Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.orgDatabase version: v2012.01.12.03
Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
User :: USER-PC [administrator]
Protection: Disabled
12/1/2012 9:39:46 PM
mbam-log-2012-01-12 (21-39-46).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 189861
Time elapsed: 10 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 24
HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (Adware.Funshion) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\CLSID\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\TypeLib\{F9BC0421-BB5C-447d-8547-BB45AFA80A4D} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\Interface\{4D89001B-5B5B-4E76-A1F5-638E49DB7A58} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\AddressSearch.JsObject.1 (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\AddressSearch.JsObject (Adware.Funshion) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\TypeLib\{D02E3AB9-7796-40cb-BDFC-20D834FE1F75} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\ASBarBroker.BDBroker.1 (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\ASBarBroker.BDBroker (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\CLSID\{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86} (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\AddressSearch.SnavHttpProtocol.1 (Adware.Funshion) -> Quarantined and deleted successfully.
HKCR\AddressSearch.SnavHttpProtocol (Adware.Funshion) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{77FEF28E-EB96-44FF-B511-3185DEA48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77FEF28E-EB96-44FF-B511-3185DEA48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A7F05EE4-0426-454F-8013-C41E3596E9E9} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKCR\thunder (Trojan.Agent) -> Delete on reboot.
HKLM\SOFTWARE\Baidu (Trojan.Cinmus) -> Quarantined and deleted successfully.
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Data: eÏ€µQáÃI·?p±?ÊŽ† -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Data: -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Æô¶¯ Internet Explorer ä¯ÀÀÆ÷.lnk (Hijack.Trace) -> Quarantined and deleted successfully.
C:\Users\User\Favorites\ÌÔ±¦Íø - ÌÔ£¡ÎÒϲ»¶.url (Malware.Trace) -> Quarantined and deleted successfully.
(end)
OTL logfile created on: 12/1/2012 9:55:47 PM - Run 4
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\User\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00004409 | Country: Malaysia | Language: ENM | Date Format: d/M/yyyy
2.97 Gb Total Physical Memory | 1.92 Gb Available Physical Memory | 64.80% Memory free
5.93 Gb Paging File | 4.82 Gb Available in Paging File | 81.31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.99 Gb Total Space | 120.34 Gb Free Space | 41.93% Space Free | Partition Type: NTFS
Drive F: | 442.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/11/29 18:34:16 | 000,194,160 | ---- | M] (深圳市迅雷网络技术有限公司) -- C:\Program Files\Thunder Network\Xmp\Program\XMP.exe
PRC - [2011/08/18 08:22:38 | 024,182,160 | ---- | M] (Dropbox, Inc.) -- C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/07/15 12:52:53 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
PRC - [2011/06/09 11:14:38 | 000,439,744 | ---- | M] (PPLive Corporation) -- C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010/12/20 14:42:04 | 000,217,088 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2010/01/22 18:42:06 | 000,462,336 | ---- | M] () -- C:\Program Files\Autodesk\Inventor 2011\Moldflow\bin\mitsijm.exe
PRC - [2009/11/16 09:04:30 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009/11/16 09:03:32 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2009/10/03 02:28:09 | 002,969,600 | ---- | M] (ANSYS, Inc.) -- C:\Program Files\ANSYS Inc\Shared Files\Licensing\win32\ansysli_server.exe
PRC - [2009/10/03 02:28:08 | 001,290,240 | ---- | M] () -- C:\Program Files\ANSYS Inc\Shared Files\Licensing\win32\ansysli_monitor.exe
PRC - [2009/07/14 09:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/14 09:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/14 09:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009/05/21 05:29:24 | 001,703,936 | ---- | M] (ANSYS, Inc.) -- C:\Program Files\ANSYS Inc\Shared Files\Licensing\win32\ansyslmd.exe
PRC - [2009/05/21 05:29:24 | 001,462,024 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\ANSYS Inc\Shared Files\Licensing\win32\lmgrd.exe
PRC - [2009/05/01 13:52:24 | 000,082,600 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 2400 Series\ezprint.exe
PRC - [2009/05/01 13:52:22 | 000,291,496 | ---- | M] () -- C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
PRC - [2009/02/20 09:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2008/09/03 13:47:00 | 000,712,704 | ---- | M] (AuthenTec, Inc) -- C:\Program Files\TrueSuite Access Manager\FpNotifier.exe
PRC - [2008/09/02 07:06:00 | 000,049,152 | ---- | M] (AuthenTec Inc.) -- C:\Windows\System32\TAMSvr.exe
PRC - [2008/08/26 01:58:20 | 000,077,824 | ---- | M] (Toshiba) -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
PRC - [2008/07/25 15:41:56 | 000,094,208 | ---- | M] () -- C:\Program Files\TrueSuite Access Manager\usbnotify.exe
PRC - [2008/07/18 20:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/04/25 04:03:12 | 000,430,080 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
PRC - [2008/04/17 15:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2008/03/20 05:35:44 | 000,716,800 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2008/02/07 05:52:52 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2008/02/07 05:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2007/12/04 09:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/22 08:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2007/09/29 08:03:46 | 000,075,136 | ---- | M] ( TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
PRC - [2007/06/16 13:01:58 | 000,448,080 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2007/03/12 13:49:46 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007/03/12 13:49:26 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007/02/12 16:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
PRC - [2006/12/11 12:12:06 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxcrcoms.exe
PRC - [2006/08/24 08:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (SafeList) ========== MOD - [2011/07/15 12:52:53 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
MOD - [2009/07/14 09:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (WPFFontCache_v0400)
SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/12/15 10:03:35 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011/10/14 15:32:40 | 000,087,728 | ---- | M] (ShenZhen Xunlei Networking Technologies,LTD) [Auto | Running] -- C:\Program Files\Common Files\Thunder Network\ServicePlatform\XLSP.dll -- (XLServicePlatform)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/03/22 22:34:49 | 001,045,256 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/12/20 14:42:04 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010/01/22 18:42:06 | 000,462,336 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\Inventor 2011\Moldflow\bin\mitsijm.exe -- (mitsijm2011)
SRV - [2009/11/16 09:12:54 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009/11/16 09:04:30 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2009/10/03 02:28:09 | 002,969,600 | ---- | M] (ANSYS, Inc.) [Auto | Running] -- C:\Program Files\ANSYS Inc\Shared Files\Licensing\win32\ansysli_server.exe -- (ANSYS, Inc. License Manager)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/02/20 09:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2008/09/02 07:06:00 | 000,049,152 | ---- | M] (AuthenTec Inc.) [Auto | Running] -- C:\Windows\System32\TAMSvr.exe -- (Authentec memory manager)
SRV - [2008/08/26 01:58:20 | 000,077,824 | ---- | M] (Toshiba) [On_Demand | Running] -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe -- (SmartFaceVWatchSrv)
SRV - [2008/07/18 20:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/05/29 07:20:16 | 000,164,600 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/04/17 15:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2008/04/12 03:57:14 | 000,124,264 | ---- | M] (TOSHIBA CORPORATION) [Auto | Stopped] -- C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2008/02/07 05:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/04 09:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/22 08:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/02/12 16:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
SRV - [2006/12/11 12:12:06 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxcrcoms.exe -- (lxcr_device)
SRV - [2006/08/24 08:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ========== DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/06/02 13:47:22 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/06/02 13:47:22 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2011/06/02 13:47:22 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd) SAMSUNG Android USB Diagnostic Serial Port (WDM)
DRV - [2011/06/02 13:47:22 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2010/12/21 13:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/12/20 14:42:04 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010/11/24 08:55:50 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/11/24 08:55:50 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2010/11/24 08:55:50 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/02/16 23:02:02 | 000,021,504 | ---- | M] (
http://www.atmel.com) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
DRV - [2009/11/16 09:06:52 | 000,095,896 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV - [2009/11/16 09:03:36 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009/11/16 08:56:12 | 000,116,520 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamon.sys -- (eamon)
DRV - [2009/07/14 09:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 09:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 09:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 07:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 07:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/14 06:09:17 | 004,194,816 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/07/14 06:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009/07/14 06:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2008/08/14 09:52:00 | 000,146,944 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atswpdrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2008/07/25 15:41:36 | 000,042,608 | ---- | M] (Alfa Corporation) [File_System | Boot | Running] -- C:\Windows\system32\Drivers\AlfaFF.sys -- (AlfaFF)
DRV - [2008/07/16 11:59:06 | 000,017,960 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2008/05/06 16:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2008/04/15 10:13:14 | 000,051,160 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2media.sys -- (O2MDRDR)
DRV - [2008/03/04 10:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/12/15 02:53:24 | 000,024,200 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2007/11/10 06:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/10/17 07:36:00 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2006/10/24 08:32:20 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?brand=TSHS&bmod=TSHSIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/redirectdomain?brand=TSHS&bmod=TSHSIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.facemoods.com/?a=ddrIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/DapCtrl: C:\Program Files\Common Files\Thunder Network\KanKan\npDapCtrl.3.1.0.1.(489).dll (ShenZhen Thunder Networking Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/DapCtrlPlugin: C:\Program Files\Common Files\Thunder Network\KanKan\npDapCtrlFirefox.2.0.5901.12.(500).dll (ShenZhen Thunder Networking Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\User\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/10/12 20:13:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/03/14 15:47:54 | 000,000,000 | ---D | M]
[2010/09/10 14:19:24 | 000,305,152 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npuuseep.dll
[2010/12/13 20:36:54 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchddr.xml
O1 HOSTS File: ([2006/09/19 05:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (ѸÀ×FLVÊÓÆµÐá̽¼°ÏÂÔØÖ§³Ö) - {0EA37B17-6B8B-4085-8257-F3A4AA69C27A} - C:\Program Files\Thunder Network\Thunder\BHO\XlBrowserAddin1.0.5.64.dll (ShenZhen Xunlei Networking Technologies,LTD)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - File not found
O2 - BHO: (ѸÀ×ÏÂÔØÖ§³Ö) - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.2.3.3254.dll (深圳市迅雷网络技术有限公司)
O2 - BHO: (A57CDFD3-A6CA-35CC-F001-C57C13EA7093 Class) - {A57CDFD3-A6CA-35CC-F001-C57C13EA7093} - File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 2400 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [FingerPrintNotifer] C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [LXCRCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [lxcrmon.exe] C:\Program Files\Lexmark 2400 Series\lxcrmon.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Facebook Update] C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [PPAP] C:\Program Files\Common Files\PPLiveNetwork\PPAP.EXE (PPLive Corporation)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - HKCU..\Run: [XMP] c:\program files\thunder network\xmp\program\XMP.exe (深圳市迅雷网络技术有限公司)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: OldEnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ʹÓÃ&ѸÀ×ÀëÏßÏÂÔØ - C:\Program Files\Thunder Network\Thunder\BHO\OfflineDownload.htm ()
O8 - Extra context menu item: &ʹÓÃ&ѸÀ×ÏÂÔØ - C:\Program Files\Thunder Network\Thunder\BHO\geturl.htm ()
O8 - Extra context menu item: &ʹÓÃ&ѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Thunder Network\Thunder\BHO\getAllurl.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: 使用迅雷看看播放器播放 - C:\Users\Public\Thunder Network\XMP4\Core\program\XmpIEMenu.htm ()
O9 - Extra Button: ²é¿´ÍøÒ³È«²¿Í¼Æ¬ - {548BF84E-9665-47f9-B635-7380F8943E90} - C:\Program Files\Thunder Network\Thunder\Program\repairimage.htm ()
O9 - Extra 'Tools' menuitem : ²é¿´ÍøÒ³È«²¿Í¼Æ¬ - {548BF84E-9665-47f9-B635-7380F8943E90} - C:\Program Files\Thunder Network\Thunder\Program\repairimage.htm ()
O9 - Extra Button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPTV\PPLive.exe (PPLive Corporation)
O9 - Extra 'Tools' menuitem : PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPTV\PPLive.exe (PPLive Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\Thunder Network\NetMon\net_monitor1.0.2.25.dll (Thunder Networking Technologies,LTD)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\Thunder Network\NetMon\net_monitor1.0.2.25.dll (Thunder Networking Technologies,LTD)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\Thunder Network\NetMon\net_monitor1.0.2.25.dll (Thunder Networking Technologies,LTD)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\Thunder Network\NetMon\net_monitor1.0.2.25.dll (Thunder Networking Technologies,LTD)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop Components:0 () -
O24 - Desktop WallPaper: C:\TOSHIBA\Wallpapers\wallpaper1.jpg
O24 - Desktop BackupWallPaper: C:\TOSHIBA\Wallpapers\wallpaper1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/06/14 14:43:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/01/29 04:00:27 | 000,000,088 | ---- | M] () - F:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{83906294-44bd-11e0-9d2c-001e651e719e}\Shell - "" = AutoRun
O33 - MountPoints2\{83906294-44bd-11e0-9d2c-001e651e719e}\Shell\AutoRun\command - "" = F:\WD SmartWare.exe -- [2010/01/22 08:13:40 | 003,330,848 | ---- | M] (Western Digital)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012/01/12 21:59:40 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{0069C927-F766-47AC-A203-63B6FD58421C}
[2012/01/12 21:59:27 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D7760EEB-E2FF-475F-8383-B11FE8004B9E}
[2012/01/12 21:34:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/12 21:34:15 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/01/12 21:34:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/12 21:01:53 | 010,847,608 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\User\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/12 20:53:00 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\TFC.exe
[2012/01/12 20:35:45 | 000,000,000 | -HSD | C] -- C:\found.000
[2012/01/12 09:34:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{344D042B-5661-49E2-9015-88A7A3E3BA13}
[2012/01/12 09:34:38 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{0F6A9D4F-EBB8-4022-BAF2-E9E1DC4ECD12}
[2012/01/11 21:34:09 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5880A93D-BF72-4910-A951-C92A875F1259}
[2012/01/11 21:33:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{6BD5C460-709A-40A7-A21D-1A5196D42E0F}
[2012/01/11 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{3FBF76E8-4770-417C-98EA-603D73CE05E0}
[2012/01/11 09:33:11 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DEF81166-C5D6-4CED-A592-1FE749AE9B30}
[2012/01/10 21:32:42 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{1B9936C3-1112-4884-ADEE-381B02FAD770}
[2012/01/10 21:32:29 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{039B2D85-BB68-4E94-B64A-3C910C26C516}
[2012/01/10 09:32:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{F034060F-07FC-4475-93EC-AD49A1A61C88}
[2012/01/10 09:31:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D0F307B7-3D8E-411E-A8EF-4CD9D6D17A62}
[2012/01/09 21:55:56 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Time Table
[2012/01/09 21:31:18 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{04D10EF8-175B-481A-9736-10B0F7934D2F}
[2012/01/09 21:31:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{9C863E6B-4B59-47D1-BF3E-4ACA8E8EC8A9}
[2012/01/09 09:30:48 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DC989E70-F6C1-4EE0-BA8B-2FAF4D637E44}
[2012/01/09 09:30:34 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{87AD55F4-3E03-43A8-9454-0A82C7808182}
[2012/01/08 21:30:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{014530B8-1CD4-4B3D-9F67-C07D834FB9D2}
[2012/01/08 09:29:34 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C90D7D97-B6AF-4987-8D8B-93B98C56A116}
[2012/01/08 09:29:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{14C9865F-B17D-4D01-84C1-A7031B0D88D3}
[2012/01/07 21:28:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{79BC198B-B6C6-4E90-B47C-ABAFADF05ADA}
[2012/01/07 21:28:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B44BFCAB-505D-42FE-8A01-72C371280987}
[2012/01/07 09:28:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FA0AA5DF-A49C-4008-B8DF-02EC7443C6BB}
[2012/01/07 09:27:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E67506AF-DA73-4602-BEA0-F8058FDC922E}
[2012/01/06 19:56:20 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{43AEBB6D-FABF-4441-B4FB-3463F1982489}
[2012/01/06 19:56:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{BE2258ED-9847-425E-8E66-668C0555D409}
[2012/01/06 07:55:34 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A55CD12D-FA73-4C50-B9B2-CA26EBB9DC29}
[2012/01/06 07:55:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{24ECC6AE-755D-4DD6-98D9-5465253D92A5}
[2012/01/06 01:31:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{178D2777-3623-4F3B-9500-09B35FA32114}
[2012/01/05 12:16:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{91A15CD3-2068-4139-B02A-57CF07AE10E1}
[2012/01/05 12:15:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{1CA4B3EF-ECBE-46D3-961C-6E005FB02B17}
[2012/01/04 23:11:33 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B16D1911-65B5-46AE-A045-73319A4CF264}
[2012/01/04 23:11:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{4AAA10F4-307E-447F-BCE3-CA0DC30FE70E}
[2012/01/04 11:11:01 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CA68780E-9DC9-4B4D-80BF-0FB051B54082}
[2012/01/04 11:10:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{6E9DCBE0-26BC-4EB9-AA28-D2FED68C1202}
[2012/01/03 23:10:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DAD5581D-44F7-4017-8231-30FF58188E2C}
[2012/01/03 23:10:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{04EBD48A-BA35-4373-BC01-A3CD721211DB}
[2012/01/03 11:09:41 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{011D4F10-D290-4AAA-8AA4-6A4631FAA7B1}
[2012/01/03 11:09:25 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{7B5AA534-F9F3-475C-812C-E07B612A5855}
[2012/01/02 23:08:56 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C3467F92-AE05-4E14-BAA3-02B4BC5BA50E}
[2012/01/02 23:08:41 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A7D75564-B7ED-466D-8173-A378EE7CF6B6}
[2012/01/02 11:08:25 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{ECE3F714-5D45-4507-8084-F70E991076C3}
[2012/01/02 11:08:12 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B818D0E1-6095-469A-BD9C-C02F4AF1B540}
[2012/01/01 21:59:37 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C365B506-6A61-431C-815D-B931684E850E}
[2012/01/01 21:59:22 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{562A07E0-D05B-4E31-B1B7-E4A2F71FA558}
[2012/01/01 09:59:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B253834D-7F90-44EB-B21A-2E67B5779F56}
[2012/01/01 09:58:54 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{02BD3376-21FA-4DD5-9535-30612C0EBD3E}
[2011/12/31 21:55:59 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CB2D0C1F-2B8F-4A03-8883-140435B3E47C}
[2011/12/31 21:55:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5CDE5497-51C9-40FA-B700-D4B29B9E956B}
[2011/12/31 09:55:27 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{62C51678-9ADF-455B-A475-4959E066B554}
[2011/12/31 09:55:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{90ED7CCE-9663-4CDD-9776-57E82E365BFD}
[2011/12/30 14:17:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D14A8FDE-5184-41D2-87AE-32B8DBC33130}
[2011/12/30 14:16:52 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{8EE077EA-25EE-4C4C-9EB9-F7F793DF1A93}
[2011/12/30 02:16:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{75A7EF83-BD22-4567-8857-E72351B56CA2}
[2011/12/30 02:16:03 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{51F78886-E2C4-4525-B7D0-09176106B7E4}
[2011/12/29 20:21:06 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2011/12/29 20:20:56 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\AVS4YOU
[2011/12/29 20:17:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2011/12/29 20:17:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2011/12/29 20:16:04 | 011,137,024 | ---- | C] (Intel Corporation) -- C:\Windows\System32\libmfxsw32.dll
[2011/12/29 20:15:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVSMedia
[2011/12/29 20:15:13 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\GdiPlus.dll
[2011/12/29 20:15:13 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3a.dll
[2011/12/29 20:15:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVS4YOU
[2011/12/29 12:54:32 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DB68AF7C-BE38-4A9A-B90F-B122285170AF}
[2011/12/29 12:54:16 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{F602FCE5-79A2-407E-AE08-9D024949C640}
[2011/12/29 01:00:58 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\anshelp
[2011/12/29 00:53:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E6C2EEAA-E079-4240-8830-AEFBE8174BA3}
[2011/12/29 00:53:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{AFFDBEBB-5D2B-4FA3-B81B-FF2934106957}
[2011/12/28 23:04:39 | 000,000,000 | ---D | C] -- C:\ProgramData\ANSYSInstall
[2011/12/28 23:03:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Ansys
[2011/12/28 23:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ANSYS 12.1
[2011/12/28 22:29:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Macrovision
[2011/12/28 22:23:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ANSYS, Inc. License Manager
[2011/12/28 22:23:22 | 000,000,000 | ---D | C] -- C:\Program Files\ANSYS Inc
[2011/12/28 22:22:24 | 000,000,000 | ---D | C] -- C:\ANSYS Inc
[2011/12/28 12:53:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A8B067C8-BE24-4F99-BE9C-B6B3E1E97538}
[2011/12/28 12:52:55 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A529AC08-C690-4057-BA37-33C1BFBAAB0D}
[2011/12/28 00:52:25 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A3EB0B3F-099B-4F76-B410-1D2127E3339D}
[2011/12/28 00:51:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5E96A52F-F63F-4F7A-8D16-325A799916B6}
[2011/12/27 08:27:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{42588F23-5A7C-4424-84B8-4A48D5F5D7E5}
[2011/12/27 08:26:49 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{EB0426A8-866E-4F05-B3C1-3F9B8703CEB1}
[2011/12/26 13:56:37 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{89028489-E87C-47E9-AF9C-92AF81C5731E}
[2011/12/26 13:56:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{766DA921-7962-4003-B812-9B260C9FB20D}
[2011/12/26 01:55:55 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{159AD3CC-9393-4740-802C-473AD0DB87A3}
[2011/12/26 01:55:42 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A397AC52-403A-40D1-9473-A9C19829D5A4}
[2011/12/25 13:55:14 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{077E699F-F636-412F-AFA4-81272ED2AF20}
[2011/12/25 13:55:01 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{EDD91ED8-1F0A-4618-A968-6C0AECD7C916}
[2011/12/25 01:54:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5DDEBA33-D82B-4813-A498-826CEB4ED15A}
[2011/12/25 01:54:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{678EBE5E-F8E6-44CF-B62E-E1FD09F0EE8C}
[2011/12/24 11:27:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{4EC8D359-2EEE-4094-B004-A0D8F6773DF8}
[2011/12/24 11:27:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{7DA65B13-22D4-4516-9683-E71C321DFAEA}
[2011/12/24 01:48:27 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
[2011/12/24 01:48:25 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDJ
[2011/12/24 01:48:23 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\VirtualDJ
[2011/12/23 23:26:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{93A94263-1730-4149-872A-E628D40CC125}
[2011/12/23 23:26:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{412DC794-ADAC-44DA-AFE0-59E10904B72E}
[2011/12/23 08:40:25 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{16DFA543-A8BC-49FB-B56E-A1D81F9AA0A3}
[2011/12/23 08:40:12 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{858B1400-30D0-49D1-B9BA-DEE7E9DC5D04}
[2011/12/22 20:37:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FD4E8E2F-6C7D-4475-BFED-427BB376CF29}
[2011/12/22 20:37:18 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{10E24754-64B2-474E-BDC8-10BE070A2CCB}
[2011/12/22 08:36:49 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{266337B3-A7DF-45B1-BC17-98080F170A23}
[2011/12/22 08:36:35 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D2AB6647-6B7F-4081-87C3-05202AB96A59}
[2011/12/21 20:36:05 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E8B5F8EE-08C5-40CD-9677-658C37DC6FAB}
[2011/12/21 20:35:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{8957A9EB-B1A3-4198-B3C4-61EFF8291B26}
[2011/12/21 13:46:24 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\My EndNote Library.Data
[2011/12/21 10:42:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Risxtd
[2011/12/21 10:42:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ResearchSoft
[2011/12/21 10:42:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote
[2011/12/21 10:42:05 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EndNote
[2011/12/21 10:41:19 | 000,000,000 | ---D | C] -- C:\Program Files\EndNote X5
[2011/12/21 10:36:20 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\EndNote
[2011/12/21 10:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Thomson.ResearchSoft.Installers
[2011/12/21 08:35:09 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B048C6F4-5A13-449B-9293-7F1B88BA6A2B}
[2011/12/21 08:34:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E9CD8023-30EE-4D56-97CF-13AA2E4B1A00}
[2011/12/20 18:43:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{67E62248-9F9A-4C51-9141-CADAD2BCCF7C}
[2011/12/20 18:43:32 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{42C99853-8D6E-4DE9-B51A-00B337259CF4}
[2011/12/20 00:40:48 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{4B685733-1011-4EEA-9B8E-3E071F0F00F1}
[2011/12/20 00:40:35 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{99D4C316-5135-41DA-9739-00C30BC811C2}
[2011/12/19 12:40:18 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{19F5E4E4-98A5-47D1-BA9A-76EF5685715B}
[2011/12/19 12:40:05 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{3F838259-1864-42EF-9E80-E8A38B30732F}
[2011/12/19 00:39:34 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D1C564E3-4656-488D-A959-B32771F614BD}
[2011/12/19 00:39:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{9F05C88F-57A4-4CB9-97C0-BB182E3B98BD}
[2011/12/18 12:39:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{19678C42-B2FC-4319-AD14-9304BB4A2243}
[2011/12/18 12:38:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{3B234D1C-E599-454B-952A-1B73AB35E86E}
[2011/12/18 00:38:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FEF12182-277D-4B3C-88A6-58EB42441A17}
[2011/12/18 00:38:02 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{87BD89C9-4EAC-406C-BCA6-EBDD6E27F158}
[2011/12/17 12:37:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{27BC5CB5-1297-4DD5-ADF9-2532372AD56E}
[2011/12/17 12:37:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E3855965-8D6E-4232-8539-4C2EAC939F35}
[2011/12/17 00:36:59 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{909BF084-5114-4917-85ED-1BEB57024864}
[2011/12/17 00:36:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{87637081-B90A-4366-8BE1-23C0BB9878F8}
[2011/12/16 12:36:28 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{08F2344E-6002-4171-92E5-0F169D95AF3B}
[2011/12/16 12:36:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A4FBF35E-3577-41B9-B633-2B7B0A0F571A}
[2011/12/16 00:35:46 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{8692E21A-C214-41A2-AB62-08D87A2F28ED}
[2011/12/16 00:35:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{417F3E7C-CB9A-4EFF-9608-CD69BD6F20D4}
[2011/12/15 12:35:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{AC6C4359-8B84-4BF0-A399-F62E4414B6D2}
[2011/12/15 12:34:59 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FED91FDC-3759-4179-AC52-45197E64AE00}
[2011/12/15 00:34:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{2D358CBF-7D6A-4FD6-8062-82BC19E30175}
[2011/12/15 00:34:16 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A37BDD45-E547-4754-B2FD-F6E66469A94D}
[2011/12/14 12:33:59 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B1AC74C3-BDF6-44A7-97F4-153A6A475B63}
[2011/12/14 12:33:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{8C86ABBA-09FB-40DB-8263-EB5D077DFF5E}
[2011/12/14 00:33:16 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{23E4C2E3-429F-427C-9E41-385B85B311E3}
[2011/12/14 00:33:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CD38CDE8-B060-4F54-88FC-03C1CAAB42C1}
[2011/03/17 09:09:51 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxcrserv.dll
[2011/03/17 09:09:51 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxcrusb1.dll
[2011/03/17 09:09:51 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxcrcomc.dll
[2011/03/17 09:09:51 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxcrpmui.dll
[2011/03/17 09:09:51 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxcrlmpm.dll
[2011/03/17 09:09:51 | 000,537,520 | ---- | C] ( ) -- C:\Windows\System32\lxcrcoms.exe
[2011/03/17 09:09:51 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxcrcomm.dll
[2011/03/17 09:09:51 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxcrinpa.dll
[2011/03/17 09:09:51 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxcriesc.dll
[2011/03/17 09:09:51 | 000,385,968 | ---- | C] ( ) -- C:\Windows\System32\lxcrih.exe
[2011/03/17 09:09:51 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXCRhcp.dll
[2011/03/17 09:09:51 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxcrprox.dll
[2011/03/17 09:09:51 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxcrpplc.dll
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/01/12 21:57:23 | 006,329,208 | ---- | M] () -- C:\Users\User\Desktop\Wonder Girls - The DJ Is Mine (320kbps) [www.k2nblog.com].rar.crdownload
[2012/01/12 21:54:16 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/12 21:54:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/12 21:53:53 | 2388,287,488 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/12 21:49:48 | 000,000,025 | ---- | M] () -- C:\Users\User\AppData\Roaming\CoreAVC.ini
[2012/01/12 21:49:28 | 000,137,728 | ---- | M] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/12 21:37:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/12 21:34:17 | 000,001,078 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/12 21:32:43 | 000,721,876 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/01/12 21:32:43 | 000,145,776 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/01/12 21:32:24 | 010,847,608 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\User\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/12 21:07:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2536658832-274290432-161746704-1000UA.job
[2012/01/12 20:53:22 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\TFC.exe
[2012/01/12 20:17:44 | 000,006,768 | ---- | M] () -- C:\bootsqm.dat
[2012/01/12 19:39:05 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2536658832-274290432-161746704-1000UA.job
[2012/01/11 10:39:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2536658832-274290432-161746704-1000Core.job
[2012/01/10 23:00:36 | 005,134,295 | ---- | M] () -- C:\Users\User\Desktop\Kim Dong Ryul- Like a Child (Ft Alex).mp3
[2012/01/10 21:39:38 | 001,408,423 | ---- | M] () -- C:\Users\User\Desktop\scan0002.pdf
[2012/01/10 16:49:20 | 000,002,969 | ---- | M] () -- C:\Users\User\Desktop\HiJackThis.lnk
[2012/01/08 23:05:57 | 002,007,556 | ---- | M] () -- C:\Users\User\Desktop\Keihin_Carb_ Manual.pdf
[2012/01/08 23:01:21 | 001,257,462 | ---- | M] () -- C:\Users\User\Desktop\vmmanual.pdf
[2012/01/08 14:31:51 | 000,870,578 | ---- | M] () -- C:\Users\User\Desktop\p81a.pdf
[2012/01/08 14:31:22 | 000,960,962 | ---- | M] () -- C:\Users\User\Desktop\p61a.pdf
[2012/01/08 14:29:59 | 000,627,811 | ---- | M] () -- C:\Users\User\Desktop\p39a.pdf
[2012/01/08 09:30:36 | 000,038,520 | ---- | M] () -- C:\Users\User\Desktop\Presentation EME3056.zip
[2012/01/08 02:41:15 | 000,005,872 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/08 02:41:15 | 000,005,872 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/07 10:08:33 | 000,002,403 | ---- | M] () -- C:\Users\User\Desktop\Google Chrome.lnk
[2012/01/04 19:12:43 | 001,327,922 | ---- | M] () -- C:\Users\User\Desktop\cmme tut with ht note.zip
[2011/12/30 07:07:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2536658832-274290432-161746704-1000Core.job
[2011/12/30 02:06:14 | 000,544,464 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/29 20:17:12 | 000,001,170 | ---- | M] () -- C:\Users\User\Desktop\AVS Video Editor.lnk
[2011/12/28 22:32:55 | 000,000,285 | ---- | M] () -- C:\Users\User\Documents\LICSERVER.INFO
[2011/12/24 01:48:33 | 000,001,015 | ---- | M] () -- C:\Users\User\Deskt