OTL.txt #2
========== Files/Folders - Created Within 30 Days ==========
[2012/02/07 15:49:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/03 18:48:14 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/02/03 14:42:47 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/02/03 13:42:23 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\tdsskiller
[2012/02/02 18:39:36 | 000,000,000 | ---D | C] -- C:\ProgramData\RegAce
[2012/02/02 18:39:17 | 000,000,000 | ---D | C] -- C:\Windows\RegAce
[2012/02/02 17:22:28 | 000,799,880 | ---- | C] (Crawler.com ) -- C:\Users\Owner\Desktop\SpywareTerminatorSetup.exe
[2012/02/02 17:19:08 | 004,395,020 | R--- | C] (Swearware) -- C:\Users\Owner\Desktop\ComboFix.exe
[2012/02/02 17:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/02/02 17:09:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/02/02 16:45:16 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012/02/02 16:26:42 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2012/02/02 16:21:38 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/02/02 16:20:58 | 000,116,016 | ---- | C] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\18676779.sys
[2012/02/02 15:51:54 | 015,795,464 | ---- | C] (Mozilla) -- C:\Users\Owner\Desktop\Firefox Setup 10.0.exe
[2012/02/02 15:00:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Threat Expert
[2012/02/02 14:42:36 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll0208.old
[2012/02/02 14:42:34 | 002,246,608 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll0208.old
[2012/02/02 14:38:12 | 000,230,952 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012/02/02 14:38:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012/02/02 14:38:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools
[2012/02/02 14:37:35 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012/02/02 14:37:33 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\TestApp
[2012/02/02 14:36:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Binnerup Consult
[2012/02/02 14:36:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My Movies
[2012/02/02 14:30:02 | 000,000,000 | ---D | C] -- C:\ProgramData\CPA_VA
[2012/02/02 14:28:58 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\COMODO
[2012/02/02 14:01:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\My Movies for Windows Media Center 4.01 Build 2
[2012/02/02 12:28:04 | 003,834,832 | ---- | C] (PC Tools) -- C:\Users\Owner\Desktop\sdsetup.exe
[2012/02/02 12:09:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2012/02/02 12:09:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Comodo
[2012/02/02 11:58:09 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com
[2012/02/02 11:57:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/02/02 11:57:52 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012/02/02 11:57:52 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012/02/02 11:28:52 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2012/02/02 11:28:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5
[2012/02/02 10:34:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\gmer
[2012/02/01 19:05:49 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/02/01 16:39:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/02/01 16:39:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/02/01 13:47:00 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/02/01 13:47:00 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\temp
[2012/02/01 13:34:42 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/02/01 13:34:42 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/02/01 13:34:42 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/02/01 13:34:36 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/01/30 13:09:01 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\VideoReDo-TVSuite4
[2012/01/30 13:09:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoReDoTVSuite4
[2012/01/29 17:19:36 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo
[2012/01/29 17:19:36 | 000,000,000 | ---D | C] -- C:\Program Files\MediaInfo
[2012/01/29 17:10:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\AnvSoft
[2012/01/28 19:02:20 | 001,446,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012/01/28 19:02:19 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2012/01/28 19:02:19 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2012/01/28 19:02:19 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012/01/28 19:02:19 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012/01/28 19:02:19 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012/01/28 18:56:44 | 000,000,000 | ---D | C] -- C:\Hauppauge
[2012/01/28 18:41:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
[2012/01/28 18:41:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Renesas Electronics
[2012/01/28 14:18:54 | 000,000,000 | ---D | C] -- D:\Documents\NetXfer
[2012/01/28 14:16:54 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Xi
[2012/01/28 14:16:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xi
[2012/01/28 14:16:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xi
[2012/01/28 13:26:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Hensense.com
[2012/01/28 13:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hensence.com
[2012/01/28 12:45:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GetFLV
[2012/01/28 12:36:06 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Moyea
[2012/01/28 12:26:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\vlc
[2012/01/28 12:26:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/01/28 12:25:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/01/28 12:18:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2012/01/28 12:12:46 | 000,000,000 | ---D | C] -- D:\Documents\Freemake
[2012/01/28 12:12:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freemake
[2012/01/28 10:57:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FDRLab
[2012/01/28 10:53:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DownloadToolz
[2012/01/28 10:42:54 | 000,000,000 | ---D | C] -- C:\Users\Owner\.streamCapture
[2012/01/28 09:43:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zune
[2012/01/27 20:21:41 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/01/27 20:21:40 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2012/01/27 20:21:39 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2012/01/27 20:21:39 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2012/01/27 20:21:38 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/01/27 20:21:38 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/01/27 20:21:38 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/01/27 20:21:38 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/01/27 20:21:38 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2012/01/27 20:21:37 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/01/27 20:21:37 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/01/27 20:21:37 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2012/01/27 20:21:36 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2012/01/27 20:21:36 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2012/01/27 20:21:36 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2012/01/27 20:21:14 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2012/01/27 20:21:07 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2012/01/27 20:21:07 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2012/01/27 20:21:06 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2012/01/27 20:21:06 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2012/01/27 20:21:06 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2012/01/27 20:21:06 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2012/01/27 20:21:06 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2012/01/27 20:21:06 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2012/01/27 20:21:06 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2012/01/27 20:21:06 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2012/01/27 20:21:05 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2012/01/27 20:21:05 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/01/27 20:21:05 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/01/27 20:21:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/01/27 20:21:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/01/27 20:21:04 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/01/27 20:21:04 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/01/27 20:21:04 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/01/27 20:21:04 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/01/27 20:21:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/01/27 20:21:03 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/01/27 20:21:03 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/01/27 20:21:03 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/01/27 20:21:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/01/27 20:21:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/01/27 20:21:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/01/27 20:21:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/01/27 20:21:02 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2012/01/27 20:21:02 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/01/27 20:21:02 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/01/27 20:21:02 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/01/27 20:21:02 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/01/27 20:21:02 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/01/27 20:21:02 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/01/27 20:21:02 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/01/27 20:21:02 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/01/27 20:21:02 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/01/27 20:21:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2012/01/27 20:21:00 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2012/01/27 20:20:59 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2012/01/27 20:20:59 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2012/01/27 20:20:59 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2012/01/27 20:20:59 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2012/01/27 20:20:59 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Mpeg2Data.ax
[2012/01/27 20:20:59 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2012/01/27 20:20:59 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSDvbNP.ax
[2012/01/27 20:20:59 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
[2012/01/27 20:20:58 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax
[2012/01/27 20:20:54 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2012/01/27 20:20:54 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2012/01/27 20:20:54 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012/01/27 20:20:54 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012/01/27 20:20:52 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2012/01/27 20:20:51 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2012/01/27 20:20:50 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcjt32.dll
[2012/01/27 20:20:50 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbctrac.dll
[2012/01/27 20:20:50 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll
[2012/01/27 20:20:50 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccu32.dll
[2012/01/27 20:20:50 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccr32.dll
[2012/01/27 20:20:49 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbctrac.dll
[2012/01/27 20:20:49 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll
[2012/01/27 20:20:49 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccu32.dll
[2012/01/27 20:20:49 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccr32.dll
[2012/01/27 20:20:46 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/01/27 20:20:46 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/01/27 20:20:43 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll
[2012/01/27 20:20:42 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2012/01/27 20:20:42 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2012/01/27 20:18:48 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/01/27 20:18:47 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/01/27 20:18:47 | 003,902,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/01/27 20:18:44 | 001,739,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2012/01/27 20:16:24 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2012/01/27 20:16:24 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2012/01/27 20:10:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\rtmpexplorer
[2012/01/27 20:10:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\rtmpdump-2.4
[2012/01/27 20:00:51 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\My Movies for Windows Media Center 3.21
[2012/01/27 14:40:28 | 000,257,784 | -H-- | C] (Bytescout) -- C:\Windows\SysWow64\BytescoutScreenCapturingFilter.dll
[2012/01/27 14:40:28 | 000,175,864 | -H-- | C] (Bytescout) -- C:\Windows\SysWow64\BytescoutVideoMixerFilter.dll
[2012/01/27 14:40:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
[2012/01/27 14:40:25 | 000,566,008 | -H-- | C] (Bytescout) -- C:\Windows\SysNative\BytescoutScreenCapturing.dll
[2012/01/27 14:40:25 | 000,421,624 | -H-- | C] (Bytescout) -- C:\Windows\SysWow64\BytescoutScreenCapturing.dll
[2012/01/27 14:40:25 | 000,361,720 | -H-- | C] (Bytescout) -- C:\Windows\SysNative\BytescoutScreenCapturingFilter.dll
[2012/01/27 14:40:25 | 000,231,672 | -H-- | C] (Bytescout) -- C:\Windows\SysNative\BytescoutVideoMixerFilter.dll
[2012/01/27 14:40:17 | 000,000,000 | ---D | C] -- C:\Program Files\Apowersoft
[2012/01/27 14:05:41 | 000,000,000 | ---D | C] -- D:\Documents\Streaming Video Recorder
[2012/01/27 14:05:05 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012/01/27 14:01:51 | 000,029,288 | -H-- | C] (Wondershare) -- C:\Windows\SysNative\drivers\Apowersoft_AudioDevice.sys
[2012/01/27 14:01:51 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Apowersoft
[2012/01/27 10:42:10 | 000,000,000 | ---D | C] -- C:\Windows\Applian Director
[2012/01/27 10:42:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Applian Director
[2012/01/27 10:41:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Replay Video Capture
[2012/01/24 16:11:11 | 000,000,000 | ---D | C] -- D:\Documents\Moyea
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/07 17:28:24 | 000,013,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/07 17:28:24 | 000,013,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/07 17:25:21 | 000,798,720 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/07 17:25:21 | 000,675,098 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/02/07 17:25:21 | 000,126,088 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/02/07 17:20:55 | 000,000,343 | ---- | M] () -- C:\Windows\lgfwup.ini
[2012/02/07 17:19:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/07 17:19:28 | 534,941,695 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/05 03:00:00 | 000,000,396 | ---- | M] () -- C:\Windows\tasks\RegAce Scheduled Scan - Owner.job
[2012/02/03 19:10:55 | 001,474,832 | ---- | M] () -- C:\Windows\SysNative\drivers\sfi.dat
[2012/02/03 14:42:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/02/03 11:30:43 | 001,008,141 | ---- | M] () -- C:\Users\Owner\Desktop\rkill.com
[2012/02/03 10:31:19 | 002,040,543 | ---- | M] () -- C:\Users\Owner\Desktop\tdsskiller.zip
[2012/02/03 10:29:46 | 001,008,141 | ---- | M] () -- C:\Users\Owner\Desktop\rkill.scr
[2012/02/03 10:29:21 | 000,000,335 | ---- | M] () -- C:\Users\Owner\Desktop\FixExe.reg
[2012/02/03 10:25:15 | 000,302,592 | ---- | M] () -- C:\Users\Owner\Desktop\h7ikfgyy.exe
[2012/02/02 23:25:56 | 000,000,017 | ---- | M] () -- C:\Users\Owner\AppData\Local\resmon.resmoncfg
[2012/02/02 19:34:25 | 000,000,331 | ---- | M] () -- C:\Start_.cmd
[2012/02/02 17:38:26 | 000,001,167 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/02 17:22:33 | 000,799,880 | ---- | M] (Crawler.com ) -- C:\Users\Owner\Desktop\SpywareTerminatorSetup.exe
[2012/02/02 17:19:19 | 004,395,020 | R--- | M] (Swearware) -- C:\Users\Owner\Desktop\ComboFix.exe
[2012/02/02 16:27:19 | 000,025,160 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro36.sys
[2012/02/02 16:20:58 | 000,116,016 | ---- | M] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\18676779.sys
[2012/02/02 15:52:18 | 015,795,464 | ---- | M] (Mozilla) -- C:\Users\Owner\Desktop\Firefox Setup 10.0.exe
[2012/02/02 14:38:40 | 001,519,975 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/02/02 13:59:44 | 000,017,920 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/02 12:28:36 | 003,834,832 | ---- | M] (PC Tools) -- C:\Users\Owner\Desktop\sdsetup.exe
[2012/02/02 10:33:57 | 000,294,216 | ---- | M] () -- C:\Users\Owner\Desktop\gmer.zip
[2012/02/01 16:39:55 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/02/01 16:39:48 | 000,812,378 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/01/30 15:05:15 | 000,001,547 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/01/29 17:16:45 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/01/28 18:57:20 | 000,000,658 | ---- | M] () -- C:\Users\Owner\Desktop\CD Digital 3.4.lnk
[2012/01/28 12:47:06 | 037,665,066 | ---- | M] () -- C:\Users\Owner\Desktop\cd-digital-34.exe
[2012/01/28 11:25:20 | 000,417,352 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/01/28 11:12:40 | 054,363,179 | ---- | M] () -- D:\Documents\kehrcjeu.flv
[2012/01/28 09:43:17 | 000,000,964 | ---- | M] () -- C:\Users\Public\Desktop\Zune.lnk
[2012/01/27 20:03:31 | 000,000,228 | ---- | M] () -- C:\Users\Owner\.swfinfo
[2012/01/27 17:40:02 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/01/23 17:31:48 | 000,002,034 | -H-- | M] () -- D:\Documents\Default.rdp
[2012/01/23 15:28:54 | 155,893,257 | ---- | M] () -- D:\Documents\BTV_1_23_2012_(BUILD_6525).zip
[2012/01/21 16:52:04 | 158,110,986 | ---- | M] () -- D:\Documents\BTV_1_21_2012_(BUILD_6525).zip
[2012/01/16 16:28:50 | 000,149,456 | ---- | M] (PC Tools) -- C:\Windows\SGDetectionTool.dll0208.old
[2012/01/16 16:28:48 | 002,246,608 | ---- | M] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll0208.old
[2012/01/16 16:28:28 | 000,767,952 | ---- | M] () -- C:\Windows\BDTSupport.dll0208.old
[2012/01/11 16:19:08 | 000,230,952 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/03 11:30:42 | 001,008,141 | ---- | C] () -- C:\Users\Owner\Desktop\rkill.com
[2012/02/03 10:31:12 | 002,040,543 | ---- | C] () -- C:\Users\Owner\Desktop\tdsskiller.zip
[2012/02/03 10:29:43 | 001,008,141 | ---- | C] () -- C:\Users\Owner\Desktop\rkill.scr
[2012/02/03 10:29:19 | 000,000,335 | ---- | C] () -- C:\Users\Owner\Desktop\FixExe.reg
[2012/02/03 10:25:07 | 000,302,592 | ---- | C] () -- C:\Users\Owner\Desktop\h7ikfgyy.exe
[2012/02/02 23:25:56 | 000,000,017 | ---- | C] () -- C:\Users\Owner\AppData\Local\resmon.resmoncfg
[2012/02/02 19:34:25 | 000,000,331 | ---- | C] () -- C:\Start_.cmd
[2012/02/02 18:39:37 | 000,000,396 | ---- | C] () -- C:\Windows\tasks\RegAce Scheduled Scan - Owner.job
[2012/02/02 17:38:26 | 000,001,167 | ---- | C] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/02 17:37:44 | 000,001,179 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/02/02 16:27:19 | 000,025,160 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro36.sys
[2012/02/02 14:42:37 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll0208.old
[2012/02/02 14:38:21 | 001,519,975 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/02/02 12:11:26 | 001,474,832 | ---- | C] () -- C:\Windows\SysNative\drivers\sfi.dat
[2012/02/02 10:33:54 | 000,294,216 | ---- | C] () -- C:\Users\Owner\Desktop\gmer.zip
[2012/02/01 16:39:43 | 000,001,934 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/02/01 13:34:42 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/01 13:34:42 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/01 13:34:42 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/02/01 13:34:42 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/02/01 13:34:42 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/30 15:05:15 | 000,001,547 | ---- | C] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/01/29 17:16:43 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2012/01/28 18:57:19 | 000,000,658 | ---- | C] () -- C:\Users\Owner\Desktop\CD Digital 3.4.lnk
[2012/01/28 12:46:47 | 037,665,066 | ---- | C] () -- C:\Users\Owner\Desktop\cd-digital-34.exe
[2012/01/28 11:01:50 | 054,363,179 | ---- | C] () -- D:\Documents\kehrcjeu.flv
[2012/01/28 09:43:17 | 000,000,964 | ---- | C] () -- C:\Users\Public\Desktop\Zune.lnk
[2012/01/27 20:03:31 | 000,000,228 | ---- | C] () -- C:\Users\Owner\.swfinfo
[2012/01/27 14:40:28 | 000,376,432 | -H-- | C] () -- C:\Windows\SysWow64\x86.zip
[2012/01/23 15:27:07 | 155,893,257 | ---- | C] () -- D:\Documents\BTV_1_23_2012_(BUILD_6525).zip
[2012/01/21 16:50:24 | 158,110,986 | ---- | C] () -- D:\Documents\BTV_1_21_2012_(BUILD_6525).zip
[2011/07/27 19:49:32 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\rmc_rtspdl.dll
[2011/07/27 18:36:05 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\WS_ATLMovie.dll
[2011/07/27 13:19:23 | 000,017,920 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/26 15:30:24 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\IcdSptSvps.dll
[2011/07/26 15:30:23 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\mp3dec.dll
[2011/07/26 15:30:23 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\dsp_trc.dll
[2011/07/26 10:01:44 | 000,237,568 | R--- | C] () -- C:\Windows\SysWow64\qtmlClient.dll
[2011/07/26 10:01:44 | 000,000,000 | ---- | C] () -- C:\Windows\Graffiti5.2Pin.ini
[2011/07/24 12:14:54 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011/07/24 12:09:26 | 000,000,343 | ---- | C] () -- C:\Windows\lgfwup.ini
[2011/07/23 09:17:28 | 000,812,378 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/21 19:56:25 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/07/20 15:44:12 | 000,142,337 | ---- | C] () -- C:\Windows\SysWow64\Wait.exe
[2011/07/20 13:28:49 | 000,000,387 | ---- | C] () -- C:\Windows\HCWBlast.ini
[2011/07/20 13:28:35 | 000,035,344 | ---- | C] () -- C:\Windows\Irremote.ini
[2011/07/20 12:30:01 | 000,163,840 | ---- | C] () -- C:\Windows\SysWow64\hcwChDB.dll
[2011/07/20 12:30:01 | 000,000,483 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/07/20 12:30:01 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/07/20 12:29:11 | 000,003,120 | ---- | C] () -- C:\Windows\HCWPNP.INI
[2011/07/20 12:07:20 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2011/07/20 11:55:18 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2011/07/19 13:28:59 | 000,241,664 | ---- | C] () -- C:\Windows\SysWow64\uuirtdrv.dll
[2011/02/09 23:03:48 | 000,000,326 | ---- | C] () -- C:\Windows\primopdf.ini
[2009/08/27 02:04:12 | 000,207,400 | R--- | C] () -- C:\Windows\GSetup.exe
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp

FC5A2B2
< End of report >