O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKU\S-1-5-21-772419714-465867292-1252962964-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BkupTray] C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [ePower_DMC] C:\Programme\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WarReg_PopUp] C:\Programme\Acer\WR_PopUp\WarReg_PopUp.exe (Acer Incorporated)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-772419714-465867292-1252962964-1000..\Run: [{12239928-8A3D-80EC-268D-D5669DDAD859}] C:\Users\user\AppData\Roaming\Axazeg\qefyu.exe File not found
O4 - HKU\S-1-5-21-772419714-465867292-1252962964-1000..\Run: [AVSolution] C:\Program Files\Antivir Solution Basic\avsolution.exe ()
O4 - HKU\S-1-5-21-772419714-465867292-1252962964-1000..\Run: [excqvjfl] C:\Users\user\AppData\Local\ickmfiqrv\qorcibltssd.exe ()
O4 - HKU\S-1-5-21-772419714-465867292-1252962964-1000..\Run: [userinit] C:\Users\user\AppData\Roaming\sdra64.exe File not found
O9 - Extra Button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programme\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe ()
O24 - Desktop WallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{3ba57094-ea6a-11de-9d63-001eec5c8dc0}\Shell - = AutoRun
O33 - MountPoints2\{3ba57094-ea6a-11de-9d63-001eec5c8dc0}\Shell\AutoRun\command - = F:\NokiaPCIA_Autorun.exe -- File not found
O33 - MountPoints2\{f1af926a-b5c1-11de-aa57-001eec5c8dc0}\Shell - = AutoRun
O33 - MountPoints2\{f1af926a-b5c1-11de-aa57-001eec5c8dc0}\Shell\AutoRun\command - = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{f1af9279-b5c1-11de-aa57-001eec5c8dc0}\Shell - = AutoRun
O33 - MountPoints2\{f1af9279-b5c1-11de-aa57-001eec5c8dc0}\Shell\AutoRun\command - = F:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- %1 %*
O35 - HKLM\..exefile [open] -- %1 %*
O37 - HKLM\...com [@ = comfile] -- %1 %*
O37 - HKLM\...exe [@ = exefile] -- %1 %*
========== Files/Folders - Created Within 90 Days ==========
[2010.07.23 04:25:05 | 000,000,000 | ---D | C] -- C:\Programme\Windows Portable Devices
[2010.07.23 04:04:26 | 000,000,000 | ---D | C] -- C:\Programme\7-Zip
[2010.07.23 04:00:55 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.07.23 04:00:27 | 000,153,376 | ---- | C] (Oracle) -- C:\Windows\System32\javaws.exe
[2010.07.23 04:00:27 | 000,145,184 | ---- | C] (Oracle) -- C:\Windows\System32\javaw.exe
[2010.07.23 04:00:27 | 000,145,184 | ---- | C] (Oracle) -- C:\Windows\System32\java.exe
[2010.07.23 03:58:03 | 000,000,000 | ---D | C] -- C:\Programme\Unlocker
[2010.07.23 03:57:02 | 000,000,000 | ---D | C] -- C:\Users\user\Desktop\AntiMalware
[2010.07.23 01:36:55 | 000,000,000 | ---D | C] -- C:\Users\user\Desktop\LOGS
[2010.07.23 00:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.07.23 00:50:33 | 000,423,656 | ---- | C] (Oracle) -- C:\Windows\System32\deployJava1.dll
[2010.07.22 22:20:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2010.07.22 22:20:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2010.07.22 22:20:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2010.07.22 21:26:45 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2010.07.22 20:48:23 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Silverlight
[2010.07.22 18:44:05 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Seven Zip
[2010.07.22 18:09:13 | 000,000,000 | ---D | C] -- C:\Programme\Antivir Solution Basic
[2010.07.22 16:29:49 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\ickmfiqrv
[2010.07.21 18:15:11 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Roaming\lowsec
[2010.07.14 16:36:31 | 000,000,000 | ---D | C] -- C:\Windows\Hewlett-Packard
[2010.06.09 17:06:56 | 000,000,000 | ---D | C] -- C:\Programme\SweetIM
[2010.05.29 16:16:33 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\PX Storage Engine
[2008.07.22 10:01:25 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
========== Files - Modified Within 90 Days ==========
[2010.07.23 04:52:37 | 000,767,488 | ---- | M] () -- C:\Windows\System32\drivers\jqmghmj.sys
[2010.07.23 04:51:53 | 002,621,440 | -HS- | M] () -- C:\Users\user\NTUSER.DAT
[2010.07.23 04:38:36 | 000,000,916 | ---- | M] () -- C:\Users\Public\Desktop\Antivir Solution Basic.lnk
[2010.07.23 04:34:29 | 001,445,310 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.07.23 04:34:29 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.07.23 04:34:29 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.07.23 04:34:29 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.07.23 04:34:29 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.07.23 04:28:19 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2010.07.23 04:28:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.07.23 04:28:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.07.23 04:27:59 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.07.23 04:27:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.07.23 04:24:59 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2010.07.23 04:24:44 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2010.07.23 04:24:39 | 000,524,288 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.07.23 04:24:39 | 000,065,536 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.07.23 04:24:36 | 002,447,281 | -H-- | M] () -- C:\Users\user\AppData\Local\IconCache.db
[2010.07.23 04:01:51 | 000,000,201 | ---- | M] () -- C:\Users\user\Desktop\Startup - Verknüpfung.lnk
[2010.07.23 04:00:15 | 000,423,656 | ---- | M] (Oracle) -- C:\Windows\System32\deployJava1.dll
[2010.07.23 04:00:15 | 000,153,376 | ---- | M] (Oracle) -- C:\Windows\System32\javaws.exe
[2010.07.23 04:00:15 | 000,145,184 | ---- | M] (Oracle) -- C:\Windows\System32\javaw.exe
[2010.07.23 04:00:15 | 000,145,184 | ---- | M] (Oracle) -- C:\Windows\System32\java.exe
[2010.07.23 00:46:56 | 000,000,134 | ---- | M] () -- C:\Users\user\Desktop\Java - Verknüpfung.lnk
[2010.07.22 22:24:40 | 000,296,648 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.07.22 20:43:26 | 000,000,134 | ---- | M] () -- C:\Users\user\Desktop\System - Verknüpfung.lnk
[2010.07.22 20:43:15 | 000,000,134 | ---- | M] () -- C:\Users\user\Desktop\Programme und Funktionen - Verknüpfung.lnk
[2010.07.22 20:43:01 | 000,000,134 | ---- | M] () -- C:\Users\user\Desktop\Geräte-Manager - Verknüpfung.lnk
[2010.07.22 19:47:14 | 000,000,527 | ---- | M] () -- C:\Users\user\Desktop\Temp - Verknüpfung (2).lnk
[2010.07.22 19:16:47 | 000,000,798 | ---- | M] () -- C:\Users\user\Desktop\Temp - Verknüpfung.lnk
[2010.07.22 19:10:07 | 000,071,400 | ---- | M] () -- C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.07.22 17:27:53 | 000,000,104 | ---- | M] () -- C:\Users\user\Desktop\Computer - Verknüpfung.lnk
[2010.07.01 17:21:09 | 000,001,832 | ---- | M] () -- C:\Users\user\Desktop\Cyberlink PowerDirector.lnk
[2010.06.29 17:40:10 | 000,005,632 | ---- | M] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.29 16:16:33 | 000,001,978 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Photoshop Lightroom 2.6.lnk
[2010.05.04 04:58:45 | 000,057,667 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2010.04.24 14:30:43 | 000,000,486 | ---- | M] () -- C:\Users\user\Documents\message-delivery-status-attachment
========== Files Created - No Company Name ==========
[2010.07.23 04:38:36 | 000,000,916 | ---- | C] () -- C:\Users\Public\Desktop\Antivir Solution Basic.lnk
[2010.07.23 04:24:59 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2010.07.23 04:24:44 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2010.07.23 04:01:51 | 000,000,201 | ---- | C] () -- C:\Users\user\Desktop\Startup - Verknüpfung.lnk
[2010.07.23 04:01:21 | 000,081,920 | ---- | C] () -- C:\Windows\System32\Startup.cpl
[2010.07.23 00:46:56 | 000,000,134 | ---- | C] () -- C:\Users\user\Desktop\Java - Verknüpfung.lnk
[2010.07.22 20:47:03 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010.07.22 20:43:26 | 000,000,134 | ---- | C] () -- C:\Users\user\Desktop\System - Verknüpfung.lnk
[2010.07.22 20:43:15 | 000,000,134 | ---- | C] () -- C:\Users\user\Desktop\Programme und Funktionen - Verknüpfung.lnk
[2010.07.22 20:43:01 | 000,000,134 | ---- | C] () -- C:\Users\user\Desktop\Geräte-Manager - Verknüpfung.lnk
[2010.07.22 19:47:14 | 000,000,527 | ---- | C] () -- C:\Users\user\Desktop\Temp - Verknüpfung (2).lnk
[2010.07.22 19:16:47 | 000,000,798 | ---- | C] () -- C:\Users\user\Desktop\Temp - Verknüpfung.lnk
[2010.07.22 17:27:53 | 000,000,104 | ---- | C] () -- C:\Users\user\Desktop\Computer - Verknüpfung.lnk
[2010.07.22 16:30:52 | 000,767,488 | ---- | C] () -- C:\Windows\System32\drivers\jqmghmj.sys
[2010.05.29 16:16:33 | 000,001,978 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Photoshop Lightroom 2.6.lnk
[2010.04.24 14:30:42 | 000,000,486 | ---- | C] () -- C:\Users\user\Documents\message-delivery-status-attachment
[2009.09.11 18:21:55 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.04.21 18:39:54 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2009.04.21 18:39:10 | 000,000,025 | ---- | C] () -- C:\Windows\CSES20.ini
[2008.09.30 06:48:32 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2008.09.30 06:48:32 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2008.08.21 08:05:45 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.05.21 00:20:54 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll
[2008.05.21 00:20:54 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll
[2008.05.20 23:20:51 | 000,204,800 | ---- | C] () -- C:\Windows\System32\SysHook.dll
[2008.05.20 23:15:50 | 000,487,424 | ---- | C] () -- C:\Windows\System32\INT15.dll
[2008.05.20 22:59:29 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2001.12.26 16:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001.09.03 23:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001.07.30 16:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001.07.23 22:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
========== LOP Check ==========
[2008.05.20 23:42:38 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Acer GameZone Console
[2010.07.09 16:31:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Axazeg
[2009.04.23 16:16:58 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\eSobi
[2010.07.22 19:09:39 | 000,000,000 | -HSD | M] -- C:\Users\user\AppData\Roaming\lowsec
[2009.04.21 19:01:04 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Template
[2010.07.06 20:29:00 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Xaum
[2010.07.23 04:25:15 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006.09.18 23:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009.04.11 08:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008.05.21 08:34:21 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006.09.18 23:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008.09.30 07:55:19 | 000,000,020 | ---- | M] () -- C:\Medion.ini
[2010.07.23 04:26:41 | 3768,049,664 | -HS- | M] () -- C:\pagefile.sys
[2008.09.30 07:49:28 | 000,000,060 | ---- | M] () -- C:\Partition.txt
[2008.05.20 23:00:53 | 000,000,650 | ---- | M] () -- C:\RHDSetup.log
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008.07.08 17:26:16 | 000,421,888 | ---- | M] (Advanced Micro Devices, Inc.)
Unable to obtain MD5 -- C:\Windows\System32\ATIDEMGX.dll
[2009.04.11 08:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009.04.11 08:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008.01.21 05:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 05:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 05:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 >
[2010.07.23 04:55:04 | 000,767,488 | ---- | M] () -- C:\Windows\System32\drivers\jqmghmj.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\user\Documents\TruckersinPolen.mpg:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\user\Documents\tier-sex.mpeg:TOC.WMV
< End of report >