O33 - MountPoints2\{2b5fba38-609c-11e1-9781-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{2b5fba38-609c-11e1-9781-00262d6687ae}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2d542b6d-b060-11df-87fc-f449ec9a4553}\Shell - "" = AutoRun
O33 - MountPoints2\{2d542b6d-b060-11df-87fc-f449ec9a4553}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2d542b7d-b060-11df-87fc-f449ec9a4553}\Shell - "" = AutoRun
O33 - MountPoints2\{2d542b7d-b060-11df-87fc-f449ec9a4553}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2df5c158-b24b-11df-a4a5-daa85ca5f450}\Shell - "" = AutoRun
O33 - MountPoints2\{2df5c158-b24b-11df-a4a5-daa85ca5f450}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2df5c187-b24b-11df-a4a5-daa85ca5f450}\Shell - "" = AutoRun
O33 - MountPoints2\{2df5c187-b24b-11df-a4a5-daa85ca5f450}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{3867eb8a-d733-11e1-a4c3-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{3867eb8a-d733-11e1-a4c3-00262d6687ae}\Shell\AutoRun\command - "" = E:\Setup.exe /Auto
O33 - MountPoints2\{4f7ca30e-6006-11e1-a4b7-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{4f7ca30e-6006-11e1-a4b7-00262d6687ae}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{825ea06b-f38c-11de-851d-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{825ea06b-f38c-11de-851d-00262d6687ae}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{8d468b87-db65-11e1-9075-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{8d468b87-db65-11e1-9075-00262d6687ae}\Shell\AutoRun\command - "" = E:\.\Setup.exe AUTORUN=1
O33 - MountPoints2\{9ba05f86-5a7d-11e1-94b3-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{9ba05f86-5a7d-11e1-94b3-00262d6687ae}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\{a2cfaa8a-3323-11e1-9544-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{a2cfaa8a-3323-11e1-9544-00262d6687ae}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{a2cfaa99-3323-11e1-9544-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{a2cfaa99-3323-11e1-9544-00262d6687ae}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{ac492bd2-5f8b-11e0-93eb-dac7f61ab93d}\Shell - "" = AutoRun
O33 - MountPoints2\{ac492bd2-5f8b-11e0-93eb-dac7f61ab93d}\Shell\AutoRun\command - "" = E:\.\ShowModem.exe
O33 - MountPoints2\{b8fc976c-b6f0-11df-929f-9988dce4bc41}\Shell - "" = AutoRun
O33 - MountPoints2\{b8fc976c-b6f0-11df-929f-9988dce4bc41}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{d5b1d222-4ab8-11e1-a4cd-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{d5b1d222-4ab8-11e1-a4cd-00262d6687ae}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{e937e4b9-c167-11e1-9869-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{e937e4b9-c167-11e1-9869-00262d6687ae}\Shell\AutoRun\command - "" = E:\.\Setup.exe AUTORUN=1
O33 - MountPoints2\{f041e910-7686-11e1-92c6-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{f041e910-7686-11e1-92c6-00262d6687ae}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{f80820d4-874c-11e1-b459-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f80820d4-874c-11e1-b459-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe /Auto
O33 - MountPoints2\{f9786a76-a9d5-11e1-afe7-00262d6687ae}\Shell - "" = AutoRun
O33 - MountPoints2\{f9786a76-a9d5-11e1-afe7-00262d6687ae}\Shell\AutoRun\command - "" = E:\.\Setup.exe AUTORUN=1
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\.\Setup.exe AUTORUN=1
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ========== [2012/08/14 12:34:22 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/08/14 12:28:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/08/14 12:28:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2012/08/14 12:25:24 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\user\Desktop\erunt-setup.exe
[2012/08/14 12:15:11 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2012/08/14 09:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/08/11 15:08:51 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{E0A81ABA-9799-430D-8B94-0C667376BACF}
[2012/08/08 16:23:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Malwarebytes
[2012/08/08 16:23:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/08 16:23:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/08 16:23:34 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/08 16:23:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/06 03:27:42 | 000,000,000 | ---D | C] -- C:\Windows\fr
[2012/08/06 03:05:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2012/08/06 03:00:02 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/08/06 02:00:17 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{1AB07BBA-41FE-4C0D-9F9A-20018A3BBC93}
[2012/08/06 01:59:12 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{7414E2BF-A395-496D-88C4-94E291CFA906}
[2012/08/04 10:30:52 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Simply Super Software
[2012/08/04 10:30:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2012/08/04 10:30:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2012/08/04 10:30:28 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Simply Super Software
[2012/08/04 10:30:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2012/08/04 09:23:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Health
[2012/08/04 09:23:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HDD Health
[2012/08/04 08:02:57 | 000,051,496 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\stflt.sys
[2012/08/04 08:02:32 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Spyware Terminator
[2012/08/04 08:02:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Spyware Terminator
[2012/08/04 08:02:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012
[2012/08/04 06:34:48 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012/08/04 06:15:34 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/08/04 06:15:31 | 000,019,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys
[2012/08/02 23:46:55 | 000,120,832 | ---- | C] (TCT International Mobile Ltd) -- C:\Windows\SysNative\drivers\jrdusbser.sys
[2012/08/02 23:46:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HSPA USB MODEM
[2012/08/02 23:46:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HSPA USB MODEM
[2012/08/02 13:54:05 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\SkinSoft
[2012/08/02 13:53:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Connectify
[2012/08/02 13:52:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Connectify
[2012/08/02 13:52:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Connectify
[2012/08/02 13:12:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gophoto.it
[2012/08/02 13:11:59 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Mozilla
[2012/08/02 12:57:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\smartdl
[2012/08/02 12:53:49 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Vuze Downloads
[2012/08/02 12:43:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/08/02 12:42:35 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Babylon
[2012/08/02 12:42:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012/08/02 12:42:14 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\ExpressFiles
[2012/08/02 12:42:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ExpressFiles
[2012/08/02 12:29:13 | 000,000,000 | ---D | C] -- C:\Users\user\.swt
[2012/08/02 12:29:09 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Azureus
[2012/07/30 17:46:56 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\ZTEMTUI
[2012/07/30 13:32:08 | 000,102,240 | ---- | C] (DEVGURU Co., LTD.(
www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2012/07/28 19:38:21 | 000,000,000 | ---D | C] -- C:\Hotspot Shield
[2012/07/28 03:47:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/07/26 16:51:40 | 000,124,160 | ---- | C] (Incorporated) -- C:\Windows\SysNative\drivers\CT_U_USBSER.sys
[2012/07/24 20:11:54 | 000,041,704 | ---- | C] (AnchorFree Inc.) -- C:\Windows\SysNative\drivers\hssdrv6.sys
[2012/07/24 01:15:23 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{DD726CCF-DEF7-4AB4-8AA6-6B6BC2B691EF}
[2012/07/24 01:15:10 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{E6B0F519-6D16-4419-9CAA-BBB3B16138CE}
[2012/07/24 01:14:25 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{9E7BC138-2CBD-4FFC-BC59-BB1A877F7E17}
[2012/07/24 01:14:12 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{00D73346-A3CD-4689-BD4F-8377C04E2C8E}
[2012/07/24 01:14:01 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{B53D6974-04A1-4ED4-A6B4-962DA2EAB036}
[2012/07/24 01:13:46 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{AE53E95B-7663-4234-8322-9F7E219ECC84}
[2012/07/24 01:13:31 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{C56C112D-F129-4BDD-A34F-689C5BE93021}
[2012/07/24 01:13:18 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{72008D76-15DC-46A2-9C66-67538C86E0B5}
[2012/07/24 00:17:06 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{FABFAC95-85D9-4F02-8773-D368742BC1AC}
[2012/07/15 19:34:36 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{7C5FE201-B6CD-4048-B1E0-CA8DD28A0CB2}
[2012/07/15 19:31:34 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{A79CE528-F772-4FBD-B41F-DE8E7BB87694}
[2012/07/15 19:30:10 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{D341C4F1-37F2-4DBD-A2BD-F8D81B72A2A4}
[2012/03/15 21:04:21 | 002,823,304 | ---- | C] (Citrix Systems, Inc.) -- C:\Users\user\ica32t.exe
[2009/10/29 05:58:47 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\user\Desktop\*.tmp files -> C:\Users\user\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/08/14 13:00:55 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012/08/14 12:28:14 | 000,001,068 | ---- | M] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/08/14 12:28:12 | 000,000,869 | ---- | M] () -- C:\Users\user\Desktop\ERUNT.lnk
[2012/08/14 12:26:00 | 000,005,024 | ---- | M] () -- C:\Users\user\Desktop\erunt-loc_fr.zip
[2012/08/14 12:25:27 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\user\Desktop\erunt-setup.exe
[2012/08/14 12:23:00 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/14 12:15:49 | 000,000,417 | ---- | M] () -- C:\Users\user\Desktop\scan.zip
[2012/08/14 12:15:18 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2012/08/14 12:13:02 | 000,001,438 | ---- | M] () -- C:\Users\user\Desktop\HijackThis.exe - Raccourci.lnk
[2012/08/14 11:17:05 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1071871065-2305765665-148178615-1000UA.job
[2012/08/14 10:49:14 | 000,198,449 | ---- | M] () -- C:\Users\user\Desktop\00-PAD-nickW.pdf
[2012/08/14 10:12:35 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/14 10:12:35 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/14 10:12:27 | 001,570,468 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/14 10:12:27 | 000,711,842 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2012/08/14 10:12:27 | 000,623,288 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/08/14 10:12:27 | 000,133,946 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2012/08/14 10:12:27 | 000,109,410 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/08/14 10:04:41 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/14 10:04:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/14 10:04:14 | 2360,020,992 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/14 09:43:29 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/08/14 09:41:57 | 000,001,926 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/08/14 02:12:18 | 003,436,216 | ---- | M] () -- C:\Users\user\Desktop\depliant_multi_projet.pdf
[2012/08/12 23:17:00 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1071871065-2305765665-148178615-1000Core.job
[2012/08/12 11:54:21 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012/08/12 11:54:21 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012/08/08 16:25:51 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/04 11:21:45 | 000,006,576 | ---- | M] () -- C:\bootsqm.dat
[2012/08/04 10:30:34 | 000,001,103 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2012/08/04 08:02:57 | 000,051,496 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\stflt.sys
[2012/08/04 08:02:29 | 000,001,002 | ---- | M] () -- C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
[2012/08/02 23:46:52 | 000,001,935 | ---- | M] () -- C:\Users\Public\Desktop\HSPA USB MODEM.lnk
[2012/08/02 13:53:23 | 000,000,995 | ---- | M] () -- C:\Users\Public\Desktop\Connectify.lnk
[2012/08/02 13:51:05 | 010,123,850 | ---- | M] () -- C:\Users\user\Cntfy.3.4.rar
[2012/08/02 13:12:06 | 000,384,844 | ---- | M] () -- C:\Users\user\AppData\Local\funmoods-speeddial.crx
[2012/08/02 12:44:07 | 000,000,098 | ---- | M] () -- C:\user.js
[2012/08/02 12:28:43 | 000,000,009 | ---- | M] () -- C:\END
[2012/08/02 09:11:16 | 000,262,564 | ---- | M] () -- C:\Users\user\KT02.07r7.pdf
[2012/08/02 09:10:28 | 000,027,479 | ---- | M] () -- C:\Users\user\CNCOH-01-12.pdf
[2012/08/02 09:08:40 | 000,395,763 | ---- | M] () -- C:\Users\user\AUTORISATION_PRG_RAM_ETE_2012[1].pdf
[2012/08/02 08:44:48 | 000,154,134 | ---- | M] () -- C:\Users\user\Carnet_d'annonces_v4.pdf
[2012/07/30 13:32:08 | 000,102,240 | ---- | M] (DEVGURU Co., LTD.(
www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2012/07/26 22:08:29 | 000,131,072 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2012/07/24 20:11:54 | 000,041,704 | ---- | M] (AnchorFree Inc.) -- C:\Windows\SysNative\drivers\hssdrv6.sys
[2012/07/24 00:56:35 | 000,017,214 | ---- | M] () -- C:\Users\user\Mon film.wlmp
[2012/07/19 19:32:59 | 000,000,664 | RHS- | M] () -- C:\Users\user\ntuser.pol
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\user\Desktop\*.tmp files -> C:\Users\user\Desktop\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/08/14 13:00:55 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012/08/14 12:28:14 | 000,001,068 | ---- | C] () -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/08/14 12:28:12 | 000,000,869 | ---- | C] () -- C:\Users\user\Desktop\ERUNT.lnk
[2012/08/14 12:26:00 | 000,005,024 | ---- | C] () -- C:\Users\user\Desktop\erunt-loc_fr.zip
[2012/08/14 12:15:48 | 000,000,417 | ---- | C] () -- C:\Users\user\Desktop\scan.zip
[2012/08/14 12:13:02 | 000,001,438 | ---- | C] () -- C:\Users\user\Desktop\HijackThis.exe - Raccourci.lnk
[2012/08/14 10:49:14 | 000,198,449 | ---- | C] () -- C:\Users\user\Desktop\00-PAD-nickW.pdf
[2012/08/14 09:41:57 | 000,001,926 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/08/14 02:12:27 | 003,436,216 | ---- | C] () -- C:\Users\user\Desktop\depliant_multi_projet.pdf
[2012/08/08 16:23:39 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/05 15:51:11 | 000,002,845 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Online Plug-in.lnk
[2012/08/04 11:21:45 | 000,006,576 | ---- | C] () -- C:\bootsqm.dat
[2012/08/04 10:30:34 | 000,001,103 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2012/08/04 10:30:31 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012/08/04 10:30:31 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012/08/04 08:02:29 | 000,001,002 | ---- | C] () -- C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
[2012/08/02 23:46:52 | 000,001,935 | ---- | C] () -- C:\Users\Public\Desktop\HSPA USB MODEM.lnk
[2012/08/02 13:53:23 | 000,000,995 | ---- | C] () -- C:\Users\Public\Desktop\Connectify.lnk
[2012/08/02 13:50:49 | 010,123,850 | ---- | C] () -- C:\Users\user\Cntfy.3.4.rar
[2012/08/02 13:12:19 | 000,384,844 | ---- | C] () -- C:\Users\user\AppData\Local\funmoods-speeddial.crx
[2012/08/02 12:44:07 | 000,000,098 | ---- | C] () -- C:\user.js
[2012/08/02 12:28:42 | 000,000,009 | ---- | C] () -- C:\END
[2012/08/02 09:11:14 | 000,262,564 | ---- | C] () -- C:\Users\user\KT02.07r7.pdf
[2012/08/02 09:10:27 | 000,027,479 | ---- | C] () -- C:\Users\user\CNCOH-01-12.pdf
[2012/08/02 09:08:40 | 000,395,763 | ---- | C] () -- C:\Users\user\AUTORISATION_PRG_RAM_ETE_2012[1].pdf
[2012/08/02 08:44:47 | 000,154,134 | ---- | C] () -- C:\Users\user\Carnet_d'annonces_v4.pdf
[2012/07/15 19:30:18 | 000,017,214 | ---- | C] () -- C:\Users\user\Mon film.wlmp
[2012/04/21 06:02:15 | 000,001,916 | ---- | C] () -- C:\Users\user\Start Download Manager.lnk
[2012/03/15 21:04:22 | 000,001,145 | ---- | C] () -- C:\Users\user\launch.ica
[2012/02/13 22:05:45 | 000,002,018 | ---- | C] () -- C:\Users\user\Adobe Reader 9.lnk
[2012/01/18 00:49:24 | 000,001,839 | ---- | C] () -- C:\Users\user\Météo Aéro.lnk
[2011/11/26 01:52:44 | 000,002,216 | ---- | C] () -- C:\Users\user\Google Earth.lnk
[2011/09/05 14:14:58 | 000,000,084 | ---- | C] () -- C:\Windows\winamp.ini
[2011/09/05 14:14:57 | 000,000,373 | ---- | C] () -- C:\Windows\HomeCollections.ini
[2011/09/05 14:14:57 | 000,000,079 | ---- | C] () -- C:\Windows\FavoritList.ini
[2011/08/07 07:06:16 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/08/07 07:06:16 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/08/04 20:20:27 | 000,001,126 | ---- | C] () -- C:\Users\user\Spyware Terminator.lnk
[2011/08/04 06:30:10 | 000,001,032 | ---- | C] () -- C:\Users\user\The Cleaner 2012.lnk
[2011/08/04 02:02:58 | 000,001,064 | ---- | C] () -- C:\Users\user\Ad-Aware.lnk
[2011/08/03 05:52:44 | 000,001,845 | ---- | C] () -- C:\Users\user\avast! Free Antivirus.lnk
[2011/08/01 12:47:58 | 000,001,833 | ---- | C] () -- C:\Users\user\Athan.lnk
[2011/07/21 13:58:07 | 000,001,096 | ---- | C] () -- C:\Users\user\RealPlayer.lnk
[2011/05/11 19:06:57 | 000,000,000 | ---- | C] () -- C:\Users\user\AppData\Local\{E3C3B448-E65C-4740-9EF3-8AE776850F04}
[2011/05/07 21:20:11 | 000,000,000 | ---- | C] () -- C:\Users\user\AppData\Local\{A9844672-9603-46AD-9894-B44D813CCCCD}
[2011/04/05 17:58:29 | 000,135,168 | ---- | C] () -- C:\Windows\SysWow64\ChgService.exe
[2011/02/20 04:24:31 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\GIF89.DLL
[2011/02/17 22:59:48 | 000,001,893 | ---- | C] () -- C:\Users\user\Soulseek.lnk
[2011/01/12 17:23:47 | 000,000,000 | ---- | C] () -- C:\Windows\WD.INI
[2011/01/09 02:13:03 | 000,000,571 | ---- | C] () -- C:\Windows\SysWow64\FeMakro.ini
[2011/01/09 02:13:03 | 000,000,497 | ---- | C] () -- C:\Windows\SysWow64\FeAnim.ini
[2010/12/20 17:49:38 | 000,000,664 | RHS- | C] () -- C:\Users\user\ntuser.pol
[2010/12/19 19:54:01 | 000,000,032 | ---- | C] () -- C:\Windows\qlogiwebupdate.INI
[2010/12/19 19:53:06 | 000,000,146 | ---- | C] () -- C:\Windows\Qlogigra.ini
[2010/11/01 19:14:08 | 000,000,486 | ---- | C] () -- C:\Users\user\AppData\Roaming\wklnhst.dat
[2010/08/31 15:00:02 | 000,153,000 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2010/08/25 19:34:30 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 19:34:30 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 19:34:30 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2010/08/25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/08/25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/03/11 14:48:03 | 000,007,611 | ---- | C] () -- C:\Users\user\AppData\Local\Resmon.ResmonCfg
[2010/03/08 21:14:16 | 004,448,256 | ---- | C] () -- C:\Program Files (x86)\data.sli
[2010/03/08 21:13:59 | 000,500,224 | ---- | C] () -- C:\Program Files (x86)\satlist.exe
[2010/03/08 21:13:59 | 000,307,200 | ---- | C] () -- C:\Program Files (x86)\export.sli
[2010/03/08 21:13:59 | 000,221,184 | ---- | C] () -- C:\Program Files (x86)\export2.sli
[2009/12/23 20:03:38 | 000,006,144 | ---- | C] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ========== [2010/01/12 21:11:23 | 000,000,000 | -HSD | M] -- C:\Users\user\AppData\Roaming\.#
[2011/01/17 15:47:49 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\.k3d
[2010/03/11 13:55:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AchrafCherti
[2012/08/02 13:24:47 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Azureus
[2012/08/02 12:42:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Babylon
[2011/03/05 07:47:57 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Bandoo
[2011/02/20 03:43:39 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Canneverbe Limited
[2011/01/17 16:40:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\eSobi
[2010/12/23 02:05:02 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\eTeks
[2012/08/02 12:42:28 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ExpressFiles
[2010/03/01 15:45:10 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeAudioPack
[2011/04/06 17:35:25 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeBurner
[2010/03/01 23:09:05 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeCDRipper
[2009/12/24 09:56:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\GameConsole
[2012/06/13 16:30:02 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ICAClient
[2011/01/12 23:01:51 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\LiveCAD3
[2012/07/11 17:09:14 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Open Garden
[2010/11/01 19:10:48 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenOffice.org
[2010/01/22 14:39:28 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PowerCinema
[2010/12/18 19:01:31 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Scilab
[2010/05/03 02:05:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ScreeNet iSaver
[2012/08/04 10:30:28 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Simply Super Software
[2011/01/12 01:22:49 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SodeaSoft
[2009/12/31 23:30:06 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SoftDMA
[2011/01/17 17:08:14 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Software Informer
[2012/08/04 08:02:32 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Spyware Terminator
[2012/06/28 21:32:46 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Temp
[2010/11/01 19:14:10 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Template
[2011/08/04 06:30:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\thecleaner
[2012/02/04 13:30:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\uTorrent
[2010/12/22 14:45:38 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Windows Live Writer
[2012/08/02 01:33:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ZTEEVDO
[2012/07/30 17:46:56 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ZTEMTUI
[2012/08/12 23:17:00 | 000,001,070 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1071871065-2305765665-148178615-1000Core.job
[2012/08/14 11:17:05 | 000,001,092 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1071871065-2305765665-148178615-1000UA.job
[2012/07/11 12:00:00 | 000,000,522 | ---- | M] () -- C:\Windows\Tasks\One-Click Tweak.job
[2012/08/12 18:30:04 | 000,032,496 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/08/07 21:06:59 | 000,000,292 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{676BECFA-04BD-475A-AE97-5C25D7F1D41D}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2007/11/07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: AGP440.SYS >[2009/07/14 01:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >[2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >[2009/07/14 01:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 01:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CTFMON.EXE >[2009/07/14 01:39:02 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=42B6A94DD747DF2B5F628A2752E62A98 -- C:\Windows\SysNative\ctfmon.exe
[2009/07/14 01:39:02 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=42B6A94DD747DF2B5F628A2752E62A98 -- C:\Windows\winsxs\amd64_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.1.7600.16385_none_f9257e7aaa4290ce\ctfmon.exe
[2009/07/14 01:14:16 | 000,008,704 | ---- | M] (Microsoft Corporation) MD5=4A3CDCEF8ED41B221F3DBEF5792FB52D -- C:\Windows\SysWOW64\ctfmon.exe
[2009/07/14 01:14:16 | 000,008,704 | ---- | M] (Microsoft Corporation) MD5=4A3CDCEF8ED41B221F3DBEF5792FB52D -- C:\Windows\winsxs\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.1.7600.16385_none_9d06e2f6f1e51f98\ctfmon.exe
< MD5 for: EXPLORER.EXE >[2011/02/26 06:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 05:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 01:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 05:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 05:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 05:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 06:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 06:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 12:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 06:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 05:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 06:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 05:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 13:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 06:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 05:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 01:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 06:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 06:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2012/07/31 23:46:21 | 000,000,763 | ---- | M] () MD5=EB7A70844BB475A75C937C06C3F9D79E -- C:\Kernel\explorer.exe
[2009/08/03 06:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: IASTOR.SYS >[2009/06/05 01:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/06/05 01:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Windows\SysNative\drivers\iaStor.sys
[2009/06/05 01:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2009/06/05 01:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
< MD5 for: IASTORV.SYS >[2010/11/20 13:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 13:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 06:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 06:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011/03/11 06:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 06:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 06:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 06:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >[2009/07/14 01:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010/11/20 13:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010/11/20 13:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 12:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010/11/20 12:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >[2009/07/14 01:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 06:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 06:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011/03/11 06:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 06:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 06:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 06:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 13:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 13:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >[2009/07/14 01:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 12:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/20 12:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 13:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010/11/20 13:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: USERINIT.EXE >[2010/11/20 12:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 12:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 01:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 01:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 13:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 13:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WININIT.EXE >[2009/07/14 01:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009/07/14 01:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009/07/14 01:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009/07/14 01:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >[2010/11/20 13:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/20 13:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 01:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 07:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 06:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > ========== Alternate Data Streams ========== @Alternate Data Stream - 150 bytes -> C:\ProgramData\Temp:CB0AACC9
< End of report >