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{0836768D-4922-48EC-BEB0-59CBDDAF9A15}
[2012/01/13 09:09:57 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{9506A0D0-E21B-48AD-8610-05FA4F2078B5}
[2012/01/13 09:09:46 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{D72CD3CA-AA28-4DD3-9621-8C9F8E416947}
[2012/01/12 09:36:10 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{0651B325-9BE6-4CCA-B23E-9562E166CFF8}
[2012/01/12 09:35:59 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{F69DC11F-50CC-43C0-A9F1-6A547137669F}
[2012/01/11 14:47:15 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{3267714C-2B08-4105-8F70-C2AF8E8BAEBE}
[2012/01/11 14:47:03 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{1F2615EC-A5E7-467B-8E91-B75094CA6D7B}
[2012/01/10 14:12:32 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{C7BDC543-E56A-4F1C-9B32-3DB50E1E3EB8}
[2012/01/10 14:12:21 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{967BB9CE-3D44-4463-B0CB-4482BD719BB5}
[2012/01/09 10:00:07 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{985E792B-70BB-4589-B1CD-CB50CE3C591F}
[2012/01/06 22:19:38 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{6FB35338-12FD-4419-ABAB-7118241673FF}
[2012/01/06 22:19:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{291136B3-010A-4612-B309-D9B99689637C}
[2012/01/06 10:19:09 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{D11560C0-585C-4981-BCF8-827088C077CB}
[2012/01/06 10:18:57 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\{24D3A806-7A5D-4FE3-8D38-DC6D331890AC}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Dan\Desktop\*.tmp files -> C:\Users\Dan\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/02/04 14:49:55 | 000,727,310 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/04 14:49:55 | 000,628,858 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/02/04 14:49:55 | 000,110,784 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/02/04 14:49:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Dan\Desktop\OTL.exe
[2012/02/04 14:47:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/03 14:06:03 | 000,014,864 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/03 14:06:03 | 000,014,864 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/03 13:58:19 | 529,883,135 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/03 13:53:06 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/02/02 19:05:12 | 004,395,020 | R--- | M] (Swearware) -- C:\Users\Dan\Desktop\ComboFix.exe
[2012/02/02 12:07:17 | 000,000,000 | ---- | M] () -- C:\Users\Dan\defogger_reenable
[2012/02/02 12:05:13 | 000,607,017 | ---- | M] (Swearware) -- C:\Users\Dan\Desktop\dds.pif
[2012/02/02 12:05:06 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Dan\Desktop\dds.com
[2012/02/02 12:04:35 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Dan\Desktop\dds.scr
[2012/01/31 19:34:44 | 000,006,114 | ---- | M] () -- C:\Users\Dan\Desktop\hijackthis 2
[2012/01/31 18:28:11 | 000,002,965 | ---- | M] () -- C:\Users\Dan\Desktop\HiJackThis.lnk
[2012/01/31 18:17:26 | 000,001,130 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/31 17:19:54 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/31 16:56:24 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/31 12:28:02 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/31 12:10:06 | 005,354,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/01/30 23:42:44 | 000,347,231 | ---- | M] () -- C:\Users\Dan\Desktop\hosts.rtf
[2012/01/30 19:43:39 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/01/30 19:38:03 | 000,000,237 | ---- | M] () -- C:\user.js
[2012/01/17 11:35:49 | 002,427,692 | ---- | M] () -- C:\Users\Dan\Desktop\158.jpg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Dan\Desktop\*.tmp files -> C:\Users\Dan\Desktop\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/02/02 12:07:17 | 000,000,000 | ---- | C] () -- C:\Users\Dan\defogger_reenable
[2012/01/31 19:34:44 | 000,006,114 | ---- | C] () -- C:\Users\Dan\Desktop\hijackthis 2
[2012/01/31 18:28:11 | 000,002,965 | ---- | C] () -- C:\Users\Dan\Desktop\HiJackThis.lnk
[2012/01/31 18:17:26 | 000,001,142 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/01/31 18:17:26 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/31 17:18:39 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/31 16:56:24 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/31 12:28:02 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/31 10:43:44 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CS5.5.lnk
[2012/01/31 10:43:28 | 000,001,277 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mocha for After Effects CS5.5.lnk
[2012/01/31 10:43:21 | 000,001,185 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2012/01/31 10:43:13 | 000,001,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS5.5.lnk
[2012/01/31 10:42:53 | 000,001,278 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2012/01/31 10:42:47 | 000,001,537 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Pixel Bender Toolkit 2.6.lnk
[2012/01/31 10:42:02 | 000,001,379 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2012/01/31 10:41:59 | 000,001,551 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2012/01/30 23:42:44 | 000,347,231 | ---- | C] () -- C:\Users\Dan\Desktop\hosts.rtf
[2012/01/30 19:38:03 | 000,000,237 | ---- | C] () -- C:\user.js
[2012/01/17 11:35:48 | 002,427,692 | ---- | C] () -- C:\Users\Dan\Desktop\158.jpg
[2011/09/16 11:54:44 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011/09/16 11:54:44 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/09/16 11:54:44 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/09/16 11:54:44 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/06/22 15:45:28 | 000,001,456 | ---- | C] () -- C:\Users\Dan\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/04/29 15:19:13 | 000,035,328 | ---- | C] () -- C:\Users\Dan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/28 18:37:18 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/03/28 18:37:18 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/03/28 18:37:18 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/03/28 18:37:18 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/03/28 18:37:18 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/03/22 14:52:01 | 000,108,544 | RHS- | C] () -- C:\Windows\SysWow64\msinfo329.dll
[2011/02/17 19:40:10 | 000,734,810 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/16 16:52:27 | 000,044,344 | ---- | C] () -- C:\Windows\SysWow64\drivers\Seqcal.sys
[2011/02/16 14:39:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 05:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
< End of report >