< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3317595147-3054500285-3432206008-1000\] > -> HKEY_USERS\S-1-5-21-3317595147-3054500285-3432206008-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-3317595147-3054500285-3432206008-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3317595147-3054500285-3432206008-1000\] > -> HKEY_USERS\S-1-5-21-3317595147-3054500285-3432206008-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-3317595147-3054500285-3432206008-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] ->
http://download.microsoft.com/downlo...eckControl.cab [Windows Genuine Advantage Validation Tool] ->
{233C1507-6A77-46A4-9443-F871F945D258} [HKLM] ->
http://download.macromedia.com/pub/s...irector/sw.cab [Shockwave ActiveX Control] ->
{3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} [HKLM] ->
http://dl.tvunetworks.com/TVUAx.cab [CTVUAxCtrl Object] ->
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] ->
http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.1.cab [DLM Control] ->
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} [HKLM] ->
http://download.divx.com/player/DivXBrowserPlugin.cab [DivXBrowserPlugin Object] ->
{8100D56A-5661-482C-BEE8-AFECE305D968} [HKLM] ->
http://upload.facebook.com/controls/...Uploader55.cab [Facebook Photo Uploader 5 Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] ->
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab [Java Plug-in 1.6.0_16] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] ->
http://fpdownload.macromedia.com/get.../ultrashim.cab [Reg Error: Key error.] ->
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab [Java Plug-in 1.6.0_07] ->
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab [Java Plug-in 1.6.0_16] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab [Java Plug-in 1.6.0_16] ->
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] ->
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab [Reg Error: Key error.] ->
{EDFCB7CB-942C-4822-AF14-F0B687409848} [HKLM] ->
http://cdnimg.piczo.com/images/uploa...t_uploader.cab [Image Uploader Control] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.2.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapt ers\ ->
{CA416AA5-6787-423D-995B-FD11229B8A46}\\DhcpNameServer -> 192.168.2.1 (Intel(R) PRO/Wireless 3945ABG Network Connection) ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
C:\PROGRA~1\PCSECU~1\THESHI~1\r3hook.dll -> C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\r3hook.dll -> [2007/03/09 19:51:16 | 00,061,440 | ---- | M] (Kaspersky Lab)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\explorer.exe -> [2009/04/11 06:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
klogon -> C:\Windows\System32\klogon.dll -> [2007/08/23 13:03:48 | 00,204,864 | ---- | M] (PCSecurityShield)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell ExecuteHooks ->
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Stub Execution Hook] -> [2009/02/12 14:19:32 | 02,217,848 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent] -> File not found
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\autoexec.bat [REM Dummy file for NTVDMPATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> C:\autoexec.bat [ NTFS ] -> [2008/03/07 15:43:13 | 00,000,074 | ---- | M] ()
D:\AUTOMODE [@echo off | IF EXIST C:\ST_RP\MANUALMODE ECHO MANUAL BATCH MODE ALREADY SET ! | IF NOT EXIST C:\ST_RP\MANUALMODE ECHO SET TO MANUAL BATCH EXECUTION ! | IF NOT EXIST C:\ST_RP\MANUALMODE IF EXIST C:\ST_RP\AUTOMODE DEL C:\ST_RP\AUTOMODE /F > NUL | IF NOT EXIST C:\ST_RP\MANUALMODE COPY C:\ST_RP\SET_AUTO_MODE.CMD C:\ST_RP\MANUALMODE > NUL | ECHO. | ] -> D:\AUTOMODE [ NTFS ] -> [2005/09/11 15:18:54 | 00,000,340 | -HS- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2 ->
\{6d8ad00d-f11a-11dd-81b7-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{6d8ad00d-f11a-11dd-81b7-001e68a25524}\shell\AutoRun\command
\{6d8ad00d-f11a-11dd-81b7-001e68a25524}\shell\AutoRun\command\\"" -> F:\ckwxkwg.exe [F:\ckwxkwg.exe] -> File not found
\{6d8ad00d-f11a-11dd-81b7-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{6d8ad00d-f11a-11dd-81b7-001e68a25524}\shell\explore\Command
\{6d8ad00d-f11a-11dd-81b7-001e68a25524}\shell\explore\Command\\"" -> F:\ckwxkwg.exe [F:\ckwxkwg.exe] -> File not found
\{6d8ad00d-f11a-11dd-81b7-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{6d8ad00d-f11a-11dd-81b7-001e68a25524}\shell\open\Command
\{6d8ad00d-f11a-11dd-81b7-001e68a25524}\shell\open\Command\\"" -> F:\ckwxkwg.exe [F:\ckwxkwg.exe] -> File not found
\{72b705e0-237b-11de-ae87-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{72b705e0-237b-11de-ae87-001e68a25524}\shell\AutoRun\command
\{72b705e0-237b-11de-ae87-001e68a25524}\shell\AutoRun\command\\"" -> F:\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe [F:\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe] -> File not found
\{72b705e0-237b-11de-ae87-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{72b705e0-237b-11de-ae87-001e68a25524}\shell\open\command
\{72b705e0-237b-11de-ae87-001e68a25524}\shell\open\command\\"" -> F:\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe [F:\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe] -> File not found
\{75a8b331-7f78-11dd-91cf-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{75a8b331-7f78-11dd-91cf-001e68a25524}\shell
\{75a8b331-7f78-11dd-91cf-001e68a25524}\shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{75a8b331-7f78-11dd-91cf-001e68a25524}\shell\AutoRun\command
\{75a8b331-7f78-11dd-91cf-001e68a25524}\shell\AutoRun\command\\"" -> F:\AutoRun.exe [F:\AutoRun.exe] -> File not found
\{75a8b35a-7f78-11dd-91cf-001e68a25524}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{75a8b35a-7f78-11dd-91cf-001e68a25524}\shell
\{75a8b35a-7f78-11dd-91cf-001e68a25524}\shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{75a8b35a-7f78-11dd-91cf-001e68a25524}\shell\AutoRun\command
\{75a8b35a-7f78-11dd-91cf-001e68a25524}\shell\AutoRun\command\\"" -> F:\AutoRun.exe [F:\AutoRun.exe] -> File not found
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* -> File not found
exefile [open] -> "%1" %* -> File not found
[Files/Folders - Created Within 30 Days]
C:\Users\m\AppData\Roaming\BitDefender -> C:\Users\Muffin\AppData\Roaming\BitDefender -> [2009/10/31 22:55:38 | 00,000,000 | ---D | C]
BitDefender -> C:\ProgramData\BitDefender -> [2009/10/31 22:54:36 | 00,000,000 | ---D | C]
C:\ProgramData\BitDefender -> C:\ProgramData\BitDefender -> [2009/10/31 22:54:36 | 00,000,000 | ---D | C]
C:\Program Files\BitDefender -> C:\Program Files\BitDefender -> [2009/10/31 22:54:36 | 00,000,000 | ---D | C]
Config.Msi -> C:\Config.Msi -> [2009/10/31 22:54:31 | 00,000,000 | -HSD | C]
C:\Program Files\Common Files\BitDefender -> C:\Program Files\Common Files\BitDefender -> [2009/10/31 22:49:03 | 00,000,000 | ---D | C]
C:\Users\m\AppData\Local\Threat Expert -> C:\Users\Muffin\AppData\Local\Threat Expert -> [2009/10/31 22:01:57 | 00,000,000 | ---D | C]
C:\Program Files\Trend Micro -> C:\Program Files\Trend Micro -> [2009/10/31 21:52:47 | 00,000,000 | ---D | C]
C:\Program Files\iPod -> C:\Program Files\iPod -> [2009/10/31 21:24:47 | 00,000,000 | ---D | C]
C:\Program Files\iTunes -> C:\Program Files\iTunes -> [2009/10/31 21:24:44 | 00,000,000 | ---D | C]
wmp.dll -> C:\Windows\System32\wmp.dll -> [2009/10/29 19:57:10 | 10,627,584 | ---- | C] (Microsoft Corporation)
unregmp2.exe -> C:\Windows\System32\unregmp2.exe -> [2009/10/29 19:57:07 | 00,310,784 | ---- | C] (Microsoft Corporation)
wmploc.DLL -> C:\Windows\System32\wmploc.DLL -> [2009/10/29 19:57:04 | 08,147,456 | ---- | C] (Microsoft Corporation)
wups2.dll -> C:\Windows\System32\wups2.dll -> [2009/10/27 13:38:07 | 00,044,768 | ---- | C] (Microsoft Corporation)
wucltux.dll -> C:\Windows\System32\wucltux.dll -> [2009/10/27 13:38:06 | 02,421,760 | ---- | C] (Microsoft Corporation)
wuaueng.dll -> C:\Windows\System32\wuaueng.dll -> [2009/10/27 13:38:06 | 01,929,952 | ---- | C] (Microsoft Corporation)
wuauclt.exe -> C:\Windows\System32\wuauclt.exe -> [2009/10/27 13:38:06 | 00,053,472 | ---- | C] (Microsoft Corporation)
wuapi.dll -> C:\Windows\System32\wuapi.dll -> [2009/10/27 13:37:05 | 00,575,704 | ---- | C] (Microsoft Corporation)
wudriver.dll -> C:\Windows\System32\wudriver.dll -> [2009/10/27 13:37:05 | 00,087,552 | ---- | C] (Microsoft Corporation)
wups.dll -> C:\Windows\System32\wups.dll -> [2009/10/27 13:37:05 | 00,035,552 | ---- | C] (Microsoft Corporation)
wuwebv.dll -> C:\Windows\System32\wuwebv.dll -> [2009/10/27 13:36:53 | 00,171,608 | ---- | C] (Microsoft Corporation)
wuapp.exe -> C:\Windows\System32\wuapp.exe -> [2009/10/27 13:36:53 | 00,033,792 | ---- | C] (Microsoft Corporation)
Unit 4 -> C:\Users\m\Desktop\Unit 4 -> [2009/10/22 16:04:53 | 00,000,000 | ---D | C]
javaws.exe -> C:\Windows\System32\javaws.exe -> [2009/10/21 16:37:25 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.)
javaw.exe -> C:\Windows\System32\javaw.exe -> [2009/10/21 16:37:25 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.)
java.exe -> C:\Windows\System32\java.exe -> [2009/10/21 16:37:25 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.)
mshtml.dll -> C:\Windows\System32\mshtml.dll -> [2009/10/16 18:38:24 | 05,940,224 | ---- | C] (Microsoft Corporation)
ieframe.dll -> C:\Windows\System32\ieframe.dll -> [2009/10/16 18:38:23 | 11,069,440 | ---- | C] (Microsoft Corporation)
iertutil.dll -> C:\Windows\System32\iertutil.dll -> [2009/10/16 18:38:22 | 01,985,536 | ---- | C] (Microsoft Corporation)
urlmon.dll -> C:\Windows\System32\urlmon.dll -> [2009/10/16 18:38:22 | 01,208,832 | ---- | C] (Microsoft Corporation)
wininet.dll -> C:\Windows\System32\wininet.dll -> [2009/10/16 18:38:22 | 00,916,480 | ---- | C] (Microsoft Corporation)
msfeeds.dll -> C:\Windows\System32\msfeeds.dll -> [2009/10/16 18:38:22 | 00,594,432 | ---- | C] (Microsoft Corporation)
occache.dll -> C:\Windows\System32\occache.dll -> [2009/10/16 18:38:22 | 00,206,848 | ---- | C] (Microsoft Corporation)
mshtml.tlb -> C:\Windows\System32\mshtml.tlb -> [2009/10/16 18:38:21 | 01,638,912 | ---- | C] (Microsoft Corporation)
inetcpl.cpl -> C:\Windows\System32\inetcpl.cpl -> [2009/10/16 18:38:21 | 01,469,440 | ---- | C] (Microsoft Corporation)
iedkcs32.dll -> C:\Windows\System32\iedkcs32.dll -> [2009/10/16 18:38:21 | 00,387,584 | ---- | C] (Microsoft Corporation)
iepeers.dll -> C:\Windows\System32\iepeers.dll -> [2009/10/16 18:38:21 | 00,184,320 | ---- | C] (Microsoft Corporation)
ie4uinit.exe -> C:\Windows\System32\ie4uinit.exe -> [2009/10/16 18:38:21 | 00,173,056 | ---- | C] (Microsoft Corporation)
ieui.dll -> C:\Windows\System32\ieui.dll -> [2009/10/16 18:38:21 | 00,164,352 | ---- | C] (Microsoft Corporation)
ieUnatt.exe -> C:\Windows\System32\ieUnatt.exe -> [2009/10/16 18:38:21 | 00,133,632 | ---- | C] (Microsoft Corporation)
iesysprep.dll -> C:\Windows\System32\iesysprep.dll -> [2009/10/16 18:38:21 | 00,109,056 | ---- | C] (Microsoft Corporation)
iesetup.dll -> C:\Windows\System32\iesetup.dll -> [2009/10/16 18:38:21 | 00,071,680 | ---- | C] (Microsoft Corporation)
iernonce.dll -> C:\Windows\System32\iernonce.dll -> [2009/10/16 18:38:21 | 00,055,808 | ---- | C] (Microsoft Corporation)
msfeedsbs.dll -> C:\Windows\System32\msfeedsbs.dll -> [2009/10/16 18:38:21 | 00,055,296 | ---- | C] (Microsoft Corporation)
jsproxy.dll -> C:\Windows\System32\jsproxy.dll -> [2009/10/16 18:38:21 | 00,025,600 | ---- | C] (Microsoft Corporation)
msfeedssync.exe -> C:\Windows\System32\msfeedssync.exe -> [2009/10/16 18:38:21 | 00,013,312 | ---- | C] (Microsoft Corporation)
msv1_0.dll -> C:\Windows\System32\msv1_0.dll -> [2009/10/16 18:38:06 | 00,218,624 | ---- | C] (Microsoft Corporation)
ntkrnlpa.exe -> C:\Windows\System32\ntkrnlpa.exe -> [2009/10/16 18:38:00 | 03,600,456 | ---- | C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\System32\ntoskrnl.exe -> [2009/10/16 18:38:00 | 03,548,216 | ---- | C] (Microsoft Corporation)
msasn1.dll -> C:\Windows\System32\msasn1.dll -> [2009/10/16 18:37:35 | 00,060,928 | ---- | C] (Microsoft Corporation)
srv2.sys -> C:\Windows\System32\drivers\srv2.sys -> [2009/10/16 18:37:00 | 00,144,896 | ---- | C] (Microsoft Corporation)
WMSPDMOD.DLL -> C:\Windows\System32\WMSPDMOD.DLL -> [2009/10/16 18:32:14 | 00,604,672 | ---- | C] (Microsoft Corporation)
Ilford pics -> C:\Users\m\Desktop\Ilford pics -> [2009/10/11 12:04:15 | 00,000,000 | ---D | C]
YEAR 11 -> C:\Users\m\Desktop\YEAR 11 -> [2009/10/09 17:22:21 | 00,000,000 | ---D | C]
Baacck up -> C:\Users\m\Desktop\Baacck up -> [2009/10/08 17:56:34 | 00,000,000 | ---D | C]
Office Genuine Advantage -> C:\ProgramData\Office Genuine Advantage -> [2009/10/07 19:29:15 | 00,000,000 | ---D | C]
C:\ProgramData\Office Genuine Advantage -> C:\ProgramData\Office Genuine Advantage -> [2009/10/07 19:29:15 | 00,000,000 | ---D | C]
Office Genuine Advantage -> C:\Users\m\Office Genuine Advantage -> [2009/10/07 19:29:12 | 00,000,000 | ---D | C]
kerberos.dll -> C:\Windows\System32\kerberos.dll -> [2009/10/07 19:15:18 | 00,499,712 | ---- | C] (Microsoft Corporation)
wdigest.dll -> C:\Windows\System32\wdigest.dll -> [2009/10/07 19:15:17 | 00,175,104 | ---- | C] (Microsoft Corporation)
schannel.dll -> C:\Windows\System32\schannel.dll -> [2009/10/07 19:15:16 | 00,270,848 | ---- | C] (Microsoft Corporation)
lsasrv.dll -> C:\Windows\System32\lsasrv.dll -> [2009/10/07 19:15:15 | 01,259,008 | ---- | C] (Microsoft Corporation)
ksecdd.sys -> C:\Windows\System32\drivers\ksecdd.sys -> [2009/10/07 19:15:15 | 00,439,864 | ---- | C] (Microsoft Corporation)
secur32.dll -> C:\Windows\System32\secur32.dll -> [2009/10/07 19:15:14 | 00,072,704 | ---- | C] (Microsoft Corporation)
lsass.exe -> C:\Windows\System32\lsass.exe -> [2009/10/07 19:15:14 | 00,009,728 | ---- | C] (Microsoft Corporation)
klif.sys -> C:\Windows\System32\drivers\klif.sys -> [2009/10/03 14:43:55 | 00,115,992 | ---- | C] (Kaspersky Lab)
New Folder -> C:\ProgramData\New Folder -> [2009/10/03 14:34:51 | 00,000,000 | ---D | C]
C:\ProgramData\New Folder -> C:\ProgramData\New Folder -> [2009/10/03 14:34:51 | 00,000,000 | ---D | C]
C:\Program Files\Microsoft Office Outlook Connector -> C:\Program Files\Microsoft Office Outlook Connector -> [2009/10/03 13:04:47 | 00,000,000 | ---D | C]
C:\Program Files\Microsoft Sync Framework -> C:\Program Files\Microsoft Sync Framework -> [2009/10/03 13:04:03 | 00,000,000 | ---D | C]
C:\Program Files\Microsoft SQL Server Compact Edition -> C:\Program Files\Microsoft SQL Server Compact Edition -> [2009/10/03 13:02:20 | 00,000,000 | ---D | C]
C:\Program Files\Microsoft -> C:\Program Files\Microsoft -> [2009/10/03 13:01:26 | 00,000,000 | ---D | C]
MpSigStub.exe -> C:\Windows\System32\MpSigStub.exe -> [2009/10/02 18:17:09 | 00,195,440 | ---- | C] (Microsoft Corporation)
[Files/Folders - Modified Within 30 Days]
ntuser.dat -> C:\Users\m\ntuser.dat -> [2009/11/01 17:23:59 | 03,407,872 | -HS- | M] ()
fidbox.dat -> C:\Windows\System32\drivers\fidbox.dat -> [2009/11/01 17:21:28 | 08,123,168 | -HS- | M] ()
bdod.bin -> C:\Windows\System32\bdod.bin -> [2009/11/01 16:54:45 | 00,081,984 | ---- | M] ()
perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2009/11/01 16:50:56 | 24,661,410 | ---- | M] ()
perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2009/11/01 16:50:55 | 12,718,740 | ---- | M] ()
PerfStringBackup.INI -> C:\Windows\System32\PerfStringBackup.INI -> [2009/11/01 16:50:51 | 00,004,888 | ---- | M] ()
hpqp.ini -> C:\Users\Public\Documents\hpqp.ini -> [2009/11/01 16:48:04 | 00,001,413 | ---- | M] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009/11/01 16:45:29 | 00,027,459 | ---- | M] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009/11/01 16:45:29 | 00,027,459 | ---- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2009/11/01 16:44:33 | 00,000,880 | ---- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009/11/01 16:43:59 | 00,003,344 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009/11/01 16:43:59 | 00,003,344 | -H-- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2009/11/01 16:43:53 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009/11/01 16:43:43 | 00,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/11/01 16:43:40 | 32,195,78880 | -HS- | M] ()
fidbox.idx -> C:\Windows\System32\drivers\fidbox.idx -> [2009/11/01 16:42:51 | 00,106,352 | -HS- | M] ()
ntuser.dat{a201812a-51d6-11de-9737-001e68a25524}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\m\ntuser.dat{a201812a-51d6-11de-9737-001e68a25524}.TMContainer00000000000000000001.regtrans-ms -> [2009/11/01 16:42:49 | 00,524,288 | -HS- | M] ()
ntuser.dat{a201812a-51d6-11de-9737-001e68a25524}.TM.blf -> C:\Users\m\ntuser.dat{a201812a-51d6-11de-9737-001e68a25524}.TM.blf -> [2009/11/01 16:42:49 | 00,065,536 | -HS- | M] ()
IconCache.db -> C:\Users\m\AppData\Local\IconCache.db -> [2009/11/01 16:42:19 | 02,392,677 | -H-- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2009/11/01 16:38:02 | 00,000,884 | ---- | M] ()
ProductTweaks.xml -> C:\Windows\System32\ProductTweaks.xml -> [2009/10/31 22:59:14 | 00,000,850 | ---- | M] ()
user_gensett.xml -> C:\Windows\System32\user_gensett.xml -> [2009/10/31 22:59:14 | 00,000,385 | ---- | M] ()
bitdefnder keys.docx -> C:\Users\m\Documents\bitdefnder keys.docx -> [2009/10/31 22:34:40 | 00,010,243 | ---- | M] ()
Microsoft Office Word 2007.lnk -> C:\Users\m\Desktop\Microsoft Office Word 2007.lnk -> [2009/10/31 22:33:58 | 00,002,627 | ---- | M] ()
iTunes.lnk -> C:\Users\Public\Desktop\iTunes.lnk -> [2009/10/31 21:25:47 | 00,001,804 | ---- | M] ()
User_Feed_Synchronization-{CBA5FD6D-B830-4123-88F3-8762709A0DA1}.job -> C:\Windows\tasks\User_Feed_Synchronization-{CBA5FD6D-B830-4123-88F3-8762709A0DA1}.job -> [2009/10/31 21:16:23 | 00,000,410 | -H-- | M] ()
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009/10/31 19:47:08 | 00,027,459 | ---- | M] ()
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009/10/31 19:47:08 | 00,027,459 | ---- | M] ()
HPCeeScheduleForm.job -> C:\Windows\tasks\HPCeeScheduleForm.job -> [2009/10/31 19:46:14 | 00,000,306 | ---- | M] ()
jagex_runescape_preferences2.dat -> C:\Users\m\jagex_runescape_preferences2.dat -> [2009/10/31 18:52:47 | 00,000,063 | ---- | M] ()
jagex_runescape_preferences.dat -> C:\Users\m\jagex_runescape_preferences.dat -> [2009/10/31 17:59:11 | 00,000,038 | ---- | M] ()
klin.dat -> C:\Windows\System32\drivers\klin.dat -> [2009/10/14 17:54:21 | 00,108,059 | ---- | M] ()
klick.dat -> C:\Windows\System32\drivers\klick.dat -> [2009/10/14 17:54:21 | 00,095,259 | ---- | M] ()
Ghost N stuff.lnk -> C:\Users\m\Desktop\Ghost N stuff.lnk -> [2009/10/13 19:51:54 | 00,000,457 | ---- | M] ()
Recycling poem.doc -> C:\Users\m\Documents\Recycling poem.doc -> [2009/10/10 20:09:38 | 00,027,136 | ---- | M] ()
Twisters.docx -> C:\Users\m\Documents\Twisters.docx -> [2009/10/05 19:25:35 | 00,011,090 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\m\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/10/04 12:24:21 | 00,058,368 | ---- | M] ()
klif.sys -> C:\Windows\System32\drivers\klif.sys -> [2009/10/03 14:43:55 | 00,115,992 | ---- | M] (Kaspersky Lab)
mrt.exe -> C:\Windows\System32\mrt.exe -> [2009/10/02 18:01:57 | 25,198,016 | ---- | M] (Microsoft Corporation)
[Files - No Company Name]
bdod.bin -> C:\Windows\System32\bdod.bin -> [2009/10/31 23:16:52 | 00,081,984 | ---- | C] ()
ProductTweaks.xml -> C:\Windows\System32\ProductTweaks.xml -> [2009/10/31 22:59:14 | 00,000,850 | ---- | C] ()
user_gensett.xml -> C:\Windows\System32\user_gensett.xml -> [2009/10/31 22:59:14 | 00,000,385 | ---- | C] ()
fidbox.idx -> C:\Windows\System32\drivers\fidbox.idx -> [2009/10/31 22:58:48 | 00,106,352 | -HS- | C] ()
fidbox.dat -> C:\Windows\System32\drivers\fidbox.dat -> [2009/10/31 22:58:39 | 08,027,040 | -HS- | C] ()
bitdefnder keys.docx -> C:\Users\m\Documents\bitdefnder keys.docx -> [2009/10/31 22:34:38 | 00,010,243 | ---- | C] ()
iTunes.lnk -> C:\Users\Public\Desktop\iTunes.lnk -> [2009/10/31 21:25:47 | 00,001,804 | ---- | C] ()
HPCeeScheduleForm.job -> C:\Windows\tasks\HPCeeScheduleForm.job -> [2009/10/31 18:35:33 | 00,000,306 | ---- | C] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/10/29 17:48:46 | 32,195,78880 | -HS- | C] ()
Ghost N stuff.lnk -> C:\Users\m\Desktop\Ghost N stuff.lnk -> [2009/10/13 19:51:54 | 00,000,457 | ---- | C] ()
Recycling poem.doc -> C:\Users\m\Documents\Recycling poem.doc -> [2009/10/10 20:09:36 | 00,027,136 | ---- | C] ()
Twisters.docx -> C:\Users\m\Documents\Twisters.docx -> [2009/10/05 19:25:35 | 00,011,090 | ---- | C] ()
klin.dat -> C:\Windows\System32\drivers\klin.dat -> [2009/10/03 14:45:19 | 00,108,059 | ---- | C] ()
klick.dat -> C:\Windows\System32\drivers\klick.dat -> [2009/10/03 14:45:19 | 00,095,259 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\System32\EhStorAuthn.dll -> [2009/09/24 17:28:54 | 00,117,248 | ---- | C] ()
OGACheckControl.dll -> C:\Windows\System32\OGACheckControl.dll -> [2009/08/03 14:07:42 | 00,403,816 | ---- | C] ()
ODBC.INI -> C:\Windows\ODBC.INI -> [2009/03/25 17:05:52 | 00,000,376 | ---- | C] ()
xlive.dll.cat -> C:\Windows\System32\xlive.dll.cat -> [2008/10/22 04:29:06 | 00,173,550 | ---- | C] ()
zlib1.dll -> C:\Windows\System32\zlib1.dll -> [2007/10/31 09:39:54 | 00,059,904 | ---- | C] ()
sysprepMCE.dll -> C:\Windows\System32\sysprepMCE.dll -> [2006/11/02 12:35:32 | 00,005,632 | ---- | C] ()
win.ini -> C:\Windows\win.ini -> [2006/11/02 10:23:31 | 00,000,331 | ---- | C] ()
system.ini -> C:\Windows\system.ini -> [2006/11/02 10:23:31 | 00,000,219 | ---- | C] ()
pacerprf.ini -> C:\Windows\System32\pacerprf.ini -> [2006/11/02 07:40:29 | 00,013,750 | ---- | C] ()
WdfCoInstaller01000.dll -> C:\Windows\System32\WdfCoInstaller01000.dll -> [2006/03/09 09:58:00 | 01,060,424 | ---- | C] ()
[Alternate Data Streams]
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP

1B5B4F1
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP

FC5A2B2
< End of report >
[/code]