NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.jbg711 - C:\Windows\System32\G711Coder.acm (soft.netnest.com.cn)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.H264 - C:\Windows\System32\jbh264vfw.dll ()
Drivers32: vidc.H265 - C:\Windows\System32\jbh264vfw.dll ()
Drivers32: vidc.imm4 - C:\Windows\System32\vcmimm4.dll ()
Drivers32: vidc.imm5 - C:\Windows\System32\vcmimm5.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\DivX.dll (DivXNetworks, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/13 23:52:02 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Nesys\Desktop\OTL.exe
[2012/06/13 16:53:06 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/13 11:22:56 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/13 11:22:56 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/13 11:22:56 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/13 11:17:49 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/06/13 11:17:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/13 11:13:27 | 004,557,191 | R--- | C] (Swearware) -- C:\Users\Nesys\Desktop\ComboFix.exe
[2012/06/13 08:20:22 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/06/12 17:01:45 | 000,000,000 | ---D | C] -- C:\Users\Nesys\Desktop\bootkit_remover
[2012/06/12 16:39:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/12 16:39:36 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/06/12 16:39:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/12 11:43:45 | 000,000,000 | ---D | C] -- C:\ProgramData\BDLogging
[2012/06/12 11:43:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2012
[2012/06/12 11:43:01 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Bitdefender
[2012/06/12 11:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Bitdefender
[2012/06/12 11:28:51 | 000,360,976 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\bdfsfltr.sys
[2012/06/12 11:28:47 | 000,340,624 | ---- | C] (BitDefender S.R.L.) -- C:\Windows\System32\drivers\trufos.sys
[2012/06/12 11:18:03 | 000,000,000 | ---D | C] -- C:\Program Files\Bitdefender
[2012/06/12 10:54:37 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\QuickScan
[2012/06/12 10:51:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bitdefender
[2012/06/11 22:04:12 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Local\Zello
[2012/06/11 22:03:27 | 000,000,000 | ---D | C] -- C:\Program Files\Zello
[2012/06/09 15:55:21 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
[2012/06/09 15:55:20 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012/06/09 15:55:20 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/06/09 15:20:18 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012/06/07 21:39:57 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Local\Loudtalks
[2012/06/07 21:39:50 | 000,000,000 | ---D | C] -- C:\Program Files\Loudtalks Lite
[2012/06/03 10:02:02 | 000,000,000 | ---D | C] -- C:\Users\Nesys\Desktop\Newest Folder
[2012/06/02 21:54:22 | 000,000,000 | ---D | C] -- C:\Users\Nesys\Documents\FIFA 10
[2012/06/02 21:53:03 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Leadertech
[2012/06/02 21:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\EA Sports
[2012/06/02 21:42:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012/06/02 21:41:44 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012/06/02 21:41:42 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\DAEMON Tools Lite
[2012/06/02 21:41:33 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\OpenCandy
[2012/06/02 21:41:33 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2012/06/02 21:40:21 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012/06/02 21:39:57 | 014,229,744 | ---- | C] (DT Soft Ltd) -- C:\Users\Nesys\Desktop\DTLite4454-0315.exe
[2012/06/02 21:35:27 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicDisc
[2012/06/02 21:35:25 | 000,116,736 | ---- | C] (MagicISO, Inc.) -- C:\Windows\System32\drivers\mcdbus.sys
[2012/06/02 21:35:24 | 000,000,000 | ---D | C] -- C:\Program Files\MagicDisc
[2012/06/02 21:32:11 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/05/31 10:41:18 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends
[2012/05/31 10:24:50 | 000,000,000 | ---D | C] -- C:\xampp
[2012/05/25 00:00:10 | 000,000,000 | ---D | C] -- C:\ThunderboltTempRoot
[2012/05/24 23:55:06 | 000,000,000 | ---D | C] -- C:\Thunderbolt
[2012/05/24 23:39:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC
[2012/05/24 23:38:55 | 000,000,000 | ---D | C] -- C:\Program Files\Spirent Communications
[2012/05/24 23:38:05 | 000,000,000 | ---D | C] -- C:\Program Files\HTC
[2012/05/24 13:10:48 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Local\join.me
[2012/05/23 12:22:35 | 000,000,000 | ---D | C] -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nationwide DVR
[2012/05/23 12:22:34 | 000,000,000 | ---D | C] -- C:\networkdvr
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/13 23:52:02 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Nesys\Desktop\OTL.exe
[2012/06/13 23:28:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1006101457-4197215139-1718751079-1000UA.job
[2012/06/13 23:02:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/13 22:07:25 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/13 22:07:25 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/13 21:59:35 | 000,000,385 | ---- | M] () -- C:\Windows\System32\user_gensett.xml
[2012/06/13 21:57:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/13 21:57:48 | 2616,598,528 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/13 12:28:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1006101457-4197215139-1718751079-1000Core.job
[2012/06/13 11:47:26 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/06/13 11:13:49 | 004,557,191 | R--- | M] (Swearware) -- C:\Users\Nesys\Desktop\ComboFix.exe
[2012/06/13 08:19:06 | 000,000,995 | ---- | M] () -- C:\Users\Nesys\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/06/12 16:39:37 | 000,001,031 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/12 11:43:19 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_avchv_01009.Wdf
[2012/06/12 11:43:03 | 000,002,056 | ---- | M] () -- C:\Users\Public\Desktop\Bitdefender Internet Security 2012.lnk
[2012/06/12 10:47:52 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012/06/12 09:43:20 | 000,042,702 | ---- | M] () -- C:\Windows\capture.ini
[2012/06/12 09:43:20 | 000,038,857 | ---- | M] () -- C:\Windows\mapping.ini
[2012/06/12 09:40:34 | 000,134,519 | ---- | M] () -- C:\Windows\addrbook.ini
[2012/06/11 22:03:27 | 000,000,893 | ---- | M] () -- C:\Users\Public\Desktop\Zello.lnk
[2012/06/09 20:14:02 | 000,000,913 | ---- | M] () -- C:\Users\Nesys\Desktop\SopCast.lnk
[2012/06/09 17:40:13 | 000,692,378 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/09 17:40:13 | 000,129,540 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/02 21:42:43 | 000,001,860 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012/06/02 21:41:44 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012/06/02 21:40:14 | 014,229,744 | ---- | M] (DT Soft Ltd) -- C:\Users\Nesys\Desktop\DTLite4454-0315.exe
[2012/06/02 21:35:27 | 000,000,923 | ---- | M] () -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2012/06/02 21:35:27 | 000,000,887 | ---- | M] () -- C:\Users\Nesys\Desktop\MagicDisc.lnk
[2012/05/31 10:41:18 | 000,000,606 | ---- | M] () -- C:\Users\Nesys\Desktop\XAMPP Control Panel.lnk
[2012/05/24 23:42:26 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/05/24 21:51:56 | 000,251,558 | ---- | M] () -- C:\Users\Nesys\Desktop\Credit report screen.jpg
[2012/05/24 13:10:50 | 000,000,968 | ---- | M] () -- C:\Users\Nesys\Desktop\join.me.lnk
[2012/05/23 12:22:42 | 000,045,056 | ---- | M] () -- C:\Windows\System32\uninst.exe
[2012/05/23 12:22:42 | 000,000,595 | ---- | M] () -- C:\Windows\dvr2.ini
[2012/05/23 12:22:38 | 000,001,454 | ---- | M] () -- C:\Users\Nesys\Desktop\Nationwide DVR Client.lnk
[2012/05/21 17:38:22 | 000,083,360 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIRfsClientNP.dll
[2012/05/21 17:38:21 | 000,087,424 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIinit.dll
[2012/05/21 17:38:21 | 000,030,592 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIport.dll
[2012/05/19 01:21:21 | 757,367,495 | ---- | M] () -- C:\VS920ZV3_02.S3_02.P58012.R5.cab
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/13 21:59:35 | 000,000,385 | ---- | C] () -- C:\Windows\System32\user_gensett.xml
[2012/06/13 11:22:56 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/13 11:22:56 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/13 11:22:56 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/13 11:22:56 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/13 11:22:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/13 08:19:06 | 000,000,995 | ---- | C] () -- C:\Users\Nesys\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/06/12 16:39:37 | 000,001,031 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/12 11:43:19 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_avchv_01009.Wdf
[2012/06/12 11:43:03 | 000,002,056 | ---- | C] () -- C:\Users\Public\Desktop\Bitdefender Internet Security 2012.lnk
[2012/06/11 22:03:27 | 000,001,759 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zello.lnk
[2012/06/11 22:03:27 | 000,000,893 | ---- | C] () -- C:\Users\Public\Desktop\Zello.lnk
[2012/06/02 21:42:43 | 000,001,860 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012/06/02 21:35:27 | 000,000,923 | ---- | C] () -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2012/06/02 21:35:27 | 000,000,887 | ---- | C] () -- C:\Users\Nesys\Desktop\MagicDisc.lnk
[2012/05/31 10:41:18 | 000,000,606 | ---- | C] () -- C:\Users\Nesys\Desktop\XAMPP Control Panel.lnk
[2012/05/24 23:42:26 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/05/24 21:51:52 | 000,251,558 | ---- | C] () -- C:\Users\Nesys\Desktop\Credit report screen.jpg
[2012/05/24 13:10:50 | 000,000,976 | ---- | C] () -- C:\Users\Nesys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk
[2012/05/24 13:10:50 | 000,000,968 | ---- | C] () -- C:\Users\Nesys\Desktop\join.me.lnk
[2012/05/23 12:04:56 | 000,001,454 | ---- | C] () -- C:\Users\Nesys\Desktop\Nationwide DVR Client.lnk
[2012/05/19 01:09:15 | 757,367,495 | ---- | C] () -- C:\VS920ZV3_02.S3_02.P58012.R5.cab
[2012/05/04 15:57:57 | 000,113,768 | ---- | C] () -- C:\Windows\WiaInst.exe
[2012/05/04 15:38:35 | 000,010,820 | ---- | C] () -- C:\Users\Nesys\AppData\Roaming\SmarThruOptions.xml
[2012/05/04 15:38:25 | 000,172,032 | ---- | C] () -- C:\Windows\System32\SecSNMP.dll
[2012/05/04 15:38:20 | 000,000,124 | ---- | C] () -- C:\Windows\Readiris.ini
[2012/05/04 15:38:08 | 000,023,040 | ---- | C] () -- C:\Windows\System32\irisco32.dll
[2012/04/26 23:59:55 | 000,036,864 | ---- | C] () -- C:\Windows\System32\jbh264vfw.dll
[2012/04/26 23:59:55 | 000,022,016 | ---- | C] () -- C:\Windows\System32\Russian.dll
[2012/04/26 23:59:52 | 000,536,576 | ---- | C] () -- C:\Windows\System32\JBNVSDK.dll
[2012/04/26 23:59:52 | 000,046,080 | ---- | C] () -- C:\Windows\System32\hi_mjpeg_dec_w.dll
[2012/02/14 12:04:50 | 000,024,576 | ---- | C] () -- C:\Windows\System32\MegaShareMemInterface.dll
[2012/02/14 12:04:49 | 001,089,536 | ---- | C] () -- C:\Windows\System32\decoderdll.dll
[2012/02/14 12:04:48 | 000,036,864 | ---- | C] () -- C:\Windows\System32\netdecdll.dll
[2012/02/14 12:04:48 | 000,024,576 | ---- | C] () -- C:\Windows\System32\decompress.dll
[2012/02/14 12:04:45 | 000,019,968 | ---- | C] () -- C:\Windows\System32\Cpuinf32.dll
[2012/02/14 12:04:40 | 000,000,229 | ---- | C] () -- C:\Windows\AngelCam.dat
[2012/01/16 19:00:00 | 000,000,537 | ---- | C] () -- C:\Windows\xxclone.ini
[2011/12/16 19:03:38 | 000,023,040 | ---- | C] () -- C:\Windows\System32\Spanish.dll
[2011/12/16 19:03:36 | 000,023,040 | ---- | C] () -- C:\Windows\System32\Portuguese.dll
[2011/09/20 16:04:05 | 001,970,176 | ---- | C] () -- C:\Windows\System32\vcmimm4.dll
[2011/09/20 16:04:05 | 001,572,864 | ---- | C] () -- C:\Windows\System32\vcmimm5.dll
[2011/09/20 16:04:05 | 000,685,913 | ---- | C] () -- C:\Windows\unins000.exe
[2011/09/20 16:04:05 | 000,000,829 | ---- | C] () -- C:\Windows\unins000.dat
[2011/09/15 12:39:51 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2011/08/08 13:43:54 | 000,129,536 | ---- | C] () -- C:\Windows\System32\np_hoem_x.dll
[2011/07/05 12:42:59 | 000,000,151 | ---- | C] () -- C:\Windows\Wininit.INI
[2011/06/27 15:30:54 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/06/27 15:29:47 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/06/17 15:03:04 | 000,241,731 | ---- | C] () -- C:\Windows\System32\StillImgLib.dll
[2011/06/17 15:03:04 | 000,094,208 | ---- | C] () -- C:\Windows\System32\ilgcl.dll
[2011/06/17 15:03:04 | 000,000,644 | ---- | C] () -- C:\Windows\System32\ax_japanese.ini
[2011/06/17 15:03:04 | 000,000,591 | ---- | C] () -- C:\Windows\System32\ax_english.ini
[2011/06/17 12:17:02 | 000,000,193 | ---- | C] () -- C:\ProgramData\RmUserCfg.ini
[2011/06/17 12:17:02 | 000,000,000 | ---- | C] () -- C:\ProgramData\IpAndPort.fig
[2011/05/28 11:20:51 | 000,111,744 | ---- | C] () -- C:\Windows\System32\AFCtl.exe
[2011/05/17 14:44:48 | 000,000,152 | ---- | C] () -- C:\Windows\NView09.dat
[2011/05/11 03:54:12 | 000,104,408 | ---- | C] () -- C:\Windows\System32\MaCommAPI.dll
[2011/05/11 03:53:34 | 000,047,064 | ---- | C] () -- C:\Windows\System32\MaMakeUp.dll
[2011/04/29 11:24:58 | 003,822,956 | -H-- | C] () -- C:\Windows\System32\IRAS.sys
[2011/04/03 14:05:12 | 000,013,931 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
[2011/03/11 12:31:14 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2011/03/10 11:42:00 | 000,066,452 | ---- | C] () -- C:\Windows\ptz.ini
[2011/03/10 11:21:33 | 000,053,120 | ---- | C] () -- C:\Windows\System32\drivers\Cap05.sys
[2011/03/10 11:21:33 | 000,042,880 | ---- | C] () -- C:\Windows\System32\drivers\Cap04.sys
[2011/03/10 11:21:33 | 000,041,472 | ---- | C] () -- C:\Windows\System32\drivers\Cap01.sys
[2011/03/10 11:21:33 | 000,036,608 | ---- | C] () -- C:\Windows\System32\drivers\Cap03.sys
[2011/03/10 11:21:33 | 000,009,216 | ---- | C] () -- C:\Windows\System32\drivers\Cap02.sys
[2011/03/09 23:13:26 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/03/09 23:13:26 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/03/02 16:03:58 | 000,000,019 | ---- | C] () -- C:\Windows\UMSMC.INI
[2011/03/01 10:36:48 | 000,000,160 | ---- | C] () -- C:\Windows\tsearch.ini
[2011/01/26 14:16:44 | 000,151,552 | ---- | C] () -- C:\Windows\System32\utf8_2_font.dll
[2011/01/18 14:36:40 | 000,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2011/01/11 18:05:18 | 000,008,592 | ---- | C] () -- C:\Windows\System32\ractrlkeyhook.dll
[2010/10/28 16:07:12 | 000,212,992 | ---- | C] () -- C:\Windows\System32\MyAVCD.dll
[2010/10/28 16:00:56 | 000,512,000 | ---- | C] () -- C:\Windows\System32\ndmpeg4v.dll
[2010/10/17 00:44:57 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/10/07 12:17:37 | 000,036,864 | ---- | C] () -- C:\Windows\System32\SvcMan.exe
[2010/10/05 10:33:34 | 000,015,873 | ---- | C] () -- C:\Windows\CMSdata.ini
[2010/10/05 10:33:34 | 000,000,000 | ---- | C] () -- C:\Windows\event.ini
[2010/09/25 16:09:11 | 000,042,702 | ---- | C] () -- C:\Windows\capture.ini
[2010/09/25 16:09:11 | 000,038,857 | ---- | C] () -- C:\Windows\mapping.ini
[2010/09/25 16:08:20 | 000,134,519 | ---- | C] () -- C:\Windows\addrbook.ini
[2010/09/25 16:07:29 | 000,045,056 | ---- | C] () -- C:\Windows\System32\uninst.exe
[2010/09/25 16:07:28 | 000,000,595 | ---- | C] () -- C:\Windows\dvr2.ini
[2010/09/25 10:57:30 | 000,000,600 | ---- | C] () -- C:\Users\Nesys\AppData\Local\PUTTY.RND
[2010/09/22 23:26:36 | 000,000,040 | ---- | C] () -- C:\Windows\Hjimesv.ini
[2010/09/22 23:22:07 | 000,000,016 | ---- | C] () -- C:\Windows\System32\winhcfga.ini
[2010/09/20 21:08:11 | 000,000,095 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2010/09/20 21:03:50 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2010/08/23 14:36:46 | 000,221,184 | ---- | C] () -- C:\Windows\System32\AVC_AX_742_H264.dll
[2010/08/23 14:33:12 | 000,049,152 | ---- | C] () -- C:\Windows\System32\AVC_AX_742_SCALE.dll
[2010/08/23 14:28:12 | 000,086,016 | ---- | C] () -- C:\Windows\System32\AVC_AX_742_JPEG.dll
[2010/06/17 18:07:24 | 000,159,251 | ---- | C] () -- C:\Windows\System32\swscale-0.11.0.dll
[2010/06/17 18:07:24 | 000,070,163 | ---- | C] () -- C:\Windows\System32\avutil-50.19.0.dll
[2010/06/17 18:07:22 | 000,798,739 | ---- | C] () -- C:\Windows\System32\avcodec-52.77.0.dll
[2010/06/17 18:07:22 | 000,085,504 | ---- | C] () -- C:\Windows\System32\avformat-52.68.0.dll
========== LOP Check ==========
[2010/09/23 14:08:44 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Acoustica
[2012/04/27 08:24:46 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\ANV_DVR
[2012/03/28 12:12:46 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Ashampoo
[2011/05/25 11:51:51 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Audacity
[2010/11/11 09:44:08 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Avery
[2012/06/12 11:43:01 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Bitdefender
[2012/06/13 21:56:22 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\BitTorrent
[2010/10/02 18:25:01 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\BitZipper
[2011/11/06 14:35:39 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\CheckPoint
[2010/12/28 23:44:16 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\com.adobe.ExMan
[2012/06/02 21:43:17 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\DAEMON Tools Lite
[2012/06/13 22:24:55 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Dropbox
[2012/06/12 16:33:06 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\FileZilla
[2010/12/30 12:19:02 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Genie-Soft
[2011/03/17 12:41:34 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\HandBrake
[2010/09/23 00:00:20 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Hnc
[2012/04/27 00:04:30 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\JiaboVideo
[2012/06/02 21:53:03 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Leadertech
[2012/06/02 21:41:36 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\OpenCandy
[2012/06/12 11:22:07 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\QuickScan
[2011/08/12 11:41:16 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Resource Tuner
[2011/08/01 10:24:03 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\SanDisk
[2012/05/04 15:38:38 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\SmarThru4
[2012/03/05 09:14:34 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\TeamViewer
[2010/11/16 11:57:31 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\TightVNC
[2011/01/10 01:35:26 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\TomTom
[2011/06/21 08:44:16 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\Video Application
[2011/10/17 19:36:34 | 000,000,000 | ---D | M] -- C:\Users\Nesys\AppData\Roaming\XnView
[2012/04/02 23:10:11 | 000,032,570 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/09/30 10:00:31 | 000,001,024 | ---- | M] () -- C:\.rnd
[2010/09/20 21:03:19 | 000,000,032 | ---- | M] () -- C:\audio.log
[2009/06/10 14:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2011/12/03 18:49:40 | 000,000,205 | ---- | M] () -- C:\chrome.manifest
[2012/06/13 16:54:07 | 000,026,077 | ---- | M] () -- C:\ComboFix.txt
[2011/12/03 18:49:40 | 000,000,811 | ---- | M] () -- C:\compile.bat
[2009/06/10 14:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2012/05/08 12:32:04 | 001,023,277 | ---- | M] () -- C:\debuglog.txt
[2011/04/21 17:17:58 | 000,000,044 | ---- | M] () -- C:\DebugTraceAP.log
[2012/06/13 21:57:48 | 2616,598,528 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/03 18:49:40 | 000,001,420 | ---- | M] () -- C:\install.rdf
[2011/03/02 19:34:19 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/03/07 20:31:22 | 000,000,198 | ---- | M] () -- C:\maintenance_log.rtf
[2011/03/02 19:34:19 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012/06/13 21:57:49 | 3488,800,768 | -HS- | M] () -- C:\pagefile.sys
[2012/06/12 16:26:49 | 000,000,949 | ---- | M] () -- C:\rkill.log
[2012/04/01 20:45:39 | 000,141,666 | ---- | M] () -- C:\TDSSKiller.2.7.23.0_01.04.2012_20.44.47_log.txt
[2012/06/12 16:22:13 | 000,004,762 | ---- | M] () -- C:\TDSSKiller.2.7.23.0_12.06.2012_16.21.51_log.txt
[2012/04/04 23:22:05 | 000,272,628 | ---- | M] () -- C:\TDSSKiller.2.7.25.0_04.04.2012_23.20.04_log.txt
[2012/04/04 23:25:14 | 000,146,824 | ---- | M] () -- C:\TDSSKiller.2.7.25.0_04.04.2012_23.22.16_log.txt
[2012/04/04 23:45:09 | 000,271,818 | ---- | M] () -- C:\TDSSKiller.2.7.25.0_04.04.2012_23.41.33_log.txt
[2012/06/07 00:35:36 | 000,284,632 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_07.06.2012_00.25.10_log.txt
[2012/06/12 16:23:47 | 000,145,128 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_12.06.2012_16.22.39_log.txt
[2012/01/17 00:42:19 | 000,000,237 | ---- | M] () -- C:\user.js
[2012/05/19 01:21:21 | 757,367,495 | ---- | M] () -- C:\VS920ZV3_02.S3_02.P58012.R5.cab
< %systemroot%\Fonts\*.com >
[2009/07/13 21:52:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 14:31:19 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 18:15:05 | 000,070,144 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\CNBPP3.DLL
[2009/07/13 18:15:35 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2011/05/12 18:32:42 | 000,082,184 | ---- | M] (Microsoft Corporation.) -- C:\Windows\system32\spool\prtprocs\w32x86\lmdippr8.dll
[2012/05/21 17:38:22 | 000,052,096 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\system32\spool\prtprocs\w32x86\LMIproc.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2009/10/26 03:45:02 | 000,019,968 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Windows\system32\spool\prtprocs\w32x86\sx450spc.dll
[2010/11/20 05:21:36 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 11:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/13 08:09:08 | 000,000,221 | -HS- | M] () -- C:\Users\Nesys\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/07/20 23:03:54 | 001,563,648 | ---- | M] () -- C:\Users\Nesys\Desktop\CamFinder.exe
[2012/06/13 11:13:49 | 004,557,191 | R--- | M] (Swearware) -- C:\Users\Nesys\Desktop\ComboFix.exe
[2012/06/02 21:40:14 | 014,229,744 | ---- | M] (DT Soft Ltd) -- C:\Users\Nesys\Desktop\DTLite4454-0315.exe
[2011/10/11 10:12:15 | 000,973,979 | ---- | M] (Bllua ) -- C:\Users\Nesys\Desktop\Instalar_RDesc_2.32.exe
[2012/06/13 23:52:02 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Nesys\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/06/13 23:02:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/13 12:28:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1006101457-4197215139-1718751079-1000Core.job
[2012/06/13 23:28:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1006101457-4197215139-1718751079-1000UA.job
[2012/06/13 21:59:43 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/04/02 23:10:11 | 000,032,570 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 14:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2012/04/08 00:11:41 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2012/04/08 00:11:41 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/03/02 19:08:07 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/03/02 19:08:08 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/04/08 00:12:52 | 000,000,402 | -HS- | M] () -- C:\Users\Nesys\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/06/17 12:17:02 | 000,000,000 | ---- | M] () -- C:\ProgramData\IpAndPort.fig
[2011/06/17 12:17:02 | 000,000,193 | ---- | M] () -- C:\ProgramData\RmUserCfg.ini
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >
< >
========== Files - Unicode (All) ==========
[2011/02/10 15:14:00 | 000,204,389 | ---- | M] ()(C:\Users\Nesys\Documents\Ext2Fsd-v100 ???.pdf) -- C:\Users\Nesys\Documents\Ext2Fsd-v100 사용법.pdf
[2011/02/10 15:14:00 | 000,204,389 | ---- | C] ()(C:\Users\Nesys\Documents\Ext2Fsd-v100 ???.pdf) -- C:\Users\Nesys\Documents\Ext2Fsd-v100 사용법.pdf
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP

FC5A2B2
< End of report >