O9:
64bit: - Extra Button: Encarta Search - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - Reg Error: Key error. File not found
O9:
64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - File not found
O9:
64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - File not found
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - File not found
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - File not found
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.203.16.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5DF5E1FA-3943-4034-ABAD-16866D6A1FDD}: DhcpNameServer = 10.203.16.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8A7D8241-19A5-4FE2-B26E-F93BEC902BA1}: NameServer = 202.126.40.5 222.127.143.5
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E765B085-F525-4AA0-9320-BF430A12C1E9}: NameServer = 202.126.40.5 222.127.143.5
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\SysNative\WPDShServiceObj.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/16 08:11:12 | 000,000,000 | ---D | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/07/16 08:11:18 | 000,000,000 | ---D | M] - D:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/11/17 05:37:37 | 000,142,336 | R--- | M] () - E:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2010/12/21 09:42:30 | 000,000,047 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs:
64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (
www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/10 17:06:18 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\Zen of Sudoku
[2011/09/10 13:33:05 | 000,000,000 | ---D | C] -- C:\New folder
[2011/09/10 12:45:45 | 000,118,784 | ---- | C] (ZTE Incorporated) -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys
[2011/09/10 12:45:44 | 000,118,784 | ---- | C] (ZTE Incorporated) -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys
[2011/09/09 14:59:59 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\compile
[2011/09/09 11:36:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/09/08 16:16:02 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\pcsp v0.5.2
[2011/09/08 09:43:50 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\games
[2011/09/08 06:36:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/09/08 06:36:30 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/09/08 06:36:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/09/08 06:36:11 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/09/08 06:36:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/09/08 06:06:15 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\techspot
[2011/09/07 11:30:37 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\psp
[2011/09/07 10:57:14 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\TS3Client
[2011/09/07 10:56:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2011/09/07 10:56:34 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2011/09/06 13:56:04 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\LogInExample
[2011/09/06 13:27:50 | 000,000,000 | ---D | C] -- C:\ProgramData\InterAction studios
[2011/09/06 13:26:34 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\Chicken Invaders 4 - Ultimate Omelette
[2011/09/06 11:06:20 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\test
[2011/09/06 11:03:21 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Local\Connectify
[2011/09/06 11:03:03 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Connectify
[2011/09/05 13:00:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2011/09/05 13:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011/09/05 06:03:53 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/09/02 17:30:55 | 000,000,000 | ---D | C] -- C:\Users\acer\Documents\raffle
[2011/09/02 09:08:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
[2011/09/02 09:04:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQLyog Community
[2011/09/01 09:57:45 | 000,000,000 | ---D | C] -- C:\ProgramData\hssff
[2011/09/01 08:38:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Expat Shield
[2011/09/01 08:36:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Expat Shield
[2011/08/31 18:54:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Connectify
[2011/08/31 05:52:33 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\PACE Anti-Piracy
[2011/08/31 05:52:33 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Local\PACE Anti-Piracy
[2011/08/31 05:52:33 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy
[2011/08/29 18:50:01 | 000,000,000 | ---D | C] -- C:\ICC_Backup
[2011/08/28 15:38:19 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Local\Facebook
[2011/08/28 01:00:55 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\MozillaControl
[2011/08/28 00:59:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\'Full Speed' Internet Booster + Performance Tests
[2011/08/27 19:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Connection Counter
[2011/08/26 12:17:46 | 000,009,216 | ---- | C] (ZTE Incorporated) -- C:\Windows\SysNative\drivers\massfilter.sys
[2011/08/26 11:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Uniblue
[2011/08/26 11:15:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2011/08/26 11:15:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Uniblue
[2011/08/26 11:00:39 | 000,000,000 | ---D | C] -- C:\ProgramData\BabylonUpdater
[2011/08/26 11:00:26 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Local\Babylon
[2011/08/26 11:00:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2011/08/26 11:00:21 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\Babylon
[2011/08/26 10:59:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Easy Downloads
[2011/08/25 17:46:33 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
[2011/08/24 06:51:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CommView for WiFi
[2011/08/24 06:50:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CommViewWiFi
[2011/08/24 06:34:25 | 000,000,000 | ---D | C] -- C:\aircrack
[2011/08/22 20:04:26 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\ae
[2011/08/22 02:50:28 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\VPN
[2011/08/22 02:22:10 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/08/21 22:56:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[2011/08/21 22:56:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinPcap
[2011/08/21 22:56:19 | 000,000,000 | ---D | C] -- C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cain
[2011/08/21 22:56:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain
[2011/08/21 22:56:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cain
[2011/08/21 19:07:08 | 000,000,000 | ---D | C] -- C:\Expat Shield
[2011/08/21 13:56:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
[2011/08/20 22:11:16 | 000,000,000 | ---D | C] -- C:\Users\acer\Documents\Poker Superstars II Documents
[2011/08/20 11:26:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sun Broadband Wireless
[2011/08/20 11:25:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sun Broadband Wireless
[2011/08/20 07:34:45 | 000,000,000 | ---D | C] -- C:\Users\acer\Documents\My Cheat Tables
[2011/08/20 07:34:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cheat Engine 6
[2011/08/18 12:13:20 | 000,000,000 | ---D | C] -- C:\Users\acer\Desktop\My Music
[2011/08/13 01:09:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2010/06/04 09:00:03 | 000,049,464 | ---- | C] ( ) -- C:\Windows\AutosetFrequency.exe
[1 C:\Users\acer\AppData\Local\*.tmp files -> C:\Users\acer\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/11 06:26:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/11 05:02:29 | 001,209,110 | ---- | M] () -- C:\Users\acer\Desktop\vision.rar
[2011/09/10 21:24:59 | 001,517,364 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/10 21:24:59 | 000,738,742 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/09/10 21:24:59 | 000,481,560 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2011/09/10 21:24:59 | 000,151,844 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2011/09/10 21:24:59 | 000,151,844 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/09/10 21:13:20 | 000,022,672 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/10 21:13:20 | 000,022,672 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/10 18:26:01 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/10 18:07:12 | 000,000,216 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2011/09/10 18:07:11 | 000,000,218 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
[2011/09/10 18:06:27 | 000,077,824 | ---- | M] () -- C:\Windows\KMSEmulator.exe
[2011/09/10 18:01:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/10 18:01:10 | 1556,180,992 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/10 12:39:13 | 525,806,555 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/09/10 12:27:35 | 000,001,098 | ---- | M] () -- C:\Users\acer\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/09/09 11:35:58 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/09/08 07:55:56 | 000,000,086 | ---- | M] () -- C:\Windows\SysNative\RegRuns00-X64
[2011/09/08 07:55:54 | 000,002,053 | ---- | M] () -- C:\Windows\SysNative\mSIOI00-X64
[2011/09/08 07:55:53 | 000,004,098 | ---- | M] () -- C:\Windows\SysNative\ToolB-01-X64
[2011/09/08 07:55:50 | 000,000,153 | ---- | M] () -- C:\Windows\SysNative\ToolB-00-X64
[2011/09/07 11:47:15 | 000,000,000 | ---- | M] () -- C:\Users\acer\Documents\dbact.sql
[2011/09/07 10:39:43 | 000,000,702 | ---- | M] () -- C:\Windows\ODBCINST.INI
[2011/09/07 05:56:19 | 000,001,096 | ---- | M] () -- C:\Users\acer\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2011/09/06 09:42:01 | 000,001,078 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000UA.job
[2011/09/06 09:06:00 | 000,000,926 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000UA.job
[2011/09/05 20:12:36 | 000,000,193 | ---- | M] () -- C:\Windows\popcinfo.dat
[2011/09/05 18:06:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000Core.job
[2011/09/04 07:05:00 | 000,000,000 | ---- | M] () -- C:\Users\acer\AppData\Local\{7E3364A0-F95B-4240-B4D1-5810D05E6AA0}
[2011/09/02 21:35:34 | 000,000,600 | ---- | M] () -- C:\Users\acer\PUTTY.RND
[2011/09/02 09:23:14 | 000,458,752 | ---- | M] () -- C:\Users\acer\Documents\Database3.mdb
[2011/09/02 09:04:58 | 000,001,087 | ---- | M] () -- C:\Users\acer\Application Data\Microsoft\Internet Explorer\Quick Launch\SQLyog Community.lnk
[2011/09/01 08:23:08 | 000,000,433 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
[2011/09/01 06:40:54 | 000,000,911 | ---- | M] () -- C:\Users\acer\Desktop\School.lnk
[2011/09/01 05:34:15 | 000,560,982 | ---- | M] () -- C:\Users\acer\Documents\SysInspector-NECCO-110901-0526.zip
[2011/08/31 19:06:05 | 000,000,000 | ---- | M] () -- C:\Users\acer\AppData\Local\{3D26E813-51FD-4FBE-B664-EA957DB584D1}
[2011/08/27 15:15:37 | 000,054,327 | ---- | M] () -- C:\Users\acer\Documents\Level 0 revise.graphml
[2011/08/27 14:22:22 | 000,021,245 | ---- | M] () -- C:\Users\acer\Documents\Level 1 Returned MOdule revised.graphml
[2011/08/27 14:19:54 | 000,027,586 | ---- | M] () -- C:\Users\acer\Documents\leve 1 Borrow Module.graphml
[2011/08/26 12:17:46 | 000,009,216 | ---- | M] (ZTE Incorporated) -- C:\Windows\SysNative\drivers\massfilter.sys
[2011/08/26 10:44:57 | 000,016,494 | ---- | M] () -- C:\Users\acer\Documents\Level 1 Update Module revised.graphml
[2011/08/25 13:08:05 | 005,268,816 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/25 09:46:21 | 001,516,080 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/23 02:18:07 | 030,519,015 | ---- | M] () -- C:\Users\acer\Documents\20questions.wma
[2011/08/23 01:29:54 | 001,971,595 | ---- | M] () -- C:\Users\acer\Documents\Untitled (2).wma
[2011/08/23 01:26:07 | 000,040,895 | ---- | M] () -- C:\Users\acer\Documents\Untitled.wma
[2011/08/21 23:14:14 | 000,237,568 | ---- | M] () -- C:\Users\acer\Documents\db2.mdb
[2011/08/21 23:13:36 | 000,352,256 | ---- | M] () -- C:\Users\acer\Documents\db21.mdb
[2011/08/21 23:13:10 | 000,397,312 | ---- | M] () -- C:\Users\acer\Documents\Database2.accdb
[2011/08/21 23:07:04 | 000,569,344 | ---- | M] () -- C:\Users\acer\Documents\Database1.accdb
[2011/08/21 19:06:48 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\cd.dat
[2011/08/21 14:46:44 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/08/21 14:44:38 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_AuxiliaryDisplayEnhancedDriver_01_09_00.Wdf
[2011/08/21 14:40:34 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jucdcecm_01007.Wdf
[2011/08/21 14:32:19 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_hwgpssensor_01_09_00.Wdf
[2011/08/19 21:19:51 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/08/18 12:36:44 | 000,032,610 | ---- | M] () -- C:\Users\acer\DURAN, Necco.jpg
[2011/08/13 08:35:25 | 000,401,934 | ---- | M] () -- C:\Users\acer\Documents\Image (2).rtf
[1 C:\Users\acer\AppData\Local\*.tmp files -> C:\Users\acer\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/11 05:02:28 | 001,209,110 | ---- | C] () -- C:\Users\acer\Desktop\vision.rar
[2011/09/10 12:27:35 | 000,001,098 | ---- | C] () -- C:\Users\acer\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/09/08 07:55:55 | 000,000,086 | ---- | C] () -- C:\Windows\SysNative\RegRuns00-X64
[2011/09/08 07:55:54 | 000,002,053 | ---- | C] () -- C:\Windows\SysNative\mSIOI00-X64
[2011/09/08 07:55:53 | 000,004,098 | ---- | C] () -- C:\Windows\SysNative\ToolB-01-X64
[2011/09/08 07:55:50 | 000,000,153 | ---- | C] () -- C:\Windows\SysNative\ToolB-00-X64
[2011/09/08 06:36:30 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/09/08 06:36:30 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/09/08 06:36:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/09/08 06:36:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/09/08 06:36:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/09/07 11:47:14 | 000,000,000 | ---- | C] () -- C:\Users\acer\Documents\dbact.sql
[2011/09/07 08:34:23 | 525,806,555 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/09/07 05:56:19 | 000,001,096 | ---- | C] () -- C:\Users\acer\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2011/09/05 18:01:10 | 000,000,926 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000UA.job
[2011/09/05 18:01:07 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000Core.job
[2011/09/04 07:05:00 | 000,000,000 | ---- | C] () -- C:\Users\acer\AppData\Local\{7E3364A0-F95B-4240-B4D1-5810D05E6AA0}
[2011/09/02 09:04:58 | 000,001,087 | ---- | C] () -- C:\Users\acer\Application Data\Microsoft\Internet Explorer\Quick Launch\SQLyog Community.lnk
[2011/09/02 08:25:43 | 000,458,752 | ---- | C] () -- C:\Users\acer\Documents\Database3.mdb
[2011/09/01 06:40:54 | 000,000,911 | ---- | C] () -- C:\Users\acer\Desktop\School.lnk
[2011/09/01 05:34:14 | 000,560,982 | ---- | C] () -- C:\Users\acer\Documents\SysInspector-NECCO-110901-0526.zip
[2011/08/31 19:05:25 | 000,000,000 | ---- | C] () -- C:\Users\acer\AppData\Local\{3D26E813-51FD-4FBE-B664-EA957DB584D1}
[2011/08/27 14:22:21 | 000,021,245 | ---- | C] () -- C:\Users\acer\Documents\Level 1 Returned MOdule revised.graphml
[2011/08/27 14:19:19 | 000,027,586 | ---- | C] () -- C:\Users\acer\Documents\leve 1 Borrow Module.graphml
[2011/08/23 02:18:06 | 030,519,015 | ---- | C] () -- C:\Users\acer\Documents\20questions.wma
[2011/08/23 01:29:53 | 001,971,595 | ---- | C] () -- C:\Users\acer\Documents\Untitled (2).wma
[2011/08/23 01:26:04 | 000,040,895 | ---- | C] () -- C:\Users\acer\Documents\Untitled.wma
[2011/08/22 14:02:42 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/08/21 19:06:48 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cd.dat
[2011/08/21 14:46:44 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/08/21 14:44:38 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_AuxiliaryDisplayEnhancedDriver_01_09_00.Wdf
[2011/08/21 14:40:34 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jucdcecm_01007.Wdf
[2011/08/21 14:32:19 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_hwgpssensor_01_09_00.Wdf
[2011/08/21 12:09:50 | 000,000,834 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2011/08/19 21:19:51 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/08/18 12:36:42 | 000,032,610 | ---- | C] () -- C:\Users\acer\DURAN, Necco.jpg
[2011/08/13 08:35:12 | 000,401,934 | ---- | C] () -- C:\Users\acer\Documents\Image (2).rtf
[2011/08/06 19:56:17 | 000,000,111 | ---- | C] () -- C:\Windows\SysWow64\sysinter.drv
[2011/08/04 06:56:44 | 000,000,193 | ---- | C] () -- C:\Windows\popcinfo.dat
[2011/07/27 16:01:45 | 000,011,875 | ---- | C] () -- C:\Windows\UN091114.INI
[2011/07/24 12:38:11 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/07/22 09:53:27 | 000,000,132 | ---- | C] () -- C:\Users\acer\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/07/16 19:04:31 | 000,077,824 | ---- | C] () -- C:\Windows\KMSEmulator.exe
[2011/07/15 06:54:36 | 000,000,000 | ---- | C] () -- C:\Users\acer\AppData\Roaming\debuggee.mdmp
[2011/07/15 06:07:04 | 000,000,702 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/07/15 06:07:04 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/04/27 20:57:30 | 000,000,132 | ---- | C] () -- C:\Users\acer\AppData\Roaming\Adobe AIFF Format CS5 Prefs
[2011/04/01 17:03:20 | 000,210,032 | ---- | C] () -- C:\Windows\SysWow64\DBCLIENT.DLL
[2011/03/16 21:24:40 | 000,000,000 | ---- | C] () -- C:\Users\acer\AppData\Roaming\wklnhst.dat
[2011/03/11 22:51:44 | 000,151,040 | ---- | C] () -- C:\Windows\SysWow64\wimadll.dll
[2011/03/04 01:13:55 | 000,031,831 | ---- | C] () -- C:\Users\acer\AppData\Roaming\UserTile.png
[2011/03/01 06:28:20 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\InsDrvZD.dll
[2011/03/01 06:28:20 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\ZyDelReg.exe
[2011/03/01 06:28:20 | 000,015,872 | ---- | C] () -- C:\Windows\SysWow64\InsDrvZD64.DLL
[2011/02/16 22:22:57 | 000,007,600 | ---- | C] () -- C:\Users\acer\AppData\Local\resmon.resmoncfg
[2010/10/09 20:14:50 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2010/10/09 20:14:49 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010/10/09 20:14:45 | 000,810,496 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010/10/09 20:14:45 | 000,183,808 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010/10/09 20:14:44 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/09/30 21:52:26 | 000,204,498 | ---- | C] () -- C:\Windows\hpwins26.dat
[2010/09/11 16:23:06 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/09/02 19:34:42 | 000,013,312 | ---- | C] () -- C:\Users\acer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/23 16:22:52 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/07/21 09:32:49 | 001,516,080 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/08 10:37:14 | 000,101,544 | ---- | C] () -- C:\Program Files\Common Files\LinkInstaller.exe
[2010/06/26 01:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2010/06/05 00:29:34 | 000,982,220 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2010/06/05 00:29:34 | 000,134,592 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2010/06/05 00:29:34 | 000,092,216 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2010/06/05 00:29:33 | 000,439,300 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2010/06/05 00:29:33 | 000,001,005 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/06/05 00:28:19 | 000,001,787 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2010/06/04 09:22:50 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2010/06/04 09:00:03 | 000,632,056 | ---- | C] () -- C:\Windows\Image.dll
[2010/06/04 09:00:03 | 000,206,208 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2010/06/04 09:00:03 | 000,025,848 | ---- | C] () -- C:\Windows\USB_VIDEO_REG.exe
[2010/06/04 09:00:03 | 000,000,637 | ---- | C] () -- C:\Windows\AutoSetFrequency.ini
[2010/06/04 09:00:03 | 000,000,378 | ---- | C] () -- C:\Windows\PidList.ini
[2010/06/04 08:56:56 | 000,001,005 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2010/06/04 08:53:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/04/14 07:39:43 | 000,000,193 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2010/04/14 07:39:43 | 000,000,166 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2010/04/14 07:39:43 | 000,000,147 | ---- | C] () -- C:\Windows\WisPriority.ini
[2009/08/18 14:31:57 | 000,000,370 | ---- | C] () -- C:\Windows\hpwmdl26.dat
[2009/07/14 13:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 10:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 10:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 08:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 07:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 05:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 05:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2008/11/20 23:17:12 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\myodbc3i.exe
[2008/11/20 23:17:12 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\myodbc3m.exe
[2006/11/07 22:03:36 | 000,000,016 | ---- | C] () -- C:\Windows\SysWow64\REWCACHE.DAT
[2006/05/19 19:39:58 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
[2000/07/15 00:00:00 | 000,030,720 | ---- | C] () -- C:\Windows\REGTLIB.EXE
[1998/06/10 00:00:00 | 000,015,120 | ---- | C] () -- C:\Windows\SysWow64\REPUTIL.DLL
========== LOP Check ==========
[2011/04/04 21:27:30 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Artogon
[2011/08/26 11:00:21 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Babylon
[2011/03/03 03:53:47 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Big Fish Games
[2011/02/18 10:05:41 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\BitComet
[2011/09/01 06:20:17 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\BitDefender
[2011/03/10 08:31:51 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Blue Tea Games
[2011/07/17 18:36:24 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Bullzip
[2011/08/01 20:21:03 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/08/23 15:46:59 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/08/23 16:22:49 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\CometNetwork
[2010/10/11 01:25:26 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\CometPlayer
[2011/03/12 14:00:07 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\DAEMON Tools Lite
[2011/09/07 10:44:29 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\DMCache
[2011/03/13 13:23:04 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\DriverCure
[2011/03/13 05:30:59 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Dropbox
[2010/09/13 14:49:12 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/02/18 14:36:14 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\ESET
[2011/02/16 18:19:44 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\eSobi
[2011/02/17 23:25:15 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\fizzy
[2011/09/01 06:20:18 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\FlashGet
[2011/03/26 18:28:15 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\GetRightToGo
[2011/09/01 06:30:23 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Hide IP NG
[2010/10/11 14:54:56 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\iLike
[2010/09/22 12:23:34 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\IMVUClient
[2011/03/03 07:01:12 | 000,000,000 | RHSD | M] -- C:\Users\acer\AppData\Roaming\install
[2011/03/08 02:46:58 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\JCreator
[2011/09/01 06:20:19 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Kalydo
[2011/02/27 21:22:28 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\LolClient
[2011/02/27 05:55:32 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\MysteriousCaseOfJekyllAndHyde
[2011/09/01 06:20:38 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Opera
[2011/08/31 05:52:34 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\PACE Anti-Piracy
[2011/03/13 13:23:04 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\ParetoLogic
[2010/11/06 18:41:12 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\PlayFirst
[2011/03/13 23:36:49 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\QuickScan
[2011/08/12 21:54:11 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Rovio
[2011/09/01 06:30:26 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Softouch
[2011/09/07 11:52:59 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\SQLyog
[2011/07/09 19:44:51 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/09/01 06:20:39 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Synaptics
[2011/03/16 21:25:46 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Template
[2011/09/01 06:20:39 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Thinstall
[2010/12/26 00:15:05 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\TigerPlayer
[2011/09/01 06:30:31 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Transcend
[2011/09/07 11:02:10 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\TS3Client
[2011/09/01 06:21:03 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\TuneUp Software
[2011/02/16 14:33:36 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\USBSafelyRemove
[2011/09/05 06:00:32 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\uTorrent
[2011/08/04 06:59:58 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\WildTangent
[2011/08/06 12:44:44 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\yWorks
[2011/09/10 17:06:27 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Zen of Sudoku
[2011/02/28 09:39:35 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\Zentimo
[2011/09/01 06:21:08 | 000,000,000 | ---D | M] -- C:\Users\acer\AppData\Roaming\ZIP RAR ACE Password Recovery
[2011/07/14 08:24:02 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\ESET
[2011/08/04 18:40:51 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\funkitron
[2011/07/14 07:56:17 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\Kalydo
[2011/08/04 08:14:44 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\Rovio
[2011/07/14 07:56:17 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\SQLyog
[2011/07/30 16:54:24 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/07/26 12:36:43 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\Synaptics
[2011/07/14 20:33:44 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\TuneUp Software
[2011/07/14 08:23:56 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\USBSafelyRemove
[2011/08/04 18:40:35 | 000,000,000 | ---D | M] -- C:\Users\DURAN\AppData\Roaming\Zen of Sudoku
[2011/08/30 01:28:04 | 000,000,000 | ---D | M] -- C:\Users\EHNN\AppData\Roaming\ESET
[2011/08/30 01:28:02 | 000,000,000 | ---D | M] -- C:\Users\EHNN\AppData\Roaming\Synaptics
[2011/09/10 18:07:12 | 000,000,216 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2011/09/10 18:07:11 | 000,000,218 | ---- | M] () -- C:\Windows\Tasks\AutoKMSDaily.job
[2011/09/05 18:06:00 | 000,000,904 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000Core.job
[2011/09/06 09:06:00 | 000,000,926 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2915824604-787655904-4174257227-1000UA.job
[2011/08/26 13:52:24 | 000,032,616 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/08/19 21:19:51 | 000,001,024 | ---- | M] () -- C:\.rnd
[2009/07/14 09:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/07/28 04:40:53 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011/09/09 13:15:47 | 000,041,435 | ---- | M] () -- C:\ComboFix.txt
[2011/09/10 18:01:10 | 1556,180,992 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/10 18:01:20 | 3145,728,000 | -HS- | M] () -- C:\pagefile.sys
[2010/04/20 23:34:44 | 000,021,629 | RHS- | M] () -- C:\Patch.rev
[2010/07/10 17:40:46 | 000,000,216 | RHS- | M] () -- C:\Preload.rev
[2011/09/10 08:37:10 | 000,151,106 | ---- | M] () -- C:\TDSSKiller.2.5.20.0_10.09.2011_08.28.07_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 13:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 13:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 13:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 13:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 04:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2011/03/04 22:23:38 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/09 01:26:20 | 000,000,221 | -HS- | M] () -- C:\Users\acer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2006/05/19 19:53:02 | 000,013,022 | ---- | M] () -- C:\Windows\snp2uvc.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 05:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/09/02 10:49:03 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/09/02 10:49:03 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2010/06/04 08:50:38 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2010/06/04 08:50:38 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/09/02 10:49:03 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/08/09 10:36:33 | 000,000,402 | -HS- | M] () -- C:\Users\acer\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
Acer Crystal Eye webcam.exe
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/03/15 12:20:12 | 000,000,000 | ---- | M] ()(C:\Windows\SysNative\?????) -- C:\Windows\SysNative\獷楬汢捯污
[2011/03/15 12:18:33 | 000,000,000 | ---- | C] ()(C:\Windows\SysNative\?????) -- C:\Windows\SysNative\獷楬汢捯污
[2010/07/10 17:40:36 | 000,000,000 | -HSD | M](C:\Users\acer\[??] ???) -- C:\Users\acer\[開始] 功能表
[2010/07/10 17:38:43 | 000,000,000 | -HSD | M](C:\ProgramData\[??] ???) -- C:\ProgramData\[開始] 功能表
[2010/07/10 17:38:43 | 000,000,000 | -HSD | M](C:\ProgramData\??) -- C:\ProgramData\桌面
[2010/07/10 17:38:43 | 000,000,000 | -HSD | M](C:\ProgramData\[??] ???) -- C:\ProgramData\[開始] 功能表
[2010/07/10 17:38:43 | 000,000,000 | -HSD | M](C:\ProgramData\??) -- C:\ProgramData\桌面
(C:\Users\acer\[??] ???) -- C:\Users\acer\[開始] 功能表
(C:\ProgramData\[??] ???) -- C:\ProgramData\[開始] 功能表
(C:\ProgramData\??) -- C:\ProgramData\桌面
========== Alternate Data Streams ==========
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:697DDE2B
@Alternate Data Stream - 191 bytes -> C:\ProgramData\Temp:8E5EA40F
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:93DE1838
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:E36F5B57
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:ABE89FFE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:5D7E5A8F
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:0207454C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:798A3728
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:B0456F0C
@Alternate Data Stream - 1236 bytes -> C:\Users\acer\AppData\Local\Temp:hDR8O7GyPXCLHMY5K7YpAS81NPCQ
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp

5AD7675
< End of report >