Dear Expersts
I have been a spectator for a while using this website to widen my knowledge and it is very much appreciated what you guys are doing here.
Let me thank you guys/gals in advance for your time and help.
Last week my machine was infected with a rootkit virus and I have failed to remove it. I am a computer guy and I fixed hundreds of infected machines in the past but this one gets me!
The symptoms are:
1. Google links are redirected.
2. Every so often (sometimes 5 times an hour sometimes once very two hours) explorer.exe will open up multiple tcp connections to servers and ip addresses that I don't recognize and play random but repetative commertials/radio stations sounds bytes. Ususally not a complete commercial and it usually last for 5-10 seconds.
3. Once in a while (once or twice a day) a window titled "message from webpage" will be opened by explorer.exe with a lable "Thanks" and a button "OK".
I used AVG, ESET, Microsoft Security Essentials, Exterminate It, Malwarebytes, CCleaner and ComboFix and by now all scans gives the computer a clean bill of health but the symptoms are not removed.
Five days ago eset gave me this report but now it gives a clean report.
C:\$RECYCLE.BIN\S-1-5-21-266775593-2276910581-870900397-1000\$R3DXH1U.txt Eicar test file cleaned by deleting - quarantined
C:\Windows\Installer\{b815768f-eb22-5c7b-fbca-993571e2f1aa}\U\00000008.@ Win64/Agent.BA trojan cleaned by deleting - quarantined
C:\Windows\Installer\{b815768f-eb22-5c7b-fbca-993571e2f1aa}\U\80000032.@ a variant of Win32/Sirefef.FD trojan cleaned by deleting - quarantined
Operating memory a variant of Win32/Sirefef.EZ trojan
I use AnVir to follow the explorer.exe process and I have a report of the tcp connections it creates right before playing the sound and I will post it if you would ask me to.
Following you will find all the reports you have asked in the Preperation Guide.
Once again thanks, yur help is truly appreaciated.
Sean
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:52 on 28/07/2012 (Sean Einy)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
OTL logfile created on: 7/28/2012 11:54:05 AM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Sean Einy\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.91 Gb Total Physical Memory | 2.94 Gb Available Physical Memory | 49.81% Memory free
11.82 Gb Paging File | 6.99 Gb Available in Paging File | 59.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.71 Gb Total Space | 210.03 Gb Free Space | 36.11% Space Free | Partition Type: NTFS
Computer Name: SEANEINY-LT | User Name: Sean Einy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/07/28 10:42:32 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Sean Einy\Downloads\OTL.exe
PRC - [2012/07/25 09:25:32 | 001,147,488 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2012/07/04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
PRC - [2012/06/14 11:38:54 | 006,080,112 | ---- | M] (AnVir Software) -- C:\Program Files (x86)\AnVir Task Manager Pro\AnVir.exe
PRC - [2012/06/13 03:48:50 | 002,321,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2012/04/05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2012/02/14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/11/03 17:20:58 | 000,803,144 | ---- | M] (AVG) -- C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
========== Modules (No Company Name) ========== MOD - [2012/07/25 09:25:39 | 000,132,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.1.5\SiteSafety.dll
MOD - [2012/07/25 09:25:32 | 001,147,488 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2012/07/09 21:09:00 | 000,438,296 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppgooglenaclpluginchrome.dll
MOD - [2012/07/09 21:08:59 | 003,972,120 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
MOD - [2012/07/09 21:07:39 | 000,554,520 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\libglesv2.dll
MOD - [2012/07/09 21:07:37 | 000,117,784 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\libegl.dll
MOD - [2012/07/09 21:07:22 | 000,140,328 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\avutil-51.dll
MOD - [2012/07/09 21:07:21 | 000,262,184 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\avformat-54.dll
MOD - [2012/07/09 21:07:19 | 002,386,984 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\avcodec-54.dll
MOD - [2011/11/03 17:21:06 | 000,350,024 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup\madExcept_.bpl
MOD - [2011/11/03 17:21:06 | 000,184,136 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup\madBasic_.bpl
MOD - [2011/11/03 17:21:06 | 000,050,504 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup\madDisAsm_.bpl
MOD - [2011/03/16 14:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/12/21 02:15:30 | 001,041,248 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
MOD - [2010/10/20 17:08:14 | 000,122,720 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\OUTLCTL.DLL
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2012/03/20 18:43:38 | 001,030,600 | ---- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:
64bit: - [2010/11/16 10:18:12 | 000,822,704 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:
64bit: - [2010/10/20 14:41:50 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV:
64bit: - [2010/10/18 19:28:48 | 000,489,384 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:
64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:
64bit: - [2010/09/17 10:14:34 | 000,531,832 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ThpSrv.exe -- (Thpsrv)
SRV:
64bit: - [2010/09/01 12:00:06 | 000,911,872 | ---- | M] (Intel® Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe -- (WiMAXAppSrv)
SRV:
64bit: - [2010/09/01 11:54:22 | 000,408,576 | ---- | M] (Red Bend Ltd.) [Disabled | Stopped] -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe -- (DMAgent)
SRV:
64bit: - [2010/07/28 10:27:16 | 000,267,192 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:
64bit: - [2010/07/19 18:08:30 | 001,429,776 | ---- | M] (Intel® Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:
64bit: - [2010/07/19 17:48:36 | 000,340,240 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:
64bit: - [2010/07/19 17:46:54 | 000,838,928 | ---- | M] (Intel® Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:
64bit: - [2010/02/05 17:44:48 | 000,137,560 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:
64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2007/11/07 09:11:22 | 004,466,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90)
SRV - [2012/07/26 14:13:29 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/06/13 03:48:50 | 002,321,560 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe -- (avgfws)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2012/01/03 06:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/22 08:33:11 | 000,179,712 | ---- | M] (Cougar Mountain Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Cougar Mountain Software\Denali\CMSLicenseService.exe -- (CMSLicenseService)
SRV - [2011/12/22 05:31:08 | 000,045,056 | ---- | M] (Intuit) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2011/11/09 00:24:42 | 000,013,160 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\759\g2aservice.exe -- (GoToAssist)
SRV - [2011/08/19 10:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011/02/11 13:45:52 | 000,054,136 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2010/12/20 18:30:38 | 002,656,280 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/12/20 18:30:36 | 000,325,656 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/05/20 16:15:00 | 000,110,736 | R--- | M] (InterVideo) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/11 14:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/02/19 03:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/11/18 16:45:28 | 000,061,440 | ---- | M] (Intuit Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2012/07/25 09:25:40 | 000,031,080 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:
64bit: - [2012/04/19 04:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:
64bit: - [2012/03/19 05:17:26 | 000,383,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:
64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012/02/22 05:25:32 | 000,289,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:
64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2012/01/31 04:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:
64bit: - [2011/12/23 13:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:
64bit: - [2011/12/23 13:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:
64bit: - [2011/12/23 13:31:58 | 000,124,496 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:
64bit: - [2011/08/19 10:27:30 | 004,869,024 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:
64bit: - [2011/08/19 10:27:30 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:
64bit: - [2011/06/09 20:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2011/05/25 22:21:28 | 000,174,680 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:
64bit: - [2011/05/23 01:03:28 | 000,048,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV:
64bit: - [2011/05/09 22:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:
64bit: - [2011/04/05 03:10:16 | 012,262,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:
64bit: - [2011/03/10 23:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/10 23:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/12/18 14:45:46 | 000,482,384 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tos_sps64.sys -- (tos_sps64)
DRV:
64bit: - [2010/12/10 13:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:
64bit: - [2010/12/10 13:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:
64bit: - [2010/11/20 06:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/20 04:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/11/20 02:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:
64bit: - [2010/10/23 19:25:56 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:
64bit: - [2010/10/19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:
64bit: - [2010/10/15 00:28:16 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:
64bit: - [2010/09/13 18:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:
64bit: - [2010/07/28 11:46:18 | 007,821,312 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:
64bit: - [2010/07/12 11:36:10 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:
64bit: - [2010/06/17 06:09:04 | 000,119,680 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jrdusbser.sys -- (jrdusbser)
DRV:
64bit: - [2010/05/16 17:28:36 | 000,175,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpmp.sys -- (bpmp)
DRV:
64bit: - [2010/05/16 17:28:28 | 000,081,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpusb.sys -- (bpusb)
DRV:
64bit: - [2010/05/16 17:28:26 | 000,071,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpenum.sys -- (bpenum)
DRV:
64bit: - [2010/03/12 19:21:52 | 000,097,280 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl)
DRV:
64bit: - [2010/03/11 20:17:42 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2009/12/17 15:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:
64bit: - [2009/11/03 04:06:36 | 000,087,552 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrSerIb.sys -- (BrSerIb)
DRV:
64bit: - [2009/11/03 04:06:36 | 000,014,592 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrUsbSib.sys -- (BrUsbSIb)
DRV:
64bit: - [2009/08/09 14:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:
64bit: - [2009/07/30 21:02:36 | 000,044,912 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter)
DRV:
64bit: - [2009/07/30 20:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:
64bit: - [2009/07/14 15:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:
64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/07/13 17:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:
64bit: - [2009/07/13 17:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:
64bit: - [2009/06/29 16:16:20 | 000,014,784 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Thpevm.sys -- (Thpevm)
DRV:
64bit: - [2009/06/29 10:25:22 | 000,034,880 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\thpdrv.sys -- (Thpdrv)
DRV:
64bit: - [2009/06/22 17:06:38 | 000,035,008 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:
64bit: - [2009/06/19 19:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:
64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2008/05/06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:
64bit: - [2007/04/17 11:51:50 | 000,014,112 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.toshiba.com/g/IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {06EAC5F6-CB1A-4EFB-9E32-8F7109F62A99}
IE:
64bit: - HKLM\..\SearchScopes\{06EAC5F6-CB1A-4EFB-9E32-8F7109F62A99}: "URL" =
http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNFIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {06EAC5F6-CB1A-4EFB-9E32-8F7109F62A99}
IE - HKLM\..\SearchScopes\{06EAC5F6-CB1A-4EFB-9E32-8F7109F62A99}: "URL" =
http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com/?PC=BNHPIE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
https://isearch.avg.com/search?cid={D92D30EE-9D41-4315-B197-AC1F34E80E1E}&mid=511a3b52c88e47d0a0b96939b2a8187e-e4e20aace1ef4c0012e0809ef5978d969aa6b4b2&lang=en&ds=AVG&pr=pr&d=2012-07-25 09:25:43&v=12.1.0.21&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ========== FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.1.5\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Sean Einy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Sean Einy\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Sean Einy\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Sean Einy\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/07/14 07:00:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/04/10 16:34:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/25 09:23:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\12.1.0.21\ [2012/07/25 09:25:56 | 000,000,000 | ---D | M]
[2011/04/27 12:35:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sean Einy\AppData\Roaming\Mozilla\Extensions
========== Chrome ========== CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Sean Einy\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Sean Einy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.1.0.10441_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.1.5\\npsitesafety.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 7 U5 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Sean Einy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Sean Einy\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: AVG Secure Search = C:\Users\Sean Einy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdgpjclefcppbhifgmbncakhhphkggdb\12.1.0.21_0\
CHR - Extension: AVG Do Not Track = C:\Users\Sean Einy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Sean Einy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
O1 HOSTS File: ([2012/07/28 05:37:39 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AGFormHelperObj Class) - {6620E618-1AB9-4EB2-ACA4-CBBE9066DBE6} - C:\Program Files (x86)\agat\AGForm\AGFormsHelper.dll (Agat software solutions)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.21\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.21\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O9:
64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:
64bit: - Extra Button: Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9:
64bit: - Extra 'Tools' menuitem : Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Value error. File not found
O9 - Extra Button: Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra 'Tools' menuitem : Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: freestockcharts.com ([www] http in Trusted sites)
O16 - DPF: {3F932FFA-F092-4FDB-92C5-1285978614D2}
http://99.66.30.201/WATCH_16R.cab (WATCH_16R Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://akamaicdn.webex.com/client/WBXclient-T27L10NSP25-10481/nbr/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com//activex/ractrl.cab?lmi=928 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1369DE61-AAE1-41CD-89A3-D9BAA5F7CF1C}: DhcpNameServer = 83.224.70.78 83.224.70.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4529415C-FBE7-4CB1-90A6-8C985949D998}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{73E71A5F-D0ED-42E2-A657-1BB1EAECA890}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\intu-help-qb2 - No CLSID value found
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks Enterprise Solutions 9.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.1.5\ViProtocol.dll ()
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\759\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\759\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
MsConfig:64bit - StartUpFolder: C:^Users^Sean Einy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
00TCrdMain - hkey= - key= - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg:
AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg:
AdobeCS5ServiceManager - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg:
AppleSyncNotifier - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
APSDaemon - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
BCSSync - hkey= - key= - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
Best Buy pc app - hkey= - key= - File not found
MsConfig:64bit - StartUpReg:
BrMfcWnd - hkey= - key= - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
MsConfig:64bit - StartUpReg:
ControlCenter3 - hkey= - key= - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
MsConfig:64bit - StartUpReg:
DivXUpdate - hkey= - key= - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MsConfig:64bit - StartUpReg:
eO5n4fG5kp5RHK - hkey= - key= - File not found
MsConfig:64bit - StartUpReg:
Facebook Update - hkey= - key= - C:\Users\Sean Einy\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
MsConfig:64bit - StartUpReg:
Google Update - hkey= - key= - C:\Users\Sean Einy\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig:64bit - StartUpReg:
GoToAssist Express Expert - hkey= - key= - C:\Users\Sean Einy\AppData\Local\Citrix\GoToAssist Express Expert\330\g2ax_start.exe (Citrix Online, a division of Citrix Systems, Inc.)
MsConfig:64bit - StartUpReg:
hkarUPRvGgiU.exe - hkey= - key= - File not found
MsConfig:64bit - StartUpReg:
HotKeysCmds - hkey= - key= - C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
MsConfig:64bit - StartUpReg:
HSON - hkey= - key= - C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
HWSetup - hkey= - key= - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
MsConfig:64bit - StartUpReg:
IgfxTray - hkey= - key= - C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
MsConfig:64bit - StartUpReg:
IntelWireless - hkey= - key= - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
MsConfig:64bit - StartUpReg:
IntelWirelessWiMAX - hkey= - key= - C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (Intel® Corporation)
MsConfig:64bit - StartUpReg:
Intuit SyncManager - hkey= - key= - C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
MsConfig:64bit - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
KeNotify - hkey= - key= - C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
MsConfig:64bit - StartUpReg:
LWS - hkey= - key= - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg:
MobileDocuments - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
ModemListener - hkey= - key= - C:\Program Files (x86)\HSPA USB MODEM\ModemListener.exe ()
MsConfig:64bit - StartUpReg:
MSC - hkey= - key= - File not found
MsConfig:64bit - StartUpReg:
msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
Persistence - hkey= - key= - C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
MsConfig:64bit - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
RtHDVBg - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
MsConfig:64bit - StartUpReg:
RtHDVCpl - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
MsConfig:64bit - StartUpReg:
Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - StartUpReg:
SmartFaceVWatcher - hkey= - key= - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
SmoothView - hkey= - key= - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
SVPWUTIL - hkey= - key= - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
MsConfig:64bit - StartUpReg:
SwitchBoard - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg:
SynTPEnh - hkey= - key= - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
MsConfig:64bit - StartUpReg:
Teco - hkey= - key= - C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
ThpSrv - hkey= - key= - C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
ToshibaAppPlace - hkey= - key= - C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe (Toshiba)
MsConfig:64bit - StartUpReg:
ToshibaServiceStation - hkey= - key= - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TosNC - hkey= - key= - C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TosReelTimeMonitor - hkey= - key= - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TosSENotify - hkey= - key= - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TosVolRegulator - hkey= - key= - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TosWaitSrv - hkey= - key= - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TPwrMain - hkey= - key= - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
MsConfig:64bit - StartUpReg:
TSleepSrv - hkey= - key= - C:\Program Files (x86)\Toshiba\TOSHIBA Sleep Utility\TSleepSrv.exe (TOSHIBA)
MsConfig:64bit - StartUpReg:
TWebCamera - hkey= - key= - C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
MsConfig:64bit - StartUpReg:
VirtualCloneDrive - hkey= - key= - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
MsConfig:64bit - State: "services" - Reg Error: Key error.
MsConfig:64bit - State: "startup" - Reg Error: Key error.
Drivers32:
64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:
64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:
64bit: MSVideo - vfwwdm32.dll (Microsoft Corporation)
Drivers32:
64bit: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32:
64bit: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\windows\SysWow64\sirenacm.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iyuv - C:\windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\windows\SysWow64\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012/07/28 08:15:58 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/28 06:00:27 | 000,000,000 | ---D | C] -- C:\windows\temp
[2012/07/28 03:23:02 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/07/27 15:16:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco Systems
[2012/07/27 15:13:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Cisco Systems
[2012/07/27 13:18:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedTestPro
[2012/07/27 13:18:17 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedTestPro
[2012/07/27 13:17:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AF Uninstalls
[2012/07/27 12:45:58 | 000,021,568 | ---- | C] ( Fluke Networks Inc.) -- C:\windows\SysNative\amdriver_x64.sys
[2012/07/27 12:45:55 | 000,055,360 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\windows\SysNative\drivers\amtransv_x64.sys
[2012/07/27 12:42:55 | 000,032,768 | ---- | C] (AirMagnet) -- C:\windows\SysWow64\AmDriver.dll
[2012/07/27 12:42:55 | 000,010,240 | ---- | C] ( Fluke Networks Inc.) -- C:\windows\SysWow64\AmDriver.sys
[2012/07/27 12:42:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Crystal Decisions
[2012/07/27 12:42:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AirMagnet Inc
[2012/07/26 17:50:15 | 004,719,842 | R--- | C] (Swearware) -- C:\Users\Sean Einy\Desktop\ComboFix.exe
[2012/07/26 17:40:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/07/26 17:40:05 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/07/26 17:37:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2012/07/26 17:37:32 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2012/07/26 14:37:57 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (Disabled by AnVir)
[2012/07/26 14:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2012/07/26 09:53:50 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\ChemTable Software
[2012/07/26 09:53:38 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\ChemTable Software
[2012/07/26 09:53:36 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager Pro
[2012/07/26 02:16:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2012/07/26 02:16:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2012/07/26 02:16:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2012/07/26 02:11:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/25 13:02:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/07/25 13:02:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
[2012/07/25 13:00:42 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012/07/25 09:38:47 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\AVG
[2012/07/25 09:37:46 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012/07/25 09:37:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/07/25 09:26:31 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\AVG2012
[2012/07/25 09:26:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/07/25 09:26:00 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\AVG Secure Search
[2012/07/25 09:25:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2012/07/25 09:25:40 | 000,031,080 | ---- | C] (AVG Technologies) -- C:\windows\SysNative\drivers\avgtpx64.sys
[2012/07/25 09:25:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
[2012/07/25 09:25:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
[2012/07/25 09:24:26 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\drivers\AVG
[2012/07/25 09:22:48 | 000,000,000 | ---D | C] -- C:\$AVG
[2012/07/25 09:22:45 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2012/07/25 09:22:45 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\AVG
[2012/07/25 09:22:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2012/07/25 09:15:55 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012/07/24 11:18:05 | 000,000,000 | ---D | C] -- C:\windows\Minidump
[2012/07/23 10:20:08 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\Curiolab
[2012/07/23 10:10:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exterminate It!
[2012/07/23 10:10:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Exterminate It!
[2012/07/23 09:57:20 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\GetRightToGo
[2012/07/23 09:30:34 | 000,000,000 | -HSD | C] -- C:\windows\SysWow64\%APPDATA%
[2012/07/23 03:17:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ewido anti-malware
[2012/07/22 20:01:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/22 20:01:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/22 16:41:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/07/22 16:40:19 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/07/22 16:40:18 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/07/22 16:32:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/07/22 16:32:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/07/22 12:57:46 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\f-secure
[2012/07/22 12:57:37 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure
[2012/07/21 11:46:36 | 000,000,000 | ---D | C] -- C:\windows\pss
[2012/07/21 09:55:27 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2012/07/21 09:42:02 | 000,000,000 | ---D | C] -- C:\ProgramData\PrevxCSI
[2012/07/21 01:55:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/07/21 01:55:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/07/21 01:55:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/07/21 01:17:38 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Roaming\Malwarebytes
[2012/07/21 01:17:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/18 08:22:46 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{DBA9C281-2264-4184-A9A4-19D7B845F9E8}
[2012/07/18 08:22:34 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{1842D095-D22D-4510-B0CD-C1E9E260685F}
[2012/07/15 14:42:12 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{72733EA5-C2A4-4E86-9F07-D737F7914D16}
[2012/07/15 14:41:57 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{11AA586B-B047-4548-ACE9-B074734BE411}
[2012/07/14 18:32:51 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{15B67294-1BDE-46EF-A70B-687186A9BB9F}
[2012/07/14 18:32:39 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{06C42994-6CAE-42A2-8D01-4030A9C36B9B}
[2012/07/14 18:32:25 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\Tracing
[2012/07/14 18:30:10 | 000,000,000 | ---D | C] -- C:\windows\en
[2012/07/14 18:23:33 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{0715E8B1-5250-453C-939C-26EE51D3C16F}
[2012/07/14 18:23:21 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{99971E97-A739-45D7-8CF4-2681688E4C02}
[2012/07/14 18:23:10 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{EA9793E5-5BB9-447B-87C2-C7465E0D399A}
[2012/07/14 18:22:58 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{9B3E6804-B06F-43DB-882F-B44E7CB3B18E}
[2012/07/07 18:56:44 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{9561ABDE-0FF0-491D-9716-51EE651F8428}
[2012/07/07 18:56:24 | 000,000,000 | ---D | C] -- C:\Users\Sean Einy\AppData\Local\{F04CEB5C-E7B7-4E3A-8F03-445721544307}
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/07/28 12:01:04 | 000,000,924 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-266775593-2276910581-870900397-1000UA.job
[2012/07/28 11:52:01 | 000,000,904 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/28 11:42:08 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/07/28 10:59:02 | 000,000,944 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-266775593-2276910581-870900397-1000UA.job
[2012/07/28 10:52:01 | 000,000,900 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/28 10:20:01 | 000,000,887 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections10.htm
[2012/07/28 09:44:44 | 000,000,887 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections9.htm
[2012/07/28 08:52:56 | 000,013,351 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections8.htm
[2012/07/28 08:49:26 | 000,005,012 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections7.htm
[2012/07/28 08:47:04 | 000,004,204 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections6.htm
[2012/07/28 05:37:39 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2012/07/28 04:12:04 | 000,016,304 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/28 04:12:04 | 000,016,304 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/28 04:09:48 | 000,863,096 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/07/28 04:09:48 | 000,721,362 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/07/28 04:09:48 | 000,143,454 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/07/28 04:04:12 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/07/28 04:04:07 | 463,486,975 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/28 03:20:44 | 004,719,842 | R--- | M] (Swearware) -- C:\Users\Sean Einy\Desktop\ComboFix.exe
[2012/07/28 02:55:56 | 102,354,748 | ---- | M] () -- C:\windows\SysNative\drivers\AVG\incavi.avm
[2012/07/28 02:01:01 | 000,000,872 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-266775593-2276910581-870900397-1000Core.job
[2012/07/27 14:49:24 | 000,001,429 | ---- | M] () -- C:\Users\Sean Einy\Desktop\CopyTrans Control Center.lnk
[2012/07/27 13:59:01 | 000,000,922 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-266775593-2276910581-870900397-1000Core.job
[2012/07/27 12:44:52 | 000,017,486 | ---- | M] () -- C:\windows\SysNative\drivers\etc\services
[2012/07/26 20:27:52 | 000,002,336 | ---- | M] () -- C:\Users\Sean Einy\Documents\AnVir_Connections5.htm
[2012/07/26 20:12:07 | 000,025,677 | ---- | M] () -- C:\Users\Sean Einy\Documents\AnVir_Connections4.htm
[2012/07/26 19:53:59 | 000,013,224 | ---- | M] () -- C:\Users\Sean Einy\Documents\AnVir_Connections3.htm
[2012/07/26 18:41:32 | 000,001,448 | ---- | M] () -- C:\Users\Sean Einy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/07/26 18:00:03 | 000,002,446 | ---- | M] () -- C:\Users\Sean Einy\Desktop\Document.rtf
[2012/07/26 17:46:21 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2012/07/26 17:40:08 | 000,000,833 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/07/26 17:37:32 | 000,001,275 | ---- | M] () -- C:\Users\Sean Einy\Desktop\Revo Uninstaller.lnk
[2012/07/26 16:38:58 | 000,016,233 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections1.htm
[2012/07/26 16:11:51 | 000,011,433 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections.htm
[2012/07/26 15:10:39 | 000,031,252 | ---- | M] () -- C:\windows\SysNative\drivers\AVG\iavichjg.avm
[2012/07/26 09:53:37 | 000,001,121 | ---- | M] () -- C:\Users\Sean Einy\Application Data\Microsoft\Internet Explorer\Quick Launch\AnVir Task Manager Pro.lnk
[2012/07/26 09:53:37 | 000,001,097 | ---- | M] () -- C:\Users\Sean Einy\Desktop\AnVir Task Manager Pro.lnk
[2012/07/25 09:35:02 | 000,027,520 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\dt.dat
[2012/07/25 09:26:03 | 000,000,976 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012/07/25 09:25:40 | 000,031,080 | ---- | M] (AVG Technologies) -- C:\windows\SysNative\drivers\avgtpx64.sys
[2012/07/25 09:24:26 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\drivers\AVG\incavi.avm
[2012/07/25 09:24:26 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\drivers\AVG\iavifw.avm
[2012/07/25 09:24:26 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/07/24 23:35:15 | 000,880,682 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/07/24 20:02:33 | 005,113,000 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/07/24 15:10:19 | 000,001,303 | ---- | M] () -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/07/23 19:31:55 | 000,259,939 | ---- | M] () -- C:\Users\Sean Einy\Desktop\dang.psd
[2012/07/23 17:49:18 | 000,001,456 | ---- | M] () -- C:\Users\Sean Einy\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/07/23 17:49:17 | 000,027,886 | ---- | M] () -- C:\Users\Sean Einy\Desktop\danggggggggg.jpg
[2012/07/23 17:30:21 | 000,021,493 | ---- | M] () -- C:\Users\Sean Einy\Desktop\Dangggg.jpg
[2012/07/23 17:21:40 | 000,029,164 | ---- | M] () -- C:\Users\Sean Einy\Desktop\photo.PNG
[2012/07/23 10:10:20 | 000,001,092 | ---- | M] () -- C:\Users\Public\Desktop\Exterminate It!.lnk
[2012/07/22 23:42:43 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/07/22 21:38:39 | 000,000,053 | ---- | M] () -- C:\windows\wininit.ini
[2012/07/22 20:01:05 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/22 16:41:14 | 000,001,794 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/07/21 19:10:22 | 000,001,440 | -HS- | M] () -- C:\windows\4837805drv.spi
[2012/07/11 19:37:46 | 001,842,504 | ---- | M] () -- C:\Users\Sean Einy\Desktop\Party App.onepkg
[2012/07/11 10:56:57 | 000,002,432 | ---- | M] () -- C:\Users\Sean Einy\Desktop\Google Chrome.lnk
[2012/07/07 16:33:40 | 000,000,978 | ---- | M] () -- C:\Users\Sean Einy\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/07/07 16:33:40 | 000,000,954 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/07/28 10:19:59 | 000,000,887 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections10.htm
[2012/07/28 09:44:38 | 000,000,887 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections9.htm
[2012/07/28 08:52:56 | 000,013,351 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections8.htm
[2012/07/28 08:49:25 | 000,005,012 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections7.htm
[2012/07/28 08:46:59 | 000,004,204 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections6.htm
[2012/07/28 02:55:56 | 102,354,748 | ---- | C] () -- C:\windows\SysNative\drivers\AVG\incavi.avm
[2012/07/27 15:16:26 | 000,002,186 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Connect.lnk
[2012/07/26 20:27:52 | 000,002,336 | ---- | C] () -- C:\Users\Sean Einy\Documents\AnVir_Connections5.htm
[2012/07/26 20:12:07 | 000,025,677 | ---- | C] () -- C:\Users\Sean Einy\Documents\AnVir_Connections4.htm
[2012/07/26 19:53:59 | 000,013,224 | ---- | C] () -- C:\Users\Sean Einy\Documents\AnVir_Connections3.htm
[2012/07/26 18:41:31 | 000,001,420 | ---- | C] () -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/07/26 18:41:30 | 000,001,454 | ---- | C] () -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/07/26 18:41:30 | 000,001,448 | ---- | C] () -- C:\Users\Sean Einy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/07/26 17:40:08 | 000,000,833 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/07/26 17:37:32 | 000,001,275 | ---- | C] () -- C:\Users\Sean Einy\Desktop\Revo Uninstaller.lnk
[2012/07/26 16:38:58 | 000,016,233 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections1.htm
[2012/07/26 16:11:51 | 000,011,433 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir_Connections.htm
[2012/07/26 15:10:39 | 000,031,252 | ---- | C] () -- C:\windows\SysNative\drivers\AVG\iavichjg.avm
[2012/07/26 14:59:50 | 000,002,446 | ---- | C] () -- C:\Users\Sean Einy\Desktop\Document.rtf
[2012/07/26 09:53:37 | 000,001,097 | ---- | C] () -- C:\Users\Sean Einy\Desktop\AnVir Task Manager Pro.lnk
[2012/07/26 02:16:46 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2012/07/26 02:16:46 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2012/07/26 02:16:46 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2012/07/26 02:16:46 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2012/07/26 02:16:46 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2012/07/25 09:35:02 | 000,027,520 | ---- | C] () -- C:\Users\Sean Einy\AppData\Local\dt.dat
[2012/07/25 09:26:03 | 000,000,976 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012/07/25 09:24:26 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\drivers\AVG\incavi.avm
[2012/07/25 09:24:26 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\drivers\AVG\iavifw.avm
[2012/07/25 09:24:26 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/07/24 15:10:19 | 000,001,303 | ---- | C] () -- C:\Users\Sean Einy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/07/23 19:31:55 | 000,259,939 | ---- | C] () -- C:\Users\Sean Einy\Desktop\dang.psd
[2012/07/23 17:49:17 | 000,027,886 | ---- | C] () -- C:\Users\Sean Einy\Desktop\danggggggggg.jpg
[2012/07/23 17:30:21 | 000,021,493 | ---- | C] () -- C:\Users\Sean Einy\Desktop\Dangggg.jpg
[2012/07/23 17:21:40 | 000,029,164 | ---- | C] () -- C:\Users\Sean Einy\Desktop\photo.PNG
[2012/07/23 10:10:20 | 000,001,092 | ---- | C] () -- C:\Users\Public\Desktop\Exterminate It!.lnk
[2012/07/22 20:01:05 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/22 16:41:14 | 000,001,794 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/07/21 19:09:55 | 000,001,440 | -HS- | C] () -- C:\windows\4837805drv.spi
[2012/07/21 09:42:02 | 000,000,053 | ---- | C] () -- C:\windows\wininit.ini
[2012/07/19 14:46:45 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/07/19 14:46:45 | 000,002,497 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012/07/19 14:46:45 | 000,002,301 | ---- | C] () -- C:\Users\Public\Desktop\QuickBooks Enterprise Solutions 9.0.lnk
[2012/07/19 14:46:45 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012/07/19 14:46:45 | 000,001,385 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2012/07/19 14:46:45 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2012/07/19 14:46:45 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012/07/19 14:46:45 | 000,001,316 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2012/07/19 14:46:45 | 000,001,261 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2012/07/19 14:46:45 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2012/07/19 14:46:45 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2012/07/19 14:46:45 | 000,001,126 | ---- | C] () -- C:\Users\Public\Desktop\MiniTool Power Data Recovery 6.6.lnk
[2012/07/19 14:46:45 | 000,000,954 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/07/19 14:46:44 | 000,002,123 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Wireless Display.lnk
[2012/07/19 14:46:44 | 000,001,737 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyTvIL.lnk
[2012/07/19 14:46:44 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012/07/19 14:46:44 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012/07/19 14:46:43 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/07/19 14:46:43 | 000,002,495 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crystal Reports XI Release 2.lnk
[2012/07/19 14:46:43 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/07/19 14:46:43 | 000,001,796 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BD DVD PLAYER.lnk
[2012/07/19 14:46:42 | 000,001,008 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/07/18 08:29:27 | 000,000,830 | ---- | C] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/07/07 19:18:14 | 001,842,504 | ---- | C] () -- C:\Users\Sean Einy\Desktop\Party App.onepkg
[2012/07/07 16:33:40 | 000,000,978 | ---- | C] () -- C:\Users\Sean Einy\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/08 10:19:54 | 000,004,096 | ---- | C] () -- C:\Users\Sean Einy\AppData\Local\keyfile3.drm
[2012/03/09 18:25:56 | 000,303,444 | ---- | C] () -- C:\Users\Sean Einy\IMG_0607.JPG
[2012/03/08 09:32:15 | 000,284,789 | ---- | C] () -- C:\Users\Sean Einy\IMG_0606.JPG
[2012/03/02 00:35:02 | 000,095,572 | ---- | C] () -- C:\Users\Sean Einy\IMG_7003.jpg
[2012/03/02 00:35:02 | 000,065,166 | ---- | C] () -- C:\Users\Sean Einy\IMG_6201.jpg
[2012/03/02 00:35:02 | 000,056,572 | ---- | C] () -- C:\Users\Sean Einy\IMG_7447.jpg
[2012/03/02 00:35:02 | 000,044,395 | ---- | C] () -- C:\Users\Sean Einy\IMG_7248.jpg
[2012/02/21 19:44:41 | 001,803,999 | ---- | C] () -- C:\Users\Sean Einy\IMG_9270.png
[2012/02/17 12:07:24 | 000,469,259 | ---- | C] () -- C:\Users\Sean Einy\vfr lver and cover.xps
[2012/02/12 12:33:21 | 000,148,917 | ---- | C] () -- C:\Users\Sean Einy\428635_187566244677896_137350106366177_238514_943907922_n.jpg
[2012/02/07 10:44:29 | 000,000,110 | ---- | C] () -- C:\windows\QBChanUtil_Trigger.ini
[2012/02/05 10:12:37 | 000,000,021 | ---- | C] () -- C:\windows\SurCode.INI
[2012/01/22 08:23:21 | 000,067,855 | ---- | C] () -- C:\Users\Sean Einy\reading letters and numbers.jpg
[2011/12/13 13:21:35 | 000,000,132 | ---- | C] () -- C:\Users\Sean Einy\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2011/12/13 13:20:05 | 000,000,132 | ---- | C] () -- C:\Users\Sean Einy\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/11/12 15:36:22 | 000,005,120 | ---- | C] () -- C:\Users\Sean Einy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/30 04:13:27 | 000,000,132 | ---- | C] () -- C:\Users\Sean Einy\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/08/24 04:38:08 | 000,001,456 | ---- | C] () -- C:\Users\Sean Einy\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/08/19 10:26:20 | 010,898,456 | ---- | C] () -- C:\windows\SysWow64\LogiDPP.dll
[2011/08/19 10:26:20 | 000,336,408 | ---- | C] () -- C:\windows\SysWow64\DevManagerCore.dll
[2011/08/19 10:26:20 | 000,104,472 | ---- | C] () -- C:\windows\SysWow64\LogiDPPApp.exe
[2011/07/13 22:32:38 | 000,000,308 | ---- | C] () -- C:\windows\Brpfx04a.ini
[2011/07/13 22:32:38 | 000,000,094 | ---- | C] () -- C:\windows\brpcfx.ini
[2011/07/13 22:32:20 | 000,000,426 | ---- | C] () -- C:\windows\BRWMARK.INI
[2011/07/13 22:32:20 | 000,000,034 | ---- | C] () -- C:\windows\SysWow64\BD7840W.DAT
[2011/07/13 22:31:32 | 000,106,496 | ---- | C] () -- C:\windows\SysWow64\BrMuSNMP.dll
[2011/07/13 22:31:31 | 000,000,066 | ---- | C] () -- C:\windows\Brfaxrx.ini
[2011/07/13 22:31:31 | 000,000,000 | ---- | C] () -- C:\windows\brdfxspd.dat
[2011/07/13 22:31:22 | 000,045,056 | ---- | C] () -- C:\windows\SysWow64\BRTCPCON.DLL
[2011/07/13 22:31:15 | 000,000,114 | ---- | C] () -- C:\windows\SysWow64\BRLMW03A.INI
[2011/05/08 13:41:28 | 000,007,603 | ---- | C] () -- C:\Users\Sean Einy\AppData\Local\Resmon.ResmonCfg
[2011/04/26 16:26:30 | 000,000,316 | ---- | C] () -- C:\windows\ODBC.INI
[2011/04/25 21:29:38 | 000,880,682 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011/04/05 03:07:00 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/05 03:07:00 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/01/27 08:55:20 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/01/11 18:05:18 | 000,008,592 | ---- | C] () -- C:\windows\SysWow64\ractrlkeyhook.dll
[2010/11/09 12:09:58 | 000,028,672 | ---- | C] () -- C:\windows\SysWow64\SPCtl.dll
========== LOP Check ========== [2012/07/24 10:11:20 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\applianz
[2012/03/20 18:56:37 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Autodesk
[2012/07/25 09:40:57 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\AVG
[2012/07/25 09:26:31 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\AVG2012
[2011/08/13 05:07:06 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/07/26 09:53:50 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\ChemTable Software
[2011/12/28 22:28:34 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Cougar_Mountain_Software
[2012/07/23 10:20:08 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Curiolab
[2011/09/21 04:06:19 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\DVDVideoSoft
[2011/09/21 04:06:05 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/07/22 12:57:46 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\f-secure
[2011/11/16 23:39:01 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Garmin
[2012/07/23 10:10:15 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\GetRightToGo
[2011/12/09 08:15:59 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Leadertech
[2012/02/05 10:12:37 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\PACE Anti-Piracy
[2011/05/14 09:36:22 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\SharePod
[2011/07/14 09:09:48 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/05/08 13:44:08 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Toshiba
[2012/07/28 08:15:59 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\uTorrent
[2011/04/25 20:38:25 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\WinBatch
[2011/09/30 03:26:03 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\Windows Live Writer
[2012/02/20 01:21:02 | 000,000,000 | ---D | M] -- C:\Users\Sean Einy\AppData\Roaming\WindSolutions
[2012/07/27 13:59:01 | 000,000,922 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-266775593-2276910581-870900397-1000Core.job
[2012/07/28 10:59:02 | 000,000,944 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-266775593-2276910581-870900397-1000UA.job
[2012/07/24 05:07:49 | 000,032,564 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\system32\*.sys /90 > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav > < %SYSTEMDRIVE%\*.* >[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2010/12/28 23:38:27 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/07/28 06:00:02 | 000,041,822 | ---- | M] () -- C:\ComboFix.txt
[2012/07/28 04:04:07 | 463,486,975 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/28 04:04:07 | 2049,642,495 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll > < %systemroot%\*. /mp /s > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > ========== Files - Unicode (All) ==========[2011/10/29 02:24:44 | 000,021,889 | ---- | M] ()(C:\Users\Sean Einy\Documents\?? ?? ?? ??? ???????? ????.docx) -- C:\Users\Sean Einy\Documents\לו זה לא היה וירטואלי כרגע.docx
[2011/09/25 04:49:25 | 000,017,042 | ---- | M] ()(C:\Users\Sean Einy\Documents\????-????.docx) -- C:\Users\Sean Einy\Documents\שאול-גבאי.docx
[2011/09/25 02:44:37 | 000,017,042 | ---- | C] ()(C:\Users\Sean Einy\Documents\????-????.docx) -- C:\Users\Sean Einy\Documents\שאול-גבאי.docx
[2011/09/12 16:44:25 | 000,021,889 | ---- | C] ()(C:\Users\Sean Einy\Documents\?? ?? ?? ??? ???????? ????.docx) -- C:\Users\Sean Einy\Documents\לו זה לא היה וירטואלי כרגע.docx
[2011/09/09 04:11:29 | 000,239,942 | ---- | M] ()(C:\Users\Sean Einy\Documents\?????? ???? ?? ????.pdf) -- C:\Users\Sean Einy\Documents\שנוניי לשון של עודד.pdf
[2011/09/09 04:11:28 | 000,239,942 | ---- | C] ()(C:\Users\Sean Einy\Documents\?????? ???? ?? ????.pdf) -- C:\Users\Sean Einy\Documents\שנוניי לשון של עודד.pdf
[2011/09/03 03:38:22 | 000,018,727 | ---- | M] ()(C:\Users\Sean Einy\Documents\?????? ???? ?? ????.docx) -- C:\Users\Sean Einy\Documents\שנוניי לשון של עודד.docx
[2011/09/03 03:38:22 | 000,018,727 | ---- | C] ()(C:\Users\Sean Einy\Documents\?????? ???? ?? ????.docx) -- C:\Users\Sean Einy\Documents\שנוניי לשון של עודד.docx
[2011/08/31 04:38:48 | 000,178,810 | ---- | M] ()(C:\Users\Sean Einy\Documents\??? ???? ??? ???.pdf) -- C:\Users\Sean Einy\Documents\למה ליבך כמו קרח.pdf
[2011/08/31 04:38:47 | 000,178,810 | ---- | C] ()(C:\Users\Sean Einy\Documents\??? ???? ??? ???.pdf) -- C:\Users\Sean Einy\Documents\למה ליבך כמו קרח.pdf
[2011/08/31 04:36:36 | 000,002,970 | ---- | M] ()(C:\Users\Sean Einy\Documents\????? ???? ??? ???? ??? ???.txt) -- C:\Users\Sean Einy\Documents\מילות השיר למה ליבך כמו קרח.txt
[2011/08/31 04:36:36 | 000,002,970 | ---- | C] ()(C:\Users\Sean Einy\Documents\????? ???? ??? ???? ??? ???.txt) -- C:\Users\Sean Einy\Documents\מילות השיר למה ליבך כמו קרח.txt
[2011/08/29 03:16:46 | 000,018,232 | ---- | M] ()(C:\Users\Sean Einy\Documents\????? ?????? ?????? ???? ?????? ??? ????? ?????????? ????? ????? ??????.docx) -- C:\Users\Sean Einy\Documents\תחרות חופשית והגדלת היצע להורדת שכר הדירה ובעיקבותיו הורדת מחירי הדירות.docx
[2011/08/24 07:09:56 | 000,013,360 | ---- | M] ()(C:\Users\Sean Einy\Documents\?????? ?????? ??? ???? ???.docx) -- C:\Users\Sean Einy\Documents\לאיילי המקסים שאת ליבי כבש.docx
[2011/08/23 04:11:56 | 000,013,360 | ---- | C] ()(C:\Users\Sean Einy\Documents\?????? ?????? ??? ???? ???.docx) -- C:\Users\Sean Einy\Documents\לאיילי המקסים שאת ליבי כבש.docx
[2011/08/17 04:57:30 | 000,018,232 | ---- | C] ()(C:\Users\Sean Einy\Documents\????? ?????? ?????? ???? ?????? ??? ????? ?????????? ????? ????? ??????.docx) -- C:\Users\Sean Einy\Documents\תחרות חופשית והגדלת היצע להורדת שכר הדירה ובעיקבותיו הורדת מחירי הדירות.docx
========== Alternate Data Streams ========== @Alternate Data Stream - 998 bytes -> C:\ProgramData\Microsoft:3OuS5vxwInL9PZjpL0e1
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 1209 bytes -> C:\ProgramData\Microsoft:TY8N6KoV6KReKPABPL
< End of report >