here you go:
OTL logfile created on: 21-8-2011 2:11:38 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Marius\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: | Country: | Language: | Date Format:
4,00 Gb Total Physical Memory | 2,98 Gb Available Physical Memory | 74,41% Memory free
8,00 Gb Paging File | 6,99 Gb Available in Paging File | 87,37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279,47 Gb Total Space | 131,10 Gb Free Space | 46,91% Space Free | Partition Type: NTFS
Computer Name: WM-TELRAAM | User Name: Marius | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Marius\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\LSoft Technologies Inc\Active@ Hard Disk Monitor\DiskMonitorService.exe (LSoft Technologies Inc)
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (PnkBstrB) -- C:\Windows\SysWow64\PnkBstrB.exe ()
SRV - (PnkBstrA) -- C:\Windows\SysWow64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Active@ Disk Monitor) -- C:\Program Files (x86)\LSoft Technologies Inc\Active@ Hard Disk Monitor\DiskMonitorService.exe (LSoft Technologies Inc)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:
64bit: - (WFLR6654) WinFast TV2000 XP Expert (FM1216MK3) -- C:\Windows\SysNative\drivers\wfeaglxt.sys (Leadtek Research Inc.)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:
64bit: - (61883) -- C:\Windows\SysNative\drivers\61883.sys (Microsoft Corporation)
DRV:
64bit: - (Avc) -- C:\Windows\SysNative\drivers\avc.sys (Microsoft Corporation)
DRV:
64bit: - (MSDV) -- C:\Windows\SysNative\drivers\msdv.sys (Microsoft Corporation)
DRV:
64bit: - (AVCSTRM) -- C:\Windows\SysNative\drivers\avcstrm.sys (Microsoft Corporation)
DRV:
64bit: - (MSTAPE) -- C:\Windows\SysNative\drivers\mstape.sys (Microsoft Corporation)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:
64bit: - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) -- C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {f4e6547e-325b-403c-a3bb-ad29ed37a92f} - C:\Program Files (x86)\SearchElf_1.2\prxtbSea0.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://localhost:8080/sabnzbd/
IE - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 93 9F FE EE 87 AA CB 01 [binary data]
IE - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\..\URLSearchHook: {f4e6547e-325b-403c-a3bb-ad29ed37a92f} - C:\Program Files (x86)\SearchElf_1.2\prxtbSea0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google.com (in English)"
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.type: 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010-08-30 22:58:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-06-25 23:53:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-06-12 23:56:27 | 000,000,000 | ---D | M]
[2011-07-18 12:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011-07-18 12:33:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
[2011-06-25 23:53:33 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010-03-27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2011-07-18 12:33:36 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011-05-06 15:38:57 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011-08-21 00:18:39 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SearchElf 1.2 Toolbar) - {f4e6547e-325b-403c-a3bb-ad29ed37a92f} - C:\Program Files (x86)\SearchElf_1.2\prxtbSea0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (SearchElf 1.2 Toolbar) - {f4e6547e-325b-403c-a3bb-ad29ed37a92f} - C:\Program Files (x86)\SearchElf_1.2\prxtbSea0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\..\Toolbar\WebBrowser: (SearchElf 1.2 Toolbar) - {F4E6547E-325B-403C-A3BB-AD29ED37A92F} - C:\Program Files (x86)\SearchElf_1.2\prxtbSea0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - Startup: C:\Users\All Users\Adobe [2010-10-11 21:10:32 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ALM [2010-08-30 23:07:00 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Apple [2011-06-12 17:16:04 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Application Data [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\AVAST Software [2011-07-16 18:37:50 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Canneverbe Limited [2011-01-29 16:27:09 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\CanonBJ [2010-08-30 21:18:37 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\All Users\CyberLink [2010-12-21 00:44:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\DAEMON Tools Lite [2011-07-20 19:16:27 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Desktop [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Documents [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\EA Core [2011-04-08 15:07:22 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Electronic Arts [2011-04-08 15:07:22 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Favorites [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\LightScribe [2010-12-21 00:45:35 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Malwarebytes [2011-07-18 00:08:14 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\McAfee [2011-03-25 15:07:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Microsoft [2010-11-17 19:06:31 | 000,000,000 | --SD | M]
O4 - Startup: C:\Users\All Users\Microsoft Help [2011-08-11 03:05:18 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Nero [2011-06-18 20:34:24 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\PACE Anti-Piracy [2010-08-30 23:14:04 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\regid.1986-12.com.adobe [2010-08-30 23:13:49 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Spotnet [2011-06-18 14:37:24 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Start Menu [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Sun [2011-03-25 15:08:38 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Temp [2011-07-16 17:52:35 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Templates [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2011-06-12 17:18:02 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Anja\AppData [2010-09-11 01:00:15 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Anja\Application Data [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Contacts [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\Cookies [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Desktop [2010-12-21 00:39:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\My Documents [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Downloads [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\Favorites [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\Links [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\Local Settings [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Music [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\My Documents [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\NetHood [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\ntuser.dat ()
O4 - Startup: C:\Users\Anja\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Anja\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Anja\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\Anja\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Anja\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Anja\ntuser.ini ()
O4 - Startup: C:\Users\Anja\Pictures [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\PrintHood [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Recent [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Saved Games [2010-11-02 18:25:09 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\Searches [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Anja\SendTo [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Start Menu [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Templates [2010-09-11 01:00:15 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Anja\Videos [2010-09-11 01:00:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\AppData [2009-07-14 05:20:08 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Default\Application Data [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Desktop [2010-12-21 00:39:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Documents [2009-07-14 07:08:56 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Downloads [2009-07-14 04:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Favorites [2009-07-14 04:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Links [2009-07-14 04:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\Local Settings [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Music [2009-07-14 04:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\My Documents [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\NetHood [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\NTUSER.DAT ()
O4 - Startup: C:\Users\Default\NTUSER.DAT ()
O4 - Startup: C:\Users\Default\NTUSER.DAT.LOG1 ()
O4 - Startup: C:\Users\Default\NTUSER.DAT.LOG2 ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Default\Pictures [2009-07-14 04:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\PrintHood [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Recent [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Saved Games [2009-07-14 04:34:59 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Default\SendTo [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Start Menu [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Templates [2009-07-14 07:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Videos [2009-07-14 04:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\.rnd ()
O4 - Startup: C:\Users\Marius\AppData [2010-09-01 18:16:19 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Marius\Application Data [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\Contacts [2010-12-30 22:42:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\Cookies [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\defogger_reenable ()
O4 - Startup: C:\Users\Marius\Desktop [2011-08-21 02:10:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\My Documents [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\Downloads [2011-08-15 17:15:16 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\Favorites [2010-12-30 22:42:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\Links [2011-01-28 13:23:04 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\Local Settings [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\Music [2011-06-12 21:44:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\My Documents [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\NetHood [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\ntuser.dat ()
O4 - Startup: C:\Users\Marius\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Marius\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Marius\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\Marius\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Marius\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Marius\ntuser.dat{73b76479-17ef-11e0-8f10-0022152d4f24}.TM.blf ()
O4 - Startup: C:\Users\Marius\ntuser.dat{73b76479-17ef-11e0-8f10-0022152d4f24}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Marius\ntuser.dat{73b76479-17ef-11e0-8f10-0022152d4f24}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Marius\ntuser.dat{bac50f20-4a59-11e0-a45e-0022152d4f24}.TM.blf ()
O4 - Startup: C:\Users\Marius\ntuser.dat{bac50f20-4a59-11e0-a45e-0022152d4f24}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Marius\ntuser.dat{bac50f20-4a59-11e0-a45e-0022152d4f24}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Marius\ntuser.ini ()
O4 - Startup: C:\Users\Marius\Pictures [2011-05-25 16:00:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\PrintHood [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\profielfoto (1 of 1).jpg ()
O4 - Startup: C:\Users\Marius\Recent [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\sabnzbd [2011-01-28 12:36:02 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Marius\Saved Games [2011-04-08 15:44:53 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\Searches [2010-12-30 22:42:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Marius\SendTo [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\Start Menu [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\Templates [2010-09-01 18:16:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Marius\Thumbs.db ()
O4 - Startup: C:\Users\Marius\Videos [2010-12-30 22:42:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\AppData [2011-08-21 00:23:00 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\CyberLink [2010-12-21 00:44:40 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\D-2785-7947-8747 [2002-01-01 07:09:57 | 000,000,000 | RHSD | M]
O4 - Startup: C:\Users\Public\Desktop [2011-07-23 23:48:03 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\desktop [2011-07-23 23:48:03 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Documents [2010-08-30 23:00:22 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Downloads [2009-07-14 06:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Favorites [2009-07-14 04:34:59 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Libraries [2010-09-21 18:46:37 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Music [2009-07-14 06:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Pictures [2009-07-14 06:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Recorded TV [2011-05-18 18:46:29 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\S-3685-5437-5687 [2002-01-01 07:09:57 | 000,000,000 | RHSD | M]
O4 - Startup: C:\Users\Public\Videos [2009-07-14 06:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\Adobe Flash Builder 4 [2010-08-30 23:02:33 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Wim\AppData [2010-08-29 16:06:48 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Wim\Application Data [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Contacts [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\Cookies [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\CyberLink [2010-12-21 00:44:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Wim\Desktop [2011-03-08 16:22:29 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\My Documents [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Downloads [2011-03-09 17:10:20 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\Favorites [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\Links [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\Local Settings [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Music [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\My Documents [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\NetHood [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\ntuser.dat ()
O4 - Startup: C:\Users\Wim\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Wim\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Wim\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\Wim\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Wim\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Wim\ntuser.ini ()
O4 - Startup: C:\Users\Wim\Pictures [2010-11-13 17:42:25 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\PP_MOTION.TMP [2010-12-21 00:45:33 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Wim\PP_ROTATE_SLIDE.TMP [2010-12-21 00:44:40 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Wim\PrintHood [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Recent [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Saved Games [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\Searches [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wim\SendTo [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Start Menu [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Sti_Trace.log ()
O4 - Startup: C:\Users\Wim\Templates [2010-08-29 16:06:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wim\Videos [2010-08-29 16:30:27 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\AppData [2010-09-03 15:53:54 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Wytske\Application Data [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Contacts [2010-09-03 15:54:13 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\Cookies [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Desktop [2010-12-21 00:39:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\My Documents [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Downloads [2010-09-03 15:54:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\Favorites [2010-09-03 15:54:13 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\Links [2010-09-03 15:54:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\Local Settings [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Music [2010-09-03 15:54:13 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\My Documents [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\NetHood [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\ntuser.dat ()
O4 - Startup: C:\Users\Wytske\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Wytske\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Wytske\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\Wytske\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Wytske\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Wytske\ntuser.ini ()
O4 - Startup: C:\Users\Wytske\Pictures [2011-03-22 23:35:54 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\PrintHood [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Recent [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Saved Games [2010-11-01 15:20:33 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\Searches [2010-09-03 15:54:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Wytske\SendTo [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Start Menu [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Templates [2010-09-03 15:53:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Wytske\Videos [2010-09-03 15:54:13 | 000,000,000 | R--D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3157286681-3811045524-2669837648-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.254
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-08-21 00:23:00 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011-08-20 23:57:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011-08-20 23:57:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011-08-20 23:57:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011-08-20 23:57:30 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011-08-20 23:57:27 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-08-20 23:57:27 | 000,000,000 | ---D | C] -- \Qoobox
[2011-07-23 14:14:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-08-21 00:18:39 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011-08-21 00:12:58 | 000,013,440 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-08-21 00:12:58 | 000,013,440 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-08-21 00:08:42 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011-08-21 00:08:42 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011-08-21 00:08:42 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011-08-21 00:04:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011-08-21 00:04:18 | 3220,475,904 | -HS- | M] () -- C:\hiberfil.sys
[2011-08-15 02:20:19 | 000,000,156 | ---- | M] () -- C:\Users\Marius\defogger_reenable
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-08-20 23:57:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011-08-20 23:57:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011-08-20 23:57:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011-08-20 23:57:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011-08-20 23:57:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011-08-15 02:20:19 | 000,000,156 | ---- | C] () -- C:\Users\Marius\defogger_reenable
[2011-07-16 10:49:38 | 000,065,536 | RHS- | C] () -- C:\Windows\SysWow64\scrrunn.dll
[2011-06-18 20:16:23 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2011-03-27 13:10:18 | 000,000,025 | -H-- | C] () -- C:\Windows\UBURN.DAT
[2011-01-29 19:10:04 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011-01-29 19:09:54 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011-01-29 19:09:50 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2010-12-21 00:39:15 | 000,000,000 | ---- | C] () -- C:\Windows\lgfwup.ini
[2010-10-30 18:01:19 | 000,013,368 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsUpIO.sys
[2010-10-30 18:01:07 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2010-10-30 18:01:07 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2010-10-30 17:59:37 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010-08-30 01:54:21 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK
[2010-08-30 01:54:19 | 000,383,562 | RHS- | C] () -- \bootmgr
[2010-08-29 15:57:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010-08-29 15:55:34 | 3220,475,904 | -HS- | C] () -- \hiberfil.sys
[2009-07-14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009-07-14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009-07-14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009-07-14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009-07-14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009-06-10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007-12-28 17:22:02 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
========== Alternate Data Streams ==========
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:39413AC3
< End of report >