[2022/03/24 13:48:16 | 000,000,852 | ---- | M] () -- C:\Windows\SysNative\drivers\RTKHDRC0.DAT
[2022/03/24 12:22:36 | 000,000,712 | ---- | M] () -- C:\Windows\SysNative\drivers\RTEQEX1.DAT
[2022/03/24 12:22:36 | 000,000,712 | ---- | M] () -- C:\Windows\SysNative\drivers\RTEQEX0.DAT
[2015/03/06 21:11:07 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/06 21:10:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/03/06 16:14:26 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015/03/06 15:53:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/06 15:47:58 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/03/06 15:47:52 | 3336,736,768 | -HS- | M] () -- C:\hiberfil.sys
[2015/03/06 15:42:19 | 000,001,097 | ---- | M] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2015/03/06 13:49:09 | 000,002,303 | ---- | M] () -- C:\Users\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/03/06 12:51:43 | 000,001,118 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/02/22 08:41:39 | 000,000,017 | ---- | M] () -- C:\Users\Tony\AppData\Local\resmon.resmoncfg
[2015/02/15 08:43:59 | 000,493,368 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2015/03/06 15:42:19 | 000,001,097 | ---- | C] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2015/03/06 15:00:15 | 000,000,273 | ---- | C] () -- C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Menu.lnk
[2015/03/06 13:48:58 | 000,002,303 | ---- | C] () -- C:\Users\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/03/06 13:48:33 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/06 13:48:33 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/06 12:51:43 | 000,001,118 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/03/01 13:58:55 | 000,002,432 | ---- | C] () -- C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wikipedia.lnk
[2015/02/25 09:14:16 | 000,002,332 | ---- | C] () -- C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pandora.lnk
[2015/02/22 08:41:39 | 000,000,017 | ---- | C] () -- C:\Users\Tony\AppData\Local\resmon.resmoncfg
[2015/02/11 08:28:57 | 000,391,526 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2014/09/23 03:57:19 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014/09/23 03:47:11 | 000,172,097 | ---- | C] () -- C:\Windows\SysWow64\NoMSGuninstall.exe
[2014/09/23 03:47:11 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\UMonit64.exe
[2014/09/23 03:47:11 | 000,001,519 | ---- | C] () -- C:\Windows\SysWow64\_IconCfg0.ini
[2014/09/23 03:47:11 | 000,000,978 | ---- | C] () -- C:\Windows\SysWow64\ProductName.ini
[2014/09/23 03:47:11 | 000,000,184 | ---- | C] () -- C:\Windows\SysWow64\IconCfg0.ini
[2014/09/15 23:38:57 | 000,351,184 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
[2014/09/15 23:38:56 | 000,183,808 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014/09/15 23:38:56 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
[2014/03/18 05:13:28 | 000,002,255 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini
[2014/03/18 05:13:03 | 000,103,936 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2013/08/22 10:36:43 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2013/08/22 10:36:42 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2013/08/22 09:46:23 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2013/08/22 02:01:23 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2013/08/21 22:32:36 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2013/08/21 18:55:20 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2013/08/21 18:52:39 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2013/07/01 21:44:46 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[2014/09/15 23:57:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/30 19:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/30 17:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/12/19 10:12:27 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\acer
[2015/01/08 13:23:54 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\CareCenter
[2015/03/06 09:32:12 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\Dropbox
[2015/02/09 13:29:06 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\Foxit Software
[2015/01/10 10:54:32 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\WildTangent
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:581B0446
@Alternate Data Stream - 220 bytes -> C:\Users\Tony\OneDrive:ms-properties
< End of report >
[2022/03/24 12:22:36 | 000,000,712 | ---- | M] () -- C:\Windows\SysNative\drivers\RTEQEX1.DAT
[2022/03/24 12:22:36 | 000,000,712 | ---- | M] () -- C:\Windows\SysNative\drivers\RTEQEX0.DAT
[2015/03/06 21:11:07 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/06 21:10:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/03/06 16:14:26 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015/03/06 15:53:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/06 15:47:58 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/03/06 15:47:52 | 3336,736,768 | -HS- | M] () -- C:\hiberfil.sys
[2015/03/06 15:42:19 | 000,001,097 | ---- | M] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2015/03/06 13:49:09 | 000,002,303 | ---- | M] () -- C:\Users\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/03/06 12:51:43 | 000,001,118 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/02/22 08:41:39 | 000,000,017 | ---- | M] () -- C:\Users\Tony\AppData\Local\resmon.resmoncfg
[2015/02/15 08:43:59 | 000,493,368 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2015/03/06 15:42:19 | 000,001,097 | ---- | C] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2015/03/06 15:00:15 | 000,000,273 | ---- | C] () -- C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Menu.lnk
[2015/03/06 13:48:58 | 000,002,303 | ---- | C] () -- C:\Users\Tony\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/03/06 13:48:33 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/06 13:48:33 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/06 12:51:43 | 000,001,118 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/03/01 13:58:55 | 000,002,432 | ---- | C] () -- C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wikipedia.lnk
[2015/02/25 09:14:16 | 000,002,332 | ---- | C] () -- C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pandora.lnk
[2015/02/22 08:41:39 | 000,000,017 | ---- | C] () -- C:\Users\Tony\AppData\Local\resmon.resmoncfg
[2015/02/11 08:28:57 | 000,391,526 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2014/09/23 03:57:19 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014/09/23 03:47:11 | 000,172,097 | ---- | C] () -- C:\Windows\SysWow64\NoMSGuninstall.exe
[2014/09/23 03:47:11 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\UMonit64.exe
[2014/09/23 03:47:11 | 000,001,519 | ---- | C] () -- C:\Windows\SysWow64\_IconCfg0.ini
[2014/09/23 03:47:11 | 000,000,978 | ---- | C] () -- C:\Windows\SysWow64\ProductName.ini
[2014/09/23 03:47:11 | 000,000,184 | ---- | C] () -- C:\Windows\SysWow64\IconCfg0.ini
[2014/09/15 23:38:57 | 000,351,184 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
[2014/09/15 23:38:56 | 000,183,808 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014/09/15 23:38:56 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
[2014/03/18 05:13:28 | 000,002,255 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini
[2014/03/18 05:13:03 | 000,103,936 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2013/08/22 10:36:43 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2013/08/22 10:36:42 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2013/08/22 09:46:23 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2013/08/22 02:01:23 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2013/08/21 22:32:36 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2013/08/21 18:55:20 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2013/08/21 18:52:39 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2013/07/01 21:44:46 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[2014/09/15 23:57:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/30 19:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/30 17:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/12/19 10:12:27 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\acer
[2015/01/08 13:23:54 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\CareCenter
[2015/03/06 09:32:12 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\Dropbox
[2015/02/09 13:29:06 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\Foxit Software
[2015/01/10 10:54:32 | 000,000,000 | ---D | M] -- C:\Users\Tony\AppData\Roaming\WildTangent
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:581B0446
@Alternate Data Stream - 220 bytes -> C:\Users\Tony\OneDrive:ms-properties
< End of report >