Re: Prosim o pomoc s virem
Napsal: 05 črc 2012 12:11
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\Windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.RTV1 - rtvcvfw32.dll File not found
Drivers32: vidc.VP60 - C:\Windows\system32\vp6vfw.dll File not found
Drivers32: vidc.VP61 - C:\Windows\system32\vp6vfw.dll File not found
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2012.07.05 11:30:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.07.05 10:55:09 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{F156E791-6BF7-499A-B184-7C3C0178F8A9}
[2012.07.05 10:54:57 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{47EAD36E-E5F0-45AA-946E-6E49335ADF11}
[2012.07.05 10:24:15 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Rhonwyn\Desktop\OTL.exe
[2012.07.05 09:26:32 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.07.05 09:26:32 | 000,000,000 | ---D | C] -- C:\rsit
[2012.07.04 18:33:19 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\ANNO 2070
[2012.07.04 08:41:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.07.04 08:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.07.04 08:27:42 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Roaming\SUPERAntiSpyware.com
[2012.07.04 08:27:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.07.04 08:27:29 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012.07.04 08:27:29 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.07.04 07:28:16 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Roaming\Malwarebytes
[2012.07.04 07:28:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.04 07:28:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.04 07:28:03 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.04 07:28:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.02 20:39:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012.07.01 12:34:29 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Desktop\j,bljhb
[2012.06.30 13:11:14 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\x360ce.App-2.0.2.158
[2012.06.30 13:01:47 | 000,014,976 | ---- | C] (Headsoft) -- C:\Windows\SysNative\drivers\vjoy.sys
[2012.06.30 13:01:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VJoy
[2012.06.30 13:01:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VJoy
[2012.06.30 12:47:30 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\PCSX2
[2012.06.30 12:39:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BrowserCompanion
[2012.06.30 12:39:44 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Desktop\PSX Emulator
[2012.06.24 14:35:09 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{27A2645C-4C29-4DB5-9EA7-1FE11F8AE68E}
[2012.06.24 14:34:56 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{B9A923BE-72A0-469C-8CB0-1DC5860A0157}
[2012.06.22 22:02:14 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\WB Games
[2012.06.22 21:59:03 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\Downloaded Installations
[2012.06.20 16:02:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.20 16:02:31 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.20 16:02:30 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.20 16:02:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012.06.19 22:49:38 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\Macromedia
[2012.06.19 20:55:11 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{303EDC14-2EEA-4336-BBE1-12FA52A59F9E}
[2012.06.19 20:54:59 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{948EE042-3D55-4735-8DFB-5048A29AA362}
[2012.06.19 06:21:34 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012.06.19 06:21:34 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012.06.19 06:21:34 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012.06.19 06:21:25 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012.06.19 06:21:25 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012.06.19 06:21:25 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012.06.19 06:21:14 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012.06.19 06:21:14 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012.06.18 12:20:26 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{06086E9A-F30A-43AC-B5DB-C962E24FD482}
[2012.06.17 14:32:14 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\Star Wars - The Old Republic
[2012.06.14 03:00:55 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.06.14 03:00:54 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.06.14 03:00:54 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.06.14 03:00:54 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.06.14 03:00:53 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.06.14 03:00:53 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.06.14 03:00:53 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.06.14 03:00:53 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.06.14 03:00:52 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.06.14 03:00:52 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.06.14 03:00:52 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.06.14 03:00:52 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.06.14 03:00:52 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.06.13 18:08:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2012.06.13 18:07:24 | 000,198,088 | ---- | C] (Aladdin Knowledge Systems Ltd.) -- C:\Windows\SysWow64\hlvdd.dll
[2012.06.13 18:07:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mosaic
[2012.06.13 08:55:56 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012.06.13 08:55:56 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012.06.13 08:55:56 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012.06.13 08:55:46 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012.06.13 08:55:46 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012.06.13 08:55:45 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012.06.13 08:55:41 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012.06.13 08:55:39 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012.06.13 08:55:39 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012.06.12 09:53:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.06.11 10:00:51 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\Mozilla
[2012.06.11 10:00:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.06.11 10:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.06.11 09:56:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012.06.11 09:55:32 | 000,000,000 | ---D | C] -- C:\bb3101f1d1cc1083cadb8bbb
[2012.06.10 21:47:32 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{57D0F6C1-591B-4960-AFF7-B997557E6C5E}
[2012.06.10 21:47:09 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{C8002E9B-08F0-406F-B422-127F67FF250F}
[2012.06.10 09:46:56 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{47C60257-DF0C-4A47-9B2C-2F7D896DF557}
[2012.06.10 09:46:34 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{77431036-60D6-48D3-BAD6-F5326C27B360}
[2012.06.09 21:46:20 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{82B29E13-ADAF-476A-B87E-C36BA218AB92}
[2012.06.09 21:45:58 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{914D2F62-D399-4943-9474-50CB1E573D89}
[2012.06.09 09:45:34 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{D2341CC2-91D7-499A-9E0D-BBC5AE7D9590}
[2012.06.09 09:44:35 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{51C01981-9AC9-480F-AB96-D1F843C11212}
[2012.06.08 21:28:22 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{AC5545E4-3597-4B0C-BD42-D5DBB4D8B2C8}
[2012.06.08 21:28:00 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{A6BD5862-0126-4123-9143-3D1D3B338232}
[2012.06.08 09:27:47 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{F1B78D52-9FD0-4A54-845E-DCA8C231AAA8}
[2012.06.08 09:27:24 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{372C5BCE-DE38-4D26-9711-44C86DCD838F}
[2012.06.07 21:27:12 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{F7685F82-2CA8-46D2-87EC-7B7D31EB112E}
[2012.06.07 21:26:50 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{E5DEE870-333E-4FCE-8D2D-787B0528A673}
[2012.06.07 09:26:37 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{BD6A2723-0299-419A-B16B-6D7A52385BDA}
[2012.06.07 09:26:15 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{42595AEC-CE6F-4EF7-8988-9D9C2461F9E6}
[2012.06.06 21:26:02 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{7F943F83-B136-4766-9330-CC205AF9A115}
[2012.06.06 21:25:40 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{92BB5273-6D28-4F52-9CC8-9796B84AE031}
[2012.06.06 09:25:28 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{3556D5F3-BEF5-465A-B3B6-30F3B37B7998}
[2012.06.06 09:25:06 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{847D13B1-5871-49AC-ACB4-8B436F128DAF}
[2012.06.05 21:24:52 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{DF92DF96-8615-4F57-9031-935DCC6EDF22}
[2012.06.05 21:24:30 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{72856626-2B9C-4A87-80CD-1CE3F6FEE587}
========== Files - Modified Within 30 Days ==========
[2012.07.05 12:56:30 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.07.05 12:53:03 | 2134,204,415 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.05 12:44:23 | 000,022,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.05 12:44:23 | 000,022,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.05 12:37:11 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys
[2012.07.05 12:17:01 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012.07.05 10:42:09 | 000,388,470 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\cannot create file.png
[2012.07.05 10:24:21 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Rhonwyn\Desktop\OTL.exe
[2012.07.04 08:41:57 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.04 08:27:36 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.07.04 07:28:07 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.02 20:39:41 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012.07.02 20:39:32 | 001,602,266 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.07.02 20:39:32 | 000,668,322 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2012.07.02 20:39:32 | 000,654,066 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.02 20:39:32 | 000,140,918 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012.07.02 20:39:32 | 000,121,898 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.30 19:30:39 | 000,002,413 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\Google Chrome.lnk
[2012.06.30 12:50:19 | 000,040,928 | ---- | M] () -- C:\Windows\SysNative\drivers\VSPE.sys
[2012.06.30 12:40:01 | 000,000,250 | ---- | M] () -- C:\user.js
[2012.06.28 21:30:11 | 000,000,626 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\net.rtf
[2012.06.23 11:25:08 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.06.23 11:25:08 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.06.22 13:31:09 | 000,019,233 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\purple_shoes.jpg
[2012.06.22 09:51:42 | 000,000,221 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\Batman Arkham City.url
[2012.06.20 16:02:43 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.15 16:56:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.14 03:30:38 | 000,292,456 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 03:11:42 | 001,596,116 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.13 18:08:16 | 000,001,166 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.06.13 18:07:16 | 000,001,234 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\Mosaic.lnk
[2012.06.12 09:53:31 | 000,001,134 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
========== Files Created - No Company Name ==========
[2012.07.05 10:42:09 | 000,388,470 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\cannot create file.png
[2012.07.05 10:29:45 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.07.04 08:41:57 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.04 08:27:36 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.07.04 07:28:07 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.02 20:39:41 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012.07.02 20:39:37 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012.06.30 16:16:16 | 002,660,349 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\100_1412.JPG
[2012.06.30 12:50:19 | 000,040,928 | ---- | C] () -- C:\Windows\SysNative\drivers\VSPE.sys
[2012.06.30 12:40:01 | 000,000,250 | ---- | C] () -- C:\user.js
[2012.06.30 09:29:58 | 000,000,242 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\Dead Space™ 2.lnk
[2012.06.27 11:26:35 | 002,039,299 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\100_1410.JPG
[2012.06.22 13:31:03 | 000,019,233 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\purple_shoes.jpg
[2012.06.22 09:51:41 | 000,000,221 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\Batman Arkham City.url
[2012.06.20 16:02:43 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.13 18:08:16 | 000,001,178 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.06.13 18:08:16 | 000,001,166 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.06.13 18:07:16 | 000,001,234 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\Mosaic.lnk
[2012.06.12 09:53:31 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.06.12 09:53:31 | 000,001,134 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.05.12 17:01:57 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2012.05.01 14:39:17 | 000,006,144 | ---- | C] () -- C:\Users\Rhonwyn\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.04.04 12:24:14 | 000,280,976 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.04.04 12:24:13 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.03.28 23:33:10 | 000,000,542 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.02.14 22:31:22 | 001,602,266 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.02.01 19:36:18 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2012.02.01 19:28:46 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012.02.01 19:23:49 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2012.02.01 19:19:05 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.02.01 19:16:21 | 000,003,113 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.12.15 07:23:04 | 010,920,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011.12.15 07:23:04 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2011.12.15 07:23:04 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.09.28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.10.05 01:59:32 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\StarOpen.sys
========== LOP Check ==========
[2012.05.12 17:13:32 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Atari
[2012.07.04 08:46:48 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\DAEMON Tools Lite
[2012.02.19 15:03:15 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\EVEMon
[2012.07.04 18:00:42 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\GetRightToGo
[2012.06.19 18:08:19 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\GHISLER
[2012.04.30 15:05:17 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Leadertech
[2012.03.24 11:06:09 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Might & Magic Heroes VI - Game Official Demo
[2012.04.21 09:40:24 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Mount&Blade Warband
[2012.02.05 21:09:04 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Mumble
[2012.03.05 22:57:23 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Need for Speed World
[2012.04.17 17:02:25 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\OpenOffice.org
[2012.04.07 19:50:05 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Origin
[2012.02.24 14:01:19 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\PhotoFiltre
[2012.02.05 14:01:50 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\POINTERGHOSTV1
[2012.04.04 12:24:13 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\PunkBuster
[2012.03.02 10:26:33 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Rift
[2012.03.24 09:42:50 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Scoregasm
[2012.02.01 19:24:36 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Splashtop
[2012.02.02 21:04:53 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Sports Interactive
[2012.07.04 08:46:44 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\TS3Client
[2012.07.04 18:00:17 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Ubisoft
[2012.02.08 12:29:12 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\VitySoft
[2012.06.14 03:30:45 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
< MD5 for: AGP440.SYS >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2012.04.24 06:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=06E771AA596B8761107AB57E99F128D7 -- C:\Windows\SysWOW64\cryptsvc.dll
[2012.04.24 06:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=06E771AA596B8761107AB57E99F128D7 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_77ff39f3f916c65f\cryptsvc.dll
[2010.11.21 05:24:16 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll
[2012.04.24 06:28:22 | 000,142,336 | ---- | M] (Microsoft Corporation) MD5=21993009E0CCB9B4FA195F14D3408626 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_7854c7b7125b248c\cryptsvc.dll
[2012.04.24 07:37:37 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=4F5414602E2544A4554D95517948B705 -- C:\Windows\SysNative\cryptsvc.dll
[2012.04.24 07:37:37 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=4F5414602E2544A4554D95517948B705 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_d41dd577b1743795\cryptsvc.dll
[2010.11.21 05:24:32 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
[2012.04.24 07:22:32 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=B7337E9C9E5936355BB700AA33E0936E -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_d473633acab895c2\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: IASTORV.SYS >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\isapnp.sys
< MD5 for: LSASS.EXE >
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
[2011.11.17 08:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\SysNative\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
< MD5 for: NDIS.SYS >
[2010.11.21 05:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\SysNative\drivers\ndis.sys
[2010.11.21 05:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys
< MD5 for: NETLOGON.DLL >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVRAID.SYS >
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\drivers\nvraid.sys
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2010.11.21 05:23:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.21 05:23:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011.03.11 08:19:21 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SMSS.EXE >
[2009.07.14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\SysNative\smss.exe
[2009.07.14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
< MD5 for: SVCHOST.EXE >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2011.09.29 19:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010.11.21 05:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012.03.30 12:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2011.04.25 07:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011.04.25 08:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.09.29 18:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WS2_32.DLL >
[2010.11.21 05:24:28 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.21 05:24:28 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2010.11.21 05:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.21 05:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
< >
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\Windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.RTV1 - rtvcvfw32.dll File not found
Drivers32: vidc.VP60 - C:\Windows\system32\vp6vfw.dll File not found
Drivers32: vidc.VP61 - C:\Windows\system32\vp6vfw.dll File not found
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2012.07.05 11:30:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.07.05 10:55:09 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{F156E791-6BF7-499A-B184-7C3C0178F8A9}
[2012.07.05 10:54:57 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{47EAD36E-E5F0-45AA-946E-6E49335ADF11}
[2012.07.05 10:24:15 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Rhonwyn\Desktop\OTL.exe
[2012.07.05 09:26:32 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.07.05 09:26:32 | 000,000,000 | ---D | C] -- C:\rsit
[2012.07.04 18:33:19 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\ANNO 2070
[2012.07.04 08:41:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.07.04 08:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.07.04 08:27:42 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Roaming\SUPERAntiSpyware.com
[2012.07.04 08:27:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.07.04 08:27:29 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012.07.04 08:27:29 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.07.04 07:28:16 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Roaming\Malwarebytes
[2012.07.04 07:28:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.04 07:28:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.04 07:28:03 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.04 07:28:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.02 20:39:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012.07.01 12:34:29 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Desktop\j,bljhb
[2012.06.30 13:11:14 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\x360ce.App-2.0.2.158
[2012.06.30 13:01:47 | 000,014,976 | ---- | C] (Headsoft) -- C:\Windows\SysNative\drivers\vjoy.sys
[2012.06.30 13:01:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VJoy
[2012.06.30 13:01:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VJoy
[2012.06.30 12:47:30 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\PCSX2
[2012.06.30 12:39:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BrowserCompanion
[2012.06.30 12:39:44 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Desktop\PSX Emulator
[2012.06.24 14:35:09 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{27A2645C-4C29-4DB5-9EA7-1FE11F8AE68E}
[2012.06.24 14:34:56 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{B9A923BE-72A0-469C-8CB0-1DC5860A0157}
[2012.06.22 22:02:14 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\WB Games
[2012.06.22 21:59:03 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\Downloaded Installations
[2012.06.20 16:02:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.20 16:02:31 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.20 16:02:30 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.20 16:02:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012.06.19 22:49:38 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\Macromedia
[2012.06.19 20:55:11 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{303EDC14-2EEA-4336-BBE1-12FA52A59F9E}
[2012.06.19 20:54:59 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{948EE042-3D55-4735-8DFB-5048A29AA362}
[2012.06.19 06:21:34 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012.06.19 06:21:34 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012.06.19 06:21:34 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012.06.19 06:21:25 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012.06.19 06:21:25 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012.06.19 06:21:25 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012.06.19 06:21:14 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012.06.19 06:21:14 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012.06.18 12:20:26 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{06086E9A-F30A-43AC-B5DB-C962E24FD482}
[2012.06.17 14:32:14 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\Documents\Star Wars - The Old Republic
[2012.06.14 03:00:55 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.06.14 03:00:54 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.06.14 03:00:54 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.06.14 03:00:54 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.06.14 03:00:53 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.06.14 03:00:53 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.06.14 03:00:53 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.06.14 03:00:53 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.06.14 03:00:52 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.06.14 03:00:52 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.06.14 03:00:52 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.06.14 03:00:52 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.06.14 03:00:52 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.06.13 18:08:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2012.06.13 18:07:24 | 000,198,088 | ---- | C] (Aladdin Knowledge Systems Ltd.) -- C:\Windows\SysWow64\hlvdd.dll
[2012.06.13 18:07:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mosaic
[2012.06.13 08:55:56 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012.06.13 08:55:56 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012.06.13 08:55:56 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012.06.13 08:55:46 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012.06.13 08:55:46 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012.06.13 08:55:45 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012.06.13 08:55:41 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012.06.13 08:55:39 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012.06.13 08:55:39 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012.06.12 09:53:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.06.11 10:00:51 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\Mozilla
[2012.06.11 10:00:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.06.11 10:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.06.11 09:56:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012.06.11 09:55:32 | 000,000,000 | ---D | C] -- C:\bb3101f1d1cc1083cadb8bbb
[2012.06.10 21:47:32 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{57D0F6C1-591B-4960-AFF7-B997557E6C5E}
[2012.06.10 21:47:09 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{C8002E9B-08F0-406F-B422-127F67FF250F}
[2012.06.10 09:46:56 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{47C60257-DF0C-4A47-9B2C-2F7D896DF557}
[2012.06.10 09:46:34 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{77431036-60D6-48D3-BAD6-F5326C27B360}
[2012.06.09 21:46:20 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{82B29E13-ADAF-476A-B87E-C36BA218AB92}
[2012.06.09 21:45:58 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{914D2F62-D399-4943-9474-50CB1E573D89}
[2012.06.09 09:45:34 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{D2341CC2-91D7-499A-9E0D-BBC5AE7D9590}
[2012.06.09 09:44:35 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{51C01981-9AC9-480F-AB96-D1F843C11212}
[2012.06.08 21:28:22 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{AC5545E4-3597-4B0C-BD42-D5DBB4D8B2C8}
[2012.06.08 21:28:00 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{A6BD5862-0126-4123-9143-3D1D3B338232}
[2012.06.08 09:27:47 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{F1B78D52-9FD0-4A54-845E-DCA8C231AAA8}
[2012.06.08 09:27:24 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{372C5BCE-DE38-4D26-9711-44C86DCD838F}
[2012.06.07 21:27:12 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{F7685F82-2CA8-46D2-87EC-7B7D31EB112E}
[2012.06.07 21:26:50 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{E5DEE870-333E-4FCE-8D2D-787B0528A673}
[2012.06.07 09:26:37 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{BD6A2723-0299-419A-B16B-6D7A52385BDA}
[2012.06.07 09:26:15 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{42595AEC-CE6F-4EF7-8988-9D9C2461F9E6}
[2012.06.06 21:26:02 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{7F943F83-B136-4766-9330-CC205AF9A115}
[2012.06.06 21:25:40 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{92BB5273-6D28-4F52-9CC8-9796B84AE031}
[2012.06.06 09:25:28 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{3556D5F3-BEF5-465A-B3B6-30F3B37B7998}
[2012.06.06 09:25:06 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{847D13B1-5871-49AC-ACB4-8B436F128DAF}
[2012.06.05 21:24:52 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{DF92DF96-8615-4F57-9031-935DCC6EDF22}
[2012.06.05 21:24:30 | 000,000,000 | ---D | C] -- C:\Users\Rhonwyn\AppData\Local\{72856626-2B9C-4A87-80CD-1CE3F6FEE587}
========== Files - Modified Within 30 Days ==========
[2012.07.05 12:56:30 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.07.05 12:53:03 | 2134,204,415 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.05 12:44:23 | 000,022,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.05 12:44:23 | 000,022,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.05 12:37:11 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys
[2012.07.05 12:17:01 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012.07.05 10:42:09 | 000,388,470 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\cannot create file.png
[2012.07.05 10:24:21 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Rhonwyn\Desktop\OTL.exe
[2012.07.04 08:41:57 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.04 08:27:36 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.07.04 07:28:07 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.02 20:39:41 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012.07.02 20:39:32 | 001,602,266 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.07.02 20:39:32 | 000,668,322 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2012.07.02 20:39:32 | 000,654,066 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.02 20:39:32 | 000,140,918 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012.07.02 20:39:32 | 000,121,898 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.30 19:30:39 | 000,002,413 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\Google Chrome.lnk
[2012.06.30 12:50:19 | 000,040,928 | ---- | M] () -- C:\Windows\SysNative\drivers\VSPE.sys
[2012.06.30 12:40:01 | 000,000,250 | ---- | M] () -- C:\user.js
[2012.06.28 21:30:11 | 000,000,626 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\net.rtf
[2012.06.23 11:25:08 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.06.23 11:25:08 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.06.22 13:31:09 | 000,019,233 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\purple_shoes.jpg
[2012.06.22 09:51:42 | 000,000,221 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\Batman Arkham City.url
[2012.06.20 16:02:43 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.15 16:56:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.14 03:30:38 | 000,292,456 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 03:11:42 | 001,596,116 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.13 18:08:16 | 000,001,166 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.06.13 18:07:16 | 000,001,234 | ---- | M] () -- C:\Users\Rhonwyn\Desktop\Mosaic.lnk
[2012.06.12 09:53:31 | 000,001,134 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
========== Files Created - No Company Name ==========
[2012.07.05 10:42:09 | 000,388,470 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\cannot create file.png
[2012.07.05 10:29:45 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.07.04 08:41:57 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.04 08:27:36 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.07.04 07:28:07 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.02 20:39:41 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012.07.02 20:39:37 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012.06.30 16:16:16 | 002,660,349 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\100_1412.JPG
[2012.06.30 12:50:19 | 000,040,928 | ---- | C] () -- C:\Windows\SysNative\drivers\VSPE.sys
[2012.06.30 12:40:01 | 000,000,250 | ---- | C] () -- C:\user.js
[2012.06.30 09:29:58 | 000,000,242 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\Dead Space™ 2.lnk
[2012.06.27 11:26:35 | 002,039,299 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\100_1410.JPG
[2012.06.22 13:31:03 | 000,019,233 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\purple_shoes.jpg
[2012.06.22 09:51:41 | 000,000,221 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\Batman Arkham City.url
[2012.06.20 16:02:43 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.13 18:08:16 | 000,001,178 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.06.13 18:08:16 | 000,001,166 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.06.13 18:07:16 | 000,001,234 | ---- | C] () -- C:\Users\Rhonwyn\Desktop\Mosaic.lnk
[2012.06.12 09:53:31 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.06.12 09:53:31 | 000,001,134 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.05.12 17:01:57 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2012.05.01 14:39:17 | 000,006,144 | ---- | C] () -- C:\Users\Rhonwyn\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.04.04 12:24:14 | 000,280,976 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.04.04 12:24:13 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.03.28 23:33:10 | 000,000,542 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.02.14 22:31:22 | 001,602,266 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.02.01 19:36:18 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2012.02.01 19:28:46 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012.02.01 19:23:49 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2012.02.01 19:19:05 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.02.01 19:16:21 | 000,003,113 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.12.15 07:23:04 | 010,920,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011.12.15 07:23:04 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2011.12.15 07:23:04 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.09.28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.10.05 01:59:32 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\StarOpen.sys
========== LOP Check ==========
[2012.05.12 17:13:32 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Atari
[2012.07.04 08:46:48 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\DAEMON Tools Lite
[2012.02.19 15:03:15 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\EVEMon
[2012.07.04 18:00:42 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\GetRightToGo
[2012.06.19 18:08:19 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\GHISLER
[2012.04.30 15:05:17 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Leadertech
[2012.03.24 11:06:09 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Might & Magic Heroes VI - Game Official Demo
[2012.04.21 09:40:24 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Mount&Blade Warband
[2012.02.05 21:09:04 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Mumble
[2012.03.05 22:57:23 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Need for Speed World
[2012.04.17 17:02:25 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\OpenOffice.org
[2012.04.07 19:50:05 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Origin
[2012.02.24 14:01:19 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\PhotoFiltre
[2012.02.05 14:01:50 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\POINTERGHOSTV1
[2012.04.04 12:24:13 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\PunkBuster
[2012.03.02 10:26:33 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Rift
[2012.03.24 09:42:50 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Scoregasm
[2012.02.01 19:24:36 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Splashtop
[2012.02.02 21:04:53 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Sports Interactive
[2012.07.04 08:46:44 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\TS3Client
[2012.07.04 18:00:17 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\Ubisoft
[2012.02.08 12:29:12 | 000,000,000 | ---D | M] -- C:\Users\Rhonwyn\AppData\Roaming\VitySoft
[2012.06.14 03:30:45 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
< MD5 for: AGP440.SYS >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2012.04.24 06:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=06E771AA596B8761107AB57E99F128D7 -- C:\Windows\SysWOW64\cryptsvc.dll
[2012.04.24 06:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=06E771AA596B8761107AB57E99F128D7 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_77ff39f3f916c65f\cryptsvc.dll
[2010.11.21 05:24:16 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll
[2012.04.24 06:28:22 | 000,142,336 | ---- | M] (Microsoft Corporation) MD5=21993009E0CCB9B4FA195F14D3408626 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_7854c7b7125b248c\cryptsvc.dll
[2012.04.24 07:37:37 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=4F5414602E2544A4554D95517948B705 -- C:\Windows\SysNative\cryptsvc.dll
[2012.04.24 07:37:37 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=4F5414602E2544A4554D95517948B705 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_d41dd577b1743795\cryptsvc.dll
[2010.11.21 05:24:32 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
[2012.04.24 07:22:32 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=B7337E9C9E5936355BB700AA33E0936E -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_d473633acab895c2\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: IASTORV.SYS >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\isapnp.sys
< MD5 for: LSASS.EXE >
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
[2011.11.17 08:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\SysNative\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
< MD5 for: NDIS.SYS >
[2010.11.21 05:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\SysNative\drivers\ndis.sys
[2010.11.21 05:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys
< MD5 for: NETLOGON.DLL >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVRAID.SYS >
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\drivers\nvraid.sys
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2010.11.21 05:23:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.21 05:23:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011.03.11 08:19:21 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SMSS.EXE >
[2009.07.14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\SysNative\smss.exe
[2009.07.14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
< MD5 for: SVCHOST.EXE >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2011.09.29 19:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010.11.21 05:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012.03.30 12:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2011.04.25 07:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011.04.25 08:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.09.29 18:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WS2_32.DLL >
[2010.11.21 05:24:28 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.21 05:24:28 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2010.11.21 05:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.21 05:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
< >