HitmanPro 3.7.6.201
www.hitmanpro.com
Computer name . . . . : JPNB64
Windows . . . . . . . : 6.0.2.6002.X86/2
User name . . . . . . : JPNB64\Jeremy
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2013-08-03 01:36:16
Scan mode . . . . . . : Normal
Scan duration . . . . : 16m 0s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 279
Objects scanned . . . : 2,215,057
Files scanned . . . . : 48,156
Remnants scanned . . : 623,005 files / 1,543,896 keys
Suspicious files ____________________________________________________________
C:\QMSYS\bin\qmsvc.exe
Size . . . . . . . : 174,080 bytes
Age . . . . . . . : 1446.7 days (2009-08-17 09:08:33)
Entropy . . . . . : 6.7
SHA-256 . . . . . : 3FD9E1B7DFC7311021E5E17B28D1D4009CAF1E90648EAFCE5C1688ED875C252D
Service . . . . . : QMSvc
Parent Name . . . : C:\Windows\system32\services.exe
Running processes : 2416
Fuzzy . . . . . . : 22.0
The hidden file attribute bit is set. This is not common to most programs.
This program is actively listening for inbound network connections.
Starts automatically as a service during system bootup.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program starts automatically without user intervention.
The file is in use by one or more active processes.
Startup
HKLM\SYSTEM\CurrentControlSet\Services\QMSvc\
Network Ports
0.0.0.0:4242
0.0.0.0:4243
C:\Users\Jeremy\Documents\Downloads\sp23345.exe
Size . . . . . . . : 849,208 bytes
Age . . . . . . . : 1253.1 days (2010-02-26 23:01:59)
Entropy . . . . . : 7.9
SHA-256 . . . . . : F2BFDEB0C4C0B876FC7EDFC732B7773712AF71598975F127A2CEA15E198AFD0B
Product . . . . . : ROMPaq for Evo D310/D320/D510 and W4000 SFF DDR (686O2 ROM)
Publisher . . . . : Hewlett-Packard Company
Description . . . :
Version
Copyright . . . . :
RSA Key Size . . . : 512
Authenticode . . . : Valid
Fuzzy . . . . . . : 25.0
Program is code signed with a weak certificate. This is common to malware.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program is code signed with a valid Authenticode certificate.
C:\Users\Jeremy\Downloads\FSCaptureSetup74.exe
Size . . . . . . . : 2,499,922 bytes
Age . . . . . . . : 80.5 days (2013-05-14 14:03:21)
Entropy . . . . . : 8.0
SHA-256 . . . . . : F948F19E35DBAB0AA7172BC9046EC63F1CEFF5A31F9AF298904B2A6B17D89B21
Needs elevation . : Yes
Fuzzy . . . . . . : 22.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
C:\Windows\system32\WUDFUpdate_01009.dll
Size . . . . . . . : 1,837,296 bytes
Age . . . . . . . : 1206.7 days (2010-04-14 09:26:58)
Entropy . . . . . : 8.0
SHA-256 . . . . . : 6D63D31F77B9F56A70627720AA513C6FCD83117F71D3E1893966D88FF252B147
Product . . . . . : Microsoft® Windows® Operating System
Publisher . . . . : Microsoft Corporation
Description . . . : Windows Driver Foundation - User-mode Platform Device Update Co-Installer
Version . . . . . : 6.1.7600.16385
Copyright . . . . : © Microsoft Corporation. All rights reserved.
RSA Key Size . . . : 2048
Authenticode . . . : Invalid
Fuzzy . . . . . . : 32.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Cookies _____________________________________________________________________
C:\Users\Jeremy\AppData\Roaming\Microsoft\Windows\Cookies\9XDXPO0W.txt
C:\Users\Jeremy\AppData\Roaming\Microsoft\Windows\Cookies\CGL10AT2.txt
C:\Users\Jeremy\AppData\Roaming\Microsoft\Windows\Cookies\EXTVE6RK.txt