========== Files - Modified Within 30 Days ==========
[2012/07/10 09:47:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/10 09:47:14 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/10 09:47:14 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/09 18:42:09 | 000,384,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\services.exe
[2012/07/09 14:31:16 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/09 13:27:03 | 000,001,887 | ---- | M] () -- C:\Windows\diagwrn.xml
[2012/07/09 13:27:03 | 000,001,887 | ---- | M] () -- C:\Windows\diagerr.xml
[2012/07/09 13:19:01 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-418972822-4011934444-250511128-1000UA.job
[2012/07/09 10:16:18 | 004,574,937 | R--- | M] (Swearware) -- C:\Users\Carol P\Desktop\ComboFix.exe
[2012/07/08 21:01:00 | 000,000,260 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Messager.job
[2012/07/08 19:42:03 | 000,000,496 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Registration3.job
[2012/07/08 19:42:03 | 000,000,468 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3.job
[2012/07/08 19:42:03 | 000,000,424 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Pro.job
[2012/07/08 19:40:11 | 000,384,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\services.exe.63496115D08FAD5D
[2012/07/08 19:39:55 | 000,001,032 | ---- | M] () -- C:\Users\Carol P\Desktop\SpeedyPC Pro.lnk
[2012/07/08 15:43:48 | 000,001,758 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/07/08 15:43:48 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/07/08 14:45:58 | 000,605,866 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/07/08 14:45:58 | 000,104,836 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/07/07 17:50:36 | 000,000,905 | ---- | M] () -- C:\Users\Carol P\Desktop\magicJack.lnk
[2012/07/07 15:39:55 | 000,384,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\services.exe.52C74B45B7E23DDE
[2012/07/07 15:22:44 | 000,001,828 | ---- | M] () -- C:\Users\Carol P\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Security Essentials.lnk
[2012/07/07 14:52:42 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/07/07 14:52:31 | 000,001,828 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/07/07 14:52:25 | 000,722,496 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/06 20:19:00 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-418972822-4011934444-250511128-1000Core.job
[2012/07/05 22:09:08 | 000,047,204 | ---- | M] () -- C:\Users\Carol P\Desktop\Family Educational.pdf
[2012/07/05 22:08:02 | 000,029,230 | ---- | M] () -- C:\Users\Carol P\Desktop\FERPA Primer The Basics and Beyond.odt
[2012/07/05 05:32:06 | 000,000,016 | ---- | M] () -- C:\Windows\popcinfo.dat
[2012/07/04 19:31:10 | 000,586,275 | ---- | M] () -- C:\Users\Carol P\Desktop\Changing Dynamics in State Oversight of For-Profit Colleges.pdf
[2012/07/04 18:36:52 | 000,404,864 | ---- | M] () -- C:\Users\Carol P\Desktop\SUMMARY OF COMPLIANCE-2011V2 CAN.pdf
[2012/07/03 00:21:57 | 000,002,054 | ---- | M] () -- C:\Users\Carol P\Desktop\Google Chrome.lnk
[2012/07/03 00:21:57 | 000,002,016 | ---- | M] () -- C:\Users\Carol P\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/06/30 14:59:59 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\TuneUpMedic_scan_schedule_task_0b376ef0-5ff1-4233-ac54-6209f2b73b3e.job
[2012/06/27 04:17:25 | 000,001,774 | ---- | M] () -- C:\Users\Public\Desktop\Rainlendar2.lnk
[2012/06/26 08:22:30 | 010,328,618 | ---- | M] () -- C:\Users\Carol P\Desktop\PN ADULT MEDICAL SURGICAL NURSING.pdf
[2012/06/26 05:28:55 | 000,000,772 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/24 07:02:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AI RoboForm
[2012/06/23 14:31:52 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 14:31:51 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/18 14:50:37 | 000,011,464 | ---- | M] () -- C:\Users\Carol P\Documents\Foreclosure.odt
[2012/06/13 04:44:05 | 000,011,081 | ---- | M] () -- C:\Users\Carol P\Documents\Cver Page proj.5.odt
[2012/06/13 04:16:37 | 000,384,688 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/06/13 00:45:14 | 000,013,762 | ---- | M] () -- C:\Users\Carol P\Documents\Follow-up letter final.odt
[2012/06/13 00:22:09 | 000,012,473 | ---- | M] () -- C:\Users\Carol P\Documents\Carol Prew 1234 Bartholf Ave.odt
[2012/06/12 18:27:10 | 000,001,135 | ---- | M] () -- C:\Users\Carol P\Desktop\Microsoft Office - Shortcut.lnk
[2012/06/12 18:13:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
========== Files Created - No Company Name ==========
[2012/07/09 13:19:44 | 000,001,887 | ---- | C] () -- C:\Windows\diagwrn.xml
[2012/07/09 13:19:44 | 000,001,887 | ---- | C] () -- C:\Windows\diagerr.xml
[2012/07/08 19:26:30 | 000,000,496 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Registration3.job
[2012/07/08 19:26:17 | 000,001,032 | ---- | C] () -- C:\Users\Carol P\Desktop\SpeedyPC Pro.lnk
[2012/07/08 19:26:14 | 000,000,468 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Update Version3.job
[2012/07/08 19:26:13 | 000,000,424 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Pro.job
[2012/07/08 15:43:48 | 000,001,758 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/07/08 15:04:40 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/08 15:04:40 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/08 15:04:40 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/08 15:04:40 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/08 15:04:40 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/07 15:22:44 | 000,001,828 | ---- | C] () -- C:\Users\Carol P\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Security Essentials.lnk
[2012/07/07 14:52:30 | 000,001,828 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/07/05 22:09:08 | 000,047,204 | ---- | C] () -- C:\Users\Carol P\Desktop\Family Educational.pdf
[2012/07/05 22:07:59 | 000,029,230 | ---- | C] () -- C:\Users\Carol P\Desktop\FERPA Primer The Basics and Beyond.odt
[2012/07/04 19:31:10 | 000,586,275 | ---- | C] () -- C:\Users\Carol P\Desktop\Changing Dynamics in State Oversight of For-Profit Colleges.pdf
[2012/07/04 18:36:52 | 000,404,864 | ---- | C] () -- C:\Users\Carol P\Desktop\SUMMARY OF COMPLIANCE-2011V2 CAN.pdf
[2012/06/26 08:22:30 | 010,328,618 | ---- | C] () -- C:\Users\Carol P\Desktop\PN ADULT MEDICAL SURGICAL NURSING.pdf
[2012/06/18 14:50:35 | 000,011,464 | ---- | C] () -- C:\Users\Carol P\Documents\Foreclosure.odt
[2012/06/13 04:44:02 | 000,011,081 | ---- | C] () -- C:\Users\Carol P\Documents\Cver Page proj.5.odt
[2012/06/13 00:21:57 | 000,012,473 | ---- | C] () -- C:\Users\Carol P\Documents\Carol Prew 1234 Bartholf Ave.odt
[2012/06/12 23:14:13 | 000,013,762 | ---- | C] () -- C:\Users\Carol P\Documents\Follow-up letter final.odt
[2012/06/12 18:27:10 | 000,001,135 | ---- | C] () -- C:\Users\Carol P\Desktop\Microsoft Office - Shortcut.lnk
[2012/04/28 08:51:08 | 000,004,096 | -H-- | C] () -- C:\Users\Carol P\AppData\Local\keyfile3.drm
[2012/03/26 18:44:10 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012/03/23 22:48:30 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2012/03/17 06:13:14 | 000,073,220 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2012/03/17 06:13:14 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2012/03/17 06:13:13 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2012/03/17 06:13:13 | 000,029,114 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2012/03/17 06:13:13 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2012/03/17 06:13:13 | 000,021,021 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2012/03/17 06:13:13 | 000,015,670 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2012/03/17 06:13:13 | 000,013,280 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2012/03/17 06:13:13 | 000,010,673 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2012/03/17 06:13:13 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2012/03/17 06:13:13 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2012/03/17 06:13:13 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2012/03/17 06:13:13 | 000,001,137 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2012/03/17 06:13:13 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2012/03/17 06:13:13 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2012/03/17 06:13:13 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2012/03/17 06:11:18 | 000,000,079 | ---- | C] () -- C:\Windows\EPWF600.ini
[2012/02/09 21:05:44 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/07/30 02:17:48 | 000,007,168 | ---- | C] () -- C:\Users\Carol P\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/29 22:27:58 | 000,000,815 | ---- | C] () -- C:\Windows\wininit.ini
[2011/07/19 14:22:34 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2011/07/19 14:21:51 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2011/07/19 14:20:41 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011/07/15 17:18:19 | 000,000,016 | ---- | C] () -- C:\Windows\popcinfo.dat
[2011/07/13 05:09:38 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011/07/13 01:58:11 | 000,000,680 | ---- | C] () -- C:\Users\Carol P\AppData\Local\d3d9caps.dat
[2011/07/13 01:36:42 | 000,722,496 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/12 23:04:25 | 000,000,732 | ---- | C] () -- C:\Users\Carol P\AppData\Local\d3d9caps64.dat
[2011/05/24 23:44:26 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/04/27 11:21:38 | 003,268,096 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2011/04/27 00:08:34 | 000,073,216 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/03/15 05:31:48 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2008/08/21 01:52:02 | 003,107,788 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.dat
[2008/08/21 01:40:53 | 000,581,120 | ---- | C] () -- C:\Windows\mHotkey.exe
[2008/08/21 01:40:53 | 000,294,912 | ---- | C] () -- C:\Windows\PIC.dll
[2008/08/21 01:40:53 | 000,036,864 | ---- | C] () -- C:\Windows\LchDrvKey.exe
[2008/08/21 01:40:53 | 000,000,870 | ---- | C] () -- C:\Windows\mhotkey_reg.ini
[2008/08/21 01:33:48 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2008/01/20 22:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007/02/05 20:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006/11/02 11:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 11:02:31 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll
[2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
========== LOP Check ==========
[2012/07/08 19:26:27 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\DriverCure
[2012/03/23 22:33:01 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\Epson
[2011/12/29 09:03:46 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\FlixsterCollections
[2012/01/28 11:26:41 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\Foxit Software
[2011/10/10 07:52:45 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\GiftBoxPlus
[2012/07/07 03:19:03 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\GoodSync
[2011/08/06 16:28:43 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\LaunchPad
[2012/03/23 15:35:05 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\Leadertech
[2012/03/25 08:05:57 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\LibreOffice
[2012/07/07 17:50:39 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\mjusbsp
[2011/08/10 10:12:20 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\RoboForm
[2012/07/08 19:26:26 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\SpeedyPC Software
[2012/07/08 20:02:30 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\TestApp
[2011/07/30 02:34:04 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\VistaCodecs
[2012/03/08 08:34:05 | 000,000,000 | ---D | M] -- C:\Users\Carol P\AppData\Roaming\Windows Live Writer
[2011/07/13 02:45:26 | 000,000,000 | ---D | M] -- C:\ProgramData\AMD
[2011/07/12 23:05:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Application Data
[2006/11/02 11:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 11:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2012/03/23 21:39:10 | 000,000,000 | ---D | M] -- C:\ProgramData\EPSON
[2006/11/02 11:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011/08/12 10:26:36 | 000,000,000 | ---D | M] -- C:\ProgramData\GoodSync
[2011/07/13 00:51:53 | 000,000,000 | ---D | M] -- C:\ProgramData\magicJack
[2011/07/13 10:06:25 | 000,000,000 | ---D | M] -- C:\ProgramData\Napster
[2011/07/12 23:38:56 | 000,000,000 | ---D | M] -- C:\ProgramData\RoboForm
[2012/07/08 19:26:12 | 000,000,000 | ---D | M] -- C:\ProgramData\SpeedyPC Software
[2006/11/02 11:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/08/17 14:14:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Tarma Installer
[2012/07/08 20:28:57 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2006/11/02 11:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012/03/29 08:27:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Viper
[2012/05/08 18:04:40 | 000,000,000 | ---D | M] -- C:\ProgramData\VistaCodecs
[2008/08/21 01:55:57 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent
[2011/10/25 05:08:37 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch
[2008/08/21 02:09:28 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2012/05/08 05:16:28 | 000,000,284 | ---- | M] () -- C:\Windows\Tasks\GoodSync - RoboForm Online.job
[2012/07/10 09:47:41 | 000,032,644 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/07/08 19:42:03 | 000,000,424 | ---- | M] () -- C:\Windows\Tasks\SpeedyPC Pro.job
[2012/07/08 19:42:03 | 000,000,496 | ---- | M] () -- C:\Windows\Tasks\SpeedyPC Registration3.job
[2012/07/08 19:42:03 | 000,000,468 | ---- | M] () -- C:\Windows\Tasks\SpeedyPC Update Version3.job
[2012/06/30 14:59:59 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\TuneUpMedic_scan_schedule_task_0b376ef0-5ff1-4233-ac54-6209f2b73b3e.job
========== Purity Check ==========
========== Custom Scans ==========
Invalid Environment Variable: %AppData%\Roaming\Mozilla\Firefox\Profiles\*.default\extensions\
Invalid Environment Variable: %AppData%\Local\
< %systemroot%\system32\sysprep >
< *.xpi /md5 >
< %systemroot%\Downloaded Program Files\ >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile >
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: firefox.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: firefox.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\system32\ie4uinit.exe" -hide [2012/05/14 23:25:37 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\system32\ie4uinit.exe" -show [2012/05/14 23:25:37 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\system32\ie4uinit.exe" -reinstall [2012/05/14 23:25:37 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2012/05/15 02:37:18 | 000,638,048 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: iexplore.exe
< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: FIREFOX.EXE
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: FIREFOX.EXE
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2012/05/14 20:40:10 | 000,070,656 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2012/05/14 20:40:10 | 000,070,656 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2012/05/14 20:40:10 | 000,070,656 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2012/05/15 02:37:18 | 000,638,048 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: IEXPLORE.EXE
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\drivers\*.sys /90 >
[2012/04/23 12:36:50 | 000,426,616 | ---- | M] (PC Tools) -- C:\Windows\system32\drivers\PCTCore64.sys
[2012/05/11 11:14:26 | 000,251,528 | ---- | M] (PC Tools) -- C:\Windows\system32\drivers\PCTSD64.sys
[2012/05/01 10:29:44 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\rdpwd.sys
< %systemroot%\System32\config\*.sav >
[2008/01/21 00:14:16 | 026,247,168 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 00:13:53 | 000,110,592 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 00:14:16 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 08:50:51 | 019,435,520 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 08:50:51 | 001,806,336 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %SYSTEMDRIVE%\*.exe /md5 >
Invalid Environment Variable: %WinDir%\$NtUninstallKB*$. /30
< %systemdrive%\Program Files\Common Files\ComObjects\*.* /s >
< %systemroot%\*. /mp /s >
< %systemroot%\*. /rp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
Invalid Environment Variable: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\*.*
Invalid Environment Variable: %USERPROFILE%\AppData\Local\
< %systemroot%\Installer\ /s >
< %systemroot%\system32\Cache\ /s >
< %systemroot%\system32\config\systemprofile\Application Data /s >
< %PROGRAMFILES%\*. >
[2008/08/21 01:26:50 | 000,000,000 | ---D | M] -- C:\Program Files\ATI
[2011/07/13 02:45:32 | 000,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2011/07/13 06:40:40 | 000,000,000 | ---D | M] -- C:\Program Files\BigFix
[2012/06/26 05:28:54 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2011/07/13 00:02:37 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2011/07/13 02:57:19 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2011/07/12 22:48:27 | 000,000,000 | ---D | M] -- C:\Program Files\Dolby
[2011/07/12 23:05:16 | 000,000,000 | ---D | M] -- C:\Program Files\eBay
[2011/07/13 01:39:17 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2012/03/26 18:44:19 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2012/06/13 04:14:29 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2011/12/23 00:06:11 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2011/10/28 13:40:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Fix it Center
[2011/07/19 14:45:43 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2012/06/12 18:08:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2012/07/07 14:52:31 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Security Client
[2011/07/19 14:47:33 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2006/11/02 11:07:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2012/02/21 13:57:48 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2006/11/02 11:07:26 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2012/05/08 05:10:38 | 000,000,000 | ---D | M] -- C:\Program Files\Siber Systems
[2012/07/08 15:53:39 | 000,000,000 | ---D | M] -- C:\Program Files\SUPERAntiSpyware
[2006/11/02 11:44:54 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2008/01/20 23:09:40 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Calendar
[2011/07/19 14:47:26 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2012/05/09 05:33:16 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Journal
[2011/09/23 10:59:54 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2012/04/11 03:27:28 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2011/07/19 14:47:32 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2006/11/02 11:07:26 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2011/07/19 14:47:28 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Photo Gallery
[2011/07/21 03:23:08 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Portable Devices
[2011/07/19 14:47:33 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar
Invalid Environment Variable: %appdata%\*.*
< MD5 for: AFD.SYS >
[2012/01/03 10:21:38 | 000,404,992 | ---- | M] (Microsoft Corporation) MD5=022ED7EB19DFECF39C106E0F9CF2BB19 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.22770_none_362b4e6b2d472f6a\afd.sys
[2011/04/21 10:20:24 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=0CC146C4ADDEA45791B18B1E2659F4A9 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18457_none_35be4fb214130ed1\afd.sys
[2009/04/11 01:44:24 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=12415CCFD3E7CEC55B5184E67B039FE4 -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_35f2572213ec5bd2\afd.sys
[2009/04/10 22:44:26 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=12415CCFD3E7CEC55B5184E67B039FE4 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_35f2572213ec5bd2\afd.sys
[2011/04/21 09:54:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=7B8E5F3A0626CA83B706F0738830845F -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.22629_none_366a5ebb2d168a9d\afd.sys
[2011/04/21 09:42:48 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=9BB97042FA331A0FB4BDD98B9280A50A -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6001.18639_none_33ef7c5016dab752\afd.sys
[2011/04/21 09:47:41 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=B53144D2EBB0843DD0436F5EA6953F65 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6001.22905_none_34958b832fe3983b\afd.sys
[2012/01/03 10:25:21 | 000,404,992 | ---- | M] (Microsoft Corporation) MD5=C4F6CE6087760AD70960C9EB130E7943 -- C:\Windows\System32\drivers\afd.sys
[2012/01/03 10:25:21 | 000,404,992 | ---- | M] (Microsoft Corporation) MD5=C4F6CE6087760AD70960C9EB130E7943 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18564_none_35b080ce141ddbe4\afd.sys
[2008/01/20 22:48:18 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=DB37041AB857ABC7E179E856D8E1582C -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6001.18000_none_3406de1616ca9086\afd.sys
< MD5 for: ATAPI.SYS >
[2008/01/20 22:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_1d87dda2\atapi.sys
[2008/01/20 22:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008/02/22 01:29:46 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=2297D8A0E2F3E1BA55E1538BA33B9E86 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22120_none_39cac090f315177e\atapi.sys
[2008/02/22 01:30:43 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=62BD869AFA2BF2E30F9D3FF428C87D5C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_83e39703\atapi.sys
[2008/02/22 01:30:43 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=62BD869AFA2BF2E30F9D3FF428C87D5C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18023_none_394424a3d9f4c3b9\atapi.sys
[2006/11/02 08:01:02 | 000,020,072 | ---- | M] (Microsoft Corporation) MD5=DF96CF8885724430024B7522E5C95722 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_f8cccc79\atapi.sys
[2009/04/11 03:15:00 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
[2009/04/11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b6d20d6f\atapi.sys
[2009/04/11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2008/10/29 02:15:50 | 003,087,360 | ---- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2011/09/14 10:05:26 | 001,008,092 | ---- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB -- C:\Documents and Settings\Carol P\Desktop\RKill\eXplorer.exe
[2011/09/14 10:05:26 | 001,008,092 | ---- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB -- C:\Users\Carol P\Desktop\RKill\eXplorer.exe
[2009/04/11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2009/04/11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2008/10/27 22:30:12 | 003,086,848 | ---- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2008/10/29 02:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SysWOW64\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2008/10/30 01:30:07 | 003,081,216 | ---- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/20 22:48:44 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008/01/20 22:49:23 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe
< MD5 for: SERVICES.EXE >
[2008/01/20 22:50:34 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 03:10:50 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2009/04/11 00:10:52 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2012/07/09 18:42:09 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=BC81150939BD52DBC7A08C245F1FB229 -- C:\Windows\System32\services.exe
[2009/04/11 02:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009/04/10 23:28:00 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\SysWOW64\services.exe
[2009/04/10 23:28:00 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2008/01/20 22:49:44 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=DFAC660F0F139276CC9299812DE42719 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe
< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\SysWOW64\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D -- C:\Windows\System32\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe
< MD5 for: TCPIP.SYS >
[2010/06/16 13:14:29 | 001,424,264 | ---- | M] (Microsoft Corporation) MD5=0011810B5211FDACD784DE585262ECFE -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_119c298735134c99\tcpip.sys
[2010/04/06 04:35:06 | 001,423,752 | ---- | M] (Microsoft Corporation) MD5=150C1A66A7094F84560519261A309BC6 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22377_none_11681899353a0dd5\tcpip.sys
[2011/06/17 16:14:30 | 001,424,272 | ---- | M] (Microsoft Corporation) MD5=19A7321E3A5F1DDB215D2815DCC8F8E4 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22662_none_116decc535366aa6\tcpip.sys
[2011/09/20 17:06:18 | 001,426,304 | ---- | M] (Microsoft Corporation) MD5=2CC45D932BD193CD4117321D469AD6B2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18519_none_1121619c1be9f088\tcpip.sys
[2010/02/18 11:01:57 | 001,420,688 | ---- | M] (Microsoft Corporation) MD5=30C4ABC8075DEA44D7E775D434AF1753 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_0f2e179c1ecd900b\tcpip.sys
[2009/08/14 10:44:27 | 001,200,640 | ---- | M] (Microsoft Corporation) MD5=34B30202AECCB530FDDC6C6CCFA2FB46 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_bbc5fabc4a894d2a\tcpip.sys
[2010/02/18 08:25:21 | 001,200,640 | ---- | M] (Microsoft Corporation) MD5=396CF3FD8D2A4FDF55570C01894DB9DF -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.17021_none_bba931004aa006ed\tcpip.sys
[2009/08/14 14:05:16 | 001,418,840 | ---- | M] (Microsoft Corporation) MD5=3BCD46BE9988B09D3510A0EF54F0D65B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_0f32e3e61ecadee9\tcpip.sys
[2010/02/18 11:04:06 | 001,414,032 | ---- | M] (Microsoft Corporation) MD5=4680D08A2E8A2509CD9B751D7AF59606 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_0fabe61737f42f96\tcpip.sys
[2012/03/30 08:45:03 | 001,423,744 | ---- | M] (Microsoft Corporation) MD5=46D448E9117464E4D3BBF36D7E3FA48E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18604_none_112731fc1be6530b\tcpip.sys
[2010/02/18 10:22:15 | 001,423,752 | ---- | M] (Microsoft Corporation) MD5=4AD4600DF1F09EE7462152C061B683C8 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22341_none_118286a1352721f8\tcpip.sys
[2011/06/17 16:14:30 | 001,427,344 | ---- | M] (Microsoft Corporation) MD5=4DAD14118FBCF7C609F2A4CE21FBCC5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18484_none_10d0aed01c273845\tcpip.sys
[2011/09/20 17:06:18 | 001,423,744 | ---- | M] (Microsoft Corporation) MD5=73BED5067ED53A9DF05FA8EAB42578D0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_11ab004d35078d79\tcpip.sys
[2009/08/14 12:42:31 | 001,413,208 | ---- | M] (Microsoft Corporation) MD5=74B776CA1B328095FE23A3306B1613A3 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_0f6c030d3823f645\tcpip.sys
[2008/01/20 22:51:16 | 001,421,368 | ---- | M] (Microsoft Corporation) MD5=7A1183FBB802F5ABAD7FA18BC67E0858 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_0f3cadd61ec3b22c\tcpip.sys
[2010/02/18 08:27:40 | 001,198,080 | ---- | M] (Microsoft Corporation) MD5=7B0B928E318CADC23C87226BE0A1097D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21226_none_bc37d12363b92291\tcpip.sys
[2010/06/16 12:40:37 | 001,420,176 | ---- | M] (Microsoft Corporation) MD5=7D86275FB640011B372FD566C0EAFA8D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_0ede67001f09ee46\tcpip.sys
[2008/04/26 04:55:25 | 001,421,368 | ---- | M] (Microsoft Corporation) MD5=8E041924441FF8755E5B4F135C8C3767 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_0efecf2c1ef1a5d7\tcpip.sys
[2010/04/05 13:13:35 | 001,414,024 | ---- | M] (Microsoft Corporation) MD5=8E7CD6BA2F09B46CE72D308F166C0B12 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22665_none_0f8a7609380d6a12\tcpip.sys
[2010/06/16 13:11:35 | 001,426,816 | ---- | M] (Microsoft Corporation) MD5=973658A2EA9C06B2976884B9046DFC6C -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_10d97a5c1c20ef58\tcpip.sys
[2009/04/11 03:15:48 | 001,426,408 | ---- | M] (Microsoft Corporation) MD5=99D07AD0EF2C535610F6573C29BC045E -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_112826e21be57d78\tcpip.sys
[2009/04/11 00:15:50 | 001,426,408 | ---- | M] (Microsoft Corporation) MD5=99D07AD0EF2C535610F6573C29BC045E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_112826e21be57d78\tcpip.sys
[2009/08/14 12:39:38 | 001,425,992 | ---- | M] (Microsoft Corporation) MD5=A7BFF59C2F610F62E6C292074FF36A1E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_10c2d66e1c321395\tcpip.sys
[2012/03/30 08:45:03 | 001,422,720 | ---- | M] (Microsoft Corporation) MD5=AC8D5728E6AD6A7C4819D9A67008337A -- C:\Windows\System32\drivers\tcpip.sys
[2012/03/30 08:45:03 | 001,422,720 | ---- | M] (Microsoft Corporation) MD5=AC8D5728E6AD6A7C4819D9A67008337A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22828_none_119f31fd35108d3a\tcpip.sys
[2010/02/18 10:28:06 | 001,427,336 | ---- | M] (Microsoft Corporation) MD5=B4B7B375FDD672AF79B0CBE9B9A48B47 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18209_none_112c2bd61be1dd22\tcpip.sys
[2010/06/16 19:28:33 | 001,414,544 | ---- | M] (Microsoft Corporation) MD5=D43D5336BE9DD93E02EE124297295713 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_0fbe86f737e6a8d6\tcpip.sys
[2009/08/14 12:32:21 | 001,424,952 | ---- | M] (Microsoft Corporation) MD5=D45D67A18C9FD4CC637BC9D4585C0646 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_11acc42135079bb6\tcpip.sys
[2009/08/15 18:55:23 | 001,196,032 | ---- | M] (Microsoft Corporation) MD5=D4E30E6BADFF21865C3A075457CF9C00 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_bc4f6fa963a72036\tcpip.sys
[2008/04/26 04:47:15 | 001,421,368 | ---- | M] (Microsoft Corporation) MD5=F10A60005FB50698E33A1940C6EBB010 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_0f8c6d1f380baafd\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008/01/20 22:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2011/09/14 10:06:16 | 001,008,092 | ---- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB -- C:\Documents and Settings\Carol P\Desktop\RKill\uSeRiNiT.exe
[2011/09/14 10:06:16 | 001,008,092 | ---- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB -- C:\Users\Carol P\Desktop\RKill\uSeRiNiT.exe
[2008/01/20 22:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\System32\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
< MD5 for: VOLSNAP.SYS >
[2009/04/11 03:15:45 | 000,269,288 | ---- | M] (Microsoft Corporation) MD5=5280AADA24AB36B01A84A6424C475C8D -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_volume.inf_31bf3856ad364e35_6.0.6002.18005_none_73c0cc10b194374f\volsnap.sys
[2009/04/11 00:15:46 | 000,269,288 | ---- | M] (Microsoft Corporation) MD5=5280AADA24AB36B01A84A6424C475C8D -- C:\Windows\System32\drivers\volsnap.sys
[2009/04/11 00:15:46 | 000,269,288 | ---- | M] (Microsoft Corporation) MD5=5280AADA24AB36B01A84A6424C475C8D -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_d5525b4d\volsnap.sys
[2009/04/11 00:15:46 | 000,269,288 | ---- | M] (Microsoft Corporation) MD5=5280AADA24AB36B01A84A6424C475C8D -- C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.0.6002.18005_none_73c0cc10b194374f\volsnap.sys
[2006/11/02 07:51:39 | 000,247,912 | ---- | M] (Microsoft Corporation) MD5=D4674E125878F77EED0D87E6C46889AA -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_c52a9a32\volsnap.sys
[2008/01/20 22:47:03 | 000,271,416 | ---- | M] (Microsoft Corporation) MD5=DE4307412D98050239026E56A7DFF3C0 -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_47e59f7b\volsnap.sys
[2008/01/20 22:47:03 | 000,271,416 | ---- | M] (Microsoft Corporation) MD5=DE4307412D98050239026E56A7DFF3C0 -- C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.0.6001.18000_none_71d55304b4726c03\volsnap.sys
< MD5 for: WININIT.EXE >
[2008/01/20 22:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008/01/20 22:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008/01/20 22:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\System32\wininit.exe
[2008/01/20 22:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2011/09/14 10:06:26 | 001,008,092 | ---- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB -- C:\Documents and Settings\Carol P\Desktop\RKill\WiNlOgOn.exe
[2011/09/14 10:06:26 | 001,008,092 | ---- | M] () MD5=645A8F39A10306D50382EB49A6C49AAB -- C:\Users\Carol P\Desktop\RKill\WiNlOgOn.exe
[2009/04/11 03:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2009/04/11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\System32\winlogon.exe
[2009/04/11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SoftwareDistribution\Download\fce438afafdfd7622141fad99a8dd451\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:50:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP

FC5A2B2
< End of report >