O3 - HKCU\..\Toolbar\WebBrowser: (RadioBar Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files (x86)\RadioBar\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKCU\..\Toolbar\WebBrowser: (BittorrentBar_FR Toolbar) - {EF79F67A-6AD7-4715-A0F8-932FCA442023} - File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\
AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Netdrive] C:\Program Files\MacroData Inc\NetDrive\netdrive.exe (MacroData Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [Gadwin PrintScreen] C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
O4 - HKCU..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.)
O4 - HKCU..\Run: [RegistryBooster] File not found
O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [RockMelt Update] C:\Users\pierre_2\AppData\Local\RockMelt\Update\RockMeltUpdate.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883}
http://content.systemrequirementslab.co ... 1.71.0.cab (Reg Error: Key error.)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/ms ... b56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\toolbarchrome {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\toolbarchrome {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - C:\Program Files (x86)\RadioBar\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O18:
64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2503a7e0-8205-11df-bc9b-c80aa9395e41}\Shell - "" = AutoRun
O33 - MountPoints2\{2503a7e0-8205-11df-bc9b-c80aa9395e41}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{dfc58c8f-c4d5-11df-84f9-c80aa9395e41}\Shell - "" = AutoRun
O33 - MountPoints2\{dfc58c8f-c4d5-11df-84f9-c80aa9395e41}\Shell\AutoRun\command - "" = H:\NokiaPCIA_Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: ezSharedSvc - C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
========== Files/Folders - Created Within 30 Days ========== [2011/03/07 09:30:26 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\pierre_2\Desktop\OTL(2).exe
[2011/03/07 09:21:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/03/07 09:21:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2011/03/07 09:19:25 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\pierre_2\Desktop\erunt-setup.exe
[2011/03/07 09:14:47 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\pierre_2\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/07 09:13:21 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\pierre_2\Desktop\OTL.exe
[2011/03/05 23:22:51 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\AppData\Local\moovida Air
[2011/03/05 21:46:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moovida
[2011/03/05 21:46:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fluendo
[2011/03/01 19:33:05 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\Desktop\Video Copilot Presets
[2011/02/28 19:21:27 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GordonSYS CA 1.5.2
[2011/02/28 19:21:25 | 000,000,000 | ---D | C] -- C:\CA-Cheats.eu GordonSYS 1.5.2
[2011/02/25 23:41:43 | 000,000,000 | ---D | C] -- C:\Nexon
[2011/02/24 12:33:31 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\Desktop\wido0w
[2011/02/24 12:31:29 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\Desktop\After effect
[2011/02/24 11:55:39 | 000,000,000 | ---D | C] -- C:\AECS3PRESETSPATH
[2011/02/24 11:55:32 | 000,000,000 | ---D | C] -- C:\AECS3PLUGINPATH
[2011/02/24 11:10:38 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\Desktop\Tutoriel - After Effect - Planète
[2011/02/23 11:22:25 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YAMB
[2011/02/23 11:22:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAMB
[2011/02/23 11:22:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YAMB
[2011/02/23 11:11:18 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yamb 2.1.0.0 beta 2
[2011/02/23 11:11:18 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\AppData\Roaming\Yamb
[2011/02/22 21:22:02 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011/02/22 21:22:01 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011/02/22 21:22:01 | 000,475,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011/02/22 21:22:01 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/02/16 15:27:52 | 000,000,000 | ---D | C] -- C:\Users\pierre_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Alphajet PAFVirtu
[2011/02/11 12:33:44 | 000,000,000 | ---D | C] -- C:\528db2a6aacd93ccd9535c
[2011/02/10 17:11:48 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2011/02/10 17:11:47 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011/02/10 17:11:47 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011/02/10 17:11:47 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011/02/10 17:11:47 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/02/10 17:11:47 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/02/10 17:11:47 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011/02/10 17:11:47 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011/02/10 17:11:47 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011/02/10 17:11:47 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011/02/10 17:11:46 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011/02/10 17:11:46 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011/02/10 17:11:07 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\upnp.dll
[2011/02/10 17:11:07 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\upnp.dll
[2011/02/10 17:11:05 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2011/02/10 17:11:05 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscapi.dll
[2011/02/10 17:11:04 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\davclnt.dll
[2011/02/10 17:11:04 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll
[2011/02/10 17:11:04 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll
[2011/02/10 17:11:04 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll
[2011/02/10 17:11:02 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2011/02/10 17:11:00 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011/02/10 17:11:00 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10warp.dll
[2011/02/10 17:11:00 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/02/10 17:11:00 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll
[2011/02/10 17:10:59 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011/02/10 17:10:59 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/02/10 17:10:59 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll
[2011/02/10 17:10:58 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011/02/10 17:10:58 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2011/02/10 17:10:58 | 000,265,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/02/10 17:10:58 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011/02/10 17:10:58 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll
[2011/02/10 17:10:58 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2011/02/10 17:10:58 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011/02/10 17:10:57 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll
[2011/02/10 17:10:57 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011/02/10 17:10:40 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/02/10 17:10:40 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/02/10 17:10:40 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011/02/10 17:10:37 | 005,510,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2011/02/10 17:10:37 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2011/02/10 17:10:37 | 003,901,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2011/02/10 17:10:37 | 001,739,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2011/02/10 17:10:34 | 000,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2011/02/10 17:10:34 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2011/02/10 17:10:34 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2011/02/10 17:10:34 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2010/10/20 12:12:44 | 1714,928,233 | ---- | C] (gPotato.eu ) -- C:\Program Files (x86)\Rappelz_FR_Resurrection.exe
[195 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[195 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[11 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/03/07 09:30:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\pierre_2\Desktop\OTL(2).exe
[2011/03/07 09:23:11 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-2505101734-1179181130-3986266462-1003UA.job
[2011/03/07 09:21:10 | 000,000,928 | ---- | M] () -- C:\Users\pierre_2\Desktop\NTREGOPT.lnk
[2011/03/07 09:21:10 | 000,000,909 | ---- | M] () -- C:\Users\pierre_2\Desktop\ERUNT.lnk
[2011/03/07 09:19:35 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\pierre_2\Desktop\erunt-setup.exe
[2011/03/07 09:19:22 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/07 09:19:21 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/07 09:15:59 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\pierre_2\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/07 09:13:38 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\pierre_2\Desktop\OTL.exe
[2011/03/07 09:09:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/07 09:09:35 | 2211,602,432 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/07 09:05:05 | 000,001,577 | ---- | M] () -- C:\Users\pierre_2\Desktop\Reprendre le téléchargement - Adobe_After_Effects_CS5__Français_Windows64-bit.lnk
[2011/03/07 09:03:43 | 000,060,171 | ---- | M] () -- C:\Users\pierre_2\Desktop\Crack + info adobe after effect cs5.rar
[2011/03/05 21:23:00 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-2505101734-1179181130-3986266462-1003Core.job
[2011/02/27 17:05:30 | 000,000,600 | ---- | M] () -- C:\Users\pierre_2\PUTTY.RND
[2011/02/27 16:32:18 | 012,519,100 | ---- | M] () -- C:\Users\pierre_2\Desktop\360-WMD.avi
[2011/02/27 15:27:40 | 204,893,186 | ---- | M] () -- C:\Users\pierre_2\Desktop\Lego Starw Wars.avi
[2011/02/27 11:41:31 | 016,419,904 | ---- | M] () -- C:\Users\pierre_2\Desktop\Lego Starw Wars.mov-1.mp4
[2011/02/26 13:50:11 | 012,465,190 | ---- | M] () -- C:\Users\pierre_2\Desktop\baston v2.avi
[2011/02/25 23:41:42 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011/02/25 23:41:41 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011/02/25 22:04:07 | 012,491,430 | ---- | M] () -- C:\Users\pierre_2\Desktop\baston.avi
[2011/02/25 19:59:28 | 008,907,462 | ---- | M] () -- C:\Users\pierre_2\Desktop\IMG_0331.MOV
[2011/02/25 14:07:20 | 008,932,314 | ---- | M] () -- C:\Users\pierre_2\Desktop\boule d'nergie pierre.avi
[2011/02/25 12:52:38 | 010,071,898 | ---- | M] () -- C:\Users\pierre_2\Desktop\eclair pierre.avi
[2011/02/25 12:48:20 | 000,089,989 | ---- | M] () -- C:\Users\pierre_2\Desktop\Light_Saber.wav
[2011/02/23 13:50:54 | 054,763,230 | ---- | M] () -- C:\Users\pierre_2\Documents\top 5.avi
[2011/02/23 13:37:17 | 000,121,899 | ---- | M] () -- C:\Users\pierre_2\Documents\Projet sans titre.aep
[2011/02/17 11:53:18 | 733,652,992 | ---- | M] () -- C:\Users\pierre_2\Desktop\Largo Winch.avi
[2011/02/11 16:09:54 | 004,945,272 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/02/06 20:46:58 | 001,549,700 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/02/06 20:46:58 | 000,704,794 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2011/02/06 20:46:58 | 000,616,304 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/02/06 20:46:58 | 000,131,254 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2011/02/06 20:46:58 | 000,106,684 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/02/05 23:26:51 | 000,335,889 | ---- | M] () -- C:\Users\pierre_2\Documents\Document.odt
[195 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[195 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[11 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/03/07 09:21:10 | 000,000,928 | ---- | C] () -- C:\Users\pierre_2\Desktop\NTREGOPT.lnk
[2011/03/07 09:21:10 | 000,000,909 | ---- | C] () -- C:\Users\pierre_2\Desktop\ERUNT.lnk
[2011/03/07 09:03:19 | 000,060,171 | ---- | C] () -- C:\Users\pierre_2\Desktop\Crack + info adobe after effect cs5.rar
[2011/03/07 09:02:27 | 000,001,577 | ---- | C] () -- C:\Users\pierre_2\Desktop\Reprendre le téléchargement - Adobe_After_Effects_CS5__Français_Windows64-bit.lnk
[2011/03/05 21:46:34 | 000,001,129 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moovida.lnk
[2011/02/27 16:31:12 | 012,519,100 | ---- | C] () -- C:\Users\pierre_2\Desktop\360-WMD.avi
[2011/02/27 15:12:31 | 204,893,186 | ---- | C] () -- C:\Users\pierre_2\Desktop\Lego Starw Wars.avi
[2011/02/27 11:39:32 | 016,419,904 | ---- | C] () -- C:\Users\pierre_2\Desktop\Lego Starw Wars.mov-1.mp4
[2011/02/26 13:48:38 | 012,465,190 | ---- | C] () -- C:\Users\pierre_2\Desktop\baston v2.avi
[2011/02/25 23:41:42 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011/02/25 21:39:49 | 012,491,430 | ---- | C] () -- C:\Users\pierre_2\Desktop\baston.avi
[2011/02/25 19:46:37 | 008,907,462 | ---- | C] () -- C:\Users\pierre_2\Desktop\IMG_0331.MOV
[2011/02/25 14:05:26 | 008,932,314 | ---- | C] () -- C:\Users\pierre_2\Desktop\boule d'nergie pierre.avi
[2011/02/25 12:50:18 | 010,071,898 | ---- | C] () -- C:\Users\pierre_2\Desktop\eclair pierre.avi
[2011/02/25 12:48:08 | 000,089,989 | ---- | C] () -- C:\Users\pierre_2\Desktop\Light_Saber.wav
[2011/02/23 13:39:29 | 054,763,230 | ---- | C] () -- C:\Users\pierre_2\Documents\top 5.avi
[2011/02/17 11:36:56 | 733,652,992 | ---- | C] () -- C:\Users\pierre_2\Desktop\Largo Winch.avi
[2011/02/05 23:26:50 | 000,335,889 | ---- | C] () -- C:\Users\pierre_2\Documents\Document.odt
[2010/11/30 12:24:23 | 000,003,630 | ---- | C] () -- C:\Users\pierre_2\AppData\Local\index.html
[2010/10/26 15:08:21 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010/10/26 15:08:20 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2010/10/26 15:08:20 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2010/10/19 13:33:08 | 000,000,008 | ---- | C] () -- C:\Users\pierre_2\AppData\Roaming\DofusAppId0_3
[2010/10/19 13:30:35 | 000,000,008 | ---- | C] () -- C:\Users\pierre_2\AppData\Roaming\DofusAppId0_1
[2010/10/19 12:44:43 | 000,000,177 | ---- | C] () -- C:\Users\pierre_2\AppData\Roaming\D2Info0
[2010/10/19 12:39:20 | 000,000,008 | ---- | C] () -- C:\Users\pierre_2\AppData\Roaming\DofusAppId0_2
[2010/10/03 19:11:27 | 000,000,364 | ---- | C] () -- C:\Users\pierre_2\AppData\Roaming\burnaware.ini
[2010/10/01 22:08:51 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010/09/29 19:59:11 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2010/09/03 15:26:05 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2010/08/25 17:00:13 | 000,011,264 | ---- | C] () -- C:\Windows\SysWow64\Utils.dll
[2010/07/04 12:04:38 | 000,173,903 | ---- | C] () -- C:\Users\pierre_2\AppData\Roaming\NMM-MetaData.db
[2010/07/04 11:57:38 | 000,013,824 | ---- | C] () -- C:\Users\pierre_2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/02 10:02:41 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/06/28 18:12:40 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010/06/28 18:12:32 | 002,337,865 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2010/06/28 18:12:32 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010/06/14 20:15:03 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/06/13 14:34:00 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
[2010/06/13 14:28:47 | 000,035,328 | ---- | C] () -- C:\Windows\SysWow64\INETWH32.DLL
[2010/03/18 01:29:01 | 000,000,282 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini
[2010/03/18 01:29:01 | 000,000,223 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini
[2009/11/14 10:42:36 | 000,009,868 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2009/11/14 08:31:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/09/29 15:25:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007/03/29 22:00:40 | 000,203,264 | R--- | C] () -- C:\Windows\SysWow64\CddbCdda.dll
[2002/09/17 23:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
[1998/09/14 20:43:16 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\TWAIN32d.dll
========== LOP Check ========== [2010/10/19 13:41:32 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\app
[2010/06/27 17:08:24 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Astroburn Pro
[2010/07/04 18:22:46 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\BitComet
[2011/03/05 23:13:41 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\BitTorrent
[2010/06/28 17:55:33 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Canneverbe Limited
[2010/07/02 10:02:37 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\CometNetwork
[2010/07/16 09:34:57 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\CrazyLoader
[2010/06/27 17:07:34 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\DAEMON Tools Lite
[2010/10/19 14:28:12 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Dofus 2
[2010/10/19 12:39:21 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/10/19 13:33:09 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/10/19 13:44:33 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/09/11 22:01:23 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Ethereal
[2011/02/17 11:39:03 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\FileZilla
[2010/07/03 12:52:50 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\flightgear.org
[2010/07/03 12:46:39 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\fltk.org
[2010/09/29 19:59:15 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\FreeAudioPack
[2010/10/31 13:40:56 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\FreeCDRipper
[2010/12/14 20:39:45 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\gtk-2.0
[2010/09/29 14:40:06 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\MixVibes
[2010/12/23 15:21:17 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\MP3SkypeRecorder
[2011/02/04 13:59:07 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Mumble
[2011/01/27 07:07:54 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\NetDrive
[2010/11/29 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Nokia
[2010/10/09 07:37:35 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Notepad++
[2010/12/28 21:32:42 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\OfferBox
[2010/12/26 22:13:53 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\OnLive App
[2010/09/27 18:12:05 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\OpenOffice.org
[2010/07/04 12:03:13 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\PC Suite
[2010/09/11 08:05:11 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Pro Cycling Manager 2009
[2010/09/11 22:15:41 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Pro Cycling Manager 2010
[2010/12/31 11:19:08 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Publish Providers
[2011/01/08 18:38:54 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\REAPER
[2010/10/19 13:41:32 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/11/03 18:35:38 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Screaming Bee
[2010/06/28 09:37:21 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Sierra Entertainment
[2011/01/31 18:14:11 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Sony
[2010/08/25 12:13:16 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/10/01 22:07:37 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Ubisoft
[2010/08/08 21:19:01 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\WildTangent
[2011/02/23 11:14:54 | 000,000,000 | ---D | M] -- C:\Users\pierre_2\AppData\Roaming\Yamb
[2011/03/05 21:23:00 | 000,000,888 | ---- | M] () -- C:\Windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-2505101734-1179181130-3986266462-1003Core.job
[2011/03/07 09:23:11 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-2505101734-1179181130-3986266462-1003UA.job
[2011/02/17 15:33:55 | 000,032,482 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
< MD5 for: ATAPI.SYS >[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
< MD5 for: CNGAUDIT.DLL >[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CTFMON.EXE >[2009/07/14 02:39:02 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=42B6A94DD747DF2B5F628A2752E62A98 -- C:\Windows\SysNative\ctfmon.exe
[2009/07/14 02:39:02 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=42B6A94DD747DF2B5F628A2752E62A98 -- C:\Windows\winsxs\amd64_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.1.7600.16385_none_f9257e7aaa4290ce\ctfmon.exe
[2009/07/14 02:14:16 | 000,008,704 | ---- | M] (Microsoft Corporation) MD5=4A3CDCEF8ED41B221F3DBEF5792FB52D -- C:\Windows\SysWOW64\ctfmon.exe
[2009/07/14 02:14:16 | 000,008,704 | ---- | M] (Microsoft Corporation) MD5=4A3CDCEF8ED41B221F3DBEF5792FB52D -- C:\Windows\winsxs\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.1.7600.16385_none_9d06e2f6f1e51f98\ctfmon.exe
< MD5 for: EVENTLOG.DLL >[2007/05/17 21:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
< MD5 for: EXPLORER.EXE >[2010/03/18 10:24:14 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2010/03/18 10:24:14 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2009/08/03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2010/03/18 10:24:14 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2009/08/03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/03/18 10:24:14 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe
< MD5 for: IASTORV.SYS >[2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >[2009/07/14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009/07/14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >[2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
< MD5 for: SCECLI.DLL >[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
< MD5 for: USERINIT.EXE >[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
< MD5 for: WININIT.EXE >[2009/07/14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009/07/14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009/07/14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009/07/14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >[2009/07/14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[195 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >< End of report >