UVKlog

Embed Size (px)

Citation preview

=========================== UVK Scan log file =========================== System Info: UVK version: 2.6.0.0 Windows version: Microsoft windows XP X86 Build 2600 Service Pack 3 I.E. Version: 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) Time & date: 17:07 26/01/2012 System drive: C: 1.98 GB free of 12.63 GB. D: E: F: G: 18.2 GB free of 100.01 GB. 8.79 GB free of 47.72 GB. 2.23 GB free of 14.13 GB. 365.58 GB free of 365.75 GB.

WMI state: OK Processor: Intel Pentium III processor L2 Cache size: 0 Current processor usage: 14% Computer name: HA-D304E98C0259. : . Physical memory: Total: 2.99 GB. Free: 2.3 GB. Virtual memory: Total: 2 GB. Free: 1.96 GB. Last boot up time: 01/26/2012 16:56:15. Boot type: Normal boot UVK scan mode: Verify file signatures, don't show Microsoft files, include file MD5 hash. ========================= End of System Info. ======================== Searching for "autorun.inf" on HD partitions root... Mode ture No autorun.inf was found on HD partitions root. Executable file extensions state (Mode : "%1" %* .exe .msi .reg .bat .cmd .com .vbs exefile "%1" %* Msi.Package "%SystemRoot%\System32\msiexec.exe" /i regfile batfile cmdfile comfile VBSFile regedit.exe "%1" "%1" %* "%1" %* "%1" %* %SystemRoot%\System32\WScript.exe "%1" %* Extension Association Command) autorun.inf Destination file Description MD5 hash File signa Logged on user: ha. Number of users

================= End of Executable file extensions state. ================= Running processes (43): Format: Mode Executable path Description MD5 hash File signature

C:\Program Files\Emsisoft Anti-Malware\a2service.exe Ems isoft Anti-Malware Service 457E6B550AABC987AF117ED968C2F3D9 Signed : Emsi S oftware GmbH C:\WINDOWS\RTHDCPL.EXE Realtek HD Audio Control Panel 3B6E8AE318818B59A8A6AAF7C2BFF972 Signed : Realtek Semiconductor Corp. C:\WINDOWS\System32\IGFXPERS.EXE persistence Module 1D21C2B66AB945C0A73C07A8E0C928 Signed : Intel Corporation C:\WINDOWS\System32\IGFXSRVC.EXE igfxsrvc Module 90B4229C2CAC944021E9211594F Signed : Intel Corporation C:\WINDOWS\System32\HKCMD.EXE 8D29C698FE6393D5A9CA9 Signed : Intel Corporation hkcmd Module 60 FAB6E

4CCD8266E94 B7FD7 44

E:\PM\FAN MEM\UniKey\UniKeyNT.exe 6103054F562A11CE616D50A0611 Unsigned : No publisher C:\Program Files\Nimbuzz\Nimbuzz.exe 35120904C2BA242017A251756A1B5F Unsigned : No publisher

No description No description

C:\Program Files\CMC\Antivirus\CMCTrayIcon.exe ption 36546AC9E42D8B93F42477CC4264E324 Unsigned : CMC InfoSec

No descri

C:\Program Files\Internet Download Manager\IDMan.exe Int ernet Download Manager (IDM) 9E05900550121972572A85995E583987 Signed : Tone c Inc. n C:\Program Files\CMC\Antivirus\CMCCORE.EXE C24E0C245C972C35B538C02DD92125B9 Signed : No publisher No descriptio

C:\Program Files\Java\JRE7\BIN\JQS.EXE Java(TM) Quick St arter Service 973DB7AC74C554C546F8B0B7B98FB855 Signed : Oracle Corporation C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe No description 54196CDAC7E1D81D71C652E100B99E77 Unsigned : No publisher C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe AutoUpater Service Module DD0042F0C3B606A6A8B92D49AFB18AD6 Signed : Yahoo ! Inc. C:\WINDOWS\System32\CAPRPCSK.EXE Canon Advanced Printing Technology RPC Server Process 43421B4F61C8C4434991B2BCA3606D4B Signed : CA NON INC. C:\Program Files\Internet Download Manager\IEMonitor.exe Internet Download Manager agent for click monitoring in IE-based browsers 207 B16FA69F61D1895F8D8532F587E4B Signed : Tonec Inc. C:\Program Files\TeamViewer\Version7\TeamViewer.exe Team Viewer Remote Control Application CC398EEE87E3AF073CDF90AE7C513D26 Signed : TeamViewer GmbH C:\Program Files\TeamViewer\Version7\TV_w32.exe Helper p rocess for TeamViewer performance optimization and QuickConnect A139F70C028099 26BA416FD70B361A55 Signed : TeamViewer GmbH e C:\Program Files\TeamViewer\Version7\TeamViewer_Desktop.ex TeamViewer Remote Control Application FEAA1FBA666D1687AB7A34378062E6C1 S

igned : TeamViewer GmbH D:\bolzano_1989\FirefoxPortable\FirefoxPortable.exe Mozi lla Firefox, Portable Edition D1DE64658A5443079DEDBEB318D22F8A Signed : Por tableApps.com D:\bolzano_1989\FirefoxPortable\App\Firefox\firefox.exe Firefox 4E5585800B561FBEF64B27425365A36F Signed : Mozilla Corporation C:\Program Files\UVK\UVK_en.exe F557D37FAF2BB0FF73C04E5D4CF29 Signed : Carifred Ultra Virus Killer E3E

==================== End of Running processes list. ==================== Winlogon suspicious entries: Format: Mode ature Run C:\WINDOWS\system32\logonui.exe Windows Logon UI 2AF32C27EB2276424FA5EDDB Signed : Microsoft Corporation 7DB59FFF Name Destination file Description MD5 hash File sign

=================== End of Suspicious Winlogon entries. =================== Startup entries: Format: Mode ature RTHDCPL C:\WINDOWS\RTHDCPL.EXE Realtek HD Audio Control Panel 3B6E8AE318818B59A8A6AAF7C2BFF972 Signed : Realtek Semiconductor Corp. Persistence C:\WINDOWS\system32\igfxpers.exe persistence Modu le 601D21C2B66AB945C0A73C07A8E0C928 Signed : Intel Corporation IgfxTray C:\WINDOWS\system32\igfxtray.exe igfxTray Module 07E99FD256DAF061C4FFADC0AB0DDBB Signed : Intel Corporation HotKeysCmds C:\WINDOWS\system32\hkcmd.exe 8266E948D29C698FE6393D5A9CA9 Signed : Intel Corporation 3\CAPONN.EXE get MD5 hash hkcmd Module 4 4CCD Name Destination file Description MD5 hash File sign

CAPON File not found: C:\WINDOWS\system32\Spool\Drivers\w32x86\ No description Unable to get MD5 hash No signature Alcmtr File not found: ALCMTR.EXE No signature No description Unable to

Adobe ARM C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM. exe Adobe Reader and Acrobat Manager 47C1DE0A890613FFCFF1D67648EEDF90 Sign ed : Adobe Systems Incorporated UniKey E:\PM\FAN MEM\UniKey\UniKeyNT.exe D76103054F562A11CE616D50A0611 Unsigned : No publisher No description B7F

Nimbuzz C:\Program Files\Nimbuzz\Nimbuzz.exe 4435120904C2BA242017A251756A1B5F Unsigned : No publisher

No description

CMC Internet Security C:\Program Files\CMC\Antivirus\CMCTrayIco n.exe No description 36546AC9E42D8B93F42477CC4264E324 Unsigned : CMC Info Sec IDMan C:\Program Files\Internet Download Manager\IDMan.exe In ternet Download Manager (IDM) 9E05900550121972572A85995E583987 Signed : Ton ec Inc. DAEMON Tools Lite C:\Program Files\DAEMON Tools Lite\DTLite.exe DAEMON Tools Lite FCEF5DC1794CB2C4B305F780D4F7797B Signed : DT Soft Ltd PC Suite Tray File not found: D:\Nokia PC Suite 7\PCSuite.exe No description Unable to get MD5 hash No signature ======================= End of Startup entries list. ======================= = IE, BHO and Shell execute hooks: Format: Mode signature Name Destination file/url Description MD5 hash File

Start Page http://www.zing.vn/zing/?utm_source=hp&utm_medium= boom Main IE start page Unable to get MD5 hash No signature Start Page Redirect Cache nable to get MD5 hash No signature nature Local Page IE Local Page IE Start Page Redirect Cache Unable to get MD5 hash U

No sig

{0055C089-8582-441B-A0BF-17B458C2A3A8} C:\Program Files\Internet Downl oad Manager\IDMIECC.dll IDM Browser Helper Object 19C7EF6C70A60EA8B2A1A7C4EA D30E06 Signed : Internet Download Manager, Tonec Inc. {02478D38-C3F9-4efb-9B51-7695ECA05670} File not found: CLSID not found No description Unable to get MD5 hash No signature {18DF081C-E8AD-4283-A596-FA578C2EBDC3} C:\Program Files\Common Files\A dobe\Acrobat\ActiveX\AcroIEHelperShim.dll Adobe PDF Helper for Internet Explor er 8C4AC22616E77925135C221C46DC6307 Signed : Adobe Systems Incorporated {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre7\bin\ ssv.dll Java(TM) Platform SE binary CA26B867B45DF2F60D962DAC97E0CFBA Signe d : Oracle Corporation {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} C:\Documents and Settings\ha\Ap plication Data\FlashGetBHO\FlashGetBHO3.dll FlashGet Browser Helper Object 0 594C64E3730AB3ACB8DFF703CCB3E98 Signed : Trend Media Group {DBC80044-A445-435b-BC74-9C25C1C588A9} C:\Program Files\Java\jre7\bin\ jp2ssv.dll Java(TM) Platform SE binary FB7876DBBBD6D6FC8A099B7E300CCA96 Si gned : Oracle Corporation {EF99BD32-C1FB-11D2-892F-0090271D4F88} File not found: CLSI D not found No description Unable to get MD5 hash No signature

{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} File not found: CLSI D not found No description Unable to get MD5 hash No signature ================ End of IE, BHO and Shell execute hooks list. ============== = Image hijacks and Global context menus: Format: Mode ature Delete with UVK C:\Program Files\UVK\UVK_en.exe rus Killer E3EF557D37FAF2BB0FF73C04E5D4CF29 Signed : Carifred Ultra Vi Name Destination file Description MD5 hash File sign

MediaInfo C:\Program Files\K-Lite Codec Pack\Tools\MediaIn fo.exe No description AD937F57725167E2D5D7BE534FEED706 Unsigned : No publ isher SecDel C:\Program Files\LapSec\SecDel.exe 342CB9B624668F2BE0E9378A3C1ED138 Unsigned : No publisher cmcis C:\PROGRA~1\CMC\ANTIVI~1\CMCAVS~1.DLL on 662107C5EB84F3DD1481CC994BCED33A Unsigned : CMCInfoSec No description No descripti

ContMenu File not found: C:\PROGRA~1\CMC\INTERN~1\CMCCON~1 .DLL No description Unable to get MD5 hash No signature WinRAR C:\Program Files\WinRAR\rarext.dll 835B8F5523F2DC6B3F09B52DEA5B7623 Unsigned : No publisher No description

a-squared Anti-Malware Shell Extension C:\Program Files\Em sisoft Anti-Malware\a2contmenu.dll Emsisoft Anti-Malware shell extension 7A3 2472B99E13D2DC2EF4F34EA591C9B Signed : Emsi Software GmbH cmcis C:\PROGRA~1\CMC\ANTIVI~1\CMCAVS~1.DLL on 662107C5EB84F3DD1481CC994BCED33A Unsigned : CMCInfoSec No descripti

jetAudio File not found: C:\Program Files\JetAudio\JetFlEx t.dll No description Unable to get MD5 hash No signature UnlockerShellExtension C:\Program Files\Unlocker\UnlockerC OM.dll No description 49B6AF547ED4BA1FB07BF6F384FDA841 Unsigned : No publ isher Delete with UVK C:\Program Files\UVK\UVK_en.exe Virus Killer E3EF557D37FAF2BB0FF73C04E5D4CF29 Signed : Carifred SecDel C:\Program Files\LapSec\SecDel.exe on 342CB9B624668F2BE0E9378A3C1ED138 Unsigned : No publisher Ultra

No descripti

a-squared Anti-Malware Shell Extension C:\Program Files\ Emsisoft Anti-Malware\a2contmenu.dll Emsisoft Anti-Malware shell extension 7 A32472B99E13D2DC2EF4F34EA591C9B Signed : Emsi Software GmbH cmcis C:\PROGRA~1\CMC\ANTIVI~1\CMCAVS~1.DLL tion 662107C5EB84F3DD1481CC994BCED33A Unsigned : CMCInfoSec jetAudio No descrip

File not found: C:\Program Files\JetAudio\JetFl

Ext.dll

No description

Unable to get MD5 hash

No signature ISOShe

UltraISO C:\Program Files\UltraISO\isoshell.dll ll 9C9E7DD001B69E4E4A70F8DADF454867 Unsigned : EZB Systems, Inc.

UnlockerShellExtension C:\Program Files\Unlocker\Unlocke rCOM.dll No description 49B6AF547ED4BA1FB07BF6F384FDA841 Unsigned : No pu blisher WinRAR C:\Program Files\WinRAR\rarext.dll on 835B8F5523F2DC6B3F09B52DEA5B7623 Unsigned : No publisher No descripti ISOShe

UltraISO C:\Program Files\UltraISO\isoshell.dll ll 9C9E7DD001B69E4E4A70F8DADF454867 Unsigned : EZB Systems, Inc. WinRAR C:\Program Files\WinRAR\rarext.dll on 835B8F5523F2DC6B3F09B52DEA5B7623 Unsigned : No publisher == Services: type Format: Mode Service name MD5 hash File signature Service file Description

No descripti

============ End of Image hijacks and Global context menus list. ===========

State - Startup

a2AntiMalware C:\Program Files\Emsisoft Anti-Malware\a2service.ex e Emsisoft Anti-Malware 5.1 - Service Running - Boot 457E6B550AABC987AF117 ED968C2F3D9 Signed : Emsi Software GmbH cmcepa File not found: C:\Program Files\CMC\Internet Security\cmc epagent.exe CMC Endpoint Agent Stopped - Boot Unable to get MD5 hash No signature cmcipsfltr File not found: C:\Program Files\CMC\Internet Security \cmc_ipsfltr.exe No description Stopped - Boot Unable to get MD5 hash No signature cmcis C:\Program Files\CMC\Antivirus\cmccore.exe CMC Internet S ecurity Core Running - Boot C24E0C245C972C35B538C02DD92125B9 Signed : No publisher gupdate C:\Program Files\Google\Update\GoogleUpdate.exe Google Update Service (gupdate) Stopped - Boot F02A533F517EB38333CB12A9E8963773 S igned : Google Inc. gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe Google Update Service (gupdatem) Stopped - Boot F02A533F517EB38333CB12A9E8963773 Signed : Google Inc. HidServ File not found: C:\WINDOWS\System32\hidserv.dll Human I nterface Device Access Stopped - Boot Unable to get MD5 hash No signature JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe Java Quick Starter Running - Boot 973DB7AC74C554C546F8B0B7B98FB855 Signed : Oracle Corporation npggsvc C:\WINDOWS\system32\GameMon.des nProtect GameGuard Serv

ice

Stopped - Boot

2606D84D1F72015A3EA8C4A6A768DEEC

No signature

rpcapd C:\Program Files\WinPcap\rpcapd.exe Remote Packet Captur e Protocol v.0 (experimental) Stopped - Boot E51A8D02B4BD33EBA1F7A5B76C3766E D Signed : CACE Technologies ScsiAccess C:\Program Files\Photodex\ProShowProducer\ScsiAccess.e xe No description Running - Boot 54196CDAC7E1D81D71C652E100B99E77 Unsign ed : No publisher TermService C:\WINDOWS\System32\termsrv.dll Terminal Services Running - Boot A77219A971029DC2FB683E8513713803 Unsigned : Microsoft Corpo ration WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll Portable Media Serial Number Service Stopped - Boot C51B4A5C05A5475708E3C81C7765B71D Unsigned : Microsoft Corporation WudfSvc C:\WINDOWS\System32\WUDFSvc.dll Windows Driver Foundati on - User-mode Driver Framework Stopped - Boot 05231C04253C5BC30B26CBAAE680E D89 Unsigned : Microsoft Corporation YahooAUService C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServ ice.exe Yahoo! Updater Running - Boot DD0042F0C3B606A6A8B92D49AFB18AD6 S igned : Yahoo! Inc. ======================= End of Services list. ======================= Drivers: pe Format: Mode Driver name MD5 hash File signature Driver file Description State - Startup ty

a2acc C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys Emsiso ft Anti-Malware File Guard Stopped - Boot 71574A98093D94BDBB3CB74E272D29A5 Signed : Emsi Software GmbH Abiosdsk No file (Advise removing) ot Unable to get MD5 hash No signature abp480n5 No file (Advise removing) ot Unable to get MD5 hash No signature adpu160m No file (Advise removing) ot Unable to get MD5 hash No signature Aha154x No file (Advise removing) t Unable to get MD5 hash No signature aic78u2 No file (Advise removing) t Unable to get MD5 hash No signature aic78xx No file (Advise removing) t Unable to get MD5 hash No signature AliIde No file (Advise removing) Unable to get MD5 hash No signature No description No description No description No description No description No description No description Stopped - Bo Stopped - Bo Stopped - Bo Stopped - Boo Stopped - Boo Stopped - Boo Stopped - Boot

amsint No file (Advise removing) Unable to get MD5 hash No signature asc No file (Advise removing) Unable to get MD5 hash No signature

No description No description

Stopped - Boot Stopped - Boot Stopped - Bo Stopped - Boo Stopped - Boot

asc3350p No file (Advise removing) ot Unable to get MD5 hash No signature asc3550 No file (Advise removing) t Unable to get MD5 hash No signature Atdisk No file (Advise removing) Unable to get MD5 hash No signature

No description No description No description

BT File not found: C:\WINDOWS\System32\DRIVERS\btnetdrv.sys Blue tooth PAN Network Adapter Stopped - Boot Unable to get MD5 hash No signatu re BtHidBus C:\WINDOWS\System32\Drivers\BtHidBus.sys Bus Service Running - Boot CE441CCD98C5ECB10CB12FCAF97322EC Corporation. btnetBUs C:\WINDOWS\System32\Drivers\btnetBus.sys Bus Service Running - Boot D3C277A51EF9E2EC972D6221F99C0B6D ublisher Bluetooth HID Signed : IVT Bluetooth PAN Signed : No p

CbFs C:\WINDOWS\system32\drivers\cbfs.sys Callback File System D river Running - Boot A975187F3C8867F8D00A698A5282672B Signed : EldoS Corp oration cd20xrnt No file (Advise removing) ot Unable to get MD5 hash No signature Changer No file (Advise removing) t Unable to get MD5 hash No signature No description No description Stopped - Bo Stopped - Boo

cmcguardian C:\WINDOWS\System32\drivers\cmcguardian.sys CMC Guar dian Service Stopped - Boot 4A01BF5BD81FAC8840875ABEB57DB1E7 Signed : CMC Information Security CmdIde No file (Advise removing) Unable to get MD5 hash No signature Cpqarray No file (Advise removing) ot Unable to get MD5 hash No signature No description No description Stopped - Boot Stopped - Bo

cpuz135 C:\WINDOWS\system32\drivers\cpuz135_x32.sys CPUID Driver Running - Boot C2EB4539A4F6AB6EDD01BDC191619975 Signed : CPUID dac960nt No file (Advise removing) ot Unable to get MD5 hash No signature dpti2o No file (Advise removing) Unable to get MD5 hash No signature dtsoftbus01 ools Virtual Bus Driver gned : DT Soft Ltd No description No description Stopped - Bo Stopped - Boot

C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys DAEMON T Running - Boot FB38473835476A6FB272215A1D972AF9 Si

DUMeterDrv File not found: C:\Program Files\DU Meter\DUM_XP32.SYS Hagel Technologies DU Meter traffic accounting driver Stopped - Boot Unabl e to get MD5 hash No signature EagleNT File not found: C:\WINDOWS\system32\drivers\EagleNT.sys No description Stopped - Boot Unable to get MD5 hash No signature EagleXNt File not found: C:\WINDOWS\system32\drivers\EagleXNt.sys No description Stopped - Boot Unable to get MD5 hash No signature FRIdrv C:\WINDOWS\System32\drivers\FRIdrv.sys FRIdrv - Beyond Lo gic I/O Port Driver Stopped - Boot C223008EF742C15E825C8FAC0CDD2AF7 Unsign ed : Beyond Logic http://www.beyondlogic.org fsbts C:\WINDOWS\System32\Drivers\fsbts.sys No description ning - Boot 343786E182B9C9AE3066E00DEC650F50 Signed : No publisher gdrv C:\WINDOWS\gdrv.sys GIGABYTE Tools Stopped - Boot 948DD6652228F88CA7AE6CB276C Signed : Windows (R) 2000 DDK provider Run 5C230

HDAudBus C:\WINDOWS\System32\DRIVERS\HDAudBus.sys Microsoft UAA Bus Driver for High Definition Audio Running - Boot 3FCC124B6E08EE0E9351F717 DD136939 Signed : Windows (R) Server 2003 DDK provider hpn No file (Advise removing) Unable to get MD5 hash No signature No description Stopped - Boot Stopped - Boo Stopped - Boot

i2omgmt No file (Advise removing) t Unable to get MD5 hash No signature i2omp No file (Advise removing) Unable to get MD5 hash No signature

No description No description

ialm C:\WINDOWS\System32\DRIVERS\igxpmp32.sys Intel Graphics Min iport Driver Running - Boot C4018896856A1A1F1F3A0A6EE7206551 Signed : Int el Corporation IDMTDI Manager TDI Driver : Tonec Inc. C:\WINDOWS\System32\DRIVERS\idmtdi.sys Internet Download Running - Boot BFF38EAAA048E264C02F26C464665CB9 Signed No description Stopped - Boo

ini910u No file (Advise removing) t Unable to get MD5 hash No signature

IntcAzAudAddService C:\WINDOWS\System32\drivers\RtkHDAud.sys Ser vice for Realtek HD Audio (WDM) Running - Boot 557E20484A095D949912883F5AB29 E88 Signed : Realtek Semiconductor Corp. IntelIde No file (Advise removing) ot Unable to get MD5 hash No signature No description Stopped - Bo

ISODrive C:\Program Files\UltraISO\drivers\ISODrive.sys ISO DVD/ CD-ROM Device Driver Running - Boot BF71A06FF065E3FD7E32EA67DCA34885 Unsig ned : EZB Systems, Inc. IvtBtBUs C:\WINDOWS\System32\Drivers\IvtBtBus.sys Bus Service Stopped - Boot 71E1FC547CC488D5CD7BF0860C96F5AF Corporation. lbrtfdc No file (Advise removing) No description IVT Bluetooth Signed : IVT Stopped - Boo

t

Unable to get MD5 hash

No signature

Mandiant_Tools C:\bolzano_1989\IOCFinder_1.0.0\x86\lib\mktools.sys No description Stopped - Boot 625F1EA55A4C4C55226BB91C34751C23 Signed : No publisher MBAMSwissArmy C:\WINDOWS\system32\drivers\mbamswissarmy.sys Malw arebytes' Anti-Malware Stopped - Boot 0DB7527DB188C7D967A37BB51BBF3963 Sig ned : Malwarebytes Corporation mraid35x No file (Advise removing) ot Unable to get MD5 hash No signature ndisrd e Stopped - Boot urces No description Stopped - Bo

C:\WINDOWS\System32\DRIVERS\ndisrd.sys WinpkFilter Servic 0D71BEF03E0059228A4D56CCCF9A3B27 Signed : NT Kernel Reso

NdisrdMP C:\WINDOWS\System32\DRIVERS\ndisrd.sys NDISRD helper dr iver Running - Boot 0D71BEF03E0059228A4D56CCCF9A3B27 Signed : NT Kernel R esources NPF C:\WINDOWS\System32\drivers\npf.sys NetGroup Packet Filter D river Stopped - Boot 6623E51595C0076755C29C00846C4EB2 Signed : CACE Techn ologies NtTdiDr File not found: hex(2):73,00,79,00,73,00,74,00,65,00,6d,00 ,33,00,32,00,5c,00,64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4e,00,74,00,5 4,00,64,00,69,00,44,00,72,00,2e,00,73,00,79,00,73,00,00,00 No description St opped - Boot Unable to get MD5 hash No signature pccsmcfd File not found: C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys PCCS Mode Change Filter Driver Stopped - Boot Unable to get MD5 hash No signature PCIDump No file (Advise removing) t Unable to get MD5 hash No signature PDCOMP No file (Advise removing) Unable to get MD5 hash No signature PDFRAME No file (Advise removing) t Unable to get MD5 hash No signature PDRELI No file (Advise removing) Unable to get MD5 hash No signature PDRFRAME No file (Advise removing) ot Unable to get MD5 hash No signature perc2 No file (Advise removing) Unable to get MD5 hash No signature perc2hib No file (Advise removing) ot Unable to get MD5 hash No signature No description No description No description No description No description No description No description Stopped - Boo Stopped - Boot Stopped - Boo Stopped - Boot Stopped - Bo Stopped - Boot Stopped - Bo

pgglkp7e C:\WINDOWS\System32\Drivers\pgglkp7e.sys Vba32 Armour D river Running - Boot 8462D0B8AA022519E3732FA676496F59 Signed : VirusBlokA da Ltd. Ptilink C:\WINDOWS\System32\DRIVERS\ptilink.sys Direct Parallel

Link Driver Running - Boot llel Technologies, Inc.

80D317BD1C3DBC5D4FE7B1678C60CADD

Signed : Para

PxHelp20 C:\WINDOWS\System32\Drivers\PxHelp20.sys Px Engine Devi ce Driver for Windows 2000/XP Stopped - Boot E42E3433DBB4CFFE8FDD91EAB29AEA8 E Signed : Sonic Solutions ql1080 No file (Advise removing) Unable to get MD5 hash No signature Ql10wnt No file (Advise removing) t Unable to get MD5 hash No signature ql12160 No file (Advise removing) t Unable to get MD5 hash No signature ql1240 No file (Advise removing) Unable to get MD5 hash No signature ql1280 No file (Advise removing) Unable to get MD5 hash No signature No description No description No description No description No description Stopped - Boot Stopped - Boo Stopped - Boo Stopped - Boot Stopped - Boot

RapidPort C:\WINDOWS\system32\Drivers\CAPLPTN.SYS Canon Advanced Printing Technology Parallel Port Driver Stopped - Boot F210E3B0FC9E4BA24EF 682B18B0B2EA1 Signed : CANON INC. RTLE8023xp C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys Realtek 10/1 00/1000 PCI-E NIC Family NDIS XP Driver Running - Boot 89619EF503F949FAE0925 2A8B883EE11 Signed : Realtek Semiconductor Corporation SASDIFSV File not found: C:\DOCUME~1\ha\LOCALS~1\Temp\SAS_SelfExtr act\SASDIFSV.SYS No description Stopped - Boot Unable to get MD5 hash No signature SASKUTIL File not found: C:\DOCUME~1\ha\LOCALS~1\Temp\SAS_SelfExtr act\SASKUTIL.SYS No description Stopped - Boot Unable to get MD5 hash No signature SBRE C:\WINDOWS\system32\drivers\SBREdrv.sys Anti-Rootkit Engine Running - Boot C1AE5D1F53285D79A0B73A62AF20734F Signed : Sunbelt Softwar e Secdrv C:\WINDOWS\System32\DRIVERS\secdrv.sys No description topped - Boot D26E26EA516450AF9D072635C60387F4 Signed : No publisher Simbad No file (Advise removing) Unable to get MD5 hash No signature Sparrow No file (Advise removing) t Unable to get MD5 hash No signature symc810 No file (Advise removing) t Unable to get MD5 hash No signature symc8xx No file (Advise removing) t Unable to get MD5 hash No signature sym_hi No file (Advise removing) Unable to get MD5 hash No signature No description No description No description No description No description S

Stopped - Boot Stopped - Boo Stopped - Boo Stopped - Boo Stopped - Boot

sym_u3 No file (Advise removing) Unable to get MD5 hash No signature

No description

Stopped - Boot

teamviewervpn C:\WINDOWS\System32\DRIVERS\teamviewervpn.sys Team Viewer VPN Adapter Stopped - Boot 9101FFFCFCCD1A30E870A5B8A9091B10 Signed : TeamViewer GmbH TosIde No file (Advise removing) Unable to get MD5 hash No signature ultra No file (Advise removing) Unable to get MD5 hash No signature No description No description Stopped - Boot Stopped - Boot

uzy4mta1 C:\WINDOWS\system32\Drivers\uzy4mta1.sys AVZ-RK Kernel Driver Running - Boot D565AD44C6C4D934AFAD3CA4196B09AA Unsigned : No publ isher VBoxDrv ce Running - Boot ation C:\WINDOWS\System32\DRIVERS\VBoxDrv.sys VirtualBox Servi 3DE2E217627BB058BBE5E04B95A59B0C Signed : Oracle Corpor

VBoxNetAdp C:\WINDOWS\System32\DRIVERS\VBoxNetAdp.sys VirtualBox Host-Only Ethernet Adapter Running - Boot A708BBADDE4E4374BF15B0C064B7E7CE Signed : Oracle Corporation VBoxNetFlt File not found: C:\WINDOWS\System32\DRIVERS\VBoxNetFlt. sys VBoxNetFlt Service Stopped - Boot Unable to get MD5 hash No signatur e VBoxUSB C:\WINDOWS\System32\Drivers\VBoxUSB.sys VirtualBox USB Stopped - Boot BD0A488AD85D2936859888A55AF3158E Signed : Oracle Corporatio n VBoxUSBMon C:\WINDOWS\System32\DRIVERS\VBoxUSBMon.sys VirtualBox USB Monitor Driver Running - Boot C0FA5A87FA5E3AE0079F436CA1449107 Signed : Oracle Corporation VComm File not found: C:\WINDOWS\System32\DRIVERS\VComm.sys Virt ual Serial port driver Stopped - Boot Unable to get MD5 hash No signature VcommMgr File not found: C:\WINDOWS\System32\Drivers\VcommMgr.sys Bluetooth VComm Manager Service Stopped - Boot Unable to get MD5 hash No signature ViaIde No file (Advise removing) Unable to get MD5 hash No signature WDICA No file (Advise removing) Unable to get MD5 hash No signature No description No description Stopped - Boot Stopped - Boot

WudfPf C:\WINDOWS\System32\DRIVERS\WudfPf.sys Windows Driver Fou ndation - User-mode Driver Framework Platform Driver Stopped - Boot F15FEAFF FBB3644CCC80C5DA584E6311 Unsigned : Microsoft Corporation WudfRd C:\WINDOWS\System32\DRIVERS\wudfrd.sys Windows Driver Fou ndation - User-mode Driver Framework Reflector Stopped - Boot 28B524262BCE6D E1F7EF9F510BA3985B Unsigned : Microsoft Corporation ======================== End of Drivers list. ========================

Scheduled tasks: Format: Mode ure User_Feed_Synchronization-{703533FB-FE82-4E94-9BCC-75BCE651FD 4B} C:\WINDOWS\system32\msfeedssync.exe Microsoft Feeds Synchronization FE E2BA1AD38F457F418E82EA30724053 Unsigned : Microsoft Corporation User_Feed_Synchronization-{703533FB-FE82-4E94-9BCC-75BCE651FD 4B} C:\WINDOWS\system32\msfeedssync.exe Microsoft Feeds Synchronization FE E2BA1AD38F457F418E82EA30724053 Unsigned : Microsoft Corporation GoogleUpdate.exe : Google Inc. GoogleUpdate.exe : Google Inc. GoogleUpdateTaskMachineCore C:\Program Files\Google\Update\ Google Installer F02A533F517EB38333CB12A9E8963773 Signed GoogleUpdateTaskMachineCore C:\Program Files\Google\Update\ Google Installer F02A533F517EB38333CB12A9E8963773 Signed Task name Task file Description MD5 hash File signat

GoogleUpdateTaskMachineUA C:\Program Files\Google\Update\Go ogleUpdate.exe Google Installer F02A533F517EB38333CB12A9E8963773 Signed : Google Inc. chrome C:\Program Files\Google\Chrome\Application\chrome.ex e Google Chrome E5C93E2CF6C7B903799CF99F71286E1A No signature Scheduled Update for Ask Toolbar File not found: C:\Program Files\Ask.com\UpdateTask.exe No description Unable to get MD5 hash No sig nature ==================== End of Scheduled tasks list. ==================== Uninstall list: Format: Mode Uninstall entry Name Publisher Uninstall command

6DA48AFDE796708D5A4C9121A83E7617A63A9A15 Windows Driver P ackage - Nokia Modem (10/07/2010 4.6) Nokia C:\PROGRA~1\DIFX\270581355A767B F1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_0E737C5DBBFCF603DB03D27 D4DE0E55B5A00309C\nokia_bluetooth.inf Adobe AIR Adobe AIR Adobe Systems Inc. c:\Program Fil es\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:unin stall Adobe Flash Player ActiveX Adobe Flash Player 11 ActiveX Adobe Systems Incorporated C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_A ctiveX.exe -maintain activex Adobe Flash Player Plugin Adobe Flash Player 11 Plugin Adobe Systems Incorporated C:\WINDOWS\system32\Macromed\Flash\FlashUtil11e_Plu gin.exe -maintain plugin

Canon Advanced Printing Technology Canon CAPT printers No publisher C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAP1UNIK.EXE \uninst.exe" CCleaner CCleaner Piriform "C:\Program Files\CCleaner No publisher DT Soft Ltd "C:\Pro C:\Pr

CPUID CPU-Z_is1 gram Files\CPUID\CPU-Z\unins000.exe"

CPUID CPU-Z 1.58

DAEMON Tools Lite DAEMON Tools Lite ogram Files\DAEMON Tools Lite\uninst.exe

E5372C32E8562C76C24DBA6525002B1031495F34 Windows Driver P ackage - Nokia Modem (06/09/2010 7.01.0.8) Nokia C:\PROGRA~1\DIFX\270581355 A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_A6F4DB5C7B968742C0CE C6C3D94F498B3F04B319\nokbtmdm.inf Emsisoft Anti-Malware_is1 Emsisoft Anti-Malware 5.1 i Software GmbH "C:\Program Files\Emsisoft Anti-Malware\unins000.exe" RUNT\unins000.exe" ERUNT_is1 ERUNT 1.1j Lars Hederer Ems

"C:\Program Files\E C:\

FlashGet 3.3 FlashGet 3.3 http://www.FlashGet.com Program Files\FlashGet Network\FlashGet 3\uninst.exe FormatFactory FormatFactory 2.60 Files\FreeTime\FormatFactory\uninst.exe Free Time

C:\Program

Google Chrome Google Chrome Google Inc. "C:\Program F iles\Google\Chrome\Application\16.0.912.75\Installer\setup.exe" --uninstall --mu lti-install --chrome --system-level HDMI Intel(R) Graphics Media Accelerator Driver rporation C:\WINDOWS\system32\igxpun.exe -uninstall HijackThis ols\HijackThis.exe" /uninstall HijackThis 2.0.2 TrendMicro Intel Co

"O:\HBCD\WinTo Ton No pu

Internet Download Manager Internet Download Manager ec Inc. C:\Program Files\Internet Download Manager\Uninstall.exe KLiteCodecPack_is1 K-Lite Codec Pack 7.6.0 (Full) blisher "C:\Program Files\K-Lite Codec Pack\unins000.exe" ninstall.exe" LapSec LapSec No publisher

"C:\Program Files\LapSec\u C:\Program Files\N No publisher C:

Nimbuzz imbuzz\Uninstall.exe

Nimbuzz 2.0.1

Nimbuzz B.V.

Photodex Presenter Photodex Presenter \Program Files\Photodex Presenter\uninst.exe

Plants vs. Zombies Plants vs. Zombies PopCap Games C: \Program Files\PopCap Games\Plants vs. Zombies\PopUninstall.exe "C:\Program File s\PopCap Games\Plants vs. Zombies\Install.log" Plants vs. Zombies . Plants vs. Zombies . No publisher C:\Documents and Settings\ha\My Documents\Plants vs. Zombies\Uninstall.exe

ProShow Producer Photodex\ProShowProducer\uninst.exe SopCast s\SopCast\uninst.exe

ProShow Producer www.sopcast.com TeamViewer

C:\Program Files\ C:\Program File C:\Program Files "C:\P

SopCast 3.4.7

TeamViewer 7 TeamViewer 7 \TeamViewer\Version7\uninstall.exe

UltraISO_is1 UltraISO Premium V9.2 rogram Files\UltraISO\unins000.exe" Unlocker les\Unlocker\uninst.exe UVK UVK Unlocker 1.9.1 Carifred

No publisher

Cedrick Collomb

C:\Program Fi

C:\Program Files\UVK\Uninstall.exe No publis C:\Progra C:\

VirusTotalUploader2.0 VirusTotal Uploader 2.0 her "C:\Program Files\VirusTotalUploader2\uninstall.exe" WinPcapInst m Files\WinPcap\uninstall.exe WinPcap 4.0.2 CACE Technologies

WinRAR archiver Program Files\WinRAR\uninstall.exe

WinRAR 4.01 (32-bit)

win.rar GmbH

Yahoo! Messenger Yahoo! Messenger Yahoo! Inc. C:\PROG RA~1\YAHOO!\MESSEN~1\UNWISE.EXE /S C:\PROGRA~1\YAHOO!\MESSEN~1\INSTALL.LOG Yahoo! Software Update Yahoo! Software Update c. C:\PROGRA~1\Yahoo!\SOFTWA~1\UNINST~1.EXE Yahoo! In

{0ADC8340-4A94-4CE3-A721-B558F365F8D0} AccessData FTK Ima ger AccessData MsiExec.exe /X{0ADC8340-4A94-4CE3-A721-B558F365F8D0} {1EB45C7C-E24C-45C0-8E3B-E11EE4ED27D3} Mandiant Red Curta in Mandiant MsiExec.exe /I{1EB45C7C-E24C-45C0-8E3B-E11EE4ED27D3} {26A24AE4-039D-4CA4-87B4-2F83216030FF} Java(TM) 6 Update 30 Oracle MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216030FF} {26A24AE4-039D-4CA4-87B4-2F83217002FF} Java(TM) 7 Update 2 Oracle MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217002FF} {357E49E8-21BC-49ac-A401-D9529EBA6675} Security Update fo r Microsoft Visual Basic for Applications 6.5 (KB974945) No publisher (Unsup ported) {3A6D39A6-3E72-42A1-8F98-16FFE18C65E9} Crocodile Chemistr y 605 Crocodile Clips MsiExec.exe /X{3A6D39A6-3E72-42A1-8F98-16FFE18C65E9} {3D54E30E-B4EE-4666-82E2-287802EC8382} Oracle VM VirtualB ox 4.0.10 Oracle Corporation MsiExec.exe /I{3D54E30E-B4EE-4666-82E2-287802EC 8382} {44263E3F-7221-4CB7-B28D-6CCF146BE06A}_is1 CMC Antivirus (FREE) CMC Information Security "C:\Program Files\CMC\Antivirus\unins000.exe "

{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB} Adobe AIR Systems Inc. MsiExec.exe /I{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB} {4A03706F-666A-4037-7777-5F2748764D10} Sun Microsystems, Inc.

Adobe

Java Auto Updater SRI In No

{4CB2511D-A074-40E0-A5ED-A875EBBDDF49} BotHunter ternational MsiExec.exe /X{4CB2511D-A074-40E0-A5ED-A875EBBDDF49} {6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6} kia MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}

MSVC80_x86_v2

{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Google Update Help er Google Inc. MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} {A9893D59-C8E2-4D69-8A25-15A3821D4CE9}_is1 CMC Internet S ecurity 2011 UnInstaller CMC Internet Security 2011 [ODIN] "C:\Program Files \CMC\Internet Security\unins000.exe" {AC76BA86-7AD7-1033-7B44-AA1000000001} Adobe Reader X (10 .1.1) Adobe Systems Incorporated MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-AA10 00000001} {AF111648-99A1-453E-81DD-80DBBF6DAD0D} MsiExec.exe /I{AF111648-99A1-453E-81DD-80DBBF6DAD0D} MSVC90_x86 Nokia

{E1E502E2-C006-49DB-9C0C-F2196E51826F}_is1 Rootkit Unhook er LE 3.8 SR 2 UG North "C:\bolzano_1989\RkU3.8.388.590\b o l z n o\unins000 .exe" {E3B64CC5-C011-40C0-92BC-7316CD5E5688} Microsoft_VC100_CR T_SP1_x86 Nokia MsiExec.exe /I{E3B64CC5-C011-40C0-92BC-7316CD5E5688} {EBCB5C58-93B9-47FC-B154-AB4267EEA9F1} T MsiExec.exe /X{EBCB5C58-93B9-47FC-B154-AB4267EEA9F1} Memoryze MANDIAN

{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} Realtek High Defin ition Audio Driver Realtek Semiconductor Corp. RunDll32 C:\PROGRA~1\COMMON~1 \INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\ InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Se tup.exe" -l0x9 -removeonly Free Video to MP3 Converter_is1 \Program Files\Common Files\DVDVideoSoft\Uninstall.exe No publisher C:

======================= End of Uninstall list. ======================= Recently accessed programs: Format: Mode Path Description MD5 hash File signature WinRAR archiver EF0A Pro Goo

C:\Program Files\WinRAR\WinRAR.exe DFBC26E3B64CF5F484E40C99CC2C Unsigned : No publisher

C:\Program Files\Photodex\ProShowProducer\proshow.exe Show C977C0A7C47C9EBB696ED14487CD036C Signed : Photodex C:\Program Files\Google\Chrome\Application\chrome.exe

gle Chrome

E5C93E2CF6C7B903799CF99F71286E1A

Signed : Google Inc. ProS 407E99

C:\Program Files\Photodex\ProShowProducer\uninst.exe how Uninstaller (Setup) 7105A1963350862ECF40C0E87677EF58 Signed : C:\WINDOWS\system32\igfxtray.exe igfxTray Module FD256DAF061C4FFADC0AB0DDBB Signed : Intel Corporation C:\WINDOWS\system32\hkcmd.exe D29C698FE6393D5A9CA9 Signed : Intel Corporation hkcmd Module

4CCD8266E948 601 3

C:\WINDOWS\system32\igfxpers.exe persistence Module D21C2B66AB945C0A73C07A8E0C928 Signed : Intel Corporation C:\WINDOWS\RTHDCPL.EXE Realtek HD Audio Control Panel B6E8AE318818B59A8A6AAF7C2BFF972 Signed : Realtek Semiconductor Corp. C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe ssenger 1CA2943DC17355330BA5B3EFC6CA4537 Signed : Yahoo! Inc.

Yahoo! Me Yaho

C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe o! Messenger 1CA2943DC17355330BA5B3EFC6CA4537 Signed : Yahoo! Inc. C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE 1CA2943DC17355330BA5B3EFC6CA4537 Signed : Yahoo! Inc.

Yahoo! Messenger

C:\Documents and Settings\All Users\Application Data\Yahoo! \YUPDATER\YUPDATER.EXE Yahoo Auto Updater B667E99AE26AD3C45ECAA733347BA9A4 Signed : Yahoo! Inc. C:\Program Files\Internet Download Manager\IDMan.exe Inte rnet Download Manager (IDM) 9E05900550121972572A85995E583987 Signed : Tonec Inc. C:\WINDOWS\system32\igfxcfg.exe igfxcfg Module 7EB1D7EECDEC2A47D0D9C656 Signed : Intel Corporation C99CC4BC

C:\WINDOWS\system32\mshta.exe Microsoft (R) HTML Applicat ion host AD8F83F16A3CE2B093B38B279B419387 Unsigned : Microsoft Corporation C:\Program Files\PopCap Games\Plants vs. Zombies\PlantsVsZo mbies.exe Plants vs. Zombies E56B2762FE054D874913F473A32C2F31 Signed : No publisher C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe Adobe Reader and Acrobat Manager 47C1DE0A890613FFCFF1D67648EEDF90 Signed : Adobe Systems Incorporated C:\Program Files\Photodex\ProShowProducer\pxsetup.exe Pho todex ProShow Setup BEEFFE343BC9ADA878B05B321A9B9C60 Signed : Photodex Corp oration C:\Program Files\Photodex\ProShowProducer\pxplay.exe Phot odex Presenter 0435EC8167B357EC3092888DBB2B8CAF Unsigned : Photodex Corpora tion C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc -hc.exe Media Player Classic - Home Cinema 494FB76E64D9CA3F89F00BB67CA7FDFB Unsigned : MPC-HC Team

C:\Program Files\K-Lite Codec Pack\unins000.exe nstall A02FA57E0B2D140B3C53E507AB8EC81E Unsigned : No publisher

Setup/Uni

C:\WINDOWS\system32\msrating.dll Internet Ratings and Loc al User Management DLL 29BD913D8FD1FEB6728DC9B43B55C1D2 Unsigned : Microsof t Corporation C:\WINDOWS\system32\Edit.com FF937B183A2 Signed : No publisher Edit F6E368E10B600836DD349

C:\Program Files\Internet Download Manager\Uninstall.exe Internet Download Manager installer 92561AAAE66C3004C41F05CF65D5F96C Signed : Tonec Inc. ==================== End of Recently accessed programs. ==================== Contents of C: Format: Mode ature $RECYCLE.BIN get MD5 hash Directory hash Directory WINDOWS 129 Bytes No description Unable to Folder/File name Size Description MD5 hash File sign

3.45 GB 244.17 KB

No description No description

Unable to get MD5 9EC920F4179D45AF3 B2DE3452DE0 22A26C0B72DBEC Un

ntldr A6638A083D39C85 No signature

NTDETECT.COM 46.45 KB 3674C6CEC68B8C8CE7C78 Signed : No publisher boot.ini FAB9C8651E5F835E17 No signature 211 Bytes

No description No description 1.96 GB

Documents and Settings able to get MD5 hash Directory MD5 hash Directory Program Files 2 GB 0 Bytes 0 Bytes

No description

No description No description No description

Unable to get D41D8CD98F00B2 D41D8CD98F00

CONFIG.SYS 04E9800998ECF8427E No signature AUTOEXEC.BAT B204E9800998ECF8427E No signature IO.SYS 800998ECF8427E No signature MSDOS.SYS 4E9800998ECF8427E No signature Unable to get MD5 hash

0 Bytes 0 Bytes

No description No description 1.29 GB

D41D8CD98F00B204E9 D41D8CD98F00B20 No description

System Volume Information Directory Boot 13.9 MB

No description

Unable to get MD5 ha

sh

Directory 374.57 KB 211 Bytes No description No description D6AE2D5521DD93A 22A26C0B72DBEC A3B1FC483F

bootmgr EBC90D411D099FA36 No signature Boot.BAK FAB9C8651E5F835E17 No signature

BOOTSECT.BAK 1816F926096A989E374D32 No signature 5 hash Directory hash Directory Recycled Intel

512 Bytes

No description

1.57 KB 275.17 KB

No description No description

Unable to get MD Unable to get MD5 C22170EB

Boot.ini.saved 5B1D12C9DC0C6BCD294EC223 No signature D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory D5 hash Directory FOUND.010 FOUND.011 FOUND.012 FOUND.013 FOUND.014 FOUND.015 FOUND.016 FOUND.020 FOUND.017 FOUND.018

355 Bytes

No description

0 Bytes 0 Bytes 0 Bytes 0 Bytes 0 Bytes 0 Bytes 0 Bytes 0 Bytes 0 Bytes 0 Bytes

No description No description No description No description No description No description No description No description No description No description

Unable to get M Unable to get M Unable to get M Unable to get M Unable to get M Unable to get M Unable to get M Unable to get M Unable to get M Unable to get M 91B64287E9

ioSpecial.ini DE4F9DDAD50692AE118C34 No signature D5 hash Directory D5 hash Directory FOUND.019 FOUND.021 Lyrics

96 Bytes

No description

0 Bytes 0 Bytes 6.93 KB

No description No description No description

Unable to get M Unable to get M Unable to get MD5

hash

Directory CAPTv105winXP FOUND.022 FOUND.023 1.36 MB No description Unable to g

et MD5 hash Directory D5 hash Directory D5 hash Directory

0 Bytes 0 Bytes

No description No description

Unable to get M Unable to get M 2B25D699BCFCFCF8 0DE92FAA54CA1 Unable to get M BAD647470C926799 1F618B033575F 36.59

OTL.exe 567.5 KB No description 66E098BFCF5AD87C Unsigned : OldTimer Tools cmcmain.log 7200712DE0ED8D74256 No signature D5 hash Directory FOUND.024 1.25 MB 0 Bytes 98.89 KB 33.16 KB No description No description No description No description

OTL.Txt D3012181CFBDF1E0 No signature Extras.Txt 4CC7855DDC0D47569F1 No signature

TDSSKiller.2.5.1.0_23.05.2011_09.59.06_log.txt KB No description 223D5D0384FBB61FC5A3374FD3B40B7F No signature ash Directory sh Directory Directory MD5 hash Directory D5 hash Directory AVZ _OTL COPY 316.74 KB 3.55 MB 24 KB No description No description No description 0 Bytes 0 Bytes

Unable to get MD5 h Unable to get MD5 ha Unable to get MD5 hash Unable to get Unable to get M

Config.Msi FOUND.025

No description No description

CLEAN 00998ECF8427E No signature

0 Bytes

No description 3 Bytes 101.52 MB 12.72 KB

D41D8CD98F00B204E98 BC949EA893A9 Unable to D3177C9A39A

cmcpanel.log 384070C31F083CCEFD26 No signature bolzano_1989 get MD5 hash Directory PDOXUSRS.NET FECDE5E90396878416DA5 No signature D5 hash Directory FOUND.026 FOUND.027

No description No description No description

0 Bytes 0 Bytes

No description No description

Unable to get M Unable to get M

D5 hash

Directory capt810xp 3.51 MB No description 424 KB Unable to get M Unab

D5 hash Directory

Total Video Converter le to get MD5 hash Directory D04F51E4534D391A3BC60A6 cmcupdate.log No signature

No description

342.88 KB 3 Bytes

No description No description

153F27740 BC949EA893A9

cmcucore.log 384070C31F083CCEFD26 No signature ash Directory ~LD 126.31 KB

No description 1.49 GB

Unable to get MD5 h Unable to ge

pagefile.sys t MD5 hash No signature _OTL.rar 6FA80BD33209F8D6 No signature VEW.txt 331D8D0D7A951D8 No signature sh Directory Log

No description

1.29 KB 33.4 KB

No description No description

4F1660408EABF964 2D3E1C9BF100D537C

11.52 KB

No description

Unable to get MD5 ha 50.95

TDSSKiller.2.6.2.0_27.09.2011_14.40.33_log.txt KB No description 6AF0A31A15F075F1CF8F95CC3FA1F189 No signature 5 hash Directory My Music 3.45 MB No description

Unable to get MD 40.6

TDSSKiller.2.5.17.0_04.09.2011_12.29.03_log.txt 6 KB No description F3AC7CBDE6D112617BC64277B0251F92 No signature MD5 hash Directory flvrecorder 0 Bytes 13.17 KB No description No description 1.33 KB

Unable to get 5B46B443C0E No descript

_tbarlog.txt 3D4A0B24CAF4FA97C91D3 No signature

photodex-presenter-install.log ion F8BE070FC74DE56541FA0C99843D30B4 No signature 5 hash Directory MD5 hash Directory ash Directory My video DriveKey Komku 6.51 MB 893.31 KB 8.56 KB

No description No description

Unable to get MD Unable to get

No description 9.47 MB

Unable to get MD5 h Unable to

WinSetupFromUSB get MD5 hash Directory IOCs 0 Bytes

No description

No description

Unable to get MD5 ha

sh

Directory MSIc617f.tmp KRSHistory 0 Bytes 0 Bytes No description No description Unable to ge Unable to get 18.9

t MD5 hash Directory MD5 hash Directory

TDSSKiller.2.6.25.0_05.01.2012_13.58.35_log.txt 4 KB No description BB6AF61954E1B3E288B989C6A09BF747 No signature MD5 hash Directory et MD5 hash Directory SafeRecycle VIPRERESCUE 3.19 MB 138.93 MB No description No description

Unable to get Unable to g

======================= End of Contents of C:. ======================= Contents of Application Data: Format: Mode ature hash Directory Microsoft 11.32 MB 62 Bytes 0 Bytes 934.12 KB 6.58 MB No description No description No description No description Unable to get MD5 88CF0FF92A4A9FA7 Unable to get MD5 Unable to get MD5 h Folder/File name Size Description MD5 hash File sign

desktop.ini BD9B7513B2E9E22B No signature hash Directory ash Directory Directory hash Directory sh sh Directory Directory Identities Mozilla Adobe

No description

Unable to get MD5 hash Unable to get MD5 Unable to get MD5 ha Unable to get MD5 ha Unable to get MD5

Macromedia Bkav2009 Tencent VinaGame BITS

14.63 MB 0 Bytes 25.74 MB 473.33 KB

No description No description No description No description

hash Directory Directory

2.56 MB

No description 504 Bytes

Unable to get MD5 hash Unable to get

ZingDownload MD5 hash Directory WinRAR

No description

12 Bytes

No description

Unable to get MD5 has

h

Directory Directory Yahoo! 7.44 MB No description 1.02 MB Unable to get MD5 hash Unable to g Unable

Software Informer et MD5 hash Directory

No description

Youtube Downloader HD to get MD5 hash Directory hash Directory sh Directory ZingUpload Google Help 0 Bytes

26 Bytes

No description

No description No description

Unable to get MD5 Unable to get MD5 ha

114.25 KB 0 Bytes

Directory

No description 16.96 KB 5.76 KB

Unable to get MD5 hash Unable to get Unable to get MD Unable to get MD5 Unable to get MD5

SolidDocuments MD5 hash Directory 5 hash Directory hash Directory hash Directory Directory Directory hash Directory hash Directory hash Directory Directory NCH Software Photodex Netscape DMCache IDM

No description No description

520 Bytes 128.12 KB 24 KB

No description No description

No description No description

Unable to get MD5 hash Unable to get MD5 hash Unable to get MD5 Unable to get MD5 Unable to get MD5

167.64 MB

Mobipocket TeraCopy PC Suite Nokia

23.95 KB 974.33 KB 281.01 KB

No description No description No description

1.59 KB

No description 553 Bytes

Unable to get MD5 hash Unable to

TrinhduyetSocNhi get MD5 hash Directory ash Directory TeamViewer 2.8 MB

No description

No description 0 Bytes

Unable to get MD5 h Unable t

Media Player Classic o get MD5 hash Directory Avira 0 Bytes

No description

No description

Unable to get MD5 hash

Directory Directory D5 hash Directory Directory 5 hash Directory Directory D5 hash Directory sh Directory Directory ash Directory Rovio 10.72 KB No description 0 Bytes Unable to get MD5 hash Unable to get M

facemoods.com COWON 0 Bytes

No description

No description 1.65 KB

Unable to get MD5 hash Unable to get MD

GetRightToGo Inbit 0 Bytes

No description

No description

Unable to get MD5 hash Unable to get M

FlashGetBHO FlashGet vlc

463.61 KB 6.95 KB

No description

No description No description

Unable to get MD5 ha Unable to get MD5 hash Unable to get MD5 h 1.04 KB No desc

304.16 KB

Thinstall

6.67 MB

No description

Free AVI MPEG WMV MP4 FLV Video Joiner ription Unable to get MD5 hash Directory sh Directory avidemux 19.9 KB No description

Unable to get MD5 ha Unable to get MD Unable to get MD Unable to get MD5 Unable to get

5 hash Directory 5 hash Directory hash Directory

DVDVideoSoft TaskmgrPro magentictb

6.04 KB 319 Bytes 750.5 KB 35.68 KB

No description No description No description No description

InfraRecorder MD5 hash Directory h Directory Directory Directory D5 hash Directory Opera FFSJ IObit

107.65 KB 573 Bytes 4.8 MB

No description No description No description

Unable to get MD5 has Unable to get MD5 hash Unable to get MD5 hash Unable to get M Unable t

InstallShield

0 Bytes

No description 0 Bytes

SUPERAntiSpyware.com

No description

o get MD5 hash h

Directory Aegisub TP Nero 0 Bytes No description Unable to get MD5 has D

Directory

irectory Directory hash Directory

0 Bytes 48.27 KB

No description No description

Unable to get MD5 hash Unable to get MD5 hash Unable to get MD5 Unable to

Leadertech

0 Bytes

No description 90 Bytes

DAEMON Tools Lite get MD5 hash Directory Directory 5 hash Directory Sun 30.84 MB

No description

No description 0 Bytes

Unable to get MD5 hash Unable to get MD

Malwarebytes

No description

=================== End of Contents of Application Data. =================== Contents of Local Application Data: Format: Mode ature MD5 hash Directory Microsoft 4.94 MB No description 140.17 KB No description Unable to get C8 Folder/File name Size Description MD5 hash File sign

GDIPFONTCACHEV1.DAT CB369E59394E860EF474C11C8209C6 No signature 5 hash Directory Mozilla 0 Bytes

No description

Unable to get MD 2DC8486EEC6D Unable to g

IconCache.db 05F7F4DA0BBE72C975C3 No signature et MD5 hash Directory sh Directory PackageAware CMC Yahoo 86.3 KB

6.6 MB 0 Bytes

No description No description

No description

Unable to get MD5 ha Unable to get MD 130.5 KB Unable to g

5 hash Directory

134.96 KB

No description

DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini No description 7F31F211831A0D3CFFE9FAD7FE1B5725 No signature et MD5 hash Directory Identities Google 296.29 KB No description

387.93 MB

No description

Unable to get M

D5 hash

Directory Temp Help 0 Bytes 0 Bytes No description No description Unable to get MD5 h Unable to get MD5 h Unable to get Unable to get M Unable to get MD No description No description Un

ash Directory ash Directory MD5 hash Directory D5 hash Directory 5 hash Directory

Thinstall Conduit Adobe

0 Bytes 96.92 KB

No description No description No description 0 Bytes 1.14 KB

252.64 KB

WMTools Downloaded Files Unable to get MD5 hash Directory NeoSmart_Technologies able to get MD5 hash Directory hash Directory hash Directory D5 hash Directory Opera Setup Magentic 2.89 MB 0 Bytes 0 Bytes

No description No description No description

Unable to get MD5 Unable to get MD5 Unable to get M 0 Bytes 0 Bytes 0 Bytes No No No

{A2B6EB39-70B0-42A4-A5E6-6685551115EE} description D41D8CD98F00B204E9800998ECF8427E No signature {2B0A31AB-719A-478B-94DA-ED3B1FE2FC0C} description D41D8CD98F00B204E9800998ECF8427E No signature {5AF8511B-E7A7-4346-BAAD-40E35FABB9A5} description D41D8CD98F00B204E9800998ECF8427E No signature et MD5 hash Directory Passion_Zone 8.94 KB No description

Unable to g 0 Bytes 0 Bytes 0 Bytes No No No E0

{2284D7F5-5563-49C6-834F-1664F01DB98E} description D41D8CD98F00B204E9800998ECF8427E No signature {C41B2D1E-64E5-4D74-A587-FDB4624D3B17} description D41D8CD98F00B204E9800998ECF8427E No signature {C2654F77-476B-4921-AB54-39206F5A670D} description D41D8CD98F00B204E9800998ECF8427E No signature housecall.guid.cache CC7616964BB1E8BAD7D72286902F8A No signature ars.cache 98603E62C0F848A5B271 No signature census.cache 155.64 KB 184.42 KB 36 Bytes

No description

No description No description

F4E221B24797 D23CBCF2B

E69487671CBCE4B087A93E8 MD5 hash Directory

No signature Livedrive 15.66 KB No description Unable to get 0 Bytes 0 Bytes No No

{5060CA77-5DE0-4813-AB2E-9D4780DB8E15} description D41D8CD98F00B204E9800998ECF8427E No signature {B01F596D-B23A-442B-BCAD-E84FEC9D4083} description D41D8CD98F00B204E9800998ECF8427E No signature BITC5.tmp 04E9800998ECF8427E No signature BITCA.tmp 04E9800998ECF8427E No signature 0 Bytes 0 Bytes No description No description 1.15 MB

D41D8CD98F00B2 D41D8CD98F00B2 U

Norman Malware Cleaner nable to get MD5 hash Directory == Contents of Common Application Data: Format: Mode ature MD5 hash Directory Microsoft 14.1 MB 62 Bytes Folder/File name Size

No description

================= End of Contents of Local Application Data. ===============

Description

MD5 hash

File sign

No description No description

Unable to get 88CF0FF92A

desktop.ini 4A9FA7BD9B7513B2E9E22B No signature MD5 hash Directory get MD5 hash Directory Yahoo!

597.49 KB

No description

Unable to get Unable to Unable t Unable to Unable Unable

PopCap Games

0 Bytes 4.58 MB 0 Bytes

No description No description No description

SolidDocuments o get MD5 hash Directory get MD5 hash Directory NCH Software

NCH Swift Sound to get MD5 hash Directory Installations to get MD5 hash Directory t MD5 hash Directory D5 hash Directory PC Suite Adobe

14.72 KB 142.14 MB

No description No description

131.53 KB 132.22 MB

No description No description

Unable to ge Unable to get M

InterAction studios nable to get MD5 hash Directory 5 hash Directory Inbit 12 Bytes

563.07 KB No description 0 Bytes

No description

U

Unable to get MD Unab

Hagel Technologies le to get MD5 hash Directory et MD5 hash Directory Hitman Pro 519.8 KB

No description

No description

Unable to g Unable Una

InstallShield to get MD5 hash Directory

184 Bytes

No description

SUPERAntiSpyware.com ble to get MD5 hash Directory MD5 hash Directory 5 hash Directory t MD5 hash Directory 5 hash Directory D5 hash Directory kingsoft Safe 16.36 MB

542 KB

No description

No description No description

Unable to get Unable to get MD Unable to ge

311 Bytes

KRSHistory TEMP IObit

0 Bytes

No description

149 Bytes 251 Bytes

No description No description 1.29 KB

Unable to get MD Unable to get M Unabl U

DAEMON Tools Lite e to get MD5 hash Directory NokiaInstallerCache nable to get MD5 hash Directory hash Directory hash Directory Sun SRI 154 Bytes 30.38 MB

No description

406.37 MB

No description

No description No description 621 Bytes

Unable to get MD5 Unable to get MD5 Unable t

Malwarebytes o get MD5 hash Directory MD5 hash Directory = Contents of Program Files: Format: Mode ature Folder/File name Size MANDIANT

No description

51.78 KB

No description

Unable to get

================ End of Contents of Common Application Data. ===============

Description

MD5 hash

File sign

Common Files get MD5 hash Directory MD5 hash Directory ash Directory Windows NT MSN

150.77 MB 3.74 MB

No description

Unable to

No description

Unable to get

20.63 MB

No description 8.34 MB

Unable to get MD5 h Unable t

MSN Gaming Zone o get MD5 hash Directory MD5 hash Directory Messenger

No description

2.03 MB

No description 8.08 MB

Unable to get Una

Windows Media Player ble to get MD5 hash Directory Online Services o get MD5 hash Directory

No description

2.55 KB

No description

Unable t Una Unable Unable t

ComPlus Applications ble to get MD5 hash Directory Internet Explorer to get MD5 hash Directory Outlook Express o get MD5 hash Directory MD5 hash Directory t MD5 hash Directory get MD5 hash Directory NetMeeting Movie Maker WindowsUpdate

0 Bytes 4.47 MB

No description No description

4.12 MB

No description

3.08 MB 9.81 MB 0 Bytes

No description No description No description

Unable to get Unable to ge Unable to Unab

microsoft frontpage le to get MD5 hash Directory hash Directory xerox 0 Bytes

0 Bytes

No description

No description 0 Bytes

Unable to get MD5 No description Un

Uninstall Information able to get MD5 hash Directory hash Directory Intel 50.5 KB

No description 49.86 MB

Unable to get MD5 Unabl

K-Lite Codec Pack e to get MD5 hash Directory hash Directory LapSec 3.05 MB

No description

No description 0 Bytes

Unable to get MD5 No description Un

NeoSmart Technologies able to get MD5 hash Directory

Microsoft Office to get MD5 hash Directory

78.76 MB

No description

Unable U No

Microsoft ActiveSync nable to get MD5 hash Directory

204.08 KB

No description 9.84 MB

InstallShield Installation Information description Unable to get MD5 hash Directory D5 hash Directory hash Directory Realtek WinRAR 49.45 MB 5.76 MB No description No description 0 Bytes

Unable to get M Unable to get MD5 Unab

Universal Extractor le to get MD5 hash Directory get MD5 hash Directory 5 hash Directory ash Directory D5 hash Directory PopCap Games Yahoo! BDE Google

No description

84.69 MB

No description

Unable to

32.25 MB 35.81 KB

No description No description

Unable to get MD Unable to get MD5 h Unable to get M No description Unable to get Unab

281.49 MB

No description 134.55 MB No description 12.79 MB

Emsisoft Anti-Malware Unable to get MD5 hash Directory MD5 hash Directory Photodex 70.57 MB

Photodex Presenter le to get MD5 hash Directory Unable to get MD5 hash ash Directory hash Directory hash Directory 5 hash Directory

No description

Internet Download Manager Directory DIFX Adobe Inbit ERUNT 1.52 MB 108.9 MB 0 Bytes 324.33 KB

8.26 MB

No description

No description No description No description No description 153.5 KB

Unable to get MD5 h Unable to get MD5 Unable to get MD5 Unable to get MD Una

VirusTotalUploader2 ble to get MD5 hash Directory MD5 hash Directory Unlocker 209.8 KB

No description

No description

Unable to get

D5 hash Directory et MD5 hash Directory et MD5 hash Directory MD5 hash Directory MD5 hash Directory D5 hash Directory ash Directory D5 hash Directory D5 hash Directory D5 hash Directory hash Directory

apdkcfla WinDirStat TeamViewer FreeTime Minilyrics Nimbuzz CPUID Oracle Kingsoft CCleaner CMC

0 Bytes

No description

Unable to get M Unable to g Unable to g Unable to get Unable to get Unable to get M

733.03 KB 105.81 MB 112.6 MB 111 KB 40.47 MB

No description No description No description No description

No description

3.4 MB

No description

Unable to get MD5 h Unable to get M Unable to get M Unable to get M Unable to get MD5 Unable U

101.31 MB 0 Bytes 4.04 MB

No description No description No description No description 19.49 MB

132.75 MB

FlashGet Network to get MD5 hash Directory

No description

Microsoft Silverlight nable to get MD5 hash Directory D5 hash Directory 5 hash Directory D5 hash Directory SopCast IObit UltraISO 12.86 MB 325 Bytes 5.36 MB

36.63 MB No description

No description

Unable to get M Unable to get MD Unable to get M Unabl

No description No description 23.22 MB

DAEMON Tools Lite e to get MD5 hash Directory MD5 hash Directory hash Directory MD5 hash Directory WinPcap Java 191.96 KB 179.68 MB 6.69 KB

No description

No description No description No description

Unable to get Unable to get MD5 Unable to get

MSXML 6.0

Reference Assemblies able to get MD5 hash Directory D5 hash Directory MD5 hash Directory t MD5 hash Directory MSBuild MANDIANT AccessData 25.15 KB 10.26 MB 73.56 MB

34.66 MB

No description

Un

No description No description No description

Unable to get M Unable to get Unable to ge Unable to

Microsoft.NET get MD5 hash Directory sh Directory UVK 4.62 MB

23.37 KB

No description

No description

Unable to get MD5 ha

====================== End of Contents of Program Files. =================== === Lsa providers: Format: Mode Name Image path Description MD5 hash File signature

======================= End of Lsa providers list. ======================= Blocked hosts: Format: Mode Domain Line Description 205.199.44.156 registeridm.com 205.199.44.16 registeridm.com Redirected Redirected

registeridm.com domain in the hosts file registeridm.com domain in the hosts file

www.internetdownloadmanager.com oadmanager.com Blocked domain in the hosts file

127.0.0.1 www.internetdownl

======================= End of Blocked hosts list. ======================= Recent files search: Format: Mode e scr Creation date Path Description File signature

File name pattern to search: .exe .dll .com .vbs .cmd .bat .reg .sys .vb Max file age: 30 days.

2012-01-05 C:\WINDOWS\system32\drivers\fsbts.sys No descri ption 343786E182B9C9AE3066E00DEC650F50 Signed : No publisher 2012-01-05 C:\WINDOWS\system32\drivers\hitmanpro35.sys Hit man Pro 3.5 Support Driver 72472B9CE5D02E443CFF49A40355455D Signed : No pub lisher

2012-01-01 C:\WINDOWS\system32\drivers\dtsoftbus01.sys DAE MON Tools Virtual Bus Driver FB38473835476A6FB272215A1D972AF9 Signed : DT S oft Ltd 2012-01-14 C:\WINDOWS\system32\drivers\FRIdrv.sys FRIdrv Beyond Logic I/O Port Driver C223008EF742C15E825C8FAC0CDD2AF7 Unsigned : B eyond Logic http://www.beyondlogic.org 2012-01-05 C:\WINDOWS\system32\drivers\mbamswissarmy.sys M alwarebytes' Anti-Malware 0DB7527DB188C7D967A37BB51BBF3963 Signed : Malware bytes Corporation 2012-01-05 C:\WINDOWS\system32\java.exe Java(TM) Platform SE binary 078C041AC65593A812F5B2A10F53C4E8 Signed : Oracle Corporation 2012-01-05 C:\WINDOWS\system32\javaw.exe Java(TM) Platform SE binary BDD6664E0D9D9A5550038F33637265EA Signed : Oracle Corporation 2012-01-05 C:\WINDOWS\system32\javaws.exe Java(TM) Web Sta rt Launcher 3201F63F840D1609141EF3D903EBE30E Signed : Oracle Corporation 2012-01-05 C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No description DE3745A51B7AC7FEDC356A83F76C8023 Signed : No publisher 2012-01-05 C:\WINDOWS\system32\Macromed\Flash\FlashUtil11e_P lugin.exe Adobe Flash Player Installer/Uninstaller 11.1 r102 0212DFA299B02F5BA 96B5DD3101F1BC4 Signed : Adobe Systems, Inc. 2012-01-01 C:\WINDOWS\system32\DRVSTORE\dtsoftbus0_B3FBF935F 7B537FF8A4993A8EFB7A389555C7B96\dtsoftbus01.sys DAEMON Tools Virtual Bus Drive r FB38473835476A6FB272215A1D972AF9 Signed : DT Soft Ltd 2012-01-05 C:\WINDOWS\system32\deployJava1.dll Java(TM) Pl atform SE binary 62BE3A173E12D262692C8987C6504B86 Signed : Oracle Corporati on 2012-01-05 C:\WINDOWS\system32\npdeployJava1.dll NPRuntime Script Plug-in Library for Java(TM) Deploy B463A518BD6299C7ABF781540D2C2464 Signed : Oracle Corporation 2012-01-05 C:\WINDOWS\Installer\{4CB2511D-A074-40E0-A5ED-A87 5EBBDDF49}\ARPPRODUCTICON.exe No description 6E42CF0D47AF25DEA4CECDBE093D521 C Unsigned : No publisher 2012-01-05 C:\WINDOWS\Installer\{4CB2511D-A074-40E0-A5ED-A87 5EBBDDF49}\d_BotHunter_5FBF22F223CB4471AFCD7357A3508AD5.exe No description 1 01855547DA7197960A1D9D4DDE4E0CA Unsigned : No publisher 2012-01-05 C:\WINDOWS\Installer\{4CB2511D-A074-40E0-A5ED-A87 5EBBDDF49}\sm_BotHunter_EFD9E4E4FAE64C25869C7220DE80D47E.exe No description 101855547DA7197960A1D9D4DDE4E0CA Unsigned : No publisher 2012-01-20 C:\WINDOWS\Installer\{1EB45C7C-E24C-45C0-8E3B-E11 EE4ED27D3}\_6FEFF9B68218417F98F549.exe No description C75A4B72E3CFB074D0CBCE DF78771273 Unsigned : No publisher 2012-01-20 C:\WINDOWS\Installer\{1EB45C7C-E24C-45C0-8E3B-E11 EE4ED27D3}\_6F155DBBB36F7B5085D025.exe No description C75A4B72E3CFB074D0CBCE DF78771273 Unsigned : No publisher 2012-01-20 C:\WINDOWS\Installer\{1EB45C7C-E24C-45C0-8E3B-E11 EE4ED27D3}\_D8CE853555BD54FBCA75A9.exe No description C75A4B72E3CFB074D0CBCE DF78771273 Unsigned : No publisher 2012-01-10 C:\WINDOWS\assembly\GAC_MSIL\PresentationCFFRaste rizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll .NET FX OpenType /CFF Rasterizer 93F9CC2360815D8EF955407CF92B38AA Unsigned : Adobe Systems I ncorporated 2012-01-10 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Pr esentationCFFRast#\487c1bc20f6e73e8e79503898d17d102\PresentationCFFRasterizer.ni .dll .NET FX OpenType/CFF Rasterizer 7E8E8876E74854926EC3DE716D295BC3 Unsi gned : Adobe Systems Incorporated 2012-01-12 C:\WINDOWS\SmartFolders.dll Smart Folders 63D 086E92F8975409EB0176D71339609 Unsigned : AddictiveTips 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\InstallerService.exe No descripti

on

6A2EBCC5C9F053F2B9962935476C336E Unsigned : No publisher 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\InstallerServiceExec.exe No descr iption 489D7C8C18E9DAB87C3E911957F11556 Unsigned : No publisher 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\IsPinned.exe No description A21 E1E483F1198ADBB5174DF984A7B43 Unsigned : No publisher 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\CommonCustomActions\pcswpc.exe No kia Process Controller 664FB725862EC93491DDFE17E9A94EA9 Signed : No publish er 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\CommonCustomActions\RepairMplatform .exe No description C44413BEAB1AF2E97ACDD1466466DC2E Unsigned : No publis her 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\CommonCustomActions\Run_XML6_SP1.ex e No description CA1CD004B235BB59A030ECBED91EC42D Unsigned : No publisher 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer\CommonCustomActions\WMF11Runx86.exe No description 5289BFED933564DD90C29A3E240323B6 Unsigned : No publisher 2012-01-04 C:\Documents and Settings\All Users\Application D ata\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{DB2 4A9E5-A068-43DD-88D0-B51BED3C0B99}\Installer.exe Nokia Installer Application D41D8CD98F00B204E9800998ECF8427E No signature 2012-01-14 C:\Documents and Settings\All Users\Application D ata\MANDIANT\Memoryze\mktools.sys No description 625F1EA55A4C4C55226BB91C347 51C23 Signed : No publisher 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ nsj297.tmp\registry.dll No description 2880BF3BBBC8DCAEB4367DF8A30F01A8 Un signed : No publisher 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ nsj297.tmp\FindProcDLL.dll No description 6F73B00AEF6C49EAC62128EF3ECA677E Unsigned : No publisher 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ nsj297.tmp\newadvsplash.dll No description 820888931D6E1BA0A64BB34975541CF5 Unsigned : No publisher 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ nsj297.tmp\System.dll No description 959EA64598B9A3E494C00E8FA793BE7E Unsi gned : No publisher 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ pdk-ha\c1dfd1c112244dcac5529ec58250134b\perl510.dll Perl Interpreter C1DFD1C 112244DCAC5529EC58250134B Unsigned : ActiveState 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ pdk-ha\5bf8db5274d53c6ed2dd878aeff6e7d5\Cwd.dll No description 5BF8DB5274D53 C6ED2DD878AEFF6E7D5 Unsigned : No publisher 2012-01-05 C:\Documents and Settings\ha\Local Settings\Temp\ 2C.dir\InstallFlashPlayer.exe Adobe Flash Player Installer/Uninstaller 11.1 r102 2D6ECB88C7CB150DE8E93DC09B8F796D Signed : Adobe Systems, Inc. 2012-01-26 C:\Documents and Settings\ha\Local Settings\Temp\ nsf9C.tmp\registry.dll No description 2880BF3BBBC8DCAEB4367DF8A30F01A8 Uns igned : No publisher 2012-01-26 C:\Documents and Settings\ha\Local Settings\Temp\ nsf9C.tmp\FindProcDLL.dll No description 6F73B00AEF6C49EAC62128EF3ECA677E

Unsigned : No publisher 2012-01-26 C:\Documents and Settings\ha\Local Settings\Temp\ nsf9C.tmp\newadvsplash.dll No description 820888931D6E1BA0A64BB34975541CF5 Unsigned : No publisher 2012-01-26 C:\Documents and Settings\ha\Local Settings\Temp\ nsf9C.tmp\System.dll No description 959EA64598B9A3E494C00E8FA793BE7E Unsig ned : No publisher 2012-01-02 C:\Documents and Settings\ha\Application Data\Mic rosoft\Installer\{3A6D39A6-3E72-42A1-8F98-16FFE18C65E9}\ARPPRODUCTICON.exe No description 5EBF1F91D1E8ADBF12D72929442CAB75 Unsigned : No publisher 2012-01-02 C:\Documents and Settings\ha\Application Data\Mic rosoft\Installer\{3A6D39A6-3E72-42A1-8F98-16FFE18C65E9}\NewShortcut1_8D076900C37 44DDBBE7B5AB8B6736428.exe No description 5EBF1F91D1E8ADBF12D72929442CAB75 Unsigned : No publisher 2012-01-02 C:\Documents and Settings\ha\Application Data\Mic rosoft\Installer\{3A6D39A6-3E72-42A1-8F98-16FFE18C65E9}\NewShortcut5_8D076900C37 44DDBBE7B5AB8B6736428.exe No description 5EBF1F91D1E8ADBF12D72929442CAB75 Unsigned : No publisher 2012-01-26 C:\Program Files\Google\Update\Install\{5C82DBD296D6-4A74-BE03-07EB9E1720E0}\chrome_updater.exe Google Chrome BBF3EC2F60E812 4CEF937E919A815D28 Signed : Google Inc. 2012-01-26 C:\Program Files\Google\Update\Download\{4DC8B4CA -1BDA-483E-B5FA-D3C12E15B62D}\16.0.912.77\chrome_updater.exe Google Chrome B BF3EC2F60E8124CEF937E919A815D28 Signed : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\am.dll No description D0822C1719298673D627D19634EBB2F9 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ar.dll No description DBA83DC2799F3CD2B4048F4FB4B12637 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\bg.dll No description 863112DC17F1BF102D49C34A1C635F55 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\bn.dll No description 13B88C34F297A4BC78C8F7E9B483413D Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ca.dll No description 8A3A2EA968E065343073B4E441E1EAFA Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\cs.dll No description 10D0AAE32B8809E1AE1917CA13103C5B Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\da.dll No description 8B403E3D9433C4881C1D6F8601F583A8 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\de.dll No description D1CAAF0DE555DAE07A0D27494D858742 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\el.dll No description 18EB01C106B98C1325AAF5E110888FEC Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\en-GB.dll No description 24E8791113227443AD16B9852DB4D1F9 Si gned : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\en-US.dll No description CE4A6506316528FBC5BC02BABE3F3DC5 Si gned : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\es-419.dll No description CF0C33AA0EEB93CA6A6B7E914EB2D66C S igned : No publisher

2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\es.dll No description 72A3AC79A3713D9BEB442AB5F8C19472 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\et.dll No description B61921ECA015C12EA34F20E9AF7A2B84 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\fa.dll No description D9340785796A3DAF186A359BFBCBC971 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\fi.dll No description 5C0AD982A757D757627B2FDB03AE1C14 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\fil.dll No description 84D3663841BC75DE1F4967EA671A6A7C Sign ed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\fr.dll No description 459073CFF112DFD721E024ADBCA6AA7B Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\gu.dll No description D481375A3618CA87050CDD346DECA57D Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\he.dll No description C12A0EB929A874EDAA7CBEEC7F8403FF Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\hi.dll No description 95E2B52470BD34FA51891963D4E98E10 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\hr.dll No description D526FB8DEE8878C70FE3703C27815D70 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\hu.dll No description 919D993A523887B440C6200D352D6278 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\id.dll No description 757CD6D063E9285E925865D1CFA0EB2A Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\it.dll No description 337615537F516EF64CA87342F4FE10D2 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ja.dll No description BF140D88BEAEFF28BDD3AFC0EC0FBB06 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\kn.dll No description 885A21C6B2C1C97F6351F989BC708071 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ko.dll No description 79708378B41A131D1AE77B73FDF76289 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\lt.dll No description 0A105282D40E4F528A18DF19AFE6D5A5 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\lv.dll No description B34B48183ED0265AF7D4F38EBD781C6E Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ml.dll No description EFCB260BF698E768872356142F9D239F Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\mr.dll No description 477EA3364D80F09F087BFD2894801497 Signe d : No publisher

2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\nb.dll No description E46BC6E5B88E796A26012E90C9B4CCFC Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\nl.dll No description 06E17DF1D664A6F02691BE405D2F1C89 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\pl.dll No description A64135AFD91086B8A0AE3CB48AB1E8B5 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\pt-BR.dll No description 4E7E24996AF518DCC4924524977A0647 Si gned : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\pt-PT.dll No description 3AA0CEDD206B727ACA7E008B2A2A8797 Si gned : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ro.dll No description 1D644F0AAED54F0CBA3773D2F7A65E53 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ru.dll No description FDD69C9176CDCBA4B9E95575B1B4DB25 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\sk.dll No description 6524F158556F4B4D62FCF4A6F9D1AB24 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\sl.dll No description 0D90255D99B07D6907C757DC073E905D Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\sr.dll No description 0E5F1B900851767AE8B1EDABB542F885 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\sv.dll No description 6217E7FEDBBC5135A5B5E8D909608596 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\sw.dll No description 1AF53C16487930FBB1D5EE4FAA7BFF33 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\ta.dll No description EEF461EE5A51221308202C978356F443 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\te.dll No description 22097E9DC7287E4247DDCFD78AA628F3 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\th.dll No description ED6579683654B9224DF0F404951FB9A7 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\tr.dll No description 09EA90A720E456812ABF3BEB89B4B127 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\uk.dll No description C4D7E7AF588DD65263A126804C52AFA9 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\vi.dll No description ED77164FE16F68503F21141F89DF6E69 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\zh-CN.dll No description B6FD67BA98CD1838D35101EF6768A95E Si gned : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Locales\zh-TW.dll No description 5D28C950A9FCDF1CF8ABAFC81401963C Si gned : No publisher

2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\avcodec-53.dll No description 179DB748AF84332CA16099B9CF366877 Signe d : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\avformat-53.dll No description 8D1B68759519D5E1593B20A26ECB1CEE Sign ed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\avutil-51.dll No description 61E1DF3E6FBA2865EC49A07335A05B31 Signed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\chrome.dll Google Chrome B5B83FD3DE0B57DAB90CED4E853795B7 Signed : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\chrome_frame_helper.dll Chrome Frame renders the Web of the future in th e browsers of the past. It's like strapping a rocket engine to a minivan. 155B 182A038FE4ECD326B6C1D6D241FB Signed : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\gcswf32.dll No description BE0FF1633A2B280FB455CCD07C111050 Signed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\icudt.dll ICU Data DLL 1B4A64CA2F74B19EFBD429C36834229C Signed : Th e ICU Project 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\libegl.dll ANGLE libEGL Dynamic Link Library 4B07203AD338E23FFB20E931E 23DA1B5 Signed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\libglesv2.dll ANGLE libGLESv2 Dynamic Link Library 642352C3F09D705B3C7 ACB8C4C31D6FC Signed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\npchrome_frame.dll Chrome Frame renders the Web of the future in the bro wsers of the past. It's like strapping a rocket engine to a minivan. B3ACD2B23 A32F4753BD49FA54AEFC0BA Signed : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\pdf.dll Chrome PDF Viewer C9B5B6B2ED938048E2D24E4358B65299 Signed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\ppgooglenaclpluginchrome.dll No description FE697B33DB1D0B128B22380C5B 144177 Signed : No publisher 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\chrome_frame_helper.exe Chrome Frame renders the Web of the future in th e browsers of the past. It's like strapping a rocket engine to a minivan. BC06 F4F3EC6B045203AE00523C5A007E Signed : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\chrome_launcher.exe Chrome Frame renders the Web of the future in the br owsers of the past. It's like strapping a rocket engine to a minivan. 2357D94C 86E9E457E9EBF408E767B7E6 Signed : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\nacl64.exe Google Chrome 7172353BE035A8EE32AC7D8DC31C8B6C Signed : Google Inc. 2012-01-07 C:\Program Files\Google\Chrome\Application\16.0.9 12.75\Installer\setup.exe Google Chrome C599771403A8D462E7638A800726ECB0 S igned : Google Inc. 2012-01-05 C:\Program Files\Google\Chrome\Application\chrome .exe Google Chrome E5C93E2CF6C7B903799CF99F71286E1A Signed : Google Inc. 2012-01-20 C:\Program Files\Google\Chrome\Application\new_ch rome.exe Google Chrome 697D3B09D8883F72265DA274E0972042 Signed : Google I nc. 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\am.dll No description 866DE9CF3B1B771EDD5F55C69C48E06A Signe d : No publisher

2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ar.dll No description E2880D6E7C292D170DDBD7942B223BC8 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\bg.dll No description 1C9CF6F5B205A2D57B57D76F8C74F86D Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\bn.dll No description F244A0F4B831428389A2FB4893B9C61B Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ca.dll No description 4C78EC87E4F2F0AFC8D31F9939DCA8E0 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\cs.dll No description 7C8FC2911E59FB4D5D8792BD68949AC6 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\da.dll No description 274F7B415E6F5962959D37220BDE3743 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\de.dll No description E91E3D330571F68158568AEFBFE6C329 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\el.dll No description 1B52BB4CD70CBBE9CDB26789E9D08BD2 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\en-GB.dll No description 3E2388A6C370AEDD5B0B6E594E8C8A64 Si gned : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\en-US.dll No description 91D005F81A183F4CC88357195F746A9C Si gned : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\es-419.dll No description 8D0CA92C92349C9ABA3E11713AC3D830 S igned : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\es.dll No description 319982A008C16FD8474AD1563EB063B5 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\et.dll No description B3FC3C7736694D56C679065071BC0697 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\fa.dll No description 17C26769EA84ABD3AB44863613A1B78D Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\fi.dll No description 1CC1C09B30898169321D9072B5EF1FC5 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\fil.dll No description 0F9D811BD435973324289131F9E47599 Sign ed : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\fr.dll No description BB746DFE3C107EB24C72B271A1ABA010 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\gu.dll No description 890A1F23339790B5182CA3E4E12F914C Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\he.dll No description 80ABCFAC33DB355CF3E508F1187B8A2E Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\hi.dll No description B1E752E7C80F2C4AAAD2AE45C9F55D26 Signe d : No publisher

2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\hr.dll No description 16508B059CFED20B487712F24D74FED5 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\hu.dll No description 93FE2A873CB51E168F6BBDC2165FE40B Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\id.dll No description D123A4E49844564D08E32872829035C8 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\it.dll No description 860B0DE8893FA7753688BB9345750DD5 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ja.dll No description 78CAB7C9DAC7E59C31A0B96A04EC7C72 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\kn.dll No description 58C6F883044AC175B6B893B79A77671A Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ko.dll No description 4FAB3BD6E73DD3F86B047AE4E22B6118 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\lt.dll No description FBE0A4D57D941476C5C67E9D51CAC2A3 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\lv.dll No description C425768ED43E649E97F776DF985EA22F Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ml.dll No description 58D2C8E6ED9DEA3E37E809E4252F6867 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\mr.dll No description 1F74B689A250A22677792F8D63E234F9 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\nb.dll No description 488367A7544A780AE7D69E9901D6E042 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\nl.dll No description 6FFB77D485EC509B8B3B0DB45A7372B5 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\pl.dll No description B7A53A89227B247AB4D5F8BA2B6A07FD Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\pt-BR.dll No description D82D9E5756283D50F9030181D6524CDF Si gned : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\pt-PT.dll No description 762C75E65D8AF31A84C59C762AFB3BD8 Si gned : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ro.dll No description A06292073E684F606C0D1B23BC8CCC4D Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ru.dll No description 20DE49D0A52228189574D6E6D46ED1A8 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\sk.dll No description 8F502F6022DAD6FFA54ABC4938E817FA Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\sl.dll No description E95C3D258ACACFAA280B171F74F0586F Signe d : No publisher

2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\sr.dll No description 0D7839165E9D825669AD19BE0B548368 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\sv.dll No description C46C6A1E333015BBB11D8D0AB626433F Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\sw.dll No description 547937AACF5BD5AE74618D9A7ED0D279 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\ta.dll No description 3A1B597165C5196ED1779A5943A4BFB4 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\te.dll No description F43D24E6BEACCF12CB2404AB4D7944B9 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\th.dll No description 377F45EAC6D5D8B596030F6F13ABFCA3 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\tr.dll No description AD4CDBC658F8D64407B143340D5D47D2 Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\uk.dll No description 6D2563187C2C5744AE8EEC0F825E291D Signe d : No publisher 2012-01-20 C:\Program Files\Google\Chrome\Application\16.0.9 12.77\Locales\vi.dll No description 83AB52FCAF228EC8DECCFFB177808E33 Signe d :