========== Files/Folders - Created Within 30 Days ==========
[2019/10/09 10:40:57 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2
[2013/06/23 12:31:49 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/06/23 12:30:40 | 000,000,000 | ---D | C] -- C:\JRT
[2013/06/23 12:16:26 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\ali\Desktop\OTL.exe
[2013/06/23 12:15:52 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\ali\Desktop\JRT.exe
[2013/06/21 18:03:09 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Local\Temporary Projects
[2013/06/21 17:05:49 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG
[2013/06/21 17:03:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2013/06/21 15:55:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\S34NCS OC
[2013/06/21 15:55:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\S34NCS OC
[2013/06/21 15:45:52 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\S34NCS
[2013/06/21 08:19:20 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Local\temp
[2013/06/21 08:08:26 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013/06/21 08:05:35 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/06/21 07:09:31 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/06/20 20:20:13 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\Pics
[2013/06/20 20:19:04 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\Txt files
[2013/06/20 11:35:45 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Local\NVIDIA
[2013/06/20 09:05:12 | 000,000,000 | ---D | C] -- C:\Windows\gif
[2013/06/20 07:53:14 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/20 07:53:14 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/20 07:53:14 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/20 07:52:59 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/20 07:52:44 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/20 07:48:25 | 005,081,560 | R--- | C] (Swearware) -- C:\Users\ali\Desktop\ComboFix.exe
[2013/06/20 04:25:45 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\vlc
[2013/06/20 04:25:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/06/20 04:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/06/20 04:19:12 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/06/20 04:19:10 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/06/20 04:19:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013/06/20 04:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/06/20 04:07:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/06/20 04:06:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2013/06/20 04:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013/06/19 14:03:19 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\Testing
[2013/06/19 07:37:00 | 000,000,000 | ---D | C] -- C:\Windows\en
[2013/06/19 07:25:04 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013/06/19 07:24:57 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2013/06/19 06:45:48 | 000,000,000 | ---D | C] -- C:\Program Files\Types
[2013/06/19 02:45:23 | 000,070,256 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vsock.sys
[2013/06/19 02:45:23 | 000,067,224 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\vsocklib.dll
[2013/06/19 02:45:23 | 000,063,128 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vsocklib.dll
[2013/06/19 02:45:15 | 000,067,224 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmx86.sys
[2013/06/19 02:44:32 | 000,357,016 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vmnetdhcp.exe
[2013/06/19 02:44:28 | 000,435,864 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vmnat.exe
[2013/06/19 02:44:28 | 000,030,360 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmnetuserif.sys
[2013/06/19 02:44:12 | 000,933,528 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\vnetlib64.dll
[2013/06/19 02:43:58 | 000,052,376 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\hcmon.sys
[2013/06/19 02:43:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
[2013/06/19 02:43:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\VMware
[2013/06/19 02:40:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\VMware
[2013/06/19 02:40:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Shared Virtual Machines
[2013/06/18 16:06:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla Server
[2013/06/18 10:17:13 | 000,000,000 | -H-D | C] -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/06/18 10:14:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Gate
[2013/06/18 10:13:48 | 000,000,000 | ---D | C] -- C:\Program Files\Red Gate
[2013/06/16 03:02:08 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Local\VSIXInstaller
[2013/06/15 21:46:15 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\Skype
[2013/06/12 23:57:45 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\VBNet Themes
[2013/06/11 18:40:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nokia
[2013/06/11 16:30:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/06/10 21:10:09 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Local\Brice_Lambson
[2013/06/10 21:08:08 | 000,000,000 | ---D | C] -- C:\Program Files\Image Resizer for Windows
[2013/06/10 21:08:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image Resizer for Windows
[2013/06/10 21:08:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Resizer for Windows
[2013/06/07 23:15:21 | 000,000,000 | ---D | C] -- C:\RegBackup
[2013/06/07 22:57:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/06/07 21:11:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/06/07 21:10:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013/06/07 20:55:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MeteorEntertainment
[2013/06/07 20:55:26 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2013/06/06 02:34:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/06/06 02:33:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2013/06/06 02:33:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2013/06/06 02:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2013/06/06 02:30:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2013/06/06 02:30:35 | 000,000,000 | R--D | C] -- C:\MSOCache
[2013/06/05 13:49:05 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\NuGet
[2013/06/03 15:52:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/06/03 15:52:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013/06/03 13:55:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
[2013/06/03 13:39:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Web Tools
[2013/06/02 23:33:40 | 000,360,448 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx4ole14.ocx
[2013/06/02 23:33:39 | 000,610,304 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_pdf.dll
[2013/06/02 23:33:39 | 000,552,960 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_rtf.dll
[2013/06/02 23:33:39 | 000,385,024 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_xml.dll
[2013/06/02 23:33:39 | 000,253,952 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_png.flt
[2013/06/02 23:33:39 | 000,217,088 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_tls.dll
[2013/06/02 23:33:39 | 000,073,728 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_tif.flt
[2013/06/02 23:33:39 | 000,065,536 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_wnd.dll
[2013/06/02 23:33:39 | 000,053,248 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_wmf.flt
[2013/06/02 23:33:38 | 001,056,768 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_dox.dll
[2013/06/02 23:33:38 | 000,765,952 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14.dll
[2013/06/02 23:33:38 | 000,667,648 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_doc.dll
[2013/06/02 23:33:38 | 000,331,776 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_css.dll
[2013/06/02 23:33:38 | 000,327,680 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_obj.dll
[2013/06/02 23:33:38 | 000,249,856 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_htm.dll
[2013/06/02 23:33:38 | 000,200,704 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_jpg.flt
[2013/06/02 23:33:38 | 000,131,072 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_ic.dll
[2013/06/02 23:33:38 | 000,061,440 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_bmp.flt
[2013/06/02 23:33:38 | 000,057,344 | ---- | C] (The Imaging Source Europe GmbH) -- C:\Windows\SysWow64\tx14_gif.flt
[2013/06/02 23:33:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Word PDF Converter
[2013/06/02 20:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2013/06/02 20:24:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2013/06/02 20:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express
[2013/06/02 20:22:06 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 10.0
[2013/05/31 21:30:49 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\Microsoft FxCop
[2013/05/31 03:01:42 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013/05/30 21:34:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Visual Studio
[2013/05/30 13:34:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Sidebar
[2013/05/30 13:23:08 | 000,181,064 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2013/05/29 15:50:11 | 000,000,000 | ---D | C] -- C:\Users\ali\Documents\Visual Studio 2012
[2013/05/29 15:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK
[2013/05/29 15:39:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 4 SDK
[2013/05/29 15:28:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2013/05/29 15:16:23 | 000,000,000 | ---D | C] -- C:\Program Files\Application Verifier
[2013/05/29 15:16:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Verifier
[2013/05/29 15:14:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows App Certification Kit
[2013/05/29 15:00:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
[2013/05/29 15:00:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft
[2013/05/29 14:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2013/05/29 14:28:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2013/05/29 14:26:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NuGet
[2013/05/29 14:20:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft WCF Data Services
[2013/05/29 14:20:21 | 000,000,000 | ---D | C] -- C:\Program Files\IIS
[2013/05/29 14:20:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS
[2013/05/29 14:02:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Kits
[2013/05/29 13:24:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTML Help Workshop
[2013/05/29 13:23:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Help Viewer
[2013/05/29 13:06:36 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1033
[2013/05/29 12:31:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules
[2013/05/29 12:27:20 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\ImTOO
[2013/05/29 12:26:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImTOO
[2013/05/29 12:24:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2012
[2013/05/29 12:23:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 11.0
[2013/05/29 12:23:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1033
[2013/05/29 12:23:50 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2013/05/29 12:23:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 11.0
[2013/05/29 12:23:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SDKs
[2013/05/29 12:05:18 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1991-06.com.microsoft
[2013/05/29 12:05:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2013/05/27 19:39:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2013/05/27 19:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2013/05/26 15:12:45 | 000,000,000 | ---D | C] -- C:\Evolution Games
[2013/05/26 14:58:12 | 000,000,000 | ---D | C] -- C:\Users\ali\Desktop\Ace Evolution
[2013/05/26 14:39:29 | 000,000,000 | ---D | C] -- C:\Users\ali\AppData\Roaming\GlarySoft
[2013/05/26 14:39:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Absolute Uninstaller
[2013/05/26 02:14:39 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2012/08/15 11:20:36 | 002,174,976 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Program Files (x86)\Common Files\atimpenc.dll
========== Files - Modified Within 30 Days ==========
[2013/06/23 12:32:03 | 000,010,240 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/23 12:32:03 | 000,010,240 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/23 12:25:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/23 12:16:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ali\Desktop\OTL.exe
[2013/06/23 12:15:56 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\ali\Desktop\JRT.exe
[2013/06/23 12:15:06 | 000,648,201 | ---- | M] () -- C:\Users\ali\Desktop\adwcleaner.exe
[2013/06/22 16:02:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/22 03:43:56 | 000,119,458 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/22 03:43:56 | 000,087,182 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/06/22 03:43:56 | 000,031,794 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/06/21 17:18:56 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2013/06/21 15:55:10 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\S34NCS OC.lnk
[2013/06/21 11:48:57 | 000,001,058 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/06/21 07:08:46 | 005,081,560 | R--- | M] (Swearware) -- C:\Users\ali\Desktop\ComboFix.exe
[2013/06/20 11:34:38 | 000,001,309 | ---- | M] () -- C:\Users\Public\Desktop\GeForce Experience.lnk
[2013/06/20 04:25:35 | 000,001,028 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013/06/20 04:19:46 | 000,001,745 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/06/20 04:07:18 | 000,001,807 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/06/19 07:15:13 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013/06/19 06:45:49 | 000,000,114 | ---- | M] () -- C:\Users\ali\Desktop\Types.url
[2013/06/19 02:45:33 | 000,000,990 | ---- | M] () -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2013/06/19 02:43:38 | 000,001,024 | ---- | M] () -- C:\.rnd
[2013/06/19 02:43:31 | 000,124,444 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/19 02:43:28 | 000,002,089 | ---- | M] () -- C:\Users\Public\Desktop\VMware Workstation.lnk
[2013/06/17 04:16:59 | 000,007,596 | ---- | M] () -- C:\Users\ali\AppData\Local\Resmon.ResmonCfg
[2013/06/16 00:31:29 | 000,000,000 | ---- | M] () -- C:\Users\ali\AppData\Local\debuggee.mdmp
[2013/06/12 23:14:32 | 000,181,064 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2013/06/10 04:04:16 | 000,000,262 | ---- | M] () -- C:\Users\ali\Desktop\CP.bat
[2013/06/08 17:41:27 | 000,394,760 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/07 23:16:50 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-S34N-Microsoft-Windows-7-Home-Premium-(64-bit).dat
[2013/06/07 00:02:38 | 000,001,095 | ---- | M] () -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2013/06/05 13:57:23 | 000,000,860 | ---- | M] () -- C:\noavatar.jpg
[2013/05/31 22:48:42 | 000,012,657 | ---- | M] () -- C:\roflmfao.gif
[2013/05/31 21:06:10 | 000,001,209 | ---- | M] () -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\FileZilla.lnk
[2013/05/30 13:22:54 | 000,001,750 | ---- | M] () -- C:\Users\ali\Desktop\PsExe.lnk
[2013/05/26 16:07:22 | 000,001,475 | ---- | M] () -- C:\Users\ali\Desktop\TFC.lnk
[2013/05/26 16:07:21 | 000,001,913 | ---- | M] () -- C:\Users\ali\Desktop\DsnJumper.lnk
[2013/05/26 16:07:21 | 000,001,440 | ---- | M] () -- C:\Users\ali\Desktop\Unlocker.lnk
[2013/05/26 15:15:52 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\Launch Ace Evolution.lnk
[1 C:\Windows\SysNative\drivers\etc\*.tmp files -> C:\Windows\SysNative\drivers\etc\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/06/23 12:15:00 | 000,648,201 | ---- | C] () -- C:\Users\ali\Desktop\adwcleaner.exe
[2013/06/21 17:18:56 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2013/06/21 15:55:10 | 000,000,981 | ---- | C] () -- C:\Users\Public\Desktop\S34NCS OC.lnk
[2013/06/20 11:34:38 | 000,001,309 | ---- | C] () -- C:\Users\Public\Desktop\GeForce Experience.lnk
[2013/06/20 10:54:35 | 000,020,536 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2013/06/20 07:53:14 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/20 07:53:14 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/20 07:53:14 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/20 07:53:14 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/20 07:53:14 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/06/20 04:25:35 | 000,001,028 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013/06/20 04:19:46 | 000,001,745 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/06/20 04:07:18 | 000,001,807 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/06/19 07:36:41 | 000,001,267 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2013/06/19 07:36:29 | 000,001,336 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2013/06/19 07:31:34 | 000,001,420 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013/06/19 07:31:24 | 000,002,448 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013/06/19 06:45:49 | 000,000,114 | ---- | C] () -- C:\Users\ali\Desktop\Types.url
[2013/06/19 02:45:33 | 000,000,990 | ---- | C] () -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2013/06/19 02:43:38 | 000,001,024 | ---- | C] () -- C:\.rnd
[2013/06/19 02:43:28 | 000,002,089 | ---- | C] () -- C:\Users\Public\Desktop\VMware Workstation.lnk
[2013/06/16 00:31:29 | 000,000,000 | ---- | C] () -- C:\Users\ali\AppData\Local\debuggee.mdmp
[2013/06/07 23:16:50 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-S34N-Microsoft-Windows-7-Home-Premium-(64-bit).dat
[2013/06/07 00:02:38 | 000,001,095 | ---- | C] () -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2013/06/05 13:57:30 | 000,000,860 | ---- | C] () -- C:\noavatar.jpg
[2013/06/05 13:54:25 | 000,024,004 | ---- | C] () -- C:\msoobe.jpg
[2013/06/05 13:52:56 | 000,012,657 | ---- | C] () -- C:\roflmfao.gif
[2013/06/02 23:33:38 | 000,000,530 | ---- | C] () -- C:\Windows\SysWow64\tx14_ic.ini
[2013/05/31 21:06:10 | 000,001,209 | ---- | C] () -- C:\Users\ali\Application Data\Microsoft\Internet Explorer\Quick Launch\FileZilla.lnk
[2013/05/30 13:35:18 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2013/05/30 13:22:20 | 000,001,750 | ---- | C] () -- C:\Users\ali\Desktop\PsExe.lnk
[2013/05/29 14:28:36 | 000,002,021 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
[2013/05/26 15:15:52 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\Launch Ace Evolution.lnk
[2013/05/26 12:22:10 | 000,001,475 | ---- | C] () -- C:\Users\ali\Desktop\TFC.lnk
[2013/03/09 16:13:50 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2013/03/08 04:32:31 | 000,000,630 | ---- | C] () -- C:\Windows\cce.INI
[2013/02/19 22:19:30 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2013/02/19 22:19:30 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2013/02/19 22:19:30 | 000,000,073 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2013/02/19 22:19:29 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2013/02/19 22:19:29 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2013/02/12 13:06:52 | 000,091,264 | ---- | C] () -- C:\Windows\SysWow64\EasyHook32.dll
[2013/02/05 21:01:48 | 000,885,970 | ---- | C] () -- C:\Users\ali\AppData\Local\census.cache
[2013/02/05 20:59:16 | 000,143,171 | ---- | C] () -- C:\Users\ali\AppData\Local\ars.cache
[2013/02/05 20:28:20 | 000,000,036 | ---- | C] () -- C:\Users\ali\AppData\Local\housecall.guid.cache
[2013/01/31 10:47:29 | 000,002,143 | ---- | C] () -- C:\Windows\KillSwitch.INI
[2012/06/12 21:46:01 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2012/06/06 18:18:41 | 000,007,596 | ---- | C] () -- C:\Users\ali\AppData\Local\Resmon.ResmonCfg
[2012/06/04 09:32:27 | 000,000,000 | ---- | C] () -- C:\Windows\Net4Switch.INI
[2011/09/22 17:34:44 | 000,007,168 | ---- | C] () -- C:\Users\ali\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/03 20:07:04 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2011/08/04 02:29:36 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/02/20 02:08:34 | 000,000,600 | ---- | C] () -- C:\Users\ali\AppData\Local\PUTTY.RND
========== ZeroAccess Check ==========
[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2010/11/20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/08/29 18:16:31 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Bitdefender
[2012/08/06 05:19:24 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ESET
[2012/08/28 20:01:06 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Arkadium
[2011/08/28 19:19:02 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Asus WebStorage
[2012/03/19 17:32:24 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Avnex
[2011/03/03 22:58:42 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Blumentals
[2013/03/09 19:43:49 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Caphyon
[2012/04/19 21:40:00 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2019/10/09 10:40:57 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2
[2013/02/03 07:41:13 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Crypto Obfuscator For .Net v2013
[2013/03/08 16:39:45 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\CrystalIdea Software
[2013/06/23 12:31:06 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\DMCache
[2013/02/22 18:36:42 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Dropbox
[2011/03/15 01:57:35 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\EeeStorageUploader
[2011/11/06 17:43:27 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\ESET
[2013/01/25 20:04:04 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Eusing
[2013/05/26 15:12:36 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Evolution Games
[2013/02/08 20:26:23 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\FFSJ
[2013/03/08 00:50:03 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\FILEminimizerPictures
[2013/06/21 21:05:48 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\FileZilla
[2013/06/19 07:09:13 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\GlarySoft
[2012/07/20 05:55:11 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\HLSW
[2012/07/26 15:58:20 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\http___s34ncs.webs.com_
[2013/06/19 07:59:52 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\IDM
[2013/05/29 12:27:20 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\ImTOO
[2013/02/22 03:36:05 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\IrfanView
[2013/03/08 00:48:53 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\iVeeSoft
[2012/10/13 22:00:13 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\JustDecompile
[2012/08/28 05:19:49 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\kingsoft
[2013/02/01 12:18:41 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Mipony
[2013/01/27 03:31:52 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\MySQL
[2013/06/22 15:56:15 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Nokia
[2013/03/20 21:57:02 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Notepad++
[2011/11/19 16:08:37 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Nseries
[2013/06/05 13:49:05 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\NuGet
[2013/06/11 18:48:45 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\PC Suite
[2011/03/03 22:41:19 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\phpDesigner
[2013/03/06 15:33:32 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\QFX Software
[2012/08/14 20:11:28 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\QTTabBar
[2013/05/29 09:28:39 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\QuickScan
[2013/02/21 22:57:06 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Shadow Defender
[2013/06/06 02:14:21 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\SoftGrid Client
[2013/01/26 19:57:59 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Subversion
[2013/03/04 01:01:29 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\TaskbarHelper
[2012/07/09 09:21:37 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\TeamViewer
[2012/08/15 19:43:51 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\TechSmith
[2012/10/13 21:23:53 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Telerik
[2011/08/28 19:13:24 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\temp
[2013/03/02 12:40:10 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\TeraCopy
[2012/04/09 23:52:45 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Thunderbird
[2011/03/21 19:46:16 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\TP
[2012/05/24 23:57:06 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\ts3overlay
[2013/01/26 01:17:49 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Tunngle
[2012/03/30 15:16:05 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Unity
[2012/08/06 14:18:34 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\updatetool
[2013/02/24 19:59:21 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\VOS
[2011/04/12 16:09:30 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Webshots
[2011/02/13 01:25:21 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Windows Live Writer
[2012/08/17 01:48:59 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Xilisoft
[2012/09/01 03:54:35 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\XnRetro
[2013/02/23 01:40:56 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\XnView
[2013/02/06 13:52:33 | 000,000,000 | ---D | M] -- C:\Users\ali\AppData\Roaming\Zbshareware Lab
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:981884E7
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:52DBE86F
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:029E021F
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp

20FFA63
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:3E7393FC
< End of report >