Guest User

Boucheman/OTL Report

a guest
Dec 17th, 2012
189
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 330.81 KB | None | 0 0
  1. OTL logfile created on: 12/17/2012 6:14:06 PM - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Home\Desktop
  3. 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.0.8112.16421)
  5. Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
  6.  
  7. 7.80 Gb Total Physical Memory | 5.97 Gb Available Physical Memory | 76.48% Memory free
  8. 15.61 Gb Paging File | 13.36 Gb Available in Paging File | 85.61% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 917.66 Gb Total Space | 700.53 Gb Free Space | 76.34% Space Free | Partition Type: NTFS
  13. Drive L: | 465.73 Gb Total Space | 68.27 Gb Free Space | 14.66% Space Free | Partition Type: NTFS
  14.  
  15. Computer Name: HOME-PC | User Name: Home | Logged in as Administrator.
  16. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
  17. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
  18.  
  19. [color=#E56717]========== Processes (SafeList) ==========[/color]
  20.  
  21. PRC - [2012/12/17 18:12:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Home\Desktop\OTL.exe
  22. PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
  23. PRC - [2012/08/14 13:58:58 | 000,646,800 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
  24. PRC - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
  25. PRC - [2011/07/30 21:29:32 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
  26. PRC - [2010/11/17 09:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
  27. PRC - [2010/04/01 11:23:21 | 000,765,952 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
  28. PRC - [2010/01/27 15:01:56 | 000,237,568 | ---- | M] (Alcor Micro Corp.) -- C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
  29. PRC - [2009/06/22 07:08:37 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
  30. PRC - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
  31.  
  32.  
  33. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  34.  
  35. MOD - [2012/12/04 19:15:15 | 012,456,040 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
  36. MOD - [2012/12/04 19:15:15 | 000,460,904 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppgooglenaclpluginchrome.dll
  37. MOD - [2012/12/04 19:15:14 | 004,008,040 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
  38. MOD - [2012/12/04 19:14:29 | 000,587,880 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll
  39. MOD - [2012/12/04 19:14:28 | 000,124,520 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll
  40. MOD - [2012/12/04 19:14:21 | 000,157,304 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll
  41. MOD - [2012/12/04 19:14:20 | 000,275,576 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll
  42. MOD - [2012/12/04 19:14:19 | 002,168,952 | ---- | M] () -- C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll
  43. MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
  44. MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
  45. MOD - [2011/03/16 23:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
  46. MOD - [2010/11/24 21:44:02 | 000,375,280 | ---- | M] () -- c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
  47. MOD - [2010/11/17 09:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
  48. MOD - [2010/10/20 14:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
  49. MOD - [2010/04/01 11:24:28 | 001,159,168 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleadrs.dll
  50. MOD - [2010/04/01 11:23:27 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleascw.dll
  51. MOD - [2010/04/01 11:23:21 | 000,765,952 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
  52. MOD - [2009/11/26 02:49:41 | 000,086,180 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\DLEAcfg.dll
  53. MOD - [2009/06/22 07:08:44 | 000,196,608 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epoemdll.dll
  54. MOD - [2009/06/22 07:08:43 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epstring.dll
  55. MOD - [2009/06/22 07:08:41 | 002,203,648 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epwizres.dll
  56. MOD - [2009/06/22 07:08:37 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
  57. MOD - [2009/06/22 07:08:27 | 000,708,608 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epwizard.dll
  58. MOD - [2009/06/22 07:06:32 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\customui.dll
  59. MOD - [2009/06/22 07:06:09 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epfunct.dll
  60. MOD - [2009/06/22 07:06:03 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\eputil.dll
  61. MOD - [2009/06/22 07:05:49 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\imagutil.dll
  62. MOD - [2009/05/27 06:16:50 | 000,192,512 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleadatr.dll
  63. MOD - [2009/04/07 13:25:27 | 000,409,600 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\iptk.dll
  64. MOD - [2009/03/09 23:43:49 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleacaps.dll
  65. MOD - [2009/03/05 11:55:33 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleacnv4.dll
  66. MOD - [2009/03/02 08:25:47 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleaptp.dll
  67. MOD - [2009/02/20 07:50:18 | 000,028,672 | ---- | M] () -- C:\Windows\SysWOW64\dleasmr.dll
  68. MOD - [2009/02/20 07:49:38 | 000,299,008 | ---- | M] () -- C:\Windows\SysWOW64\dleasm.dll
  69.  
  70.  
  71. [color=#E56717]========== Services (SafeList) ==========[/color]
  72.  
  73. SRV:[b]64bit:[/b] - [2012/11/16 21:10:22 | 000,383,608 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\virusscan\mcods.exe -- (McODS)
  74. SRV:[b]64bit:[/b] - [2012/11/09 06:37:30 | 000,177,680 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
  75. SRV:[b]64bit:[/b] - [2012/11/09 06:34:50 | 000,218,320 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
  76. SRV:[b]64bit:[/b] - [2012/11/09 06:33:08 | 000,241,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
  77. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (MSK80Service)
  78. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
  79. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
  80. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
  81. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
  82. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
  83. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
  84. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
  85. SRV:[b]64bit:[/b] - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
  86. SRV:[b]64bit:[/b] - [2010/08/30 13:42:00 | 000,220,528 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\mcafee\msc\McAWFwk.exe -- (McAWFwk)
  87. SRV:[b]64bit:[/b] - [2009/12/09 14:24:07 | 001,047,552 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\dleacoms.exe -- (dlea_device)
  88. SRV:[b]64bit:[/b] - [2009/07/01 12:13:40 | 000,033,448 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dleaserv.exe -- (dleaCATSCustConnectService)
  89. SRV - [2012/12/12 01:27:13 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
  90. SRV - [2012/11/09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
  91. SRV - [2012/11/03 09:55:34 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
  92. SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
  93. SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
  94. SRV - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
  95. SRV - [2012/05/08 21:21:41 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
  96. SRV - [2011/07/30 21:29:32 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
  97. SRV - [2011/06/02 19:02:23 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
  98. SRV - [2010/11/25 04:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
  99. SRV - [2010/11/25 04:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
  100. SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
  101. SRV - [2010/03/18 15:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
  102. SRV - [2009/12/09 13:35:58 | 000,593,920 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWOW64\dleacoms.exe -- (dlea_device)
  103. SRV - [2009/07/01 12:13:40 | 000,033,448 | ---- | M] () [Auto | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe -- (dleaCATSCustConnectService)
  104. SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  105. SRV - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
  106.  
  107.  
  108. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  109.  
  110. DRV:[b]64bit:[/b] - [2012/11/09 06:40:24 | 000,069,672 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
  111. DRV:[b]64bit:[/b] - [2012/11/09 06:37:42 | 000,339,776 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
  112. DRV:[b]64bit:[/b] - [2012/11/09 06:36:30 | 000,106,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
  113. DRV:[b]64bit:[/b] - [2012/11/09 06:35:50 | 000,771,096 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
  114. DRV:[b]64bit:[/b] - [2012/11/09 06:34:58 | 000,515,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
  115. DRV:[b]64bit:[/b] - [2012/11/09 06:34:18 | 000,309,400 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
  116. DRV:[b]64bit:[/b] - [2012/11/09 06:33:58 | 000,178,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
  117. DRV:[b]64bit:[/b] - [2012/09/29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
  118. DRV:[b]64bit:[/b] - [2012/08/23 08:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
  119. DRV:[b]64bit:[/b] - [2012/08/23 08:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
  120. DRV:[b]64bit:[/b] - [2012/08/23 08:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  121. DRV:[b]64bit:[/b] - [2012/04/20 15:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)
  122. DRV:[b]64bit:[/b] - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  123. DRV:[b]64bit:[/b] - [2012/02/15 10:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
  124. DRV:[b]64bit:[/b] - [2012/01/10 21:28:18 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
  125. DRV:[b]64bit:[/b] - [2011/08/23 04:12:58 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
  126. DRV:[b]64bit:[/b] - [2011/03/11 00:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  127. DRV:[b]64bit:[/b] - [2011/03/11 00:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  128. DRV:[b]64bit:[/b] - [2011/01/15 10:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
  129. DRV:[b]64bit:[/b] - [2010/12/20 23:55:02 | 000,172,104 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdm.sys -- (sscdmdm)
  130. DRV:[b]64bit:[/b] - [2010/12/20 23:55:02 | 000,141,384 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdserd.sys -- (sscdserd)
  131. DRV:[b]64bit:[/b] - [2010/12/20 23:55:02 | 000,136,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdbus.sys -- (sscdbus)
  132. DRV:[b]64bit:[/b] - [2010/12/20 23:55:02 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdfl.sys -- (sscdmdfl)
  133. DRV:[b]64bit:[/b] - [2010/12/16 16:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
  134. DRV:[b]64bit:[/b] - [2010/11/20 21:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  135. DRV:[b]64bit:[/b] - [2010/03/19 02:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
  136. DRV:[b]64bit:[/b] - [2010/02/27 09:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
  137. DRV:[b]64bit:[/b] - [2009/10/24 06:49:46 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
  138. DRV:[b]64bit:[/b] - [2009/10/16 05:32:24 | 000,321,064 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
  139. DRV:[b]64bit:[/b] - [2009/09/17 14:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
  140. DRV:[b]64bit:[/b] - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  141. DRV:[b]64bit:[/b] - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  142. DRV:[b]64bit:[/b] - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  143. DRV:[b]64bit:[/b] - [2009/07/13 18:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
  144. DRV:[b]64bit:[/b] - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  145. DRV:[b]64bit:[/b] - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  146. DRV:[b]64bit:[/b] - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  147. DRV:[b]64bit:[/b] - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  148. DRV:[b]64bit:[/b] - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
  149. DRV:[b]64bit:[/b] - [2009/02/24 17:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
  150. DRV:[b]64bit:[/b] - [2009/01/09 14:02:08 | 000,031,744 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
  151. DRV:[b]64bit:[/b] - [2008/05/06 15:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
  152. DRV:[b]64bit:[/b] - [2006/11/01 11:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
  153. DRV - [2012/06/17 22:27:01 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\dgderdrv.sys -- (dgderdrv)
  154. DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  155.  
  156.  
  157. [color=#E56717]========== Standard Registry (All) ==========[/color]
  158.  
  159.  
  160. [color=#E56717]========== Internet Explorer ==========[/color]
  161.  
  162. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
  163. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  164. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  165. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  166. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
  167. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  168. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  169. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
  170. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
  171. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  172. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
  173. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
  174. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  175. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  176. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  177. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  178. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  179. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  180. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
  181. IE - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
  182. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  183. IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
  184.  
  185.  
  186. IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
  187. IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
  188. IE - HKU\.DEFAULT\..\SearchScopes\{9437883B-09B0-482D-A717-CC2A0B457F98}: "URL" = http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
  189. IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  190.  
  191. IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
  192. IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
  193. IE - HKU\S-1-5-18\..\SearchScopes\{9437883B-09B0-482D-A717-CC2A0B457F98}: "URL" = http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
  194. IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  195.  
  196. IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  197.  
  198. IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  199.  
  200. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
  201. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
  202. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  203. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://g.msn.com/uscon/1 [binary data]
  204. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
  205. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  206. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
  207. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
  208. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  209. IE - HKU\S-1-5-21-1526968901-1929943128-198173789-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  210.  
  211. [color=#E56717]========== FireFox ==========[/color]
  212.  
  213. FF - prefs.js..browser.search.selectedEngine: "Secure Search"
  214. FF - prefs.js..browser.startup.homepage: "http://my.daemon-search.com/"
  215. FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.11
  216. FF - prefs.js..extensions.enabledAddons: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.5.0
  217. FF - prefs.js..extensions.enabledAddons: {972ce4c6-7e08-4474-a285-3208198ce6fd}:15.0.1
  218. FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p="
  219. FF - prefs.js..network.proxy.type: 0
  220.  
  221.  
  222. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
  223. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
  224. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
  225. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  226. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
  227. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  228. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
  229. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
  230. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
  231. FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
  232. FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
  233. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll File not found
  234. FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
  235. FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
  236. FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
  237. FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  238. FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
  239. FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  240. FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  241. FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  242. FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  243. FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  244. FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  245. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
  246. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
  247. FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\6\NP_wtapp.dll ()
  248. FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  249. FF - HKCU\Software\MozillaPlugins\@plugin.couponnetwork.com/Coupon Print Activator;version=4.5: C:\Users\Home\AppData\Roaming\E-centives\NPcolPM460.dll (Invenda)
  250. FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Home\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
  251. FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Home\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
  252. FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Home\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
  253.  
  254. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/14 02:35:00 | 000,000,000 | ---D | M]
  255. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/12/14 04:44:20 | 000,000,000 | ---D | M]
  256. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/03 09:55:36 | 000,000,000 | ---D | M]
  257. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
  258. FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2012/09/29 09:54:16 | 000,000,000 | ---D | M]
  259. FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/03 09:55:36 | 000,000,000 | ---D | M]
  260. FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
  261.  
  262. [2011/06/08 21:29:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Home\AppData\Roaming\Mozilla\Extensions
  263. [2012/12/16 10:55:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\nkvulwzx.default\extensions
  264. [2012/10/11 13:56:02 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\nkvulwzx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
  265. [2012/11/19 18:05:57 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\nkvulwzx.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
  266. [2012/11/17 21:31:00 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\nkvulwzx.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
  267. [2012/12/16 10:55:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\nkvulwzx.default\extensions\staged
  268. [2011/07/05 17:43:06 | 000,002,055 | ---- | M] () -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\nkvulwzx.default\searchplugins\daemon-search.xml
  269. [2012/05/17 22:23:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
  270. [2012/11/03 09:55:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
  271. [2012/12/14 02:35:00 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
  272. [2012/11/03 09:55:35 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
  273. [2011/04/14 13:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
  274. [2012/11/03 09:55:33 | 000,001,607 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
  275. [2012/11/03 09:55:33 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
  276. [2012/11/03 09:55:33 | 000,001,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
  277. [2012/11/03 09:55:33 | 000,003,581 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
  278. [2012/12/16 10:52:55 | 000,002,024 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
  279. [2012/11/03 09:55:33 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
  280. [2012/11/03 09:55:33 | 000,001,391 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
  281. [2012/11/03 09:55:33 | 000,001,309 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
  282.  
  283. [color=#E56717]========== Chrome ==========[/color]
  284.  
  285. CHR - homepage: http://www.google.com/
  286. CHR - default_search_provider: McAfee (Enabled)
  287. CHR - default_search_provider: search_url = http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
  288. CHR - default_search_provider: suggest_url =
  289. CHR - homepage: http://www.google.com/
  290. CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
  291. CHR - plugin: Native Client (Enabled) = C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
  292. CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
  293. CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Home\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
  294. CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Home\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
  295. CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
  296. CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
  297. CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
  298. CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
  299. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
  300. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
  301. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
  302. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
  303. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
  304. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
  305. CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
  306. CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
  307. CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
  308. CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
  309. CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
  310. CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
  311. CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\6\NP_wtapp.dll
  312. CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
  313. CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
  314. CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Home\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
  315. CHR - plugin: Coupon Activator Netscape Plugin v. 4.5.0.0 (Enabled) = C:\Users\Home\AppData\Roaming\E-centives\NPcolPM460.dll
  316. CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
  317. CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
  318. CHR - Extension: Adblock Plus = C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.1_0\
  319. CHR - Extension: SiteAdvisor = C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\
  320. CHR - Extension: Reddit Enhancement Suite = C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.1.5_0\
  321.  
  322. O1 HOSTS File: ([2012/07/16 11:33:24 | 000,000,822 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  323. O2:[b]64bit:[/b] - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
  324. O2:[b]64bit:[/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  325. O2:[b]64bit:[/b] - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120701004616.dll (McAfee, Inc.)
  326. O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
  327. O2:[b]64bit:[/b] - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  328. O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  329. O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
  330. O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
  331. O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
  332. O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\mcafee\msk\mskapbho.dll ()
  333. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  334. O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
  335. O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120701004616.dll (McAfee, Inc.)
  336. O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
  337. O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
  338. O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  339. O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  340. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
  341. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  342. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
  343. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
  344. O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  345. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
  346. O4:[b]64bit:[/b] - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
  347. O4:[b]64bit:[/b] - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
  348. O4:[b]64bit:[/b] - HKLM..\Run: [dleamon.exe] C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe ()
  349. O4:[b]64bit:[/b] - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe ()
  350. O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
  351. O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
  352. O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
  353. O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
  354. O4 - HKLM..\Run: [] File not found
  355. O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
  356. O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
  357. O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
  358. O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
  359. O4 - HKLM..\Run: [Dell V310-V510 Series] C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe ()
  360. O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
  361. O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
  362. O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
  363. O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
  364. O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
  365. O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
  366. O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
  367. O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
  368. O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  369. O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  370. O4 - HKU\S-1-5-21-1526968901-1929943128-198173789-1001..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe (Alcohol Soft Development Team)
  371. O4 - HKU\.DEFAULT..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe -update activex File not found
  372. O4 - HKU\S-1-5-18..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe -update activex File not found
  373. O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  374. O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  375. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  376. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  377. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
  378. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
  379. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
  380. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
  381. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  382. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
  383. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
  384. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
  385. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
  386. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
  387. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
  388. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
  389. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
  390. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
  391. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
  392. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
  393. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
  394. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
  395. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
  396. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
  397. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
  398. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
  399. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
  400. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
  401. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
  402. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
  403. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
  404. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
  405. O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
  406. O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  407. O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
  408. O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  409. O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  410. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  411. O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  412. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  413. O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
  414. O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
  415. O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
  416. O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  417. O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  418. O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  419. O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  420. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  421. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
  422. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  423. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  424. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  425. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
  426. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  427. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  428. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
  429. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
  430. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
  431. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
  432. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
  433. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
  434. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
  435. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
  436. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
  437. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
  438. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
  439. O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
  440. O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
  441. O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  442. O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  443. O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
  444. O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
  445. O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  446. O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  447. O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
  448. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  449. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  450. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  451. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  452. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  453. O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  454. O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  455. O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  456. O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  457. O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
  458. O13[b]64bit:[/b] - gopher Prefix: missing
  459. O13 - gopher Prefix: missing
  460. O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
  461. O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
  462. O16:[b]64bit:[/b] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Reg Error: Key error.)
  463. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.0)
  464. O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
  465. O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
  466. O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
  467. O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
  468. O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.0)
  469. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
  470. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{52E96541-6429-4922-A7A8-C89169E3C11B}: DhcpNameServer = 192.168.1.1
  471. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{661637C6-1229-4B1F-B0C2-19253A4C7D05}: DhcpNameServer = 192.168.1.1
  472. O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  473. O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  474. O18:[b]64bit:[/b] - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  475. O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  476. O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  477. O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  478. O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  479. O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  480. O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  481. O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  482. O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
  483. O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  484. O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  485. O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
  486. O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  487. O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
  488. O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  489. O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
  490. O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  491. O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  492. O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
  493. O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  494. O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  495. O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
  496. O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
  497. O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  498. O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  499. O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  500. O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  501. O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  502. O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  503. O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  504. O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  505. O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  506. O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  507. O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
  508. O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  509. O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  510. O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
  511. O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  512. O18 - Protocol\Handler\ms-help - No CLSID value found
  513. O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  514. O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
  515. O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  516. O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  517. O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
  518. O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  519. O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  520. O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
  521. O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
  522. O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  523. O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  524. O18:[b]64bit:[/b] - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
  525. O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  526. O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
  527. O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  528. O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  529. O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
  530. O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  531. O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
  532. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  533. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  534. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  535. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  536. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  537. O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
  538. O20:[b]64bit:[/b] - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
  539. O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
  540. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  541. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  542. O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  543. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  544. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  545. O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  546. O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  547. O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  548. O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
  549. O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  550. O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
  551. O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
  552. O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
  553. O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
  554. O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
  555. O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
  556. O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  557. O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
  558. O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
  559. O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
  560. O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
  561. O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
  562. O31 - SafeBoot: AlternateShell - cmd.exe
  563. O32 - HKLM CDRom: AutoRun - 1
  564. O33 - MountPoints2\{6a9dc812-ae92-11e1-809c-782bcb92b426}\Shell - "" = AutoRun
  565. O33 - MountPoints2\{6a9dc812-ae92-11e1-809c-782bcb92b426}\Shell\AutoRun\command - "" = L:\AUTORUN.EXE
  566. O34 - HKLM BootExecute: (autocheck autochk *)
  567. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  568. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  569. O35 - HKLM\..comfile [open] -- "%1" %*
  570. O35 - HKLM\..exefile [open] -- "%1" %*
  571. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  572. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  573. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  574. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  575. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  576. O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
  577. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  578.  
  579.  
  580.  
  581. SafeBootMin:[b]64bit:[/b] 11451974.sys - Driver
  582. SafeBootMin:[b]64bit:[/b] 44262458.sys - Driver
  583. SafeBootMin:[b]64bit:[/b] AppMgmt - Service
  584. SafeBootMin:[b]64bit:[/b] Base - Driver Group
  585. SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
  586. SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
  587. SafeBootMin:[b]64bit:[/b] File system - Driver Group
  588. SafeBootMin:[b]64bit:[/b] Filter - Driver Group
  589. SafeBootMin:[b]64bit:[/b] HelpSvc - Service
  590. SafeBootMin:[b]64bit:[/b] mcmscsvc - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
  591. SafeBootMin:[b]64bit:[/b] MCODS - C:\Program Files\mcafee\virusscan\mcods.exe (McAfee, Inc.)
  592. SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
  593. SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
  594. SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
  595. SafeBootMin:[b]64bit:[/b] sacsvr - Service
  596. SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
  597. SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
  598. SafeBootMin:[b]64bit:[/b] vmms - Service
  599. SafeBootMin:[b]64bit:[/b] WinDefend - Service
  600. SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  601. SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  602. SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  603. SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  604. SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  605. SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  606. SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  607. SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  608. SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  609. SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  610. SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  611. SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  612. SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  613. SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  614. SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  615. SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  616. SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  617. SafeBootMin: 11451974.sys - Driver
  618. SafeBootMin: 44262458.sys - Driver
  619. SafeBootMin: AppMgmt - Service
  620. SafeBootMin: Base - Driver Group
  621. SafeBootMin: Boot Bus Extender - Driver Group
  622. SafeBootMin: Boot file system - Driver Group
  623. SafeBootMin: File system - Driver Group
  624. SafeBootMin: Filter - Driver Group
  625. SafeBootMin: HelpSvc - Service
  626. SafeBootMin: PCI Configuration - Driver Group
  627. SafeBootMin: PNP Filter - Driver Group
  628. SafeBootMin: Primary disk - Driver Group
  629. SafeBootMin: sacsvr - Service
  630. SafeBootMin: SCSI Class - Driver Group
  631. SafeBootMin: System Bus Extender - Driver Group
  632. SafeBootMin: vmms - Service
  633. SafeBootMin: WinDefend - Service
  634. SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  635. SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  636. SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  637. SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  638. SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  639. SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  640. SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  641. SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  642. SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  643. SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  644. SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  645. SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  646. SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  647. SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  648. SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  649. SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  650. SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  651.  
  652. SafeBootNet:[b]64bit:[/b] 11451974.sys - Driver
  653. SafeBootNet:[b]64bit:[/b] 44262458.sys - Driver
  654. SafeBootNet:[b]64bit:[/b] AppMgmt - Service
  655. SafeBootNet:[b]64bit:[/b] Base - Driver Group
  656. SafeBootNet:[b]64bit:[/b] BFE - Service
  657. SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
  658. SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
  659. SafeBootNet:[b]64bit:[/b] File system - Driver Group
  660. SafeBootNet:[b]64bit:[/b] Filter - Driver Group
  661. SafeBootNet:[b]64bit:[/b] HelpSvc - Service
  662. SafeBootNet:[b]64bit:[/b] McMPFSvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
  663. SafeBootNet:[b]64bit:[/b] mcmscsvc - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
  664. SafeBootNet:[b]64bit:[/b] MCODS - C:\Program Files\mcafee\virusscan\mcods.exe (McAfee, Inc.)
  665. SafeBootNet:[b]64bit:[/b] Messenger - Service
  666. SafeBootNet:[b]64bit:[/b] mfefire - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
  667. SafeBootNet:[b]64bit:[/b] mfefirek - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
  668. SafeBootNet:[b]64bit:[/b] mfefirek.sys - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
  669. SafeBootNet:[b]64bit:[/b] mfehidk - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
  670. SafeBootNet:[b]64bit:[/b] mfehidk.sys - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
  671. SafeBootNet:[b]64bit:[/b] mfevtp - C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
  672. SafeBootNet:[b]64bit:[/b] MPSSvc - Service
  673. SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
  674. SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
  675. SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
  676. SafeBootNet:[b]64bit:[/b] Network - Driver Group
  677. SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
  678. SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
  679. SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
  680. SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
  681. SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
  682. SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
  683. SafeBootNet:[b]64bit:[/b] sacsvr - Service
  684. SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
  685. SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
  686. SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
  687. SafeBootNet:[b]64bit:[/b] TDI - Driver Group
  688. SafeBootNet:[b]64bit:[/b] vmms - Service
  689. SafeBootNet:[b]64bit:[/b] WinDefend - Service
  690. SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
  691. SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  692. SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  693. SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  694. SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  695. SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  696. SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  697. SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  698. SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
  699. SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
  700. SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
  701. SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
  702. SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  703. SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  704. SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  705. SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  706. SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
  707. SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  708. SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  709. SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  710. SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  711. SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  712. SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  713. SafeBootNet: 11451974.sys - Driver
  714. SafeBootNet: 44262458.sys - Driver
  715. SafeBootNet: AppMgmt - Service
  716. SafeBootNet: Base - Driver Group
  717. SafeBootNet: BFE - Service
  718. SafeBootNet: Boot Bus Extender - Driver Group
  719. SafeBootNet: Boot file system - Driver Group
  720. SafeBootNet: File system - Driver Group
  721. SafeBootNet: Filter - Driver Group
  722. SafeBootNet: GoToAssist - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
  723. SafeBootNet: HelpSvc - Service
  724. SafeBootNet: Messenger - Service
  725. SafeBootNet: MPSSvc - Service
  726. SafeBootNet: NDIS Wrapper - Driver Group
  727. SafeBootNet: NetBIOSGroup - Driver Group
  728. SafeBootNet: NetDDEGroup - Driver Group
  729. SafeBootNet: Network - Driver Group
  730. SafeBootNet: NetworkProvider - Driver Group
  731. SafeBootNet: PCI Configuration - Driver Group
  732. SafeBootNet: PNP Filter - Driver Group
  733. SafeBootNet: PNP_TDI - Driver Group
  734. SafeBootNet: Primary disk - Driver Group
  735. SafeBootNet: rdsessmgr - Service
  736. SafeBootNet: sacsvr - Service
  737. SafeBootNet: SCSI Class - Driver Group
  738. SafeBootNet: Streams Drivers - Driver Group
  739. SafeBootNet: System Bus Extender - Driver Group
  740. SafeBootNet: TDI - Driver Group
  741. SafeBootNet: vmms - Service
  742. SafeBootNet: WinDefend - Service
  743. SafeBootNet: WudfUsbccidDriver - Driver
  744. SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  745. SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  746. SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  747. SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  748. SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  749. SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  750. SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  751. SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
  752. SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
  753. SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
  754. SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
  755. SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  756. SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  757. SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  758. SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  759. SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
  760. SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  761. SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  762. SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  763. SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  764. SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  765. SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  766.  
  767. ActiveX:[b]64bit:[/b] {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
  768. ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
  769. ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
  770. ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
  771. ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
  772. ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
  773. ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
  774. ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
  775. ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
  776. ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
  777. ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
  778. ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
  779. ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
  780. ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
  781. ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
  782. ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
  783. ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
  784. ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
  785. ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
  786. ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
  787. ActiveX:[b]64bit:[/b] {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
  788. ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
  789. ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
  790. ActiveX:[b]64bit:[/b] >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
  791. ActiveX:[b]64bit:[/b] >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
  792. ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
  793. ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
  794. ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Windows Media Player 5.2
  795. ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
  796. ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
  797. ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
  798. ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
  799. ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
  800. ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
  801. ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
  802. ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
  803. ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
  804. ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
  805. ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
  806. ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
  807. ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
  808. ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
  809. ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
  810. ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
  811. ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
  812. ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
  813. ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
  814. ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Yahoo! Messenger
  815. ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
  816. ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
  817. ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
  818. ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
  819. ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
  820. ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
  821.  
  822. Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  823. Drivers32:[b]64bit:[/b] vidc.lags - lagarith.dll ( )
  824. Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
  825. Drivers32: msacm.divxa32 - C:\Windows\SysWow64\DivXa32.acm (Packed With Joy !)
  826. Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  827. Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
  828. Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
  829. Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
  830. Drivers32: vidc.ffds - C:\Windows\SysWow64\ff_vfw.dll ()
  831. Drivers32: vidc.lags - C:\Windows\SysWow64\Lagarith.dll ( )
  832. Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
  833. Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
  834. Drivers32: vidc.xvid - C:\Windows\SysWow64\xvidvfw.dll ()
  835.  
  836. [color=#E56717]========== Files/Folders - Created Within 90 Days ==========[/color]
  837.  
  838. [2012/12/17 18:12:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Home\Desktop\OTL.exe
  839. [2012/12/17 01:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
  840. [2012/12/14 22:47:40 | 000,328,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\services.exe
  841. [2012/12/14 21:36:23 | 000,000,000 | ---D | C] -- C:\Users\Home\Desktop\RK_Quarantine
  842. [2012/12/14 02:28:56 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
  843. [2012/12/11 12:51:18 | 001,554,944 | ---- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) -- C:\Windows\SysWow64\vorbis.acm
  844. [2012/12/11 12:51:18 | 000,000,000 | ---D | C] -- C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
  845. [2012/12/08 04:39:01 | 000,000,000 | ---D | C] -- C:\Users\Home\AppData\Roaming\SpeedyPC Software
  846. [2012/12/08 04:39:01 | 000,000,000 | ---D | C] -- C:\Users\Home\AppData\Roaming\DriverCure
  847. [2012/12/08 04:37:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software
  848. [2012/12/06 15:38:40 | 000,000,000 | ---D | C] -- C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mega Codec Pack
  849. [2012/12/06 15:38:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mega Codec Pack
  850. [2012/12/01 13:20:24 | 000,000,000 | ---D | C] -- C:\Users\Home\Desktop\songs
  851. [2012/11/27 23:02:47 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll
  852. [2012/11/27 23:02:47 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
  853. [2012/11/27 23:02:47 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
  854. [2012/11/27 23:02:43 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
  855. [2012/11/27 23:02:43 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbGD.sys
  856. [2012/11/27 23:02:43 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
  857. [2012/11/27 23:02:36 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
  858. [2012/11/27 23:02:36 | 000,384,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
  859. [2012/11/27 23:02:36 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll
  860. [2012/11/27 23:02:36 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll
  861. [2012/11/27 23:02:36 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
  862. [2012/11/27 23:02:36 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll
  863. [2012/11/27 23:02:36 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll
  864. [2012/11/27 23:02:36 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
  865. [2012/11/27 23:02:36 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
  866. [2012/11/27 23:02:36 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
  867. [2012/11/27 23:02:36 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
  868. [2012/11/27 23:02:36 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
  869. [2012/11/27 23:02:36 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
  870. [2012/11/27 23:02:36 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
  871. [2012/11/27 23:02:36 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
  872. [2012/11/27 23:02:35 | 005,773,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
  873. [2012/11/27 23:02:35 | 004,916,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
  874. [2012/11/27 23:02:35 | 003,174,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
  875. [2012/11/27 23:02:35 | 001,123,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
  876. [2012/11/27 23:01:57 | 001,448,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
  877. [2012/11/27 23:01:57 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
  878. [2012/11/25 22:09:34 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
  879. [2012/11/25 22:09:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
  880. [2012/11/25 22:09:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
  881. [2012/11/20 23:09:45 | 000,000,000 | ---D | C] -- C:\Users\Home\Documents\Sound Clips
  882. [2012/11/20 03:48:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
  883. [2012/11/20 03:48:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
  884. [2012/11/20 03:48:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCH Software
  885. [2012/11/14 03:12:07 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys
  886. [2012/11/14 03:12:07 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll
  887. [2012/11/14 03:06:54 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
  888. [2012/11/14 03:06:54 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
  889. [2012/11/14 03:06:53 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
  890. [2012/11/14 03:06:53 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
  891. [2012/11/14 03:06:53 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
  892. [2012/11/14 03:06:53 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
  893. [2012/11/14 03:06:53 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
  894. [2012/11/14 03:06:53 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
  895. [2012/11/14 03:06:53 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
  896. [2012/11/14 03:06:53 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
  897. [2012/11/14 03:06:53 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
  898. [2012/11/14 03:06:52 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
  899. [2012/11/14 03:06:52 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
  900. [2012/11/14 03:06:52 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
  901. [2012/11/14 03:06:51 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
  902. [2012/11/14 03:03:54 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll
  903. [2012/11/14 03:03:53 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll
  904. [2012/11/14 03:03:53 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe
  905. [2012/11/14 03:03:53 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll
  906. [2012/11/14 02:34:37 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
  907. [2012/11/14 02:34:37 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
  908. [2012/11/14 02:34:37 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
  909. [2012/11/14 02:34:28 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
  910. [2012/11/14 02:34:28 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
  911. [2012/11/14 02:34:28 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
  912. [2012/11/14 02:34:28 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
  913. [2012/11/14 02:34:27 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
  914. [2012/11/14 02:34:27 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
  915. [2012/11/14 02:34:11 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
  916. [2012/11/14 02:34:11 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
  917. [2012/11/14 00:04:26 | 000,000,000 | ---D | C] -- C:\Users\Home\Documents\Movies
  918. [2012/10/30 23:08:52 | 000,000,000 | ---D | C] -- C:\Users\Home\Desktop\gig music
  919. [2012/10/25 08:16:20 | 000,000,000 | ---D | C] -- C:\Users\Home\Desktop\Pimsleur Spanish I
  920. [2012/10/10 07:06:22 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
  921. [2012/10/10 07:06:21 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
  922. [2012/10/10 07:06:21 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
  923. [2012/10/10 07:06:09 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
  924. [2012/10/10 07:06:09 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
  925. [2012/10/10 07:06:09 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
  926. [2012/10/10 07:06:09 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
  927. [2012/10/10 07:06:09 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
  928. [2012/10/10 07:06:08 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
  929. [2012/10/10 07:06:08 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
  930. [2012/10/10 07:06:08 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
  931. [2012/10/10 07:06:08 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
  932. [2012/10/10 07:06:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
  933. [2012/10/10 07:06:08 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
  934. [2012/10/10 07:06:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
  935. [2012/10/10 07:06:07 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
  936. [2012/10/10 07:06:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
  937. [2012/10/10 07:06:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
  938. [2012/10/10 07:06:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
  939. [2012/10/10 07:06:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
  940. [2012/10/10 07:06:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
  941. [2012/10/10 07:06:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
  942. [2012/10/10 07:06:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
  943. [2012/10/10 07:06:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
  944. [2012/10/10 07:06:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
  945. [2012/10/10 07:06:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
  946. [2012/10/10 07:06:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
  947. [2012/10/10 07:06:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
  948. [2012/10/10 07:06:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
  949. [2012/10/10 07:06:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
  950. [2012/10/10 07:06:06 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
  951. [2012/10/10 07:06:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
  952. [2012/10/10 07:06:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
  953. [2012/10/10 07:06:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
  954. [2012/10/10 07:06:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
  955. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
  956. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
  957. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
  958. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
  959. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
  960. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
  961. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
  962. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
  963. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
  964. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
  965. [2012/10/10 07:06:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
  966. [2012/10/10 07:06:05 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
  967. [2012/10/10 07:06:05 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
  968. [2012/10/10 07:06:05 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
  969. [2012/10/10 07:06:05 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
  970. [2012/10/10 07:06:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
  971. [2012/10/10 07:06:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
  972. [2012/10/10 07:06:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
  973. [2012/10/10 07:06:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
  974. [2012/10/10 07:06:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
  975. [2012/10/10 07:06:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
  976. [2012/10/10 07:06:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
  977. [2012/10/10 07:06:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
  978. [2012/10/10 07:06:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
  979. [2012/10/10 07:06:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
  980. [2012/10/10 07:06:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
  981. [2012/10/10 07:06:03 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
  982. [2012/10/10 07:06:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
  983. [2012/10/10 07:06:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
  984. [2012/10/10 07:06:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
  985. [2012/10/10 07:06:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
  986. [2012/10/10 07:06:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
  987. [2012/10/10 07:06:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
  988. [2012/10/10 07:06:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
  989. [2012/10/10 07:06:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
  990. [2012/10/10 07:06:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
  991. [2012/10/10 07:06:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
  992. [2012/10/10 07:05:49 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
  993. [2012/10/10 07:05:14 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
  994. [2012/10/10 07:05:13 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
  995. [2012/10/02 13:40:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
  996. [2012/09/28 13:25:31 | 000,196,440 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\HipShieldK.sys
  997. [2012/09/26 21:07:08 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Home\AppData\Roaming\pcouffin.sys
  998. [2012/09/26 21:07:08 | 000,000,000 | ---D | C] -- C:\Users\Home\Documents\PcSetup
  999. [2012/09/26 21:05:58 | 000,000,000 | ---D | C] -- C:\Users\Home\Documents\ConvertXToDVD
  1000. [2012/09/26 21:01:41 | 000,000,000 | ---D | C] -- C:\Users\Home\AppData\Roaming\Vso
  1001. [2012/09/26 02:18:55 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OxpsConverter.exe
  1002.  
  1003. [color=#E56717]========== Files - Modified Within 90 Days ==========[/color]
  1004.  
  1005. [2012/12/17 18:12:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Home\Desktop\OTL.exe
  1006. [2012/12/17 18:10:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  1007. [2012/12/17 18:06:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1526968901-1929943128-198173789-1001UA.job
  1008. [2012/12/17 18:06:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1526968901-1929943128-198173789-1001Core.job
  1009. [2012/12/17 17:58:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1526968901-1929943128-198173789-1001UA.job
  1010. [2012/12/17 17:27:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
  1011. [2012/12/17 14:10:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  1012. [2012/12/17 12:05:13 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1526968901-1929943128-198173789-1001Core.job
  1013. [2012/12/17 01:24:26 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  1014. [2012/12/17 01:24:26 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  1015. [2012/12/17 01:17:13 | 000,000,198 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
  1016. [2012/12/17 01:17:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  1017. [2012/12/17 01:17:05 | 1989,500,927 | -HS- | M] () -- C:\hiberfil.sys
  1018. [2012/12/16 20:23:00 | 000,000,198 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
  1019. [2012/12/14 21:35:35 | 000,756,224 | ---- | M] () -- C:\Users\Home\Desktop\RogueKiller.exe
  1020. [2012/12/13 07:59:21 | 000,002,481 | ---- | M] () -- C:\Users\Home\Desktop\Google Chrome.lnk
  1021. [2012/12/12 01:27:13 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
  1022. [2012/12/12 01:27:13 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
  1023. [2012/12/11 13:11:48 | 000,000,218 | ---- | M] () -- C:\Users\Home\.recently-used.xbel
  1024. [2012/12/11 12:51:38 | 000,001,148 | ---- | M] () -- C:\Users\Public\Desktop\FL Studio 10.lnk
  1025. [2012/12/08 04:54:34 | 000,000,545 | ---- | M] () -- C:\0.bak
  1026. [2012/12/08 04:42:08 | 000,000,546 | ---- | M] () -- C:\Users\Public\Desktop\Guitar Pro 6.lnk
  1027. [2012/12/06 20:04:06 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  1028. [2012/12/02 23:56:56 | 000,779,266 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  1029. [2012/12/02 23:56:56 | 000,660,280 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  1030. [2012/12/02 23:56:56 | 000,121,208 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  1031. [2012/11/20 03:48:13 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\WavePad Sound Editor.lnk
  1032. [2012/11/14 03:34:07 | 000,499,520 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  1033. [2012/11/09 06:40:24 | 000,069,672 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\cfwids.sys
  1034. [2012/11/09 06:37:42 | 000,339,776 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfewfpk.sys
  1035. [2012/11/09 06:37:30 | 000,177,680 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\mfevtps.exe
  1036. [2012/11/09 06:36:40 | 000,010,288 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeclnk.sys
  1037. [2012/11/09 06:36:30 | 000,106,112 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mferkdet.sys
  1038. [2012/11/09 06:35:50 | 000,771,096 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfehidk.sys
  1039. [2012/11/09 06:34:58 | 000,515,528 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfefirek.sys
  1040. [2012/11/09 06:34:18 | 000,309,400 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeavfk.sys
  1041. [2012/11/09 06:33:58 | 000,178,840 | ---- | M] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeapfk.sys
  1042. [2012/11/06 17:07:22 | 001,279,880 | ---- | M] () -- C:\Users\Home\Desktop\Hanguel.jpeg
  1043. [2012/11/03 10:02:54 | 004,464,223 | ---- | M] () -- C:\Users\Home\Desktop\Some Nights.mp3
  1044. [2012/10/12 18:07:26 | 000,517,371 | ---- | M] () -- C:\Users\Home\Desktop\C-_WEBAPP_PublicFiles_uploadfiles_466184461e584a7a958e4cc7304e6262.pdf
  1045. [2012/10/09 12:17:13 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
  1046. [2012/10/09 12:17:13 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
  1047. [2012/10/09 11:40:31 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
  1048. [2012/10/08 05:31:03 | 002,312,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
  1049. [2012/10/08 05:22:55 | 001,494,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
  1050. [2012/10/08 05:22:17 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
  1051. [2012/10/08 05:18:22 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
  1052. [2012/10/08 05:17:35 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
  1053. [2012/10/08 05:17:26 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
  1054. [2012/10/08 05:15:59 | 000,729,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
  1055. [2012/10/08 05:13:54 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
  1056. [2012/10/08 05:09:39 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
  1057. [2012/10/08 01:47:44 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
  1058. [2012/10/08 01:46:32 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
  1059. [2012/10/08 01:44:05 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
  1060. [2012/10/08 01:43:05 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
  1061. [2012/10/08 01:41:19 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
  1062. [2012/10/08 01:37:23 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
  1063. [2012/10/06 12:41:30 | 000,380,928 | ---- | M] () -- C:\Users\Home\Documents\Cars.accdb
  1064. [2012/10/06 12:41:18 | 000,622,592 | ---- | M] () -- C:\Users\Home\Documents\Database3.accdb
  1065. [2012/10/06 12:29:04 | 000,737,280 | ---- | M] () -- C:\Users\Home\Documents\Database2.accdb
  1066. [2012/10/06 11:58:29 | 000,442,368 | ---- | M] () -- C:\Users\Home\Documents\Database1.accdb
  1067. [2012/10/03 11:44:17 | 000,246,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
  1068. [2012/10/03 11:44:17 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
  1069. [2012/10/03 11:44:16 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
  1070. [2012/10/03 10:42:24 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
  1071. [2012/10/03 10:42:24 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
  1072. [2012/10/03 10:42:23 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
  1073. [2012/09/29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
  1074. [2012/09/26 21:07:08 | 000,099,384 | ---- | M] () -- C:\Users\Home\AppData\Roaming\inst.exe
  1075. [2012/09/26 21:07:08 | 000,082,816 | ---- | M] (VSO Software) -- C:\Users\Home\AppData\Roaming\pcouffin.sys
  1076. [2012/09/26 21:07:08 | 000,007,859 | ---- | M] () -- C:\Users\Home\AppData\Roaming\pcouffin.cat
  1077. [2012/09/26 21:07:08 | 000,001,167 | ---- | M] () -- C:\Users\Home\AppData\Roaming\pcouffin.inf
  1078. [2012/09/26 21:06:14 | 000,001,189 | ---- | M] () -- C:\Users\Home\AppData\Roaming\vso_ts_preview.xml
  1079. [2012/09/25 21:01:23 | 000,091,295 | ---- | M] () -- C:\Users\Home\Desktop\578350_3687003415680_2098118830_n.jpg
  1080. [2012/09/25 16:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
  1081. [2012/09/25 16:46:17 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
  1082. [2012/09/21 00:34:47 | 000,029,221 | ---- | M] () -- C:\Users\Home\Desktop\Bachianinha No1.gpx
  1083.  
  1084. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  1085.  
  1086. [2012/12/14 21:35:29 | 000,756,224 | ---- | C] () -- C:\Users\Home\Desktop\RogueKiller.exe
  1087. [2012/12/11 13:11:48 | 000,000,218 | ---- | C] () -- C:\Users\Home\.recently-used.xbel
  1088. [2012/12/11 12:51:39 | 000,001,148 | ---- | C] () -- C:\Users\Public\Desktop\FL Studio 10.lnk
  1089. [2012/12/08 04:54:33 | 000,000,545 | ---- | C] () -- C:\0.bak
  1090. [2012/11/20 03:48:13 | 000,001,132 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
  1091. [2012/11/20 03:48:13 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\WavePad Sound Editor.lnk
  1092. [2012/11/14 03:12:08 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
  1093. [2012/11/14 03:03:53 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
  1094. [2012/11/06 17:07:17 | 001,279,880 | ---- | C] () -- C:\Users\Home\Desktop\Hanguel.jpeg
  1095. [2012/11/03 10:02:49 | 004,464,223 | ---- | C] () -- C:\Users\Home\Desktop\Some Nights.mp3
  1096. [2012/10/12 18:07:01 | 000,517,371 | ---- | C] () -- C:\Users\Home\Desktop\C-_WEBAPP_PublicFiles_uploadfiles_466184461e584a7a958e4cc7304e6262.pdf
  1097. [2012/10/06 12:41:18 | 000,380,928 | ---- | C] () -- C:\Users\Home\Documents\Cars.accdb
  1098. [2012/10/06 12:29:16 | 000,622,592 | ---- | C] () -- C:\Users\Home\Documents\Database3.accdb
  1099. [2012/10/06 12:00:18 | 000,737,280 | ---- | C] () -- C:\Users\Home\Documents\Database2.accdb
  1100. [2012/10/06 11:57:01 | 000,442,368 | ---- | C] () -- C:\Users\Home\Documents\Database1.accdb
  1101. [2012/09/26 21:07:08 | 000,099,384 | ---- | C] () -- C:\Users\Home\AppData\Roaming\inst.exe
  1102. [2012/09/26 21:07:08 | 000,007,859 | ---- | C] () -- C:\Users\Home\AppData\Roaming\pcouffin.cat
  1103. [2012/09/26 21:07:08 | 000,001,167 | ---- | C] () -- C:\Users\Home\AppData\Roaming\pcouffin.inf
  1104. [2012/09/26 21:01:42 | 000,001,189 | ---- | C] () -- C:\Users\Home\AppData\Roaming\vso_ts_preview.xml
  1105. [2012/09/25 21:01:27 | 000,091,295 | ---- | C] () -- C:\Users\Home\Desktop\578350_3687003415680_2098118830_n.jpg
  1106. [2012/09/20 23:35:24 | 000,029,221 | ---- | C] () -- C:\Users\Home\Desktop\Bachianinha No1.gpx
  1107. [2012/08/31 20:40:17 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
  1108. [2012/06/10 20:34:19 | 000,000,258 | R-S- | C] () -- C:\ProgramData\ntuser.pol
  1109. [2012/06/08 02:01:37 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
  1110. [2012/05/23 17:49:32 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
  1111. [2012/05/23 17:49:32 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
  1112. [2012/05/23 17:49:32 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
  1113. [2012/05/23 17:49:32 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
  1114. [2012/05/18 23:23:16 | 000,000,090 | -HS- | C] () -- C:\Windows\cnerolf.bin
  1115. [2012/04/09 21:32:10 | 000,000,031 | ---- | C] () -- C:\Windows\SysWow64\deck.ini
  1116. [2012/03/25 19:23:40 | 000,000,184 | ---- | C] () -- C:\Windows\AutoKMS.ini
  1117. [2012/01/10 20:29:54 | 013,904,384 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
  1118. [2012/01/09 14:00:48 | 004,346,880 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
  1119. [2012/01/07 16:22:00 | 000,172,032 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
  1120. [2012/01/07 16:21:50 | 006,366,094 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-53.dll
  1121. [2012/01/07 16:21:50 | 001,007,151 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-53.dll
  1122. [2012/01/07 16:21:50 | 000,354,979 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
  1123. [2012/01/07 16:21:50 | 000,203,306 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-51.dll
  1124. [2012/01/07 16:21:50 | 000,138,727 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-2.dll
  1125. [2011/12/20 12:50:04 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
  1126. [2011/12/20 12:49:56 | 000,099,328 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
  1127. [2011/12/20 12:49:54 | 000,158,720 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
  1128. [2011/12/20 12:49:54 | 000,146,944 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
  1129. [2011/12/20 12:49:52 | 001,525,248 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
  1130. [2011/12/20 12:49:52 | 000,212,480 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
  1131. [2011/12/20 12:49:52 | 000,115,200 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
  1132. [2011/12/20 12:49:50 | 000,328,704 | ---- | C] () -- C:\Windows\SysWow64\ff_libfaad2.dll
  1133. [2011/12/20 12:49:50 | 000,260,608 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
  1134. [2011/12/20 12:49:50 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
  1135. [2011/12/07 13:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\Lagarith.dll
  1136. [2011/12/05 17:46:40 | 000,005,243 | ---- | C] () -- C:\Users\Home\AppData\Roaming\UserTile.png
  1137. [2011/09/08 08:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\SysWow64\mkx.dll
  1138. [2011/09/08 08:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\SysWow64\mp4.dll
  1139. [2011/09/08 08:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\ogm.dll
  1140. [2011/09/08 08:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\SysWow64\dxr.dll
  1141. [2011/09/08 08:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\dsmux.exe
  1142. [2011/09/08 08:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\SysWow64\ts.dll
  1143. [2011/09/08 08:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\mkv2vfr.exe
  1144. [2011/09/08 08:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\SysWow64\gdsmux.exe
  1145. [2011/09/08 07:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\mkzlib.dll
  1146. [2011/09/08 07:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\mkunicode.dll
  1147. [2011/08/31 19:51:16 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
  1148. [2011/08/31 19:51:16 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
  1149. [2011/08/31 19:51:16 | 000,105,608 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
  1150. [2011/08/20 00:49:29 | 000,000,600 | ---- | C] () -- C:\Users\Home\AppData\Roaming\winscp.rnd
  1151. [2011/07/30 17:30:28 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
  1152. [2011/07/30 15:44:21 | 000,234,536 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
  1153. [2011/07/30 15:43:36 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
  1154. [2011/07/10 20:32:50 | 000,007,598 | ---- | C] () -- C:\Users\Home\AppData\Local\Resmon.ResmonCfg
  1155. [2011/06/08 16:35:24 | 001,048,576 | ---- | C] ( ) -- C:\Windows\SysWow64\dleaserv.dll
  1156. [2011/06/08 16:35:24 | 000,847,872 | ---- | C] ( ) -- C:\Windows\SysWow64\dleausb1.dll
  1157. [2011/06/08 16:35:24 | 000,802,816 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacomc.dll
  1158. [2011/06/08 16:35:24 | 000,688,128 | ---- | C] ( ) -- C:\Windows\SysWow64\dleahbn3.dll
  1159. [2011/06/08 16:35:24 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\dleapmui.dll
  1160. [2011/06/08 16:35:24 | 000,593,920 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacoms.exe
  1161. [2011/06/08 16:35:24 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\dlealmpm.dll
  1162. [2011/06/08 16:35:24 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\DLEAinst.dll
  1163. [2011/06/08 16:35:24 | 000,372,736 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacomm.dll
  1164. [2011/06/08 16:35:24 | 000,368,640 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacfg.exe
  1165. [2011/06/08 16:35:24 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dleainpa.dll
  1166. [2011/06/08 16:35:24 | 000,344,064 | ---- | C] () -- C:\Windows\SysWow64\dleacomx.dll
  1167. [2011/06/08 16:35:24 | 000,344,064 | ---- | C] ( ) -- C:\Windows\SysWow64\dleaiesc.dll
  1168. [2011/06/08 16:35:24 | 000,323,584 | ---- | C] () -- C:\Windows\SysWow64\dleains.dll
  1169. [2011/06/08 16:35:24 | 000,319,488 | ---- | C] ( ) -- C:\Windows\SysWow64\dleaih.exe
  1170. [2011/06/08 16:35:24 | 000,262,144 | ---- | C] () -- C:\Windows\SysWow64\dleainsb.dll
  1171. [2011/06/08 16:35:24 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\dleacu.dll
  1172. [2011/06/08 16:35:24 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dleainsr.dll
  1173. [2011/06/08 16:35:24 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\dleacub.dll
  1174. [2011/06/08 16:35:24 | 000,086,180 | ---- | C] () -- C:\Windows\SysWow64\DLEAcfg.dll
  1175. [2011/06/08 16:35:24 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\dleajswr.dll
  1176. [2011/06/08 16:35:24 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dleacur.dll
  1177. [2011/05/30 07:42:50 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
  1178. [2011/05/23 01:46:30 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
  1179. [2011/04/07 23:44:10 | 000,552,960 | ---- | C] () -- C:\Windows\SysWow64\FS2AUDIO.dll
  1180. [2011/03/03 05:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\SysWow64\avi.dll
  1181. [2011/03/03 05:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\avs.dll
  1182. [2011/03/03 05:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\avss.dll
  1183. [2011/02/10 10:10:51 | 000,772,990 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  1184.  
  1185. [color=#E56717]========== ZeroAccess Check ==========[/color]
  1186.  
  1187. [2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
  1188.  
  1189. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  1190.  
  1191. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  1192.  
  1193. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  1194.  
  1195. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  1196.  
  1197. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  1198. "" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 23:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
  1199. "ThreadingModel" = Apartment
  1200.  
  1201. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  1202. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  1203. "ThreadingModel" = Apartment
  1204.  
  1205. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  1206. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
  1207. "ThreadingModel" = Free
  1208.  
  1209. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  1210. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
  1211. "ThreadingModel" = Free
  1212.  
  1213. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  1214. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
  1215. "ThreadingModel" = Both
  1216.  
  1217. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  1218.  
  1219. [color=#E56717]========== LOP Check ==========[/color]
  1220.  
  1221. [2012/02/03 22:02:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\AnvSoft
  1222. [2012/02/03 13:05:53 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Atari
  1223. [2012/12/11 13:11:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\BitLord
  1224. [2011/07/05 17:44:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\DAEMON Tools Lite
  1225. [2012/12/08 04:39:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\DriverCure
  1226. [2011/12/27 00:53:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Dropbox
  1227. [2011/07/18 17:38:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\E-centives
  1228. [2012/03/26 16:10:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Fingertapps
  1229. [2012/07/02 21:54:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Flight1
  1230. [2012/05/31 20:31:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\FS2Crew2010
  1231. [2011/06/18 19:01:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\funkitron
  1232. [2012/07/05 21:05:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Guitar Pro 6
  1233. [2012/07/02 21:54:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\HiFi
  1234. [2012/04/16 14:48:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Image-Line
  1235. [2011/08/20 10:32:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Jaran Nilsen
  1236. [2012/01/22 20:50:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Leadertech
  1237. [2012/06/22 01:14:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Learn2.com
  1238. [2011/09/24 09:24:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Namco
  1239. [2011/09/03 02:32:29 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\NCH Swift Sound
  1240. [2011/12/09 23:56:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\OpenOffice.org
  1241. [2011/07/30 03:38:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Origin
  1242. [2011/06/24 12:01:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\PCDr
  1243. [2011/12/22 21:30:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\PopCapv1000
  1244. [2012/04/09 20:53:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Propellerhead Software
  1245. [2012/04/26 23:32:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Publish Providers
  1246. [2011/07/20 16:44:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Python-Eggs
  1247. [2011/09/06 14:43:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\redsn0w
  1248. [2012/06/10 16:35:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Samsung
  1249. [2012/12/08 04:55:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Sony
  1250. [2012/12/08 04:39:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\SpeedyPC Software
  1251. [2011/11/09 13:20:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\SpinTop Games
  1252. [2012/06/28 00:50:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\SystemRequirementsLab
  1253. [2011/08/26 00:50:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\TP
  1254. [2011/10/15 04:01:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\TS3Client
  1255. [2011/06/08 17:07:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\V310-V510 Series
  1256. [2012/12/08 04:55:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Vso
  1257. [2011/06/15 19:45:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\WildTangentv1000
  1258.  
  1259. [color=#E56717]========== Purity Check ==========[/color]
  1260.  
  1261.  
  1262.  
  1263. [color=#E56717]========== Custom Scans ==========[/color]
  1264.  
  1265. [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
  1266. [2012/04/26 23:27:47 | 000,001,000 | ---- | M] () -- C:\0
  1267. [2012/12/08 04:54:34 | 000,000,545 | ---- | M] () -- C:\0.bak
  1268. [2012/10/11 21:45:18 | 000,002,554 | ---- | M] () -- C:\AS2012_Log.txt
  1269. [2011/06/02 20:48:12 | 000,032,073 | R--- | M] () -- C:\dell.sdr
  1270. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
  1271. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
  1272. [2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
  1273. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
  1274. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
  1275. [2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
  1276. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
  1277. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
  1278. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
  1279. [2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
  1280. [2012/12/17 01:17:05 | 1989,500,927 | -HS- | M] () -- C:\hiberfil.sys
  1281. [2007/11/07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
  1282. [2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
  1283. [2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
  1284. [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
  1285. [2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
  1286. [2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
  1287. [2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
  1288. [2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
  1289. [2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
  1290. [2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
  1291. [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
  1292. [2005/12/17 12:51:00 | 000,020,992 | ---- | M] (Peter L. Dowson) -- C:\makerwys.exe
  1293. [2012/12/17 01:17:06 | 4084,326,399 | -HS- | M] () -- C:\pagefile.sys
  1294. [2012/01/22 13:35:33 | 001,291,797 | ---- | M] () -- C:\s7ik.2
  1295. [2012/01/22 13:35:33 | 000,697,498 | ---- | M] () -- C:\s7ik.3
  1296. [2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
  1297. [2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
  1298. [2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
  1299.  
  1300. [color=#A23BEC]< %USERPROFILE%\*.* >[/color]
  1301. [2012/12/11 13:11:48 | 000,000,218 | ---- | M] () -- C:\Users\Home\.recently-used.xbel
  1302. [2012/12/17 18:23:40 | 007,077,888 | --S- | M] () -- C:\Users\Home\NTUSER.DAT
  1303. [2012/12/17 18:23:40 | 000,262,144 | --S- | M] () -- C:\Users\Home\ntuser.dat.LOG1
  1304. [2011/06/08 14:58:27 | 000,000,000 | --S- | M] () -- C:\Users\Home\ntuser.dat.LOG2
  1305. [2011/06/08 17:05:48 | 000,065,536 | -HS- | M] () -- C:\Users\Home\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
  1306. [2011/06/08 17:05:48 | 000,524,288 | -HS- | M] () -- C:\Users\Home\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
  1307. [2011/06/08 17:05:48 | 000,524,288 | -HS- | M] () -- C:\Users\Home\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
  1308. [2011/06/08 14:58:27 | 000,000,020 | -HS- | M] () -- C:\Users\Home\ntuser.ini
  1309.  
  1310. [color=#A23BEC]< %USERPROFILE%\temp\*.exe >[/color]
  1311.  
  1312. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*.* >[/color]
  1313. [2012/11/14 09:02:53 | 000,135,440 | ---- | M] () -- C:\Users\Home\AppData\Local\GDIPFONTCACHEV1.DAT
  1314. [2012/12/17 01:16:30 | 001,614,848 | -H-- | M] () -- C:\Users\Home\AppData\Local\IconCache.db
  1315. [2012/06/28 00:35:26 | 000,007,598 | ---- | M] () -- C:\Users\Home\AppData\Local\Resmon.ResmonCfg
  1316.  
  1317. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*. >[/color]
  1318. [2011/06/10 23:35:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Adobe
  1319. [2011/06/15 00:28:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Apple
  1320. [2011/11/12 22:53:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Apple Computer
  1321. [2011/06/08 14:58:27 | 000,000,000 | -HSD | M] -- C:\Users\Home\AppData\Local\Application Data
  1322. [2011/06/08 16:07:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Dell
  1323. [2011/06/08 14:58:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Dell Edoc Viewer
  1324. [2012/12/16 23:17:31 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Diagnostics
  1325. [2012/06/10 16:34:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Downloaded Installations
  1326. [2012/07/08 00:00:40 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\ElevatedDiagnostics
  1327. [2012/07/07 01:55:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Facebook
  1328. [2012/02/04 12:50:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Google
  1329. [2012/07/02 22:05:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\HiFi
  1330. [2011/06/08 14:58:27 | 000,000,000 | -HSD | M] -- C:\Users\Home\AppData\Local\History
  1331. [2011/12/09 23:30:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\HP
  1332. [2012/01/22 13:31:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\libimobiledevice
  1333. [2012/06/28 21:56:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Macromedia
  1334. [2012/07/02 21:50:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Microsoft
  1335. [2012/12/08 04:55:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Microsoft Game Studios
  1336. [2011/07/01 15:13:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Microsoft Games
  1337. [2011/12/09 23:41:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Microsoft Help
  1338. [2011/06/08 21:29:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Mozilla
  1339. [2011/07/30 03:38:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Origin
  1340. [2011/07/30 21:28:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\PunkBuster
  1341. [2012/06/28 21:59:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Real_Environment_Xtreme
  1342. [2011/10/02 01:34:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Research In Motion
  1343. [2012/06/17 22:31:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Samsung
  1344. [2011/09/24 11:41:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\SoftThinks
  1345. [2011/07/05 16:16:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Sonic_Solutions
  1346. [2012/04/26 23:27:38 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Sony
  1347. [2012/12/17 18:23:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Temp
  1348. [2011/06/08 14:58:27 | 000,000,000 | -HSD | M] -- C:\Users\Home\AppData\Local\Temporary Internet Files
  1349. [2011/12/22 14:59:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\VirtualStore
  1350. [2012/07/08 15:47:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\Windows Live
  1351. [2011/08/31 07:18:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{00254EC6-BB10-4E20-B8F9-E38B4D88F687}
  1352. [2012/03/19 02:25:11 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{02ABE616-13FD-4992-A407-2700761D0FA7}
  1353. [2011/06/17 20:35:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{03F87468-44D7-4E4C-B9F8-685AC38FA52A}
  1354. [2012/04/30 14:45:59 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{055DFC7D-BCC8-4F9F-90B4-5C9726F4A740}
  1355. [2011/10/08 12:41:19 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{06571AA0-CB67-4DCA-B894-2FEB56EB7221}
  1356. [2011/12/28 05:58:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{0717961F-F1EE-4B50-9590-8DADD9D18CCD}
  1357. [2012/03/21 07:06:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{077E8AED-0AA1-43EE-951B-40B98FA89F2C}
  1358. [2012/06/06 22:24:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{08CBADC1-F701-4E21-B77D-3088929DCBD4}
  1359. [2012/04/04 03:48:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{0B5EEF80-155C-4495-ACDE-FAE094F033A8}
  1360. [2011/08/23 14:04:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{0D9FDA32-59D4-4A32-AD50-7438C8905352}
  1361. [2011/09/09 12:21:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{0DAD774D-D9D2-4A14-8FC9-7D9C0F8944E2}
  1362. [2011/08/14 14:00:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{0DB12720-5002-4F7A-A1E0-605581AB2C67}
  1363. [2011/08/28 07:16:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{0F5AB677-8386-4F76-941C-939904A44A01}
  1364. [2012/01/01 18:36:24 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{10698477-AB21-4E27-AF21-5471FC675812}
  1365. [2012/05/10 03:33:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{107222F6-AF10-41C2-8EA1-2750FB8FD8EA}
  1366. [2011/08/22 22:03:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{10D31D09-E267-4E07-9210-6C52341FF76F}
  1367. [2011/08/05 01:15:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{10EB73A7-D042-4D1C-8087-7A436D89F17B}
  1368. [2011/08/15 14:00:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{10F13FC5-78B2-40D8-8BC9-602FEC4D5F45}
  1369. [2012/03/26 16:08:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{11026DE9-B6D2-40EA-93C9-270098E53B8C}
  1370. [2012/01/10 06:43:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{11E721AF-C287-42D9-9C4D-B4708165095D}
  1371. [2011/10/12 13:26:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1351E8E3-AD16-4E61-99F9-A1A9472E42B2}
  1372. [2011/07/03 04:38:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{135910A4-42B4-488B-82E6-22D18CBDEC1D}
  1373. [2011/09/10 00:21:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{13799E6C-67E8-4395-8FAE-6D6D6EF2F3E7}
  1374. [2011/07/05 17:55:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1419FCF0-5302-444E-B7E5-A52AC9C11437}
  1375. [2011/10/16 13:31:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{159214C0-2D6E-4D67-91EE-2852AEFEF3B7}
  1376. [2012/01/06 06:40:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{15F11DAB-58F1-41A5-AE13-5BF5D47334DA}
  1377. [2012/07/08 03:47:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1612236A-E111-4189-9B39-2FCEE9D42EBB}
  1378. [2012/01/06 18:40:47 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{16A2C3AD-6371-4808-B1AB-1240E2724921}
  1379. [2012/05/06 20:18:59 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{172B0E54-0987-40D1-836E-84918E402A7E}
  1380. [2011/10/13 13:28:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{174BA4EB-715B-4D3E-A93C-F56CFCD078CD}
  1381. [2011/10/18 01:32:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{17C16909-CDE3-450E-BC77-A8E308AFE4AA}
  1382. [2011/09/23 19:16:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{182A1C94-5047-4AD2-9B61-622897CA5554}
  1383. [2012/06/28 21:24:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{18F87EAD-8D68-4032-A111-A2DD87907659}
  1384. [2011/07/02 10:39:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1A316B5E-B16E-4C70-AB8C-6353711A01AF}
  1385. [2011/06/15 22:10:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1A9E7041-2F3C-45CD-8E01-6D463B72E049}
  1386. [2012/01/03 06:37:40 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1AFC6D92-28EC-4DBB-B972-46DE37450A8A}
  1387. [2012/07/08 03:46:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1C3CF58F-6A1C-4C7B-83D9-22DA3D341BC2}
  1388. [2011/08/15 14:01:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1CCFBFD7-DD84-47B3-8E3E-87F60A8E5CDE}
  1389. [2012/06/06 22:24:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1CFFB558-793C-4EE9-B310-0C0DDD48EE18}
  1390. [2011/06/08 21:57:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1D6AA7BD-19E4-4C55-B893-3833A24D830B}
  1391. [2011/12/27 17:57:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1E8A4B74-2B33-4880-B83E-C500B8B41C14}
  1392. [2011/08/18 14:03:59 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{1FC16712-5B55-4E1D-8130-786130BB6321}
  1393. [2011/08/27 19:15:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2018039B-369C-43DF-A4DE-9248E1CA136D}
  1394. [2011/12/16 21:51:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{20775496-8380-4F0D-88BD-97396BD99CE0}
  1395. [2012/06/12 21:55:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{21C4512D-2093-48C9-BABE-BCA23AC4CE88}
  1396. [2011/10/15 13:30:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{22ECE038-C06B-468A-A72E-11AA6921FD47}
  1397. [2011/10/15 01:29:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2341E097-6163-4CD0-88D0-2783581F5DB5}
  1398. [2012/05/18 03:01:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{23DCD01C-7C01-4048-A818-2BF2E9778CB7}
  1399. [2011/09/03 01:09:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2491D142-CAD9-413A-8402-DDEAD11B85E4}
  1400. [2011/07/06 21:23:47 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{24CABC9A-CEF3-41C9-A915-02AE7DD8C156}
  1401. [2011/10/14 13:29:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{26AC3FA8-F4E1-43C3-B651-29B98A2DB384}
  1402. [2011/12/15 02:50:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{26E8504D-D009-4201-A37C-C12E4E70F125}
  1403. [2011/12/15 02:52:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{286FAA7E-82E0-48CC-860F-7506CE578A2C}
  1404. [2011/12/10 14:58:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2AB5BEB1-A97D-4CD8-9D61-676262DF0D23}
  1405. [2011/10/25 22:30:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2BCEFFDF-7DFB-425E-80CC-E5DA05643C36}
  1406. [2011/12/26 17:56:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2C2DC474-25AA-4DBB-908B-72C6E2B601AF}
  1407. [2011/09/20 21:34:31 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2C525977-E5C5-4214-8F05-5DD5B9976EE4}
  1408. [2012/05/13 23:47:46 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2C949CDD-F1D3-4921-B0E2-100967A2B89A}
  1409. [2012/04/23 13:50:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2D3A0628-DC3F-470F-B622-A44C03E69C9F}
  1410. [2011/07/12 10:29:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2D9A9587-2F3E-46CF-8B8F-00921383CCD4}
  1411. [2012/03/26 16:07:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2EC6803F-7627-436B-B1B9-62DF11FC473C}
  1412. [2012/01/08 18:42:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2F8829B7-0675-4948-9F51-F62B4329B9C0}
  1413. [2011/08/29 07:17:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2FA6F8D3-8ADF-4B1A-BF7A-5B4DE5EEF882}
  1414. [2011/10/05 23:02:32 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{2FEB1BE8-1938-46E6-A619-7217BB135EF6}
  1415. [2011/06/09 21:58:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{30A79348-B7E6-44B7-931E-79622436D86A}
  1416. [2012/04/10 09:32:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{31F411B4-0832-4A39-B9C1-C77A30BB476B}
  1417. [2011/09/22 09:35:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{329FB463-64D3-4233-B748-CFC446A9C151}
  1418. [2011/08/20 02:05:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{34AB7E51-F527-4129-B9D6-82F3C970F589}
  1419. [2011/12/14 12:38:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{34C57EB9-4369-4BE5-A5D1-51FA9B94B990}
  1420. [2011/09/30 18:25:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{35FF6E93-16FA-425B-A48A-F5B38CB69775}
  1421. [2011/10/29 00:03:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{361A8BCA-4864-485D-B06F-B94EFEBF9FE1}
  1422. [2012/07/03 07:24:24 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{369FF7E9-E216-4154-A3C8-A63F5203678D}
  1423. [2012/02/24 19:30:43 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{36A768A7-5841-4719-8B26-95D81B0B2B68}
  1424. [2011/06/29 10:00:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{37115BDC-BA89-4BB0-9FB8-8B8BDF2296BC}
  1425. [2011/07/04 21:18:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{37F793BC-CA06-49CA-B9DC-5990E07D063F}
  1426. [2011/12/31 00:52:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{38242412-6F35-427E-BD3C-1EC4E9E112B6}
  1427. [2011/09/17 06:08:32 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{39BFBAC8-01D0-4E30-9F32-48D381F55C3B}
  1428. [2012/06/05 22:35:24 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{39C5156D-F3A6-459D-8233-842223F701F6}
  1429. [2011/12/17 09:51:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3A83449D-91BD-4B17-9253-D2B73032F6CE}
  1430. [2012/07/01 21:13:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3AD3EC3D-9374-4FEB-AF11-3FF0F5A46897}
  1431. [2011/08/24 23:01:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3ADBE21E-1329-48BE-9D0E-987D31F0C4EC}
  1432. [2012/01/09 18:43:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3BB64AAB-EC2C-40F6-9478-F72AD01E4DCE}
  1433. [2011/08/16 02:01:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3C3304ED-528F-43A1-8898-70D05EC20850}
  1434. [2012/02/15 15:25:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3CD1EBCC-04D1-47C5-9424-BF6CE4799EAD}
  1435. [2012/01/05 18:39:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3D8021F3-DC3E-4C46-9DC7-F42A233DB56D}
  1436. [2012/05/20 22:12:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3D88E4E6-E1DC-4658-844F-848C833AFA95}
  1437. [2012/01/06 06:40:11 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3EB6C2A5-8DC9-4C83-BFCF-C2E532E30086}
  1438. [2011/12/16 21:51:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3F6BC872-0591-46E3-9A82-03295B6700CE}
  1439. [2012/03/18 14:24:46 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{3FB74584-BE16-48B1-BF9E-39B2707DD7A6}
  1440. [2011/10/17 01:31:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4079BF85-E81D-4266-9969-18FEC46BD2D2}
  1441. [2011/09/22 21:36:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{40A4F575-BB21-408A-8BBE-1BEBE901E607}
  1442. [2011/12/11 14:59:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{40DA20B6-FAEB-483A-BCB9-20CC2168D871}
  1443. [2012/01/07 06:41:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{40FA8109-BD33-4B1D-81F1-DCB37518D305}
  1444. [2011/09/03 21:20:19 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4192672A-C2C0-406E-8DD3-0CB1C2AB3E1B}
  1445. [2011/10/16 01:30:46 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{41FE42FD-4EA6-4924-A0CE-937F90D8FA0D}
  1446. [2011/08/17 02:02:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{420232C1-5249-4C59-AE38-D8E8C877E17A}
  1447. [2011/12/23 06:17:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4263D0F4-98F4-4D79-BAAC-1690AD2F32AA}
  1448. [2012/03/17 02:23:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{44308867-6B20-4DD6-8EA9-60F74EF170B4}
  1449. [2011/08/19 14:04:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{448D0F1B-A8AD-4250-BD8F-2994FBEF69E7}
  1450. [2012/01/05 06:39:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{44CE003F-7D09-400A-B8AC-43DE91C8A4F3}
  1451. [2011/06/14 19:59:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{44E57B3F-CAA8-4868-833D-7F42FF49EEDC}
  1452. [2011/09/25 11:23:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{45231B04-142D-4F4E-A382-340118E6D6A3}
  1453. [2011/08/12 11:09:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{459A947C-E60C-4193-A3B5-0C654EFA17FB}
  1454. [2011/08/24 23:01:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{45CFE808-7BF0-4761-80B6-447734A673F9}
  1455. [2012/06/28 21:24:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4603971D-D88B-44E9-A941-48FA13929EAF}
  1456. [2011/08/10 23:07:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4677169D-D9EB-4822-A493-FA1FA6112A2E}
  1457. [2011/10/18 13:32:40 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{46D6E6E0-9CD0-4294-AD93-4D37271D0964}
  1458. [2011/09/13 19:37:28 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{47ABDFF4-23F2-4BC9-9EE5-4231BC0D93FB}
  1459. [2012/01/26 09:23:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4A2364DB-FCA2-411B-AA88-E77BFADC597F}
  1460. [2012/01/10 06:43:31 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4B4A13CC-F8E9-48CA-A25C-8282AABBD02D}
  1461. [2012/06/04 22:32:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4BB7C94B-5CE4-4E40-B0A8-8139054775B8}
  1462. [2011/08/08 02:52:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4CF4F76A-F802-4737-B9F6-192FDC0628E5}
  1463. [2011/12/12 15:00:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4DCA7DD0-F10C-4FB7-8840-3E85B7DE43EE}
  1464. [2012/07/08 15:47:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4DCD2805-CF89-44B9-BC78-2BDB40CFC1BD}
  1465. [2011/08/17 14:03:07 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4DEEE783-8AD3-46B4-8867-C2A2C5542969}
  1466. [2012/06/14 12:28:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4E52B079-C324-435D-9DA8-155547108D5B}
  1467. [2011/10/18 13:32:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{4EBA9269-F200-4970-84D6-662580FDB7E4}
  1468. [2011/09/16 06:07:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{507CDEBA-2EF7-4ED2-9FA4-EFB974DE9165}
  1469. [2011/09/23 19:16:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5095EBEB-01B3-4BFB-9328-1EDF31E5CFC8}
  1470. [2011/08/14 01:59:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{512357BC-AB1D-4319-87B2-0C9ED15FACE8}
  1471. [2011/08/30 19:18:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{51D06C13-B865-459A-ACDA-F4BEE93E132D}
  1472. [2011/10/29 00:03:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5203C95B-F8F1-4A9D-A0BC-6E71251E5C2A}
  1473. [2011/08/11 23:08:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5303B41F-C094-4EA2-8C2F-6623AD815E28}
  1474. [2011/09/04 23:06:19 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5316121B-A91A-4594-9BE1-5C09F573F80B}
  1475. [2011/07/11 19:27:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{54FF7091-8133-46BC-8F1F-796F94198675}
  1476. [2011/09/20 09:34:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{55FF81BB-E4AF-4DCF-838C-6EEF445E943E}
  1477. [2011/09/01 07:19:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5621B33D-3177-4600-AE11-450AEEB36161}
  1478. [2011/10/15 13:30:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{577F60C8-F2C5-4B3D-AEBB-1F34741C8E2E}
  1479. [2011/08/11 11:08:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{57B677FB-CDCA-4CFF-A73C-B54A754BA5FF}
  1480. [2011/12/05 18:01:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{592F3F1F-285F-433E-BA24-7C152C386103}
  1481. [2012/04/22 20:39:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5976EDA2-8B92-4AF0-AA39-FF15A9A8217B}
  1482. [2011/12/23 06:17:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5AFFC417-E3EB-43BC-8A98-E17046A00F76}
  1483. [2011/08/06 14:51:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5AFFDC40-4EF9-4E70-9E48-7836AB59E0B9}
  1484. [2011/10/16 13:31:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5BCE573E-5A17-4B39-BF4D-5EB6D4798AF0}
  1485. [2011/09/26 11:23:43 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5BF8038C-344D-4C9B-8061-49A8C70DC66A}
  1486. [2011/12/13 10:49:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5C6992E6-2815-484C-BDAC-827002994231}
  1487. [2012/01/09 06:42:40 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5C7F2A85-7B65-4BBA-8E47-B788D58E6A33}
  1488. [2011/08/16 14:02:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5C85FEA4-9400-4DAF-B67F-11660B661C72}
  1489. [2011/08/19 02:04:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5D9F991A-8930-49F0-B121-6362B729CA13}
  1490. [2011/12/27 05:57:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5DEEFCB5-5FF8-4849-99A7-0AEBB8A02619}
  1491. [2011/06/19 20:59:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5E6DBBF0-4017-4547-A4DC-E4711E268F33}
  1492. [2012/04/24 03:11:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{5F91CC24-3CA7-49E4-843D-8EC143911B40}
  1493. [2012/06/28 21:26:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{601EA051-A953-496E-940D-AADEE66DD749}
  1494. [2011/06/22 08:57:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6078C76D-5768-4C05-BBF2-F2EEBB9515EC}
  1495. [2011/09/24 23:22:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{616B853C-0D23-4CF9-A49F-05BF409F7113}
  1496. [2011/10/01 19:38:24 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6177FA68-117B-44D1-A6EB-D49493CCEB9A}
  1497. [2011/12/09 23:38:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{61D0D600-9886-4339-8AD6-F8AD3CC6B04C}
  1498. [2012/06/07 23:36:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{62DB9D8B-B6E4-4E01-A7CA-FF5869A3F547}
  1499. [2012/02/06 22:17:43 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{62ECCB1E-9F9A-464F-8FF7-CE01E5B1DCAA}
  1500. [2012/03/18 02:24:20 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{632D92BB-E71F-4B54-BB66-A8134DC7A75C}
  1501. [2012/03/15 02:21:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{636742D6-1896-4528-AE60-183BA48A23AD}
  1502. [2011/12/12 02:59:38 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{637D0F27-409E-471A-BA5D-290E50466A65}
  1503. [2012/03/21 07:06:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6388052A-8D23-431A-B0F9-6BEC58F54DBD}
  1504. [2011/06/30 14:56:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{64624E83-504A-496E-B214-665F432E2B0D}
  1505. [2011/09/18 06:09:38 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{64CB86EC-204A-4323-A214-CF9EF8622BE4}
  1506. [2012/04/24 03:11:28 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{64DA367C-F545-4997-B15F-23D0F2274CA9}
  1507. [2011/10/06 21:22:31 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{65884405-C564-413D-BD86-EC5139608319}
  1508. [2012/02/24 19:30:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{65DBB866-BB8D-4BB8-BAEE-954E379DD6C6}
  1509. [2012/03/16 02:22:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{665E409D-A4BA-4338-9CB1-57F7BD5B79B7}
  1510. [2011/10/05 23:02:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{67045865-F7F6-492C-86B2-33F32D9DC1A9}
  1511. [2011/12/24 15:41:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{67C12847-AAD2-4BC4-AD2C-784A1ED77F10}
  1512. [2011/09/16 18:08:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6835384C-7978-4B66-AA5D-A07372924C61}
  1513. [2012/01/09 18:43:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{684B71D0-0A92-4265-9409-4882FD246A17}
  1514. [2011/08/07 02:51:29 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{68EA50CC-A9FF-43B1-A75F-1265CEA22FF4}
  1515. [2012/07/03 07:24:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6BFEF9AB-13D3-4749-B384-C920D7E77FCD}
  1516. [2012/01/03 18:38:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6C6033A9-AB2E-4FCE-9123-0C91A128BA4E}
  1517. [2011/09/16 06:07:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6CDC1D09-57A6-410E-8349-D209EB64895E}
  1518. [2011/09/08 21:34:13 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6D32225B-5D75-4FAC-B246-DFEFE5F96791}
  1519. [2011/08/22 22:03:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6DC61276-6CB2-495A-B51E-8B5B9BDDCF23}
  1520. [2011/09/22 09:35:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6E0EE891-0146-49C6-9894-37211D86879B}
  1521. [2011/06/15 22:10:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6E7E0634-2FBF-4B74-8D8B-4B5B59927C5A}
  1522. [2012/01/02 06:36:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{6FC9058C-D80C-4723-8D91-3CC9C637D5C2}
  1523. [2011/09/15 18:06:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{71F7E85D-7574-4AA4-9193-8548DDD5724E}
  1524. [2012/06/04 22:31:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7252155B-7B50-45FC-A2C2-B98365F2304F}
  1525. [2011/11/09 03:20:13 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{72C8ECAC-A6BB-4A2A-B44B-825EA162E39D}
  1526. [2011/08/10 11:07:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{73FA610E-6CD1-47F5-A4A8-859EC499C53A}
  1527. [2011/08/25 21:29:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{741A396C-7F3C-4C9C-BAF1-F2D04694EDD4}
  1528. [2012/04/11 12:48:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{745995EE-2226-41BB-BB8A-F249A41CEEE5}
  1529. [2012/03/14 02:20:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7459D36E-2BB0-4E5A-901F-164938111871}
  1530. [2012/07/02 19:24:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7470E3A0-E022-4D5B-A42B-BFDC8A4B3085}
  1531. [2011/10/17 13:32:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{750DCD2E-0F8B-4E9E-B883-71D2208C37E7}
  1532. [2011/07/26 16:00:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7629EAB4-1FC5-40D5-81A6-652B796ABB3C}
  1533. [2012/07/02 19:23:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7934A9F4-805F-4F4C-875F-82203881F6D6}
  1534. [2012/04/09 21:32:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{794E1DFC-BE62-4040-8AF0-D97316F676B2}
  1535. [2012/04/23 13:50:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{79BBAC44-8829-4A83-924C-27AD06A0D01F}
  1536. [2011/07/01 22:11:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7A55C3EC-4159-4AB4-AE21-57ED165BE821}
  1537. [2012/05/10 03:33:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7A57C1A7-73D4-4C1C-B18E-BA5B080D1964}
  1538. [2011/09/18 18:09:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7D04C2EE-71B3-4A98-94C3-3F14B449DB78}
  1539. [2011/08/12 11:09:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7DC8369B-1651-4D59-96B2-31215C5C5A14}
  1540. [2011/11/22 21:57:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7FA7155E-43BD-4DE5-99A2-9470C4628928}
  1541. [2011/06/28 21:59:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{7FECD312-3383-4532-8E00-C76CB6D57E47}
  1542. [2011/08/06 02:50:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{811B25F0-1288-4A34-AC94-E24A0096D399}
  1543. [2011/09/21 09:34:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{82887F46-DD04-44A5-9DC7-52C74FEE25A0}
  1544. [2011/10/13 01:27:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{82FC3350-A7B4-4C8A-9B22-C0F13C731C53}
  1545. [2012/03/14 14:21:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{835B8805-912F-498C-8FAC-F77EBD8B1648}
  1546. [2011/10/09 12:42:13 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{83971461-474D-47A4-B4BC-0A1F90449D61}
  1547. [2011/09/10 00:22:02 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{839ECA3A-7464-4AF9-8D0F-965DDD97C0BE}
  1548. [2011/08/17 02:02:19 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{83A69353-141A-495D-896A-68C7622280CC}
  1549. [2012/05/18 03:01:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{83B47CAB-D811-4F83-BA9C-DC76E0830731}
  1550. [2011/07/29 18:41:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{83BF72F8-80D6-4B01-9BE2-7FB23D867197}
  1551. [2011/12/09 23:38:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{844859AE-4565-41A4-A271-8BDD3D560461}
  1552. [2012/05/30 22:20:09 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8493DD5D-1DA3-440F-94BD-DF76CCB5991E}
  1553. [2012/02/08 17:49:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{850FCC49-6B44-43B5-B174-7021D3AD8F6B}
  1554. [2011/08/21 14:06:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{856ABC32-8540-4DED-97A3-AB9E492099B0}
  1555. [2012/01/13 06:46:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{865559E6-1436-451C-8ED6-2025766CD425}
  1556. [2011/06/11 04:33:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{86E2E2FF-ADF9-4339-8D8F-C32DF41D1280}
  1557. [2011/08/20 14:05:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{86FD9F65-7B1B-48A7-A062-A3356FF27C60}
  1558. [2012/01/04 06:38:31 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8713BD9B-0567-4FB0-A383-30A04C489883}
  1559. [2012/01/05 18:39:47 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{879FE557-C887-4228-B4F7-FE8F5128BB45}
  1560. [2011/08/18 02:03:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{883FB9D5-B6FA-41AD-A28D-DF9976E8F755}
  1561. [2011/10/13 01:27:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{88AB621B-82AB-40BC-A98E-C58E6484C808}
  1562. [2011/06/12 22:45:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{88E2E66C-C639-4F07-96DB-D64E3E2D20E6}
  1563. [2011/12/22 18:17:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{89156C4A-EEBF-4D9F-8F17-43D007D5681C}
  1564. [2012/01/30 23:03:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{899EE7C9-710F-4A7A-9692-340A4101BAA8}
  1565. [2012/01/02 18:37:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8A2AFD93-323F-4BC3-B182-D5FF97CF26C5}
  1566. [2011/11/12 22:06:09 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8A625CDC-0C4D-4083-B68B-A481A850C002}
  1567. [2012/02/06 22:17:32 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8A8A55D4-765B-456A-8847-15FB60C96A88}
  1568. [2012/01/10 18:43:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8BBA73BD-002E-4F7D-AC81-96A326B915E5}
  1569. [2012/06/12 21:55:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8C4CADD9-3035-4510-8E36-6720ABCB3B84}
  1570. [2011/12/31 00:52:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8D1749A2-5E81-4850-B93E-6B087D11E0A7}
  1571. [2012/03/16 14:23:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8D35C758-4DE7-44CF-AF2E-A966D20C6F0A}
  1572. [2012/06/20 23:17:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8D3A2B11-DC71-4C91-9A25-948F978BA38A}
  1573. [2012/01/24 16:37:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8DCF7466-1542-4611-80C6-D4FA3B0A1D75}
  1574. [2012/01/04 18:39:09 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8DD1B60C-5099-47DE-A536-8B21AC27D78A}
  1575. [2011/11/09 03:20:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8E4634D5-973D-47EF-BDC3-7BC8BC661358}
  1576. [2011/08/21 02:06:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8E4E114B-C77B-4609-B7AF-3E91FE333D25}
  1577. [2012/05/13 23:47:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8F4F5CB0-FA51-4606-A077-130E689A5E3B}
  1578. [2011/11/23 09:58:07 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{8F896057-7A2B-44A8-8E2A-72F29848174A}
  1579. [2012/01/11 18:45:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{91EEE653-793F-4ED8-B65A-0B260DA52CC6}
  1580. [2012/01/09 06:42:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{92AA2478-552A-4FDA-BEDD-9E6BAAD1EAE0}
  1581. [2011/11/22 21:57:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9322356A-CB69-4ADD-B58F-E76BD46F255A}
  1582. [2011/09/03 21:20:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9388AF42-3E19-4977-912B-E5D3CBB98319}
  1583. [2011/12/11 02:58:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{94E7C97F-431C-4ACC-A3F6-8AE266E77E7A}
  1584. [2011/08/26 23:12:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9904D412-30F8-4FDE-AA63-4B45F79856E3}
  1585. [2012/01/30 23:02:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{990C5817-A82B-44A8-A933-2C798ED02DAF}
  1586. [2011/08/23 13:52:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{99364F9F-8F4D-4853-947E-253DA0854FF0}
  1587. [2011/10/09 12:42:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9AC34DF9-0047-4135-8C41-7DFBADA0011F}
  1588. [2011/10/08 00:40:29 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9B968622-574C-4B0F-998D-EC33433D2536}
  1589. [2012/01/13 18:47:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9BD7A1DF-5845-4640-94EC-86C06E0E01EB}
  1590. [2011/07/08 21:27:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9BE05E3A-6BFD-49FD-92CE-FD6D2EA697B8}
  1591. [2012/05/29 12:49:07 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9C854BD5-239A-4688-B168-E078270FF0BD}
  1592. [2012/05/06 20:19:11 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9CC1A719-9F0D-4966-8359-147F5C659799}
  1593. [2012/07/06 21:25:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9D2E6FC4-022A-4F84-A49D-CD17B521F292}
  1594. [2011/07/16 13:29:38 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9D69BFBD-4F98-4565-A370-92FA73960192}
  1595. [2011/08/29 19:17:28 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{9D7145DF-107C-47F7-BBCB-4944B5461727}
  1596. [2011/08/19 14:04:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A0521EE0-A33F-454A-9990-51BB8D8D7424}
  1597. [2011/10/14 01:28:38 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A1285CA4-50EE-4590-B88C-A6CDE04D4BA0}
  1598. [2011/08/26 23:12:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A1665F6B-B506-423C-82D1-AB90608DF8EC}
  1599. [2012/07/08 15:47:46 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A1C7ACEB-E61A-4D78-943A-76688647E417}
  1600. [2011/06/23 20:45:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A2B18F96-8EED-4DCE-B353-7CF335CF1257}
  1601. [2012/01/11 06:44:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A330A261-F342-46BA-933A-2BF98FDB3782}
  1602. [2011/09/08 21:34:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A41E2BC1-3BC8-4F5B-B7A5-10E395F04F9F}
  1603. [2011/06/21 18:25:28 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A53AC53E-4A6B-4AA6-AF22-775384874459}
  1604. [2011/07/13 13:09:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A5A5905A-94D5-41AC-A019-3DB765BAEFFD}
  1605. [2011/10/23 19:08:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A653A5C2-E0FE-45E3-BBD2-2B22462BC18F}
  1606. [2011/12/28 05:57:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A6E04378-10D3-4567-BDEC-807102A843E1}
  1607. [2012/01/08 06:42:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A6F5F501-D458-4208-9B86-0EED0F7794EA}
  1608. [2011/09/04 23:06:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A76C592D-FAB9-4561-A923-2C4B0E88001E}
  1609. [2011/12/05 18:01:22 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{A95D1094-23A7-4B07-AD52-BB5FB87666F4}
  1610. [2011/12/22 18:17:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{AB2C3E9A-E279-45AB-BF8E-FCD590C1BB42}
  1611. [2012/01/05 06:39:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{ABB93FE1-A279-4131-9654-34579325FFD0}
  1612. [2012/04/01 21:29:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{AC512D99-7847-40B6-B475-73B5366B347D}
  1613. [2011/09/17 06:08:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{ADBE5C23-94E5-4965-A820-5903AB8B3966}
  1614. [2012/06/05 22:35:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{AE7E599F-D702-4C29-B66F-79BDB3E4C526}
  1615. [2011/10/30 03:27:07 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B1C6647B-5672-435C-857D-81910FF8D120}
  1616. [2012/01/04 06:38:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B2458A9E-3E2F-436B-8204-2DF389FCDF23}
  1617. [2011/09/26 11:23:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B2B9F5BA-8024-4EBA-9518-BB9FC513702B}
  1618. [2012/02/08 17:49:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B2E0C86F-1455-433C-834E-DB45F8F1E103}
  1619. [2012/03/19 19:51:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B3041F16-769C-4D5D-8CAB-B6519931CACA}
  1620. [2012/01/12 18:46:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B418C97B-C639-43D1-B3EA-129D00BFC4F9}
  1621. [2011/07/17 16:28:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B50F4A86-5F9D-43B7-986E-1E211A1A9C49}
  1622. [2011/07/20 19:45:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B5C19C78-1192-4D04-BE02-C393EA5E3963}
  1623. [2011/06/10 14:47:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B69025EE-52DA-43DF-99B8-DAB61C12A301}
  1624. [2012/01/27 13:10:13 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B6C4D457-6E9D-47FB-8E4E-434ED38F190B}
  1625. [2011/10/18 01:32:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B72F6CAD-31F3-48B1-ADE9-2EB334DF0577}
  1626. [2012/07/06 21:25:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B7C08FA2-93D4-4501-9D15-3AEAF415D117}
  1627. [2011/08/30 07:17:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B7E5B0A3-C894-48A5-BE42-7590C8CA6CC8}
  1628. [2011/10/08 00:40:40 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{B9730B17-115C-4D2F-A0CD-CE3C5876389E}
  1629. [2011/08/20 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BA08BC89-A6E2-4986-821B-82178E516491}
  1630. [2011/08/10 23:07:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BA162ECD-8A8D-4462-9777-DF6F9E20D2B1}
  1631. [2012/07/01 21:13:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BA192EB0-437D-43ED-9656-ED22FD652960}
  1632. [2012/06/07 23:36:29 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BAFB44C7-8036-4007-8E7F-4A5445ECB8F1}
  1633. [2012/01/03 18:38:07 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BE29158D-D9DD-4443-B2C8-83739377DF7D}
  1634. [2012/01/03 06:37:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BE457759-8D8F-4DBD-B046-EECD143C6E3A}
  1635. [2011/11/12 22:05:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BE97152B-B2A8-4AED-89D0-0A78F765FCB4}
  1636. [2011/11/23 09:57:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BEE92143-85BC-4B4D-9DF0-2A8792C1222E}
  1637. [2012/06/20 23:17:47 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BF03763E-75B3-48A3-9CAF-0EE080DD4380}
  1638. [2011/10/17 13:31:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{BFA361FF-B9DA-4513-B317-11BEC996A529}
  1639. [2011/10/11 13:25:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C11A51D3-13A9-4C91-A3FA-393B78E684B1}
  1640. [2011/09/02 07:20:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C11B1592-CF46-4ECD-A269-2E6C3FF4B1D3}
  1641. [2012/01/08 18:42:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C1801F86-C920-4983-982A-7B0003262AD5}
  1642. [2011/09/24 11:21:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C1855BCA-5378-4017-9253-950EC4A57A1A}
  1643. [2011/10/15 01:29:31 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C198675A-6641-4C3C-B89C-31BB5ED9B567}
  1644. [2011/12/13 22:50:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C1D5AB97-8C4E-479D-AB14-2045F76B0C7B}
  1645. [2011/12/12 15:00:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C2298CA2-80AA-4A26-B6B1-AD79AEFF0A4A}
  1646. [2011/10/12 01:26:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C29591BF-65D6-43FA-8DC6-B1F999D4768B}
  1647. [2011/12/26 17:56:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C32E47D6-ED7F-4FD0-9112-93FB7692D741}
  1648. [2011/11/25 22:19:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C3C8293B-01AF-4A93-9B99-55BE3B23B679}
  1649. [2011/09/25 23:23:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C694588D-9E28-4C72-B7F5-12ABB5029CCC}
  1650. [2012/02/15 03:25:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C6F42E62-A8C1-4B20-AF91-3668D186894B}
  1651. [2011/12/13 10:49:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C78C05BC-9411-4583-B477-57AB377F223F}
  1652. [2012/04/18 03:49:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C91D5353-4980-4BCF-840D-15DC22ECC5B4}
  1653. [2011/09/18 18:10:03 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{C939EB26-3455-4D72-8973-882333C9C63A}
  1654. [2012/01/15 06:48:27 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CA52741D-BA40-4D85-AE30-7CF93E901E27}
  1655. [2011/09/24 11:21:46 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CB54EBE3-AB82-4E98-AFC2-74F24CBA0F34}
  1656. [2012/01/07 06:41:11 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CB91388F-A48C-4A32-85D9-E4FB37966F22}
  1657. [2012/01/02 06:37:02 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CBDAAD67-796D-4EFA-B3E0-FEF9AAEA265A}
  1658. [2011/08/21 14:07:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CC9C3F5F-FBAF-4580-A634-1DD131F78F85}
  1659. [2011/08/28 19:16:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CD822744-3D3C-452E-B110-B5D882A61A6A}
  1660. [2011/10/13 13:27:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CF3D11F1-1E65-4E0C-B4B3-F1A404A3FFC8}
  1661. [2012/05/29 12:48:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{CF8F16DF-7455-41A2-A2FE-5CF64B8D3F35}
  1662. [2011/09/30 18:25:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D1028DD1-9AFB-4573-9C5F-8A32325CCF2B}
  1663. [2011/12/14 12:38:17 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D11B6B5C-EBDB-4141-8843-1BEEA7D174CA}
  1664. [2011/11/25 22:20:02 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D2D72F76-ADD7-481D-A670-3EAF239513B3}
  1665. [2011/09/22 21:36:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D3C9362D-2E47-4F62-B684-2906B86B9EB8}
  1666. [2012/05/17 11:06:09 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D3CA9815-44CA-49E3-9CEC-4EE17C6112B4}
  1667. [2012/01/02 18:37:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D45C6F15-D5E8-406A-AACB-655409186370}
  1668. [2011/10/01 19:38:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D68988E6-3F5C-4F05-A2D7-4D8946E06DAB}
  1669. [2011/06/18 08:35:28 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D73CFEA2-E66F-4E2F-BAD8-16F53BB5BD20}
  1670. [2012/03/17 14:23:53 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D92AB8FA-0000-48E8-9A15-CCC5068B19A7}
  1671. [2012/05/30 22:19:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{D9D4257C-DDB9-4DB4-82EF-C08F4A2871BA}
  1672. [2012/01/24 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{DA163274-01AC-4550-8F43-A47E6D8788D4}
  1673. [2012/04/22 20:39:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{DACA11EA-85E1-41FA-A11A-A901A215E4AB}
  1674. [2011/10/25 22:30:18 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{DB0488DC-996D-4F1F-9AE4-CBF373A4430A}
  1675. [2012/01/15 06:48:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{DBE7CE1C-16A7-4804-9607-FFACEEAB6F51}
  1676. [2011/08/08 02:52:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{DDF72E8D-70AC-4D32-A797-7702762A3041}
  1677. [2012/01/01 18:36:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E0382250-6A4F-4038-B4C0-CCC2CD2E62DD}
  1678. [2011/10/09 00:41:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E08C6E2A-084E-43AF-845E-DC93D06ADE73}
  1679. [2011/08/07 14:51:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E2815C05-F4D6-49C9-94C3-C14A94BC28D6}
  1680. [2012/01/10 18:44:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E2888CA5-A297-48DD-A9C1-2964DE54291A}
  1681. [2012/01/04 18:38:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E2A4CC05-AD83-4614-B4EF-3F6C02EA9500}
  1682. [2011/12/11 02:58:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E40E3B21-95F6-41D9-B86D-0B8E84A6EBD1}
  1683. [2012/01/11 06:44:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E4B8DE72-B6E8-4368-B2E3-467E2463F786}
  1684. [2011/09/13 19:37:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E4E261A8-FF53-40AB-A6A6-943420E3297C}
  1685. [2011/09/01 19:19:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E50A3E21-09DF-48CE-8FB7-B271D36701B1}
  1686. [2011/07/28 17:22:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E60DF966-6E40-402F-8AE9-D62FA2384098}
  1687. [2011/08/31 19:19:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E65AA326-880E-411C-8E55-D94CE92E2CA2}
  1688. [2012/05/20 22:13:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E7FEF964-2209-4438-B17F-3F7D125BAA53}
  1689. [2011/12/17 09:51:59 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E845BFB6-B224-45B5-AD79-C29E73303DF4}
  1690. [2011/12/10 14:58:19 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{E9E18768-346C-4D27-A485-F0F703F7432E}
  1691. [2012/01/14 06:47:32 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EA29AEC6-CD1E-458E-BC88-1F8B4C5A2864}
  1692. [2012/01/14 18:48:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EA6E3CA0-BFBE-4F34-B254-7DC8B4109CED}
  1693. [2012/01/07 18:41:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EB33DF5E-1C39-4D29-B25F-FCBB5B3F34FA}
  1694. [2011/09/17 18:09:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EB5960F1-A931-4195-B575-04E9E4A409B6}
  1695. [2012/01/06 18:40:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EBD09799-0E4F-4D36-8E54-847200642554}
  1696. [2011/12/13 22:50:13 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EC00DAF6-88A6-4AA7-B504-1E5FF71DB251}
  1697. [2012/01/07 18:41:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{ED37A0F9-D6F2-44C3-BA91-7CF645470EB0}
  1698. [2012/06/28 21:27:08 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{EF7B0A64-1DE1-4F0C-A767-7DED1699B8F1}
  1699. [2012/04/30 14:45:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F10464EE-31F4-4D68-813F-2D80DA1C7411}
  1700. [2012/03/19 02:25:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F2C0459E-B417-4A6B-B4C9-B8B03DB3CCF7}
  1701. [2011/07/03 19:02:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F35DBA54-68DF-4BEE-B48F-8CB92BCA78C2}
  1702. [2012/04/11 00:47:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F4376746-7BFD-414D-86E0-6D72B1A3108D}
  1703. [2011/10/16 01:30:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F4A1DC0F-A8E8-4717-9299-A7A568D18D04}
  1704. [2011/07/29 18:41:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F4A62553-2D3D-4A00-AD2E-296B6AFAD281}
  1705. [2012/02/15 15:25:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F4B8E5F2-76BC-4E18-9D1B-F2E9F950531F}
  1706. [2012/03/15 14:22:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F53471BC-4BE4-4F44-8EC4-725E7BEC0100}
  1707. [2011/09/15 18:06:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F5D9FE75-38D8-48C2-BF6A-EA28F225A1B3}
  1708. [2011/09/03 01:09:29 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F6B3BDB5-D05F-48E4-80ED-59E7356D30FA}
  1709. [2011/08/25 21:29:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F6BB7953-F6F4-425B-907D-9C1D6413A511}
  1710. [2011/09/21 21:35:20 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F6C0D6D0-9796-41A7-BDEA-5C3FB84C6646}
  1711. [2012/01/12 06:45:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F6EF35F2-8F6A-4086-AD1E-5B0845C71CB3}
  1712. [2011/10/23 19:07:59 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F75935AA-A648-419D-8D9A-AFAE1518F8FC}
  1713. [2011/12/11 14:59:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F7A334C6-2746-4A52-9FF4-912C18FA42DE}
  1714. [2012/01/26 09:23:46 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F80887D1-B03E-43F5-92AC-1B8F8D5441C2}
  1715. [2011/12/12 02:59:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F8EFC25E-C701-44A4-80B2-4560366D70B3}
  1716. [2012/01/27 13:09:59 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F922C9F5-F8D1-4889-AB79-76B9B390A714}
  1717. [2011/09/02 07:20:07 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{F9929175-F971-41D8-8AB3-2E069597B6C2}
  1718. [2011/08/23 14:58:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FAEE3DD2-034B-4C7F-81B3-A284AA12BC2C}
  1719. [2011/10/17 01:31:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FB18181C-AF55-4D09-8DDD-64DE8AE5C137}
  1720. [2011/08/15 02:00:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FB6B1BF4-8C4A-4D89-BF39-FD59C3403E15}
  1721. [2012/03/19 19:51:26 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FBA2D37F-E4CB-4FF9-9D59-151CFF4FF958}
  1722. [2012/01/08 06:41:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FBD6A687-B44D-421B-A365-9140D547EF12}
  1723. [2011/10/14 13:28:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FC199136-6457-402D-9FB4-A7536F40B9D1}
  1724. [2011/12/24 15:41:19 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Local\{FDA7191D-FE6E-4EA2-A821-E2153983B057}
  1725.  
  1726. [color=#A23BEC]< %USERPROFILE%\AppData\Local\temp\*.exe >[/color]
  1727.  
  1728. [color=#A23BEC]< %USERPROFILE%\AppData\Roaming\*.* >[/color]
  1729. [2012/12/11 12:34:46 | 000,000,000 | ---- | M] () -- C:\Users\Home\AppData\Roaming\bitlord_log.txt
  1730. [2012/09/26 21:07:08 | 000,099,384 | ---- | M] () -- C:\Users\Home\AppData\Roaming\inst.exe
  1731. [2012/09/26 21:07:08 | 000,007,859 | ---- | M] () -- C:\Users\Home\AppData\Roaming\pcouffin.cat
  1732. [2012/09/26 21:07:08 | 000,001,167 | ---- | M] () -- C:\Users\Home\AppData\Roaming\pcouffin.inf
  1733. [2012/09/26 21:07:08 | 000,082,816 | ---- | M] (VSO Software) -- C:\Users\Home\AppData\Roaming\pcouffin.sys
  1734. [2011/12/05 17:46:40 | 000,005,243 | ---- | M] () -- C:\Users\Home\AppData\Roaming\UserTile.png
  1735. [2012/09/26 21:06:14 | 000,001,189 | ---- | M] () -- C:\Users\Home\AppData\Roaming\vso_ts_preview.xml
  1736. [2012/03/21 19:59:13 | 000,000,600 | ---- | M] () -- C:\Users\Home\AppData\Roaming\winscp.rnd
  1737.  
  1738. [color=#A23BEC]< %USERPROFILE%\AppData\Roaming\*. >[/color]
  1739. [2011/06/10 23:35:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Adobe
  1740. [2012/02/03 22:02:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\AnvSoft
  1741. [2011/12/05 18:01:37 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Apple Computer
  1742. [2012/02/03 13:05:53 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Atari
  1743. [2011/06/24 16:21:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\BigFishv1001
  1744. [2011/11/25 14:52:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\BigFishv1002
  1745. [2012/12/11 13:11:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\BitLord
  1746. [2011/07/05 17:44:05 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\DAEMON Tools Lite
  1747. [2011/06/08 18:05:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Dell
  1748. [2011/06/08 16:06:32 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Dell Touch Zone
  1749. [2012/03/25 17:06:54 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Download Manager
  1750. [2012/12/08 04:39:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\DriverCure
  1751. [2011/12/27 00:53:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Dropbox
  1752. [2011/07/18 17:38:35 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\E-centives
  1753. [2012/03/26 16:10:23 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Fingertapps
  1754. [2012/07/02 21:54:04 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Flight1
  1755. [2012/05/31 20:31:25 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\FS2Crew2010
  1756. [2011/06/18 19:01:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\funkitron
  1757. [2012/07/05 21:05:49 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Guitar Pro 6
  1758. [2012/07/02 21:54:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\HiFi
  1759. [2011/06/08 16:06:09 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Identities
  1760. [2012/04/16 14:48:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Image-Line
  1761. [2012/07/15 23:24:16 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\InstallShield
  1762. [2011/08/20 10:32:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Jaran Nilsen
  1763. [2012/01/22 20:50:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Leadertech
  1764. [2012/06/22 01:14:33 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Learn2.com
  1765. [2011/06/08 16:11:56 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Macromedia
  1766. [2011/06/08 16:36:09 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Macrovision
  1767. [2012/07/06 21:24:39 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Malwarebytes
  1768. [2010/11/21 01:16:41 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Media Center Programs
  1769. [2012/10/06 11:57:35 | 000,000,000 | --SD | M] -- C:\Users\Home\AppData\Roaming\Microsoft
  1770. [2011/06/08 21:29:32 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Mozilla
  1771. [2011/09/24 09:24:21 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Namco
  1772. [2012/11/20 03:48:24 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\NCH Software
  1773. [2011/09/03 02:32:29 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\NCH Swift Sound
  1774. [2011/12/09 23:56:14 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\OpenOffice.org
  1775. [2011/07/30 03:38:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Origin
  1776. [2011/06/24 12:01:52 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\PCDr
  1777. [2011/12/22 21:30:42 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\PopCapv1000
  1778. [2012/04/09 20:53:44 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Propellerhead Software
  1779. [2012/04/26 23:32:55 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Publish Providers
  1780. [2011/07/20 16:44:57 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Python-Eggs
  1781. [2011/09/06 14:43:58 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\redsn0w
  1782. [2011/07/05 17:12:00 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Roxio
  1783. [2012/06/14 13:04:48 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Roxio Burn
  1784. [2012/06/10 16:35:15 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Samsung
  1785. [2011/07/30 17:31:27 | 000,000,000 | R--D | M] -- C:\Users\Home\AppData\Roaming\SecuROM
  1786. [2012/12/10 16:24:34 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Skype
  1787. [2012/09/03 15:08:10 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\skypePM
  1788. [2012/12/08 04:55:50 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Sony
  1789. [2012/12/08 04:39:01 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\SpeedyPC Software
  1790. [2011/11/09 13:20:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\SpinTop Games
  1791. [2012/06/28 00:50:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\SystemRequirementsLab
  1792. [2011/08/26 00:50:06 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\TP
  1793. [2011/10/15 04:01:12 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\TS3Client
  1794. [2011/06/08 17:07:36 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\V310-V510 Series
  1795. [2012/12/08 04:55:51 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\Vso
  1796. [2011/06/15 19:45:45 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\WildTangentv1000
  1797. [2011/07/05 16:20:30 | 000,000,000 | ---D | M] -- C:\Users\Home\AppData\Roaming\WinRAR
  1798.  
  1799. [color=#A23BEC]< %Public%\Documents\Fonts\*.exe >[/color]
  1800.  
  1801. [color=#A23BEC]< %Public%\Documents\Config\*.exe >[/color]
  1802.  
  1803. [color=#A23BEC]< %Public%\Documents\*.* >[/color]
  1804. [2009/07/13 22:54:24 | 000,000,278 | -HS- | M] () -- C:\Users\Public\Documents\desktop.ini
  1805.  
  1806. [color=#A23BEC]< %ProgramData%\*.* >[/color]
  1807. [2012/12/17 01:17:21 | 000,001,430 | ---- | M] () -- C:\ProgramData\dleascan.log
  1808. [2012/08/31 20:40:17 | 000,000,056 | ---- | M] () -- C:\ProgramData\ezsidmv.dat
  1809. [2012/06/10 20:38:08 | 000,000,258 | R-S- | M] () -- C:\ProgramData\ntuser.pol
  1810. [2011/06/08 16:30:56 | 000,000,000 | ---- | M] () -- C:\ProgramData\UpdaterLog.txt
  1811.  
  1812. [color=#A23BEC]< %ProgramData%\*. >[/color]
  1813. [2012/09/08 03:28:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe
  1814. [2011/06/15 00:53:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple
  1815. [2011/06/15 00:29:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple Computer
  1816. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
  1817. [2011/11/09 12:36:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Big Fish Games
  1818. [2011/07/05 17:42:21 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite
  1819. [2012/05/18 02:50:50 | 000,000,000 | ---D | M] -- C:\ProgramData\Dell
  1820. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
  1821. [2012/12/04 08:44:21 | 000,000,000 | ---D | M] -- C:\ProgramData\dl_Cats
  1822. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
  1823. [2011/07/30 03:38:25 | 000,000,000 | ---D | M] -- C:\ProgramData\Electronic Arts
  1824. [2011/06/08 16:49:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Ezprint
  1825. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
  1826. [2012/07/05 21:05:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Guitar Pro 6
  1827. [2011/06/10 16:28:14 | 000,000,000 | ---D | M] -- C:\ProgramData\HipSoft
  1828. [2011/12/09 23:30:13 | 000,000,000 | ---D | M] -- C:\ProgramData\HP
  1829. [2011/06/02 19:23:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Macrovision
  1830. [2012/07/06 21:24:27 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes
  1831. [2012/09/28 13:25:45 | 000,000,000 | ---D | M] -- C:\ProgramData\McAfee
  1832. [2012/12/06 15:38:52 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft
  1833. [2012/11/14 03:16:46 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help
  1834. [2012/06/28 21:54:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla
  1835. [2012/11/20 03:48:24 | 000,000,000 | ---D | M] -- C:\ProgramData\NCH Software
  1836. [2011/09/03 02:20:12 | 000,000,000 | ---D | M] -- C:\ProgramData\NCH Swift Sound
  1837. [2011/10/30 03:38:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Origin
  1838. [2012/08/23 09:06:18 | 000,000,000 | ---D | M] -- C:\ProgramData\PC-Doctor for Windows
  1839. [2012/12/05 09:07:36 | 000,000,000 | ---D | M] -- C:\ProgramData\PCDr
  1840. [2011/06/02 19:26:11 | 000,000,000 | ---D | M] -- C:\ProgramData\PhotoShow Shared Assets
  1841. [2011/12/22 20:56:35 | 000,000,000 | ---D | M] -- C:\ProgramData\PopCap Games
  1842. [2011/12/22 20:57:21 | 000,000,000 | ---D | M] -- C:\ProgramData\PopCapY
  1843. [2012/04/09 20:53:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Propellerhead Software
  1844. [2012/11/30 22:09:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Rosetta Stone
  1845. [2012/12/11 13:06:26 | 000,000,000 | ---D | M] -- C:\ProgramData\Roxio
  1846. [2012/06/17 22:31:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Samsung
  1847. [2012/11/25 22:09:39 | 000,000,000 | ---D | M] -- C:\ProgramData\Skype
  1848. [2012/10/02 13:45:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Sonic
  1849. [2012/04/26 23:27:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony
  1850. [2012/09/08 03:33:44 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony Corporation
  1851. [2012/12/11 12:20:34 | 000,000,000 | ---D | M] -- C:\ProgramData\SpeedyPC Software
  1852. [2011/06/24 16:14:35 | 000,000,000 | ---D | M] -- C:\ProgramData\SpinTop Games
  1853. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
  1854. [2011/06/02 19:01:36 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun
  1855. [2012/11/25 12:47:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp
  1856. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
  1857. [2011/06/02 19:27:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
  1858. [2011/06/08 16:35:52 | 000,000,000 | ---D | M] -- C:\ProgramData\V310-V510 Series
  1859. [2011/06/21 18:39:54 | 000,000,000 | ---D | M] -- C:\ProgramData\VirtualizedApplications
  1860. [2011/10/15 11:21:02 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent
  1861. [2012/05/03 22:30:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Yahoo!
  1862. [2011/06/15 00:30:09 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
  1863.  
  1864. [color=#A23BEC]< %CommonProgramFiles%\*.* >[/color]
  1865.  
  1866. [color=#A23BEC]< %CommonProgramFiles%\ComObjects*.exe >[/color]
  1867.  
  1868. [color=#A23BEC]< %commonprogramfiles(x86)%\*.* >[/color]
  1869.  
  1870. [color=#A23BEC]< %ProgramFiles%\*.* >[/color]
  1871. [2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  1872.  
  1873. [color=#A23BEC]< %ProgramFiles%\*. >[/color]
  1874. [2012/05/21 17:14:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Abacus
  1875. [2011/06/02 19:21:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
  1876. [2012/02/24 19:30:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Alcohol Soft
  1877. [2012/02/03 22:02:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AnvSoft
  1878. [2011/06/15 00:28:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
  1879. [2012/04/09 21:10:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ASIO4ALL v2
  1880. [2011/11/09 12:36:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\bfgclient
  1881. [2012/02/24 18:22:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\BitLord 2
  1882. [2011/12/05 17:53:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
  1883. [2012/04/26 23:36:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\chrome
  1884. [2011/06/02 19:02:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Citrix
  1885. [2012/12/11 12:20:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
  1886. [2011/09/26 19:34:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ConvertHelper
  1887. [2011/07/05 17:48:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DAEMON Tools Toolbar
  1888. [2012/05/18 02:50:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell
  1889. [2011/06/08 16:35:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell PC Fax
  1890. [2012/03/26 16:10:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell Stage
  1891. [2011/06/08 16:35:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell Toolbar
  1892. [2011/06/29 02:58:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell Touch Software Suite
  1893. [2012/12/08 04:55:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell V310-V510 Series
  1894. [2011/09/09 16:00:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EA Games
  1895. [2011/07/05 17:50:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Elaborate Bytes
  1896. [2012/05/31 00:03:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
  1897. [2012/07/16 00:07:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\FS2Crew
  1898. [2012/04/20 16:01:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
  1899. [2012/07/02 21:54:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HiFi
  1900. [2012/06/28 22:05:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HiFiUninstaller
  1901. [2012/12/11 12:45:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Image-Line
  1902. [2012/09/08 03:07:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\InstallShield Installation Information
  1903. [2012/01/11 12:18:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
  1904. [2012/11/14 03:32:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
  1905. [2012/03/25 21:34:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
  1906. [2011/08/20 21:46:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes Agent
  1907. [2011/06/02 19:20:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jagex
  1908. [2012/07/01 20:19:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
  1909. [2012/06/22 01:14:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Learn2.com
  1910. [2012/12/06 20:05:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
  1911. [2012/06/02 23:16:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MarkAny
  1912. [2012/12/16 07:09:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\McAfee
  1913. [2011/06/02 19:18:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mcafee.com
  1914. [2012/12/06 15:38:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mega Codec Pack
  1915. [2011/06/08 16:13:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
  1916. [2012/03/25 19:11:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Analysis Services
  1917. [2012/06/28 15:12:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Games
  1918. [2012/03/25 19:10:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
  1919. [2012/05/17 21:54:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
  1920. [2011/06/02 19:16:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
  1921. [2012/03/25 19:12:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8
  1922. [2011/12/15 01:02:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft WSE
  1923. [2012/03/25 19:14:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
  1924. [2012/12/08 04:55:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
  1925. [2012/11/04 01:31:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
  1926. [2012/03/25 19:14:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
  1927. [2011/07/13 13:12:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
  1928. [2011/06/02 19:01:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Multimedia Card Reader(9106)
  1929. [2011/11/25 14:52:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - Stolen in San Francisco
  1930. [2011/11/09 12:40:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - The Curious Case of Counterfeit Cove
  1931. [2011/06/24 16:15:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - The London Caper
  1932. [2011/06/24 16:12:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - The Vegas Heist
  1933. [2012/11/20 03:48:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NCH Software
  1934. [2011/09/03 02:32:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NCH Swift Sound
  1935. [2011/12/13 21:09:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NovaLogic
  1936. [2012/05/18 02:58:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice.org 3
  1937. [2011/09/09 14:43:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Origin
  1938. [2011/07/30 15:15:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Origin Games
  1939. [2012/04/09 21:10:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Outsim
  1940. [2011/12/22 20:56:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games
  1941. [2011/09/05 01:13:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Power Tab Software
  1942. [2011/12/05 17:58:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
  1943. [2012/12/08 04:55:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\rcv4
  1944. [2012/07/02 22:14:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Real Environment Xtreme
  1945. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
  1946. [2012/02/24 20:02:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Rockstar Games
  1947. [2012/05/08 21:21:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Rosetta Stone
  1948. [2011/06/02 19:26:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Roxio
  1949. [2012/06/17 22:28:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Samsung
  1950. [2012/11/25 22:09:34 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
  1951. [2012/09/08 03:07:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sony
  1952. [2012/06/28 00:51:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SystemRequirementsLab
  1953. [2011/06/02 19:20:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TrustedID
  1954. [2009/07/13 22:57:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uninstall Information
  1955. [2012/12/14 02:55:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Unlocker
  1956. [2012/12/11 12:51:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VstPlugins
  1957. [2011/06/02 19:03:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent
  1958. [2011/06/02 19:04:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent Games
  1959. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
  1960. [2012/06/28 21:31:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
  1961. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
  1962. [2012/06/08 02:01:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
  1963. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
  1964. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
  1965. [2010/11/20 21:31:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
  1966. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
  1967. [2012/03/19 11:32:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinSCP
  1968. [2012/05/18 02:59:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Yahoo!
  1969.  
  1970. [color=#A23BEC]< %ProgramFiles(x86)%\*.* >[/color]
  1971. [2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  1972.  
  1973. [color=#A23BEC]< %ProgramFiles(x86)%\*. >[/color]
  1974. [2012/05/21 17:14:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Abacus
  1975. [2011/06/02 19:21:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
  1976. [2012/02/24 19:30:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Alcohol Soft
  1977. [2012/02/03 22:02:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AnvSoft
  1978. [2011/06/15 00:28:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
  1979. [2012/04/09 21:10:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ASIO4ALL v2
  1980. [2011/11/09 12:36:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\bfgclient
  1981. [2012/02/24 18:22:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\BitLord 2
  1982. [2011/12/05 17:53:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
  1983. [2012/04/26 23:36:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\chrome
  1984. [2011/06/02 19:02:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Citrix
  1985. [2012/12/11 12:20:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
  1986. [2011/09/26 19:34:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ConvertHelper
  1987. [2011/07/05 17:48:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DAEMON Tools Toolbar
  1988. [2012/05/18 02:50:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell
  1989. [2011/06/08 16:35:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell PC Fax
  1990. [2012/03/26 16:10:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell Stage
  1991. [2011/06/08 16:35:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell Toolbar
  1992. [2011/06/29 02:58:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell Touch Software Suite
  1993. [2012/12/08 04:55:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell V310-V510 Series
  1994. [2011/09/09 16:00:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EA Games
  1995. [2011/07/05 17:50:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Elaborate Bytes
  1996. [2012/05/31 00:03:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
  1997. [2012/07/16 00:07:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\FS2Crew
  1998. [2012/04/20 16:01:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
  1999. [2012/07/02 21:54:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HiFi
  2000. [2012/06/28 22:05:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HiFiUninstaller
  2001. [2012/12/11 12:45:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Image-Line
  2002. [2012/09/08 03:07:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\InstallShield Installation Information
  2003. [2012/01/11 12:18:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
  2004. [2012/11/14 03:32:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
  2005. [2012/03/25 21:34:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
  2006. [2011/08/20 21:46:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes Agent
  2007. [2011/06/02 19:20:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jagex
  2008. [2012/07/01 20:19:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
  2009. [2012/06/22 01:14:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Learn2.com
  2010. [2012/12/06 20:05:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
  2011. [2012/06/02 23:16:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MarkAny
  2012. [2012/12/16 07:09:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\McAfee
  2013. [2011/06/02 19:18:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mcafee.com
  2014. [2012/12/06 15:38:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mega Codec Pack
  2015. [2011/06/08 16:13:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
  2016. [2012/03/25 19:11:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Analysis Services
  2017. [2012/06/28 15:12:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Games
  2018. [2012/03/25 19:10:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
  2019. [2012/05/17 21:54:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
  2020. [2011/06/02 19:16:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
  2021. [2012/03/25 19:12:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8
  2022. [2011/12/15 01:02:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft WSE
  2023. [2012/03/25 19:14:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
  2024. [2012/12/08 04:55:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
  2025. [2012/11/04 01:31:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
  2026. [2012/03/25 19:14:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
  2027. [2011/07/13 13:12:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
  2028. [2011/06/02 19:01:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Multimedia Card Reader(9106)
  2029. [2011/11/25 14:52:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - Stolen in San Francisco
  2030. [2011/11/09 12:40:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - The Curious Case of Counterfeit Cove
  2031. [2011/06/24 16:15:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - The London Caper
  2032. [2011/06/24 16:12:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery P.I. - The Vegas Heist
  2033. [2012/11/20 03:48:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NCH Software
  2034. [2011/09/03 02:32:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NCH Swift Sound
  2035. [2011/12/13 21:09:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NovaLogic
  2036. [2012/05/18 02:58:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice.org 3
  2037. [2011/09/09 14:43:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Origin
  2038. [2011/07/30 15:15:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Origin Games
  2039. [2012/04/09 21:10:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Outsim
  2040. [2011/12/22 20:56:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games
  2041. [2011/09/05 01:13:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Power Tab Software
  2042. [2011/12/05 17:58:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
  2043. [2012/12/08 04:55:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\rcv4
  2044. [2012/07/02 22:14:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Real Environment Xtreme
  2045. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
  2046. [2012/02/24 20:02:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Rockstar Games
  2047. [2012/05/08 21:21:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Rosetta Stone
  2048. [2011/06/02 19:26:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Roxio
  2049. [2012/06/17 22:28:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Samsung
  2050. [2012/11/25 22:09:34 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
  2051. [2012/09/08 03:07:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sony
  2052. [2012/06/28 00:51:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SystemRequirementsLab
  2053. [2011/06/02 19:20:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TrustedID
  2054. [2009/07/13 22:57:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uninstall Information
  2055. [2012/12/14 02:55:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Unlocker
  2056. [2012/12/11 12:51:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VstPlugins
  2057. [2011/06/02 19:03:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent
  2058. [2011/06/02 19:04:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent Games
  2059. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
  2060. [2012/06/28 21:31:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
  2061. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
  2062. [2012/06/08 02:01:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
  2063. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
  2064. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
  2065. [2010/11/20 21:31:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
  2066. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
  2067. [2012/03/19 11:32:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinSCP
  2068. [2012/05/18 02:59:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Yahoo!
  2069.  
  2070. [color=#A23BEC]< %programdata%\Microsoft\Windows\DRM\*.tmp >[/color]
  2071.  
  2072. [color=#A23BEC]< %programdata%\Microsoft\DRM\*.tmp >[/color]
  2073.  
  2074. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Local\*.* >[/color]
  2075.  
  2076. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Roaming\*.* >[/color]
  2077.  
  2078. [color=#A23BEC]< %windir%\SysWOW64\config\systemprofile\AppData\Local\*.* >[/color]
  2079.  
  2080. [color=#A23BEC]< %windir%\SysWOW64\config\systemprofile\AppData\Roaming\*.* >[/color]
  2081.  
  2082. [color=#A23BEC]< %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.tlb >[/color]
  2083.  
  2084. [color=#A23BEC]< %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tlb >[/color]
  2085.  
  2086. [color=#A23BEC]< %windir%\temp\*.exe >[/color]
  2087.  
  2088. [color=#A23BEC]< %windir%\minidump\*.* >[/color]
  2089.  
  2090. [color=#A23BEC]< %windir%\*. >[/color]
  2091. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\addins
  2092. [2009/07/13 21:20:08 | 000,000,000 | ---D | M] -- C:\Windows\AppCompat
  2093. [2012/11/28 15:48:10 | 000,000,000 | ---D | M] -- C:\Windows\AppPatch
  2094. [2012/11/14 03:47:05 | 000,000,000 | R-SD | M] -- C:\Windows\assembly
  2095. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Boot
  2096. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Branding
  2097. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\Cursors
  2098. [2012/12/08 05:08:58 | 000,000,000 | ---D | M] -- C:\Windows\debug
  2099. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\diagnostics
  2100. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\DigitalLocker
  2101. [2012/06/28 22:18:09 | 000,000,000 | ---D | M] -- C:\Windows\Downloaded Installations
  2102. [2012/12/08 04:55:13 | 000,000,000 | ---D | M] -- C:\Windows\Downloaded Program Files
  2103. [2012/01/11 03:21:05 | 000,000,000 | ---D | M] -- C:\Windows\ehome
  2104. [2012/06/28 21:35:40 | 000,000,000 | ---D | M] -- C:\Windows\en
  2105. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\en-US
  2106. [2012/05/16 01:27:34 | 000,000,000 | ---D | M] -- C:\Windows\Flight Sim Nation Carrier
  2107. [2012/11/14 03:32:28 | 000,000,000 | R-SD | M] -- C:\Windows\Fonts
  2108. [2010/11/21 01:19:27 | 000,000,000 | ---D | M] -- C:\Windows\Globalization
  2109. [2012/11/27 08:33:04 | 000,000,000 | ---D | M] -- C:\Windows\Help
  2110. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\IME
  2111. [2012/12/08 09:01:19 | 000,000,000 | ---D | M] -- C:\Windows\inf
  2112. [2012/12/14 04:43:53 | 000,000,000 | -HSD | M] -- C:\Windows\Installer
  2113. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\L2Schemas
  2114. [2011/08/03 01:55:13 | 000,000,000 | ---D | M] -- C:\Windows\LiveKernelReports
  2115. [2012/12/08 04:54:50 | 000,000,000 | ---D | M] -- C:\Windows\Logs
  2116. [2009/07/13 23:32:40 | 000,000,000 | R-SD | M] -- C:\Windows\Media
  2117. [2012/11/14 03:47:36 | 000,000,000 | ---D | M] -- C:\Windows\Microsoft.NET
  2118. [2012/03/25 17:27:10 | 000,000,000 | ---D | M] -- C:\Windows\Minidump
  2119. [2009/07/13 20:34:34 | 000,000,000 | ---D | M] -- C:\Windows\ModemLogs
  2120. [2012/06/22 01:14:33 | 000,000,000 | ---D | M] -- C:\Windows\Occache
  2121. [2009/07/13 23:32:40 | 000,000,000 | ---D | M] -- C:\Windows\Offline Web Pages
  2122. [2012/12/08 04:55:51 | 000,000,000 | ---D | M] -- C:\Windows\panther
  2123. [2012/03/25 19:14:45 | 000,000,000 | ---D | M] -- C:\Windows\PCHEALTH
  2124. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Performance
  2125. [2009/07/13 21:20:10 | 000,000,000 | ---D | M] -- C:\Windows\PLA
  2126. [2012/11/28 00:16:10 | 000,000,000 | ---D | M] -- C:\Windows\PolicyDefinitions
  2127. [2012/12/17 18:15:28 | 000,000,000 | ---D | M] -- C:\Windows\Prefetch
  2128. [2011/07/29 02:07:35 | 000,000,000 | ---D | M] -- C:\Windows\Registration
  2129. [2012/11/28 16:42:27 | 000,000,000 | ---D | M] -- C:\Windows\rescache
  2130. [2012/11/08 01:12:27 | 000,000,000 | ---D | M] -- C:\Windows\Resources
  2131. [2009/07/13 20:35:47 | 000,000,000 | ---D | M] -- C:\Windows\SchCache
  2132. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\schemas
  2133. [2009/07/13 21:20:10 | 000,000,000 | ---D | M] -- C:\Windows\security
  2134. [2009/07/13 22:45:47 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles
  2135. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\servicing
  2136. [2011/06/02 20:27:28 | 000,000,000 | ---D | M] -- C:\Windows\Setup
  2137. [2012/03/25 19:15:40 | 000,000,000 | ---D | M] -- C:\Windows\ShellNew
  2138. [2012/12/08 04:55:49 | 000,000,000 | ---D | M] -- C:\Windows\SoftwareDistribution
  2139. [2010/11/21 01:06:49 | 000,000,000 | ---D | M] -- C:\Windows\Speech
  2140. [2012/05/31 03:27:16 | 000,000,000 | ---D | M] -- C:\Windows\Sun
  2141. [2009/07/13 20:36:55 | 000,000,000 | ---D | M] -- C:\Windows\system
  2142. [2012/12/14 22:48:55 | 000,000,000 | ---D | M] -- C:\Windows\System32
  2143. [2012/12/12 01:27:16 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64
  2144. [2009/07/13 22:57:13 | 000,000,000 | ---D | M] -- C:\Windows\TAPI
  2145. [2012/12/11 12:20:39 | 000,000,000 | ---D | M] -- C:\Windows\Tasks
  2146. [2012/12/17 17:36:47 | 000,000,000 | ---D | M] -- C:\Windows\Temp
  2147. [2009/07/13 20:34:33 | 000,000,000 | ---D | M] -- C:\Windows\tracing
  2148. [2011/06/08 16:32:29 | 000,000,000 | ---D | M] -- C:\Windows\twain_32
  2149. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\Vss
  2150. [2009/10/20 21:07:06 | 000,000,000 | ---D | M] -- C:\Windows\Web
  2151. [2012/11/28 15:49:05 | 000,000,000 | ---D | M] -- C:\Windows\winsxs
  2152.  
  2153. [color=#A23BEC]< %windir%\system32\*. >[/color]
  2154. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\0409
  2155. [2010/11/20 21:31:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\AdvancedInstallers
  2156. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\ar-SA
  2157. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\bg-BG
  2158. [2012/02/06 23:24:35 | 000,000,000 | ---D | M] -- C:\Windows\system32\C2MP
  2159. [2009/07/13 20:35:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\catroot
  2160. [2009/07/13 20:35:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\catroot2
  2161. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\com
  2162. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\config
  2163. [2010/11/20 21:31:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\cs-CZ
  2164. [2012/02/06 23:24:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\custom matrices
  2165. [2010/11/20 21:31:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\da-DK
  2166. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\de-DE
  2167. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\Dism
  2168. [2012/06/17 22:28:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\drivers
  2169. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\DriverStore
  2170. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\el-GR
  2171. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\en
  2172. [2012/11/28 00:16:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\en-US
  2173. [2010/11/20 21:31:13 | 000,000,000 | ---D | M] -- C:\Windows\system32\es-ES
  2174. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\et-EE
  2175. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\fi-FI
  2176. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\fr-FR
  2177. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\FxsTmp
  2178. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\GroupPolicy
  2179. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\GroupPolicyUsers
  2180. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\he-IL
  2181. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\hr-HR
  2182. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\hu-HU
  2183. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\icsxml
  2184. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\IME
  2185. [2009/07/13 20:36:55 | 000,000,000 | ---D | M] -- C:\Windows\system32\inetsrv
  2186. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\InstallShield
  2187. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\it-IT
  2188. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ja-JP
  2189. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ko-KR
  2190. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\LogFiles
  2191. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\lt-LT
  2192. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\lv-LV
  2193. [2011/06/02 18:59:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\Macromed
  2194. [2010/11/20 21:31:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\manifeststore
  2195. [2012/11/14 03:32:30 | 000,000,000 | ---D | M] -- C:\Windows\system32\migration
  2196. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\migwiz
  2197. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\Msdtc
  2198. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\MUI
  2199. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\nb-NO
  2200. [2009/07/13 20:34:31 | 000,000,000 | ---D | M] -- C:\Windows\system32\NDF
  2201. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\NetworkList
  2202. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\nl-NL
  2203. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\oobe
  2204. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\pl-PL
  2205. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\Printing_Admin_Scripts
  2206. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt-BR
  2207. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt-PT
  2208. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\ras
  2209. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\Recovery
  2210. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\restore
  2211. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\ro-RO
  2212. [2011/06/02 18:58:06 | 000,000,000 | ---D | M] -- C:\Windows\system32\RTCOM
  2213. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\ru-RU
  2214. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\Setup
  2215. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sk-SK
  2216. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sl-SI
  2217. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\slmgr
  2218. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\Speech
  2219. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\spp
  2220. [2010/11/20 21:31:13 | 000,000,000 | ---D | M] -- C:\Windows\system32\sppui
  2221. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sr-Latn-CS
  2222. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sv-SE
  2223. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\sysprep
  2224. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\Tasks
  2225. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\th-TH
  2226. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\tr-TR
  2227. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\uk-UA
  2228. [2011/06/09 02:00:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\Wat
  2229. [2012/11/28 00:16:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\wbem
  2230. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\WCN
  2231. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\wdi
  2232. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\WindowsPowerShell
  2233. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\winrm
  2234. [2009/07/13 21:20:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-CN
  2235. [2009/07/13 21:20:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-HK
  2236. [2009/07/13 21:20:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-TW
  2237.  
  2238. [color=#A23BEC]< %windir%\sysnative\*. >[/color]
  2239. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\0409
  2240. [2010/11/20 21:30:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\AdvancedInstallers
  2241. [2009/07/13 21:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ar-SA
  2242. [2009/07/13 21:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\bg-BG
  2243. [2011/06/02 20:45:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Boot
  2244. [2012/12/14 04:44:20 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\catroot
  2245. [2012/12/08 05:08:19 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\catroot2
  2246. [2011/06/02 19:08:58 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\CodeIntegrity
  2247. [2010/11/21 01:06:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\com
  2248. [2012/12/17 18:17:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\config
  2249. [2010/11/20 21:30:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\cs-CZ
  2250. [2010/11/20 21:30:34 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\da-DK
  2251. [2009/07/13 21:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\de-DE
  2252. [2010/11/21 01:06:50 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Dism
  2253. [2012/12/14 04:44:20 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\drivers
  2254. [2012/11/28 00:16:08 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\DriverStore
  2255. [2011/06/15 00:30:09 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\DRVSTORE
  2256. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\el-GR
  2257. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\en
  2258. [2012/11/28 00:16:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\en-US
  2259. [2010/11/20 21:30:26 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\es-ES
  2260. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\et-EE
  2261. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\fi-FI
  2262. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\fr-FR
  2263. [2009/07/13 23:09:04 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\FxsTmp
  2264. [2012/06/10 20:34:19 | 000,000,000 | -H-D | M] -- C:\Windows\sysnative\GroupPolicy
  2265. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\GroupPolicyUsers
  2266. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\he-IL
  2267. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\hr-HR
  2268. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\hu-HU
  2269. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ias
  2270. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\icsxml
  2271. [2009/07/13 21:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\IME
  2272. [2009/07/13 20:36:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\inetsrv
  2273. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\it-IT
  2274. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ja-JP
  2275. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ko-KR
  2276. [2011/07/30 15:43:36 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\LogFiles
  2277. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\lt-LT
  2278. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\lv-LV
  2279. [2011/11/12 22:53:31 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Macromed
  2280. [2010/11/20 21:30:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\manifeststore
  2281. [2009/07/13 22:45:42 | 000,000,000 | --SD | M] -- C:\Windows\sysnative\Microsoft
  2282. [2012/11/14 03:32:30 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\migration
  2283. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\migwiz
  2284. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Msdtc
  2285. [2010/11/21 01:06:50 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\MUI
  2286. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\nb-NO
  2287. [2012/11/20 03:43:24 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\NDF
  2288. [2009/07/13 21:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\NetworkList
  2289. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\nl-NL
  2290. [2011/06/08 17:06:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\oem
  2291. [2009/10/20 21:07:04 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\oobe
  2292. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pl-PL
  2293. [2010/11/21 01:06:50 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Printing_Admin_Scripts
  2294. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pt-BR
  2295. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pt-PT
  2296. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ras
  2297. [2011/06/02 20:27:44 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Recovery
  2298. [2011/06/02 19:01:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\restore
  2299. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ro-RO
  2300. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ru-RU
  2301. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Setup
  2302. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sk-SK
  2303. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sl-SI
  2304. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\slmgr
  2305. [2009/07/13 21:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\SMI
  2306. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Speech
  2307. [2009/07/13 22:53:31 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\spool
  2308. [2009/07/13 21:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\spp
  2309. [2010/11/20 21:30:26 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sppui
  2310. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sr-Latn-CS
  2311. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sv-SE
  2312. [2011/06/02 19:42:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sysprep
  2313. [2012/12/14 22:47:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Tasks
  2314. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\th-TH
  2315. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\tr-TR
  2316. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\uk-UA
  2317. [2011/06/09 02:00:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Wat
  2318. [2012/11/28 00:16:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wbem
  2319. [2010/11/21 01:06:50 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WCN
  2320. [2011/09/17 08:25:01 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wdi
  2321. [2009/07/13 23:09:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wfp
  2322. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WinBioDatabase
  2323. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WinBioPlugIns
  2324. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WindowsPowerShell
  2325. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\winevt
  2326. [2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\winrm
  2327. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-CN
  2328. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-HK
  2329. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-TW
  2330.  
  2331. [color=#A23BEC]< %Temp%\smtmp\1\*.* >[/color]
  2332.  
  2333. [color=#A23BEC]< %Temp%\smtmp\2\*.* >[/color]
  2334.  
  2335. [color=#A23BEC]< %Temp%\smtmp\3\*.* >[/color]
  2336.  
  2337. [color=#A23BEC]< %Temp%\smtmp\4\*.* >[/color]
  2338.  
  2339. [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
  2340.  
  2341. [color=#A23BEC]< %systemroot%\syswow64\*.dll /lockedfiles >[/color]
  2342.  
  2343. [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]
  2344.  
  2345. [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /90 >[/color]
  2346.  
  2347. [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
  2348.  
  2349. [color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /90 >[/color]
  2350.  
  2351. [color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /lockedfiles >[/color]
  2352.  
  2353. [color=#A23BEC]< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >[/color]
  2354.  
  2355. [color=#A23BEC]< %systemroot%\*. /rp /s >[/color]
  2356.  
  2357. [color=#A23BEC]< %systemroot%\assembly\tmp\*.* /S /MD5 >[/color]
  2358. [2012/03/25 18:23:24 | 000,329,632 | ---- | M] () MD5=5DDDB6F96BF41B9FE9C4AB0920A0E445 -- C:\Windows\assembly\tmp\003TTJOE\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
  2359. [2012/03/25 17:11:21 | 000,079,744 | ---- | M] () MD5=DC036E7CE4F62CF27D915C3FF3F7DF52 -- C:\Windows\assembly\tmp\023Z04H9\Microsoft.Office.interop.access.dao.dll
  2360. [2012/03/25 17:11:26 | 000,095,312 | ---- | M] () MD5=CDB528E57C8B2F62B773E6224CB811DE -- C:\Windows\assembly\tmp\03QA5IH0\Microsoft.Synchronization.Data.SqlServerCe.dll
  2361. [2012/03/25 13:31:26 | 000,011,656 | ---- | M] () MD5=AF6DCC105912C2A9D514D8941F1F3339 -- C:\Windows\assembly\tmp\05IZLLCO\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
  2362. [2012/03/25 13:31:14 | 000,000,902 | ---- | M] () MD5=6294F9D1634C5110426C7DAFE2F685A0 -- C:\Windows\assembly\tmp\05IZLLCO\S16HN8OK
  2363. [2012/03/25 17:55:51 | 000,011,664 | ---- | M] () MD5=EA39607C138BBADB76883FBCBD264AC4 -- C:\Windows\assembly\tmp\05L1H0HS\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
  2364. [2012/03/25 17:11:25 | 000,071,592 | ---- | M] () MD5=5949DF7B1BF7951C55A31803CD4DC6E2 -- C:\Windows\assembly\tmp\05SI77HI\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
  2365. [2012/03/25 18:24:10 | 000,081,920 | ---- | M] () MD5=A7278626DFE2AAFDDBA6B8B82AA94CEF -- C:\Windows\assembly\tmp\07NMCNAH\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll
  2366. [2012/03/25 17:11:21 | 000,011,656 | ---- | M] () MD5=0C560FE70843B466E8364DD2BC878F97 -- C:\Windows\assembly\tmp\0F17BXXS\Policy.11.0.Microsoft.Office.Interop.Word.dll
  2367. [2012/03/25 17:11:41 | 000,000,896 | ---- | M] () MD5=C018AC4E3EFFBFF5ABB8E5D9608A8762 -- C:\Windows\assembly\tmp\0F17BXXS\TNIJPG5P
  2368. [2012/03/25 13:31:26 | 000,386,944 | ---- | M] () MD5=114882E8C607D45E4769CFFC931CF5BF -- C:\Windows\assembly\tmp\0HEXFUP2\Microsoft.Office.Interop.PowerPoint.dll
  2369. [2012/03/25 13:31:23 | 000,086,016 | ---- | M] () MD5=258BA858D1A21F816B2C7F8B947C9C9D -- C:\Windows\assembly\tmp\0P6E4ONM\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.dll
  2370. [2012/03/25 18:23:49 | 000,045,056 | ---- | M] () MD5=0EBF536E40253273365C3C26A37D57EF -- C:\Windows\assembly\tmp\0QFE99ZJ\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.dll
  2371. [2012/03/25 17:11:37 | 000,110,592 | ---- | M] () MD5=3A717D3B1B2F5921871B0561E71DD4D8 -- C:\Windows\assembly\tmp\0VE3Q41S\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll
  2372. [2012/03/25 18:23:19 | 000,011,656 | ---- | M] () MD5=91EA1E932FDFFD3D8E73324C7E957DF8 -- C:\Windows\assembly\tmp\0XUUYVX8\Policy.11.0.Microsoft.Office.Interop.Access.dll
  2373. [2012/03/25 13:31:07 | 000,011,656 | ---- | M] () MD5=E1362BD9DD9E1351F27CEF1EB8384BA3 -- C:\Windows\assembly\tmp\12FIWUAN\Policy.11.0.Microsoft.Office.Interop.Access.dll
  2374. [2012/03/25 17:56:03 | 000,045,056 | ---- | M] () MD5=DE2E0DF8A33183053017C1724E30E5DC -- C:\Windows\assembly\tmp\17J6WFIV\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.dll
  2375. [2012/03/25 13:31:14 | 000,011,664 | ---- | M] () MD5=7511DBE6D0B0EA4B0383F137AEC72D55 -- C:\Windows\assembly\tmp\19FKROOS\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
  2376. [2012/03/25 17:11:11 | 000,011,664 | ---- | M] () MD5=B2E5D2F672B638CC9FEE5EFDFB09B70C -- C:\Windows\assembly\tmp\1OIGG33I\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.dll
  2377. [2012/03/25 18:23:49 | 000,038,808 | ---- | M] () MD5=907114FE32F4DFB0C5EDA360BE0740C7 -- C:\Windows\assembly\tmp\1RA7MTET\Microsoft.VisualStudio.Tools.Applications.Contract.dll
  2378. [2012/03/25 18:24:06 | 001,689,472 | ---- | M] () MD5=8EC5FD93F9A500722C02D6D8A9165E3B -- C:\Windows\assembly\tmp\1XOV50WC\Microsoft.Office.BusinessApplications.SyncServices.dll
  2379. [2012/03/25 18:23:42 | 000,011,664 | ---- | M] () MD5=89C5F582D77DDDAA775DC7629C35C592 -- C:\Windows\assembly\tmp\21IS8TS6\Policy.12.0.Microsoft.Office.Interop.Publisher.dll
  2380. [2012/03/25 17:55:55 | 000,051,072 | ---- | M] () MD5=7133E8677E11DC09D12DAB476C068DE1 -- C:\Windows\assembly\tmp\21ZGQXLH\Microsoft.Office.BusinessApplications.SyncServices.Intl.dll
  2381. [2012/03/25 17:11:09 | 000,077,824 | ---- | M] () MD5=41D096C3E61378485D7B8AAFF00C245D -- C:\Windows\assembly\tmp\22HYB4VV\Microsoft.Office.Tools.Outlook.v9.0.dll
  2382. [2012/03/25 18:23:24 | 000,370,608 | ---- | M] () MD5=99D8B5B9A5D631608242BAA23249B2E1 -- C:\Windows\assembly\tmp\29KAF8NP\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
  2383. [2012/03/25 17:55:45 | 000,286,720 | ---- | M] () MD5=F0DA890A63403E2010788FDBC1801FA7 -- C:\Windows\assembly\tmp\2EK5FXGS\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll
  2384. [2012/03/25 18:23:39 | 000,040,960 | ---- | M] () MD5=8C4B96CB6644CC8914C44EA2193959B0 -- C:\Windows\assembly\tmp\2HGTD9E8\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll
  2385. [2012/03/25 17:55:47 | 000,011,664 | ---- | M] () MD5=0826CD2CA41B5ACD3DA5164FEEA7022D -- C:\Windows\assembly\tmp\2HRCJ5SQ\policy.12.0.Microsoft.Office.InfoPath.FormControl.dll
  2386. [2012/03/25 17:56:07 | 000,000,912 | ---- | M] () MD5=8178E3FB89E1EE2F91F678D5E13367BF -- C:\Windows\assembly\tmp\2HRCJ5SQ\TGQWDN1R
  2387. [2012/03/25 17:11:13 | 000,011,664 | ---- | M] () MD5=D6971FC530C07B6B7DFD3AC9DF8695EE -- C:\Windows\assembly\tmp\2HTDP5Z5\Policy.12.0.Microsoft.Office.InfoPath.Permission.dll
  2388. [2012/03/25 18:23:43 | 000,011,656 | ---- | M] () MD5=A0925184CB51086A5A8F28D6B7597EDF -- C:\Windows\assembly\tmp\2JU3XEQA\Policy.12.0.Microsoft.Office.Interop.Excel.dll
  2389. [2012/03/25 17:11:26 | 000,131,072 | ---- | M] () MD5=B169C95A3BEFA21EBA58D21992EB6A9C -- C:\Windows\assembly\tmp\2LV5PKA8\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll
  2390. [2012/03/25 17:55:39 | 000,011,664 | ---- | M] () MD5=84C6457AF1FD3600FCEF8531A9CD325D -- C:\Windows\assembly\tmp\2LYQUESY\Policy.12.0.Microsoft.Office.Interop.Access.Dao.dll
  2391. [2012/03/25 17:55:46 | 000,115,744 | ---- | M] () MD5=DA5EE020BEF41DC95C3532CBAA1EA8F4 -- C:\Windows\assembly\tmp\2MCF1QDY\Microsoft.Synchronization.Data.Server.dll
  2392. [2012/03/25 13:31:22 | 000,212,992 | ---- | M] () MD5=4D9048A89ADEC6A302273592DC1E53F7 -- C:\Windows\assembly\tmp\2OBJ3QK1\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll
  2393. [2012/03/25 13:31:10 | 000,149,368 | ---- | M] () MD5=EB2CFA115D1D16117F7EF8A253EF53DC -- C:\Windows\assembly\tmp\2ROWVZWN\Microsoft.Office.Interop.Graph.dll
  2394. [2012/03/25 17:56:03 | 000,095,312 | ---- | M] () MD5=CDB528E57C8B2F62B773E6224CB811DE -- C:\Windows\assembly\tmp\2SWCJFCF\Microsoft.Synchronization.Data.SqlServerCe.dll
  2395. [2012/03/25 17:55:45 | 000,176,128 | ---- | M] () MD5=A41B86118BD728EF04067CCFF89006EA -- C:\Windows\assembly\tmp\2UZJFVUB\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll
  2396. [2012/03/25 18:24:11 | 000,053,248 | ---- | M] () MD5=07E7E7818586A3B3F1EC50E5E2511FC0 -- C:\Windows\assembly\tmp\2VLSJ0GB\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.dll
  2397. [2012/03/25 18:24:08 | 000,427,904 | ---- | M] () MD5=01223E1CC857F8399368D8A61BAF24B1 -- C:\Windows\assembly\tmp\2ZL9KCVR\Microsoft.Office.BusinessApplications.Tools.dll
  2398. [2012/03/25 17:55:47 | 000,546,704 | ---- | M] () MD5=46B44E2EC2A58FD51278CAE5CE1AF801 -- C:\Windows\assembly\tmp\30SJQYDQ\Microsoft.Office.Infopath.Client.Internal.Host.dll
  2399. [2012/03/25 18:23:49 | 000,143,360 | ---- | M] () MD5=BF1B6B22209E8126A184BFA2C4FB49BE -- C:\Windows\assembly\tmp\35CTW89N\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll
  2400. [2012/03/25 17:11:29 | 000,030,608 | ---- | M] () MD5=F9260C73E50DF7670237024883F0AF55 -- C:\Windows\assembly\tmp\3D412KA8\IPDMCTRL.DLL
  2401. [2012/03/25 17:11:32 | 000,513,920 | ---- | M] () MD5=9A1AD8C3023D6D56B685C9694E2068E9 -- C:\Windows\assembly\tmp\3E0WIQOA\Microsoft.SharePoint.BusinessData.Administration.Client.dll
  2402. [2012/03/25 18:23:39 | 000,051,072 | ---- | M] () MD5=7133E8677E11DC09D12DAB476C068DE1 -- C:\Windows\assembly\tmp\3E7UHCFF\Microsoft.Office.BusinessApplications.SyncServices.Intl.dll
  2403. [2012/03/25 17:56:02 | 000,143,360 | ---- | M] () MD5=BF1B6B22209E8126A184BFA2C4FB49BE -- C:\Windows\assembly\tmp\3KD3EDIO\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll
  2404. [2012/03/25 17:56:15 | 000,427,904 | ---- | M] () MD5=01223E1CC857F8399368D8A61BAF24B1 -- C:\Windows\assembly\tmp\3LMVDC6X\Microsoft.Office.BusinessApplications.Tools.dll
  2405. [2012/03/25 17:55:56 | 000,011,104 | ---- | M] () MD5=BF675629E050915C92D6D66F72B2AEB6 -- C:\Windows\assembly\tmp\3PSQ4GZA\Policy.12.0.Office.dll
  2406. [2012/03/25 17:56:18 | 000,000,850 | ---- | M] () MD5=E387AFF00A5E533338760D8E78ED8AFB -- C:\Windows\assembly\tmp\3PSQ4GZA\QSRLTLGE
  2407. [2012/03/25 17:11:25 | 000,104,368 | ---- | M] () MD5=9C7403906909E432EA6A2511D1B3CDF2 -- C:\Windows\assembly\tmp\3SJU3H3N\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
  2408. [2012/03/25 17:56:13 | 000,567,168 | ---- | M] () MD5=C5AAB920018ADA7000118F631171AF3F -- C:\Windows\assembly\tmp\3XG3Q472\Microsoft.Office.BusinessApplications.Runtime.dll
  2409. [2012/03/25 17:11:04 | 000,011,656 | ---- | M] () MD5=E922699AE3647B38A0D3E3982043A9F8 -- C:\Windows\assembly\tmp\3YQUT1D2\Policy.12.0.Microsoft.Office.Interop.Access.dll
  2410. [2012/03/25 17:56:03 | 000,045,056 | ---- | M] () MD5=0EBF536E40253273365C3C26A37D57EF -- C:\Windows\assembly\tmp\445UUOEI\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.dll
  2411. [2012/03/25 17:11:15 | 000,206,720 | ---- | M] () MD5=D42F1D676FE013CB02087394B57EAA16 -- C:\Windows\assembly\tmp\48AHJK9N\Microsoft.SharePoint.BusinessData.Administration.Client.Intl.dll
  2412. [2012/03/25 13:31:07 | 000,011,656 | ---- | M] () MD5=BCB3CF378EA51803300E39671B78B6B3 -- C:\Windows\assembly\tmp\48HUF063\Policy.12.0.Microsoft.Office.Interop.Access.dll
  2413. [2012/03/25 13:31:18 | 000,000,900 | ---- | M] () MD5=6E5E053BA637800ECBBCCDBB3C046104 -- C:\Windows\assembly\tmp\48HUF063\W7U954TP
  2414. [2012/03/25 17:11:19 | 000,025,480 | ---- | M] () MD5=95ADBFBDC616027379E0F9DCC8E35370 -- C:\Windows\assembly\tmp\4DETD2GC\Microsoft.Office.Interop.OutlookViewCtl.dll
  2415. [2012/03/25 18:24:13 | 000,013,312 | ---- | M] () MD5=D80746B2F94A3A28E380735D4B8A9EA3 -- C:\Windows\assembly\tmp\4DZFBF0P\Microsoft.stdformat.dll
  2416. [2012/03/25 17:55:52 | 000,956,288 | ---- | M] () MD5=5F20CC1396134D409FB641CC6F78623C -- C:\Windows\assembly\tmp\4GAUXCAA\microsoft.office.businessdata.dll
  2417. [2012/03/25 17:55:45 | 000,385,024 | ---- | M] () MD5=6F6C2FEB15AFB745C8BF7D0277D2DBBF -- C:\Windows\assembly\tmp\4J86TERB\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll
  2418. [2012/03/25 17:55:57 | 000,011,664 | ---- | M] () MD5=761343B53E834E3587E7517D37FE9D56 -- C:\Windows\assembly\tmp\4JYL6VN0\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
  2419. [2012/03/25 17:11:37 | 008,007,680 | ---- | M] () MD5=5440EE9CD44616D60CDE57EBDB286E95 -- C:\Windows\assembly\tmp\4UK1F9CV\Microsoft.mshtml.dll
  2420. [2012/03/25 17:55:45 | 000,370,608 | ---- | M] () MD5=99D8B5B9A5D631608242BAA23249B2E1 -- C:\Windows\assembly\tmp\4WRVCHQG\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
  2421. [2012/03/25 17:56:02 | 000,049,152 | ---- | M] () MD5=77249A017C234EC21BC60DABB8515896 -- C:\Windows\assembly\tmp\4YR9TCMF\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll
  2422. [2012/03/25 17:55:58 | 000,063,336 | ---- | M] () MD5=A8873670CF41B61641920860E49EE328 -- C:\Windows\assembly\tmp\50FRSUV9\Microsoft.Vbe.Interop.dll
  2423. [2012/03/25 13:31:23 | 000,011,656 | ---- | M] () MD5=7E9ABF813463163E3575E5C92BE71A8D -- C:\Windows\assembly\tmp\58SPR9GF\Policy.11.0.Microsoft.Office.Interop.Graph.dll
  2424. [2012/03/25 13:31:12 | 000,053,248 | ---- | M] () MD5=07E7E7818586A3B3F1EC50E5E2511FC0 -- C:\Windows\assembly\tmp\5A7VI0OQ\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.dll
  2425. [2012/03/25 17:55:57 | 000,046,968 | ---- | M] () MD5=475A31C143A723A68B3CBDDB91142650 -- C:\Windows\assembly\tmp\5DEVHREE\Microsoft.Office.Interop.OneNote.dll
  2426. [2012/03/25 18:23:25 | 000,176,128 | ---- | M] () MD5=A41B86118BD728EF04067CCFF89006EA -- C:\Windows\assembly\tmp\5DY1R3UK\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll
  2427. [2012/03/25 13:31:24 | 000,206,720 | ---- | M] () MD5=ADDDFB6CE545CF14FA57039B75C22589 -- C:\Windows\assembly\tmp\5E0EEBTR\microsoft.office.businessdata.intl.dll
  2428. [2012/03/25 17:11:21 | 000,163,248 | ---- | M] () MD5=595C46715D74E357B7B2E43CE732CE89 -- C:\Windows\assembly\tmp\5EPQZ3OU\Microsoft.Office.Access.BusinessDataCatalog.DLL
  2429. [2012/03/25 13:31:14 | 000,011,664 | ---- | M] () MD5=C8239B3E66BDB63D8A1938FE7B4DCE20 -- C:\Windows\assembly\tmp\5LNMD4LG\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
  2430. [2012/03/25 18:23:22 | 000,028,672 | ---- | M] () MD5=4C0E0A5A2D17F67E7DA61822EAE226F4 -- C:\Windows\assembly\tmp\5PDX3H1H\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll
  2431. [2012/03/25 13:31:13 | 000,011,672 | ---- | M] () MD5=ECC242CB7160EEB8E1885E200449F65E -- C:\Windows\assembly\tmp\5S4KMW97\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2432. [2012/03/25 13:31:26 | 000,000,916 | ---- | M] () MD5=30336C1CC94EDD19CDFB724E3A5AF015 -- C:\Windows\assembly\tmp\5S4KMW97\Q65F8VXQ
  2433. [2012/03/25 18:24:19 | 000,011,672 | ---- | M] () MD5=6B9BC53BC0A44CABB1F7FED4B0208D58 -- C:\Windows\assembly\tmp\5V5UGFOP\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2434. [2012/03/25 18:23:49 | 000,131,072 | ---- | M] () MD5=B169C95A3BEFA21EBA58D21992EB6A9C -- C:\Windows\assembly\tmp\5WUBQDV8\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll
  2435. [2012/03/25 17:55:46 | 000,149,368 | ---- | M] () MD5=83018ECFFD3DB34BF89C0CA0D40A214C -- C:\Windows\assembly\tmp\5XXB97E4\Microsoft.Office.Interop.Graph.dll
  2436. [2012/03/25 18:23:39 | 000,045,056 | ---- | M] () MD5=8510E5F664F1C9136E73A13B0C8E5357 -- C:\Windows\assembly\tmp\5ZYFRH0B\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll
  2437. [2012/03/25 18:23:19 | 000,011,664 | ---- | M] () MD5=84C6457AF1FD3600FCEF8531A9CD325D -- C:\Windows\assembly\tmp\61RDKA6P\Policy.12.0.Microsoft.Office.Interop.Access.Dao.dll
  2438. [2012/03/25 17:55:45 | 000,212,992 | ---- | M] () MD5=4D9048A89ADEC6A302273592DC1E53F7 -- C:\Windows\assembly\tmp\61Z0IB3C\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll
  2439. [2012/03/25 13:31:12 | 000,081,920 | ---- | M] () MD5=A7278626DFE2AAFDDBA6B8B82AA94CEF -- C:\Windows\assembly\tmp\64KJ671I\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll
  2440. [2012/03/25 17:11:34 | 000,096,128 | ---- | M] () MD5=DEC87A5053CE125612D0ECD22CE8A7CC -- C:\Windows\assembly\tmp\67KYGCRD\microsoft.office.businessapplications.diagnostics.dll
  2441. [2012/03/25 17:55:55 | 000,169,856 | ---- | M] () MD5=3B7CC62A9BD6F75BD6636B6E777F139C -- C:\Windows\assembly\tmp\68284E99\Microsoft.Office.BusinessApplications.Tools.Intl.dll
  2442. [2012/03/25 17:56:17 | 000,110,592 | ---- | M] () MD5=3A717D3B1B2F5921871B0561E71DD4D8 -- C:\Windows\assembly\tmp\6AH83Q06\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll
  2443. [2012/03/25 18:23:42 | 000,063,336 | ---- | M] () MD5=A8873670CF41B61641920860E49EE328 -- C:\Windows\assembly\tmp\6B201TY3\Microsoft.Vbe.Interop.dll
  2444. [2012/03/25 17:11:39 | 000,972,664 | ---- | M] () MD5=D50EA922CCA0943744AB75E016BDE25E -- C:\Windows\assembly\tmp\6CPNQ3SU\Microsoft.Office.Interop.Outlook.dll
  2445. [2012/03/25 18:23:30 | 000,161,656 | ---- | M] () MD5=042463EB8E2A6FADFFCE9AD2D0046BF9 -- C:\Windows\assembly\tmp\6DPABR1U\Microsoft.Office.Interop.InfoPath.dll
  2446. [2012/03/25 17:56:02 | 001,550,200 | ---- | M] () MD5=E8F52D3DB6ED411C4274FBB93EB2C8B6 -- C:\Windows\assembly\tmp\6FMTCQ96\Microsoft.Office.Interop.Excel.dll
  2447. [2012/03/25 17:56:09 | 000,011,664 | ---- | M] () MD5=B53912ED4735CF05D504D4AEA025FFE7 -- C:\Windows\assembly\tmp\6GBZN412\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
  2448. [2012/03/25 17:55:49 | 000,000,904 | ---- | M] () MD5=DCADD75D7AF7337A635A78D7C7F20D9A -- C:\Windows\assembly\tmp\6GBZN412\UKT7ZIOY
  2449. [2012/03/25 17:11:17 | 000,036,864 | ---- | M] () MD5=0C5700ED83D92BBB5E6F70AB89C26F04 -- C:\Windows\assembly\tmp\6QL79K4W\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll
  2450. [2012/03/25 13:31:13 | 000,094,208 | ---- | M] () MD5=CF53CB86A8D49F5CCA58D8FF8AE246A9 -- C:\Windows\assembly\tmp\6RBBWUBN\Microsoft.Office.Tools.v9.0.dll
  2451. [2012/03/25 17:11:25 | 000,038,808 | ---- | M] () MD5=907114FE32F4DFB0C5EDA360BE0740C7 -- C:\Windows\assembly\tmp\6SO2SUO3\Microsoft.VisualStudio.Tools.Applications.Contract.dll
  2452. [2012/03/25 18:23:32 | 000,087,936 | ---- | M] () MD5=171E5A171FADDCA58EF97EBD26837863 -- C:\Windows\assembly\tmp\6VW300VA\Microsoft.Office.Interop.InfoPath.Xml.dll
  2453. [2012/03/25 17:56:20 | 000,016,384 | ---- | M] () MD5=E1EEB7E26AB04075EECC7275239B20B3 -- C:\Windows\assembly\tmp\6VYGYSVJ\stdole.dll
  2454. [2012/03/25 17:11:37 | 000,094,208 | ---- | M] () MD5=CF53CB86A8D49F5CCA58D8FF8AE246A9 -- C:\Windows\assembly\tmp\6Z19T4MW\Microsoft.Office.Tools.v9.0.dll
  2455. [2012/03/25 17:55:58 | 000,011,656 | ---- | M] () MD5=A34037B99EBD76FA30D73E6C8503E8BA -- C:\Windows\assembly\tmp\6Z1V7A07\Policy.12.0.Microsoft.Office.Interop.Word.dll
  2456. [2012/03/25 17:56:21 | 000,000,896 | ---- | M] () MD5=F3D871161A09684A2930117D6BDAAF91 -- C:\Windows\assembly\tmp\6Z1V7A07\TA6VQQI1
  2457. [2012/03/25 18:23:56 | 000,011,664 | ---- | M] () MD5=B53912ED4735CF05D504D4AEA025FFE7 -- C:\Windows\assembly\tmp\72FJS0CF\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
  2458. [2012/03/25 18:23:32 | 000,000,904 | ---- | M] () MD5=DCADD75D7AF7337A635A78D7C7F20D9A -- C:\Windows\assembly\tmp\72FJS0CF\UW8C4ZUE
  2459. [2012/03/25 18:23:24 | 000,299,008 | ---- | M] () MD5=8447FB78623AACCCFC609F01D1723935 -- C:\Windows\assembly\tmp\734VJRE9\Microsoft.Office.Tools.Word.v9.0.dll
  2460. [2012/03/25 18:23:49 | 000,356,352 | ---- | M] () MD5=0A8FCA67378EC92E2F304E6750DD9FD1 -- C:\Windows\assembly\tmp\73I7H7QA\Microsoft.Office.Tools.Common.v9.0.dll
  2461. [2012/03/25 17:11:25 | 001,550,200 | ---- | M] () MD5=E8F52D3DB6ED411C4274FBB93EB2C8B6 -- C:\Windows\assembly\tmp\766BUPVD\Microsoft.Office.Interop.Excel.dll
  2462. [2012/03/25 17:11:34 | 000,206,720 | ---- | M] () MD5=E1C01B2AF154DE8C5FBF322C22929D5B -- C:\Windows\assembly\tmp\7C6F5Q33\microsoft.office.businessdata.intl.dll
  2463. [2012/03/25 17:55:57 | 000,011,656 | ---- | M] () MD5=812A8B0FE904EEF755646C5196A858C6 -- C:\Windows\assembly\tmp\7DBOEVD5\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
  2464. [2012/03/25 17:56:17 | 000,011,664 | ---- | M] () MD5=F94B126921F404EC30FACED9C5D6B890 -- C:\Windows\assembly\tmp\7DX70GT3\Policy.12.0.Microsoft.Office.Interop.SmartTag.dll
  2465. [2012/03/25 17:55:45 | 000,210,848 | ---- | M] () MD5=2E57C4C703D80B484CDDE2C13BA27BF1 -- C:\Windows\assembly\tmp\7FGU2MA7\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
  2466. [2012/03/25 18:23:30 | 000,014,224 | ---- | M] () MD5=E86AE27B4D35D9E7E9AA276BD84019AB -- C:\Windows\assembly\tmp\7JK10MJ1\Microsoft.Office.InfoPath.Permission.dll
  2467. [2012/03/25 18:23:58 | 000,513,920 | ---- | M] () MD5=9A1AD8C3023D6D56B685C9694E2068E9 -- C:\Windows\assembly\tmp\7LEX3LIW\Microsoft.SharePoint.BusinessData.Administration.Client.dll
  2468. [2012/03/25 13:31:14 | 000,011,664 | ---- | M] () MD5=A611CBFFCAA65D8BF465A15F9693679F -- C:\Windows\assembly\tmp\7MV4725Q\Policy.12.0.Microsoft.Office.Interop.PowerPoint.dll
  2469. [2012/03/25 17:11:10 | 000,176,128 | ---- | M] () MD5=A41B86118BD728EF04067CCFF89006EA -- C:\Windows\assembly\tmp\7OXJ0X92\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll
  2470. [2012/03/25 18:23:51 | 000,011,656 | ---- | M] () MD5=71D8A3D576F2E236B91D30608B887853 -- C:\Windows\assembly\tmp\7QK4TYKP\Policy.12.0.Microsoft.Office.Interop.Graph.dll
  2471. [2012/03/25 18:23:51 | 000,011,656 | ---- | M] () MD5=272324C3519292E26C20BCA9ADD43864 -- C:\Windows\assembly\tmp\7TJ9YHSG\Policy.11.0.Microsoft.Office.Interop.Graph.dll
  2472. [2012/03/25 17:55:54 | 000,079,744 | ---- | M] () MD5=F883843E31FAE60536A76DE8908DA097 -- C:\Windows\assembly\tmp\7Y71YGC3\Microsoft.Office.BusinessApplications.RuntimeUi.Intl.dll
  2473. [2012/03/25 18:23:39 | 000,169,856 | ---- | M] () MD5=3B7CC62A9BD6F75BD6636B6E777F139C -- C:\Windows\assembly\tmp\85QIW3DW\Microsoft.Office.BusinessApplications.Tools.Intl.dll
  2474. [2012/03/25 18:24:15 | 000,011,664 | ---- | M] () MD5=F94B126921F404EC30FACED9C5D6B890 -- C:\Windows\assembly\tmp\89LRSU7K\Policy.12.0.Microsoft.Office.Interop.SmartTag.dll
  2475. [2012/03/25 13:31:13 | 000,011,672 | ---- | M] () MD5=A1B80AAF87F8EBC0DF0857BCDF48F4BC -- C:\Windows\assembly\tmp\8A2V8Q6R\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2476. [2012/03/25 13:31:26 | 000,000,916 | ---- | M] () MD5=333236C30617B03AE650230780E21EAA -- C:\Windows\assembly\tmp\8A2V8Q6R\TZNHGHAU
  2477. [2012/03/25 17:11:29 | 000,042,880 | ---- | M] () MD5=CF202A917D36E48FAD6F57115D643536 -- C:\Windows\assembly\tmp\8ARHF9J1\microsoft.office.infopath.formcontrol.dll
  2478. [2012/03/25 13:31:24 | 000,065,536 | ---- | M] () MD5=4167FAFE231BE780D7158B0A7E5D337D -- C:\Windows\assembly\tmp\8F6GQ1K6\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.dll
  2479. [2012/03/25 18:23:48 | 000,438,272 | ---- | M] () MD5=409B1D3ED9ECAAB3D7DA66A83E1161A9 -- C:\Windows\assembly\tmp\8HG9K78W\Microsoft.Office.Tools.Excel.v9.0.dll
  2480. [2012/03/25 17:11:19 | 000,046,968 | ---- | M] () MD5=475A31C143A723A68B3CBDDB91142650 -- C:\Windows\assembly\tmp\8HZDF1IL\Microsoft.Office.Interop.OneNote.dll
  2481. [2012/03/25 17:11:19 | 000,011,664 | ---- | M] () MD5=31237BBFA5730B335B37A15D71623022 -- C:\Windows\assembly\tmp\8KHUQ1H4\Policy.12.0.Microsoft.Office.Interop.PowerPoint.dll
  2482. [2012/03/25 17:11:39 | 000,000,908 | ---- | M] () MD5=8199AE1C79C0443071D0352D70CE4DAA -- C:\Windows\assembly\tmp\8KHUQ1H4\TLWWAIB6
  2483. [2012/03/25 18:23:23 | 000,212,992 | ---- | M] () MD5=4D9048A89ADEC6A302273592DC1E53F7 -- C:\Windows\assembly\tmp\8NTYX0LP\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll
  2484. [2012/03/25 17:55:39 | 000,011,656 | ---- | M] () MD5=E922699AE3647B38A0D3E3982043A9F8 -- C:\Windows\assembly\tmp\8OJCNTFF\Policy.12.0.Microsoft.Office.Interop.Access.dll
  2485. [2012/03/25 18:23:40 | 000,036,864 | ---- | M] () MD5=0C5700ED83D92BBB5E6F70AB89C26F04 -- C:\Windows\assembly\tmp\8TYRVMOI\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll
  2486. [2012/03/25 13:31:12 | 000,036,864 | ---- | M] () MD5=AD54FE98130FA82E5A75A1906F7F14A9 -- C:\Windows\assembly\tmp\8ULFOEAR\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll
  2487. [2012/03/25 17:56:17 | 000,065,536 | ---- | M] () MD5=81ADD0B914DBF2C534BBAB1F3F4D78FF -- C:\Windows\assembly\tmp\8UU6T5H8\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.dll
  2488. [2012/03/25 17:11:20 | 000,063,336 | ---- | M] () MD5=A8873670CF41B61641920860E49EE328 -- C:\Windows\assembly\tmp\8VC4EVAP\Microsoft.Vbe.Interop.dll
  2489. [2012/03/25 17:55:59 | 001,857,400 | ---- | M] () MD5=14788241B6D6540344FE951C0607B331 -- C:\Windows\assembly\tmp\8VMKM5DI\Microsoft.Office.Interop.Access.dll
  2490. [2012/03/25 17:56:13 | 000,206,720 | ---- | M] () MD5=E1C01B2AF154DE8C5FBF322C22929D5B -- C:\Windows\assembly\tmp\8W3SPEMR\microsoft.office.businessdata.intl.dll
  2491. [2012/03/25 17:11:25 | 000,143,360 | ---- | M] () MD5=BF1B6B22209E8126A184BFA2C4FB49BE -- C:\Windows\assembly\tmp\93O8EN95\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll
  2492. [2012/03/25 13:31:16 | 000,063,336 | ---- | M] () MD5=572E69066CE577FBF849E8D715CE0B82 -- C:\Windows\assembly\tmp\9ALWYPD5\Microsoft.Vbe.Interop.dll
  2493. [2012/03/25 17:55:46 | 000,271,440 | ---- | M] () MD5=EE63BE840C77AA9DDDD5BF66BCF98F87 -- C:\Windows\assembly\tmp\9CIEVWXX\System.Data.SqlServerCe.dll
  2494. [2012/03/25 13:31:24 | 000,045,056 | ---- | M] () MD5=8EE7C7AA4D06207C01C0461A0784FF6F -- C:\Windows\assembly\tmp\9KW43B7E\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll
  2495. [2012/03/25 17:11:09 | 000,028,672 | ---- | M] () MD5=4C0E0A5A2D17F67E7DA61822EAE226F4 -- C:\Windows\assembly\tmp\9LOMJ9EQ\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll
  2496. [2012/03/25 17:11:37 | 000,013,312 | ---- | M] () MD5=D80746B2F94A3A28E380735D4B8A9EA3 -- C:\Windows\assembly\tmp\9LSBGDF2\Microsoft.stdformat.dll
  2497. [2012/03/25 17:11:17 | 000,045,056 | ---- | M] () MD5=8EE7C7AA4D06207C01C0461A0784FF6F -- C:\Windows\assembly\tmp\9MYJTSQ5\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll
  2498. [2012/03/25 17:11:37 | 000,004,096 | ---- | M] () MD5=AAA2E20588E154A10747BF1B31B55125 -- C:\Windows\assembly\tmp\9N38IAOB\msdatasrc.dll
  2499. [2012/03/25 17:56:15 | 000,081,920 | ---- | M] () MD5=A7278626DFE2AAFDDBA6B8B82AA94CEF -- C:\Windows\assembly\tmp\9OG67635\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll
  2500. [2012/03/25 13:31:12 | 000,004,096 | ---- | M] () MD5=AAA2E20588E154A10747BF1B31B55125 -- C:\Windows\assembly\tmp\9PPJSSZI\msdatasrc.dll
  2501. [2012/03/25 17:11:15 | 000,011,664 | ---- | M] () MD5=B4285A86FC714CC0574B9070FB0E511F -- C:\Windows\assembly\tmp\9TZ5U1QV\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.dll
  2502. [2012/03/25 17:11:31 | 000,011,664 | ---- | M] () MD5=B53912ED4735CF05D504D4AEA025FFE7 -- C:\Windows\assembly\tmp\9W8XFHH4\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
  2503. [2012/03/25 17:56:07 | 000,030,608 | ---- | M] () MD5=F9260C73E50DF7670237024883F0AF55 -- C:\Windows\assembly\tmp\9Y36O6PU\IPDMCTRL.DLL
  2504. [2012/03/25 17:11:39 | 000,247,680 | ---- | M] () MD5=DFC7276D34F4B66518A32F9AF48BA3F9 -- C:\Windows\assembly\tmp\A1MLQEND\Microsoft.Office.Interop.Publisher.dll
  2505. [2012/03/25 18:23:48 | 001,550,200 | ---- | M] () MD5=E8F52D3DB6ED411C4274FBB93EB2C8B6 -- C:\Windows\assembly\tmp\A6AGBXM3\Microsoft.Office.Interop.Excel.dll
  2506. [2012/03/25 17:11:17 | 000,079,744 | ---- | M] () MD5=F883843E31FAE60536A76DE8908DA097 -- C:\Windows\assembly\tmp\A6PLR0ZR\Microsoft.Office.BusinessApplications.RuntimeUi.Intl.dll
  2507. [2012/03/25 17:55:47 | 000,161,656 | ---- | M] () MD5=042463EB8E2A6FADFFCE9AD2D0046BF9 -- C:\Windows\assembly\tmp\A8Z4BZDZ\Microsoft.Office.Interop.InfoPath.dll
  2508. [2012/03/25 18:23:54 | 000,140,200 | ---- | M] () MD5=07C649EDCCEB97CBAF976053D2392CC8 -- C:\Windows\assembly\tmp\AKC2D5MV\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
  2509. [2012/03/25 17:11:26 | 000,011,656 | ---- | M] () MD5=272324C3519292E26C20BCA9ADD43864 -- C:\Windows\assembly\tmp\AKX3QFPF\Policy.11.0.Microsoft.Office.Interop.Graph.dll
  2510. [2012/03/25 18:24:20 | 000,972,664 | ---- | M] () MD5=D50EA922CCA0943744AB75E016BDE25E -- C:\Windows\assembly\tmp\ANKRHFZA\Microsoft.Office.Interop.Outlook.dll
  2511. [2012/03/25 13:31:12 | 000,229,376 | ---- | M] () MD5=FDA48714F6A291E25A1A219E89D59D9B -- C:\Windows\assembly\tmp\APP9RMWR\MSCOMCTL.DLL
  2512. [2012/03/25 18:24:11 | 008,007,680 | ---- | M] () MD5=5440EE9CD44616D60CDE57EBDB286E95 -- C:\Windows\assembly\tmp\ARLMO8QM\Microsoft.mshtml.dll
  2513. [2012/03/25 18:23:30 | 000,011,664 | ---- | M] () MD5=B2E5D2F672B638CC9FEE5EFDFB09B70C -- C:\Windows\assembly\tmp\ASPML6AC\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.dll
  2514. [2012/03/25 17:11:40 | 000,011,640 | ---- | M] () MD5=7063FF7154582442F6F533F12B3F0F20 -- C:\Windows\assembly\tmp\AV5LLDZC\Policy.12.0.Microsoft.Vbe.Interop.dll
  2515. [2012/03/25 17:11:20 | 000,000,880 | ---- | M] () MD5=C96C6F48979A5F9F131AA9FCB228B0D1 -- C:\Windows\assembly\tmp\AV5LLDZC\SYR474SA
  2516. [2012/03/25 17:11:36 | 000,665,472 | ---- | M] () MD5=4BD743C646EE2F47DDFEEAC9393E7033 -- C:\Windows\assembly\tmp\AY1ZGBI3\Microsoft.Office.BusinessApplications.RuntimeUi.dll
  2517. [2012/03/25 17:11:21 | 000,110,592 | ---- | M] () MD5=7ECB661F50F34A941A44DAC7241F7D08 -- C:\Windows\assembly\tmp\B2MT6AAW\adodb.dll
  2518. [2012/03/25 13:31:23 | 000,299,008 | ---- | M] () MD5=8447FB78623AACCCFC609F01D1723935 -- C:\Windows\assembly\tmp\B7WTBOPZ\Microsoft.Office.Tools.Word.v9.0.dll
  2519. [2012/03/25 17:11:10 | 000,286,720 | ---- | M] () MD5=F0DA890A63403E2010788FDBC1801FA7 -- C:\Windows\assembly\tmp\BA3TNYMA\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll
  2520. [2012/03/25 17:55:45 | 000,077,824 | ---- | M] () MD5=41D096C3E61378485D7B8AAFF00C245D -- C:\Windows\assembly\tmp\BAB7IN6Q\Microsoft.Office.Tools.Outlook.v9.0.dll
  2521. [2012/03/25 17:55:59 | 000,011,656 | ---- | M] () MD5=A0925184CB51086A5A8F28D6B7597EDF -- C:\Windows\assembly\tmp\BBVDM2UD\Policy.12.0.Microsoft.Office.Interop.Excel.dll
  2522. [2012/03/25 17:11:38 | 000,011,672 | ---- | M] () MD5=6B9BC53BC0A44CABB1F7FED4B0208D58 -- C:\Windows\assembly\tmp\BCN3PSD9\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2523. [2012/03/25 18:24:19 | 000,011,672 | ---- | M] () MD5=45EC3053444CA47BB540E7036F50C0BA -- C:\Windows\assembly\tmp\BCNCF1G5\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2524. [2012/03/25 18:23:40 | 000,019,320 | ---- | M] () MD5=2320EAD15BF728EC8FF5C9075B4A7B1F -- C:\Windows\assembly\tmp\BDJV18CB\Microsoft.Office.Interop.SmartTag.dll
  2525. [2012/03/25 17:56:03 | 000,131,072 | ---- | M] () MD5=B169C95A3BEFA21EBA58D21992EB6A9C -- C:\Windows\assembly\tmp\BFXLHV9K\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll
  2526. [2012/03/25 18:23:43 | 000,011,656 | ---- | M] () MD5=A34037B99EBD76FA30D73E6C8503E8BA -- C:\Windows\assembly\tmp\BLZ45QAN\Policy.12.0.Microsoft.Office.Interop.Word.dll
  2527. [2012/03/25 13:31:26 | 000,011,656 | ---- | M] () MD5=027FA86FD3041FE291464465FCDB337E -- C:\Windows\assembly\tmp\BMQXOC6O\Policy.12.0.Microsoft.Office.Interop.Outlook.dll
  2528. [2012/03/25 17:11:37 | 000,011,664 | ---- | M] () MD5=F94B126921F404EC30FACED9C5D6B890 -- C:\Windows\assembly\tmp\BPGG6PV6\Policy.12.0.Microsoft.Office.Interop.SmartTag.dll
  2529. [2012/03/25 17:56:02 | 000,071,592 | ---- | M] () MD5=5949DF7B1BF7951C55A31803CD4DC6E2 -- C:\Windows\assembly\tmp\BSLEUADP\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
  2530. [2012/03/25 13:31:13 | 000,011,104 | ---- | M] () MD5=BBF1A582F1C6155590108B38C8075759 -- C:\Windows\assembly\tmp\BVVDP7IH\Policy.11.0.Office.dll
  2531. [2012/03/25 17:11:18 | 000,065,536 | ---- | M] () MD5=4167FAFE231BE780D7158B0A7E5D337D -- C:\Windows\assembly\tmp\BWUXV1DD\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.dll
  2532. [2012/03/25 13:31:26 | 000,025,480 | ---- | M] () MD5=BE021CFEEE55BA6E1147451A259F098C -- C:\Windows\assembly\tmp\BZBECHXS\Microsoft.Office.Interop.OutlookViewCtl.dll
  2533. [2012/03/25 17:11:15 | 000,018,304 | ---- | M] () MD5=3E473BF3BBA2B5A7EE19D47BD7E1BC80 -- C:\Windows\assembly\tmp\C1M6ITEW\Microsoft.Office.BusinessApplications.Runtime.Intl.dll
  2534. [2012/03/25 17:11:10 | 000,271,440 | ---- | M] () MD5=EE63BE840C77AA9DDDD5BF66BCF98F87 -- C:\Windows\assembly\tmp\C2Q1GVJN\System.Data.SqlServerCe.dll
  2535. [2012/03/25 13:31:22 | 000,022,016 | ---- | M] () MD5=6581FE75715D9D6FF9BFD2264F825FB0 -- C:\Windows\assembly\tmp\CFE5D5EM\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll
  2536. [2012/03/25 17:11:26 | 000,045,056 | ---- | M] () MD5=DE2E0DF8A33183053017C1724E30E5DC -- C:\Windows\assembly\tmp\CG57W73B\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.dll
  2537. [2012/03/25 17:11:11 | 000,546,704 | ---- | M] () MD5=46B44E2EC2A58FD51278CAE5CE1AF801 -- C:\Windows\assembly\tmp\CGWUO1G8\Microsoft.Office.Infopath.Client.Internal.Host.dll
  2538. [2012/03/25 13:31:26 | 000,448,360 | ---- | M] () MD5=6E84AAA11121D806DADC159CED3E3DDA -- C:\Windows\assembly\tmp\CI3IAM3Q\OFFICE.DLL
  2539. [2012/03/25 18:23:56 | 000,011,664 | ---- | M] () MD5=869F08DA5E80C461F698BBB4528310F1 -- C:\Windows\assembly\tmp\CJM2WV6F\Policy.12.0.Microsoft.Office.InfoPath.dll
  2540. [2012/03/25 17:11:38 | 000,016,248 | ---- | M] () MD5=8C100E1FFC01FAFD93838D5024A47EDB -- C:\Windows\assembly\tmp\COMP1PPY\Microsoft.Office.Interop.OneNote.dll
  2541. [2012/03/25 17:11:40 | 000,011,640 | ---- | M] () MD5=375B11B5290424A3C92221235346CF3D -- C:\Windows\assembly\tmp\CUMXAGS8\Policy.11.0.Microsoft.Vbe.Interop.dll
  2542. [2012/03/25 17:11:36 | 000,077,824 | ---- | M] () MD5=64BC955B1C9DF3E7FF0453379915922D -- C:\Windows\assembly\tmp\D3SFAD8P\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.dll
  2543. [2012/03/25 13:31:23 | 000,176,128 | ---- | M] () MD5=A41B86118BD728EF04067CCFF89006EA -- C:\Windows\assembly\tmp\D4QXCA4E\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll
  2544. [2012/03/25 18:24:19 | 000,016,248 | ---- | M] () MD5=8C100E1FFC01FAFD93838D5024A47EDB -- C:\Windows\assembly\tmp\DD0MCKM6\Microsoft.Office.Interop.OneNote.dll
  2545. [2012/03/25 17:11:36 | 000,036,864 | ---- | M] () MD5=AD54FE98130FA82E5A75A1906F7F14A9 -- C:\Windows\assembly\tmp\DDK1ZOO4\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll
  2546. [2012/03/25 18:23:49 | 000,104,368 | ---- | M] () MD5=9C7403906909E432EA6A2511D1B3CDF2 -- C:\Windows\assembly\tmp\DGJDO4ZI\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
  2547. [2012/03/25 18:24:01 | 000,567,168 | ---- | M] () MD5=C5AAB920018ADA7000118F631171AF3F -- C:\Windows\assembly\tmp\DHM5XZGY\Microsoft.Office.BusinessApplications.Runtime.dll
  2548. [2012/03/25 18:23:23 | 000,022,016 | ---- | M] () MD5=6581FE75715D9D6FF9BFD2264F825FB0 -- C:\Windows\assembly\tmp\DRKD4U3F\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll
  2549. [2012/03/25 17:11:11 | 000,014,224 | ---- | M] () MD5=E86AE27B4D35D9E7E9AA276BD84019AB -- C:\Windows\assembly\tmp\DRSAHDUI\Microsoft.Office.InfoPath.Permission.dll
  2550. [2012/03/25 13:31:10 | 000,438,272 | ---- | M] () MD5=409B1D3ED9ECAAB3D7DA66A83E1161A9 -- C:\Windows\assembly\tmp\DSEA97GL\Microsoft.Office.Tools.Excel.v9.0.dll
  2551. [2012/03/25 13:31:15 | 000,016,384 | ---- | M] () MD5=E1EEB7E26AB04075EECC7275239B20B3 -- C:\Windows\assembly\tmp\DU63K7Q9\stdole.dll
  2552. [2012/03/25 13:31:18 | 000,079,744 | ---- | M] () MD5=BB39161455A053800391C52840FC010A -- C:\Windows\assembly\tmp\DWEYCHFM\Microsoft.Office.interop.access.dao.dll
  2553. [2012/03/25 17:56:09 | 000,011,664 | ---- | M] () MD5=869F08DA5E80C461F698BBB4528310F1 -- C:\Windows\assembly\tmp\DYC9JQ1E\Policy.12.0.Microsoft.Office.InfoPath.dll
  2554. [2012/03/25 17:55:49 | 000,000,888 | ---- | M] () MD5=66DFFED0DCD33FFAA9295DA912CC237C -- C:\Windows\assembly\tmp\DYC9JQ1E\SEQFYAWP
  2555. [2012/03/25 18:24:21 | 000,011,640 | ---- | M] () MD5=7063FF7154582442F6F533F12B3F0F20 -- C:\Windows\assembly\tmp\DYWM89RP\Policy.12.0.Microsoft.Vbe.Interop.dll
  2556. [2012/03/25 17:11:31 | 000,011,664 | ---- | M] () MD5=869F08DA5E80C461F698BBB4528310F1 -- C:\Windows\assembly\tmp\E6LYPTMJ\Policy.12.0.Microsoft.Office.InfoPath.dll
  2557. [2012/03/25 17:55:55 | 000,045,056 | ---- | M] () MD5=8510E5F664F1C9136E73A13B0C8E5357 -- C:\Windows\assembly\tmp\EAWNKJAP\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll
  2558. [2012/03/25 17:56:16 | 000,013,312 | ---- | M] () MD5=D80746B2F94A3A28E380735D4B8A9EA3 -- C:\Windows\assembly\tmp\EFT09YV4\Microsoft.stdformat.dll
  2559. [2012/03/25 13:31:24 | 000,036,864 | ---- | M] () MD5=0C5700ED83D92BBB5E6F70AB89C26F04 -- C:\Windows\assembly\tmp\EOAHCY20\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll
  2560. [2012/03/25 18:23:32 | 000,034,680 | ---- | M] () MD5=F4BC7DCB4BBA0919BFF710D929F7BD14 -- C:\Windows\assembly\tmp\EOV2U4OU\Microsoft.Office.InfoPath.Vsta.dll
  2561. [2012/03/25 13:31:09 | 001,550,200 | ---- | M] () MD5=79A6278FF98538E5F3E51D8A01C246E5 -- C:\Windows\assembly\tmp\EQ6XGEE7\Microsoft.Office.Interop.Excel.dll
  2562. [2012/03/25 17:56:20 | 000,386,944 | ---- | M] () MD5=2FC5B525EA23A3E1B26B5F4996894A6B -- C:\Windows\assembly\tmp\ES138FER\Microsoft.Office.Interop.PowerPoint.dll
  2563. [2012/03/25 17:11:10 | 000,370,608 | ---- | M] () MD5=99D8B5B9A5D631608242BAA23249B2E1 -- C:\Windows\assembly\tmp\EUXY8RS9\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
  2564. [2012/03/25 18:24:14 | 000,004,096 | ---- | M] () MD5=AAA2E20588E154A10747BF1B31B55125 -- C:\Windows\assembly\tmp\F1J09JCB\msdatasrc.dll
  2565. [2012/03/25 17:11:13 | 000,034,680 | ---- | M] () MD5=F4BC7DCB4BBA0919BFF710D929F7BD14 -- C:\Windows\assembly\tmp\F4SLJC39\Microsoft.Office.InfoPath.Vsta.dll
  2566. [2012/03/25 18:23:41 | 000,011,656 | ---- | M] () MD5=F09CDD3138E5EFC8662CC948636F53A5 -- C:\Windows\assembly\tmp\F5DKRXLT\Policy.12.0.Microsoft.Office.Interop.Outlook.dll
  2567. [2012/03/25 17:56:17 | 000,094,208 | ---- | M] () MD5=CF53CB86A8D49F5CCA58D8FF8AE246A9 -- C:\Windows\assembly\tmp\F7COCXPJ\Microsoft.Office.Tools.v9.0.dll
  2568. [2012/03/25 18:23:51 | 000,230,480 | ---- | M] () MD5=915B2E2620D09B0EE7C10DCEB765916C -- C:\Windows\assembly\tmp\F8DGYJVJ\System.Data.SqlServerCe.Entity.dll
  2569. [2012/03/25 17:56:15 | 000,053,248 | ---- | M] () MD5=07E7E7818586A3B3F1EC50E5E2511FC0 -- C:\Windows\assembly\tmp\FA0XX7R2\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.dll
  2570. [2012/03/25 17:55:57 | 000,011,664 | ---- | M] () MD5=31237BBFA5730B335B37A15D71623022 -- C:\Windows\assembly\tmp\FHRUP73M\Policy.12.0.Microsoft.Office.Interop.PowerPoint.dll
  2571. [2012/03/25 17:56:20 | 000,000,908 | ---- | M] () MD5=8199AE1C79C0443071D0352D70CE4DAA -- C:\Windows\assembly\tmp\FHRUP73M\WFPDCMT9
  2572. [2012/03/25 13:31:12 | 000,013,312 | ---- | M] () MD5=D80746B2F94A3A28E380735D4B8A9EA3 -- C:\Windows\assembly\tmp\FJ32NR83\Microsoft.stdformat.dll
  2573. [2012/03/25 13:31:24 | 000,077,824 | ---- | M] () MD5=DC553264A749613C331C8B989A1A9B2A -- C:\Windows\assembly\tmp\FJAN3XGT\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll
  2574. [2012/03/25 17:11:25 | 000,356,352 | ---- | M] () MD5=0A8FCA67378EC92E2F304E6750DD9FD1 -- C:\Windows\assembly\tmp\FPHOUGXH\Microsoft.Office.Tools.Common.v9.0.dll
  2575. [2012/03/25 17:56:15 | 000,665,472 | ---- | M] () MD5=4BD743C646EE2F47DDFEEAC9393E7033 -- C:\Windows\assembly\tmp\FPWRWDNF\Microsoft.Office.BusinessApplications.RuntimeUi.dll
  2576. [2012/03/25 17:11:36 | 001,689,472 | ---- | M] () MD5=8EC5FD93F9A500722C02D6D8A9165E3B -- C:\Windows\assembly\tmp\FSNU1SZV\Microsoft.Office.BusinessApplications.SyncServices.dll
  2577. [2012/03/25 17:55:55 | 000,045,056 | ---- | M] () MD5=8EE7C7AA4D06207C01C0461A0784FF6F -- C:\Windows\assembly\tmp\FUS5TDL7\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll
  2578. [2012/03/25 18:23:40 | 000,045,056 | ---- | M] () MD5=8EE7C7AA4D06207C01C0461A0784FF6F -- C:\Windows\assembly\tmp\FUTWKBUB\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll
  2579. [2012/03/25 17:11:20 | 000,011,664 | ---- | M] () MD5=AA8582B922BF6A110AD1422B40950720 -- C:\Windows\assembly\tmp\FVYI1D4I\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
  2580. [2012/03/25 18:23:24 | 000,077,824 | ---- | M] () MD5=41D096C3E61378485D7B8AAFF00C245D -- C:\Windows\assembly\tmp\FY0FNFXM\Microsoft.Office.Tools.Outlook.v9.0.dll
  2581. [2012/03/25 18:23:41 | 000,025,480 | ---- | M] () MD5=95ADBFBDC616027379E0F9DCC8E35370 -- C:\Windows\assembly\tmp\FYRRDX3B\Microsoft.Office.Interop.OutlookViewCtl.dll
  2582. [2012/03/25 17:55:45 | 000,299,008 | ---- | M] () MD5=8447FB78623AACCCFC609F01D1723935 -- C:\Windows\assembly\tmp\G1LKFVC6\Microsoft.Office.Tools.Word.v9.0.dll
  2583. [2012/03/25 17:11:10 | 000,115,744 | ---- | M] () MD5=DA5EE020BEF41DC95C3532CBAA1EA8F4 -- C:\Windows\assembly\tmp\G1V77D2B\Microsoft.Synchronization.Data.Server.dll
  2584. [2012/03/25 17:55:47 | 000,011,664 | ---- | M] () MD5=B2E5D2F672B638CC9FEE5EFDFB09B70C -- C:\Windows\assembly\tmp\G1WNAKD8\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.dll
  2585. [2012/03/25 17:56:07 | 000,000,930 | ---- | M] () MD5=F3BFE3718EC61BEB4EEF7180EC9E2F66 -- C:\Windows\assembly\tmp\G1WNAKD8\X5PASGUK
  2586. [2012/03/25 17:11:17 | 000,051,072 | ---- | M] () MD5=7133E8677E11DC09D12DAB476C068DE1 -- C:\Windows\assembly\tmp\G2WVXR1R\Microsoft.Office.BusinessApplications.SyncServices.Intl.dll
  2587. [2012/03/25 17:56:18 | 000,016,248 | ---- | M] () MD5=8C100E1FFC01FAFD93838D5024A47EDB -- C:\Windows\assembly\tmp\G457N97V\Microsoft.Office.Interop.OneNote.dll
  2588. [2012/03/25 18:23:30 | 000,059,248 | ---- | M] () MD5=D45565A49811DD248532076D4374BD43 -- C:\Windows\assembly\tmp\G49YH6PM\Microsoft.Office.Infopath.dll
  2589. [2012/03/25 17:11:38 | 000,011,672 | ---- | M] () MD5=45EC3053444CA47BB540E7036F50C0BA -- C:\Windows\assembly\tmp\G5KND4J7\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2590. [2012/03/25 13:31:13 | 000,011,104 | ---- | M] () MD5=36E29C6106F087A16A45EEA7E044C3D1 -- C:\Windows\assembly\tmp\GBN2B6A6\Policy.12.0.Office.dll
  2591. [2012/03/25 17:11:10 | 000,038,744 | ---- | M] () MD5=7137B00CD3C6AD6AAAC4D7EE614137D5 -- C:\Windows\assembly\tmp\GIG3D4SO\System.AddIn.dll
  2592. [2012/03/25 18:23:34 | 000,011,664 | ---- | M] () MD5=EA39607C138BBADB76883FBCBD264AC4 -- C:\Windows\assembly\tmp\GLA7B2KP\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
  2593. [2012/03/25 17:55:58 | 000,011,656 | ---- | M] () MD5=0C560FE70843B466E8364DD2BC878F97 -- C:\Windows\assembly\tmp\GNGE0Q7V\Policy.11.0.Microsoft.Office.Interop.Word.dll
  2594. [2012/03/25 18:23:41 | 000,011,656 | ---- | M] () MD5=812A8B0FE904EEF755646C5196A858C6 -- C:\Windows\assembly\tmp\GNY5KCLV\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
  2595. [2012/03/25 17:11:25 | 000,438,272 | ---- | M] () MD5=409B1D3ED9ECAAB3D7DA66A83E1161A9 -- C:\Windows\assembly\tmp\GRO3VMDA\Microsoft.Office.Tools.Excel.v9.0.dll
  2596. [2012/03/25 13:31:13 | 000,110,592 | ---- | M] () MD5=3A717D3B1B2F5921871B0561E71DD4D8 -- C:\Windows\assembly\tmp\GTPZEZ4H\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll
  2597. [2012/03/25 17:55:59 | 000,110,592 | ---- | M] () MD5=7ECB661F50F34A941A44DAC7241F7D08 -- C:\Windows\assembly\tmp\GUADSFMF\adodb.dll
  2598. [2012/03/25 17:56:02 | 000,028,672 | ---- | M] () MD5=6F6421474D6D385A473640A0CA79695C -- C:\Windows\assembly\tmp\GWSZ4OK3\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll
  2599. [2012/03/25 13:31:13 | 000,019,320 | ---- | M] () MD5=370BA1A9D8155AD569F79283E91888B8 -- C:\Windows\assembly\tmp\H2FF0OS1\Microsoft.Office.Interop.SmartTag.dll
  2600. [2012/03/25 18:23:24 | 000,286,720 | ---- | M] () MD5=F0DA890A63403E2010788FDBC1801FA7 -- C:\Windows\assembly\tmp\H318VCBE\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll
  2601. [2012/03/25 13:31:24 | 000,045,056 | ---- | M] () MD5=8510E5F664F1C9136E73A13B0C8E5357 -- C:\Windows\assembly\tmp\H567CKUB\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll
  2602. [2012/03/25 13:31:26 | 000,247,680 | ---- | M] () MD5=3796C003FA4D78FB569967A5E3F9325B -- C:\Windows\assembly\tmp\HE5JS9MF\Microsoft.Office.Interop.Publisher.dll
  2603. [2012/03/25 13:31:07 | 000,011,664 | ---- | M] () MD5=1AD4166C04970B0F4C69A3E7DDC3CC2D -- C:\Windows\assembly\tmp\HI7Q95BE\Policy.12.0.Microsoft.Office.Interop.Access.Dao.dll
  2604. [2012/03/25 13:31:18 | 000,000,908 | ---- | M] () MD5=8A9FDA784C76AEBFCC8266727C31A77D -- C:\Windows\assembly\tmp\HI7Q95BE\SLR46MAS
  2605. [2012/03/25 18:24:15 | 000,110,592 | ---- | M] () MD5=3A717D3B1B2F5921871B0561E71DD4D8 -- C:\Windows\assembly\tmp\HPK47KQE\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll
  2606. [2012/03/25 17:55:57 | 000,025,480 | ---- | M] () MD5=95ADBFBDC616027379E0F9DCC8E35370 -- C:\Windows\assembly\tmp\HPMEGFFZ\Microsoft.Office.Interop.OutlookViewCtl.dll
  2607. [2012/03/25 17:11:11 | 000,161,656 | ---- | M] () MD5=042463EB8E2A6FADFFCE9AD2D0046BF9 -- C:\Windows\assembly\tmp\HSVM4APU\Microsoft.Office.Interop.InfoPath.dll
  2608. [2012/03/25 17:11:09 | 000,212,992 | ---- | M] () MD5=4D9048A89ADEC6A302273592DC1E53F7 -- C:\Windows\assembly\tmp\HUFMCKST\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll
  2609. [2012/03/25 18:23:25 | 000,086,016 | ---- | M] () MD5=258BA858D1A21F816B2C7F8B947C9C9D -- C:\Windows\assembly\tmp\I3A358CY\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.dll
  2610. [2012/03/25 13:31:13 | 000,046,968 | ---- | M] () MD5=8318FE8E736EA06662275CB6E53F488E -- C:\Windows\assembly\tmp\I5W8U2B6\Microsoft.Office.Interop.OneNote.dll
  2611. [2012/03/25 13:31:24 | 000,096,128 | ---- | M] () MD5=94A1986FF31DADBE7ED939AE8C09B77A -- C:\Windows\assembly\tmp\I6SSDTYS\microsoft.office.businessapplications.diagnostics.dll
  2612. [2012/03/25 17:56:20 | 000,247,680 | ---- | M] () MD5=DFC7276D34F4B66518A32F9AF48BA3F9 -- C:\Windows\assembly\tmp\I8V37198\Microsoft.Office.Interop.Publisher.dll
  2613. [2012/03/25 17:11:08 | 000,116,632 | ---- | M] () MD5=0A37EC78BC05BC953676829C46C2D00F -- C:\Windows\assembly\tmp\I9C5OJJ8\Microsoft.BusinessData.dll
  2614. [2012/03/25 17:56:10 | 000,513,920 | ---- | M] () MD5=9A1AD8C3023D6D56B685C9694E2068E9 -- C:\Windows\assembly\tmp\ICWE9GTG\Microsoft.SharePoint.BusinessData.Administration.Client.dll
  2615. [2012/03/25 17:55:44 | 000,116,632 | ---- | M] () MD5=0A37EC78BC05BC953676829C46C2D00F -- C:\Windows\assembly\tmp\IH8AYKHZ\Microsoft.BusinessData.dll
  2616. [2012/03/25 18:23:49 | 000,045,056 | ---- | M] () MD5=DE2E0DF8A33183053017C1724E30E5DC -- C:\Windows\assembly\tmp\IHV6SZP6\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.dll
  2617. [2012/03/25 18:23:56 | 000,011,664 | ---- | M] () MD5=01DC8872B977B52FCF94C6B37E2E3EAB -- C:\Windows\assembly\tmp\IKVKP9ZN\policy.12.0.Microsoft.Office.Interop.InfoPath.dll
  2618. [2012/03/25 17:11:28 | 000,407,440 | ---- | M] () MD5=BEEF1231C4AF6BDB0E26497970EE6DDE -- C:\Windows\assembly\tmp\IT1R9NN8\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
  2619. [2012/03/25 17:55:46 | 000,374,640 | ---- | M] () MD5=E8255378F97236BA85BCB8348B22BC74 -- C:\Windows\assembly\tmp\IU63H3RQ\Microsoft.Vbe.Interop.Forms.dll
  2620. [2012/03/25 17:11:20 | 000,011,664 | ---- | M] () MD5=89C5F582D77DDDAA775DC7629C35C592 -- C:\Windows\assembly\tmp\IY5JJN7P\Policy.12.0.Microsoft.Office.Interop.Publisher.dll
  2621. [2012/03/25 17:56:02 | 000,104,368 | ---- | M] () MD5=9C7403906909E432EA6A2511D1B3CDF2 -- C:\Windows\assembly\tmp\J052PQXM\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
  2622. [2012/03/25 17:11:19 | 000,011,656 | ---- | M] () MD5=812A8B0FE904EEF755646C5196A858C6 -- C:\Windows\assembly\tmp\J0H7Y0M1\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
  2623. [2012/03/25 13:31:25 | 000,011,664 | ---- | M] () MD5=9883D76E2777A0FF724BB34C4F47C80F -- C:\Windows\assembly\tmp\J0HR3BR9\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
  2624. [2012/03/25 13:31:13 | 000,000,904 | ---- | M] () MD5=4F7AB727B60621BB36E47B682F4BFE23 -- C:\Windows\assembly\tmp\J0HR3BR9\UEAGYEAY
  2625. [2012/03/25 17:55:49 | 000,034,680 | ---- | M] () MD5=F4BC7DCB4BBA0919BFF710D929F7BD14 -- C:\Windows\assembly\tmp\J0MVF41M\Microsoft.Office.InfoPath.Vsta.dll
  2626. [2012/03/25 17:56:06 | 000,407,440 | ---- | M] () MD5=BEEF1231C4AF6BDB0E26497970EE6DDE -- C:\Windows\assembly\tmp\J1WESYSK\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
  2627. [2012/03/25 13:31:22 | 000,077,824 | ---- | M] () MD5=41D096C3E61378485D7B8AAFF00C245D -- C:\Windows\assembly\tmp\J59YZPKG\Microsoft.Office.Tools.Outlook.v9.0.dll
  2628. [2012/03/25 17:11:21 | 000,011,656 | ---- | M] () MD5=A0925184CB51086A5A8F28D6B7597EDF -- C:\Windows\assembly\tmp\J6YG0N9D\Policy.12.0.Microsoft.Office.Interop.Excel.dll
  2629. [2012/03/25 18:23:26 | 000,038,744 | ---- | M] () MD5=7137B00CD3C6AD6AAAC4D7EE614137D5 -- C:\Windows\assembly\tmp\J7E906R3\System.AddIn.dll
  2630. [2012/03/25 17:11:10 | 000,385,024 | ---- | M] () MD5=6F6C2FEB15AFB745C8BF7D0277D2DBBF -- C:\Windows\assembly\tmp\JDS5BIDD\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll
  2631. [2012/03/25 17:56:02 | 000,038,808 | ---- | M] () MD5=907114FE32F4DFB0C5EDA360BE0740C7 -- C:\Windows\assembly\tmp\JKHBUWM3\Microsoft.VisualStudio.Tools.Applications.Contract.dll
  2632. [2012/03/25 18:23:27 | 000,374,640 | ---- | M] () MD5=E8255378F97236BA85BCB8348B22BC74 -- C:\Windows\assembly\tmp\JLHB3F4K\Microsoft.Vbe.Interop.Forms.dll
  2633. [2012/03/25 13:31:10 | 000,131,072 | ---- | M] () MD5=B169C95A3BEFA21EBA58D21992EB6A9C -- C:\Windows\assembly\tmp\JLHISU5J\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll
  2634. [2012/03/25 17:11:34 | 000,567,168 | ---- | M] () MD5=C5AAB920018ADA7000118F631171AF3F -- C:\Windows\assembly\tmp\JQWB0JV1\Microsoft.Office.BusinessApplications.Runtime.dll
  2635. [2012/03/25 17:55:49 | 000,087,936 | ---- | M] () MD5=171E5A171FADDCA58EF97EBD26837863 -- C:\Windows\assembly\tmp\JRQ12Q9Q\Microsoft.Office.Interop.InfoPath.Xml.dll
  2636. [2012/03/25 17:56:21 | 000,011,640 | ---- | M] () MD5=375B11B5290424A3C92221235346CF3D -- C:\Windows\assembly\tmp\JUUBFETV\Policy.11.0.Microsoft.Vbe.Interop.dll
  2637. [2012/03/25 17:56:07 | 000,042,880 | ---- | M] () MD5=CF202A917D36E48FAD6F57115D643536 -- C:\Windows\assembly\tmp\JVF2FK2X\microsoft.office.infopath.formcontrol.dll
  2638. [2012/03/25 17:11:15 | 000,051,072 | ---- | M] () MD5=E60068937F2F8DFDAD8474C2058A28C7 -- C:\Windows\assembly\tmp\JY6FUEAH\Microsoft.Office.BusinessApplications.Tools.AutoGen.dll
  2639. [2012/03/25 17:56:17 | 000,011,664 | ---- | M] () MD5=4E0D9A85155F91CF8B9B66991C273301 -- C:\Windows\assembly\tmp\K13DM7JG\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
  2640. [2012/03/25 17:11:10 | 000,374,640 | ---- | M] () MD5=E8255378F97236BA85BCB8348B22BC74 -- C:\Windows\assembly\tmp\K6HV857K\Microsoft.Vbe.Interop.Forms.dll
  2641. [2012/03/25 13:31:13 | 000,065,536 | ---- | M] () MD5=81ADD0B914DBF2C534BBAB1F3F4D78FF -- C:\Windows\assembly\tmp\K72TYDV2\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.dll
  2642. [2012/03/25 18:23:30 | 000,011,664 | ---- | M] () MD5=0826CD2CA41B5ACD3DA5164FEEA7022D -- C:\Windows\assembly\tmp\KAB7WRUZ\policy.12.0.Microsoft.Office.InfoPath.FormControl.dll
  2643. [2012/03/25 17:55:47 | 000,059,248 | ---- | M] () MD5=D45565A49811DD248532076D4374BD43 -- C:\Windows\assembly\tmp\KAVSM5UR\Microsoft.Office.Infopath.dll
  2644. [2012/03/25 18:23:48 | 000,004,608 | ---- | M] () MD5=F8D11C60B70ACD2EC9154EE676F615BA -- C:\Windows\assembly\tmp\KBCQMN1L\extensibility.dll
  2645. [2012/03/25 13:31:10 | 000,049,152 | ---- | M] () MD5=77249A017C234EC21BC60DABB8515896 -- C:\Windows\assembly\tmp\KDVUZT9V\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll
  2646. [2012/03/25 17:11:21 | 001,857,400 | ---- | M] () MD5=14788241B6D6540344FE951C0607B331 -- C:\Windows\assembly\tmp\KEFGNIWQ\Microsoft.Office.Interop.Access.dll
  2647. [2012/03/25 17:55:47 | 000,014,224 | ---- | M] () MD5=E86AE27B4D35D9E7E9AA276BD84019AB -- C:\Windows\assembly\tmp\KEZXQ6W6\Microsoft.Office.InfoPath.Permission.dll
  2648. [2012/03/25 17:56:04 | 000,011,656 | ---- | M] () MD5=272324C3519292E26C20BCA9ADD43864 -- C:\Windows\assembly\tmp\KGZYDEPN\Policy.11.0.Microsoft.Office.Interop.Graph.dll
  2649. [2012/03/25 17:11:25 | 000,049,152 | ---- | M] () MD5=77249A017C234EC21BC60DABB8515896 -- C:\Windows\assembly\tmp\KJZ2I0S8\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll
  2650. [2012/03/25 18:23:42 | 000,011,664 | ---- | M] () MD5=AA8582B922BF6A110AD1422B40950720 -- C:\Windows\assembly\tmp\KLZK9G5Q\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
  2651. [2012/03/25 18:23:32 | 000,011,664 | ---- | M] () MD5=D6971FC530C07B6B7DFD3AC9DF8695EE -- C:\Windows\assembly\tmp\KQVQTK6P\Policy.12.0.Microsoft.Office.InfoPath.Permission.dll
  2652. [2012/03/25 18:23:43 | 001,857,400 | ---- | M] () MD5=14788241B6D6540344FE951C0607B331 -- C:\Windows\assembly\tmp\KXOR7BDO\Microsoft.Office.Interop.Access.dll
  2653. [2012/03/25 13:31:12 | 000,077,824 | ---- | M] () MD5=64BC955B1C9DF3E7FF0453379915922D -- C:\Windows\assembly\tmp\KYT61UYR\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.dll
  2654. [2012/03/25 13:31:28 | 000,011,656 | ---- | M] () MD5=0660718DE1A3740CD87109BE1BEEC730 -- C:\Windows\assembly\tmp\KZQI48M3\Policy.12.0.Microsoft.Office.Interop.Excel.dll
  2655. [2012/03/25 13:31:18 | 001,857,400 | ---- | M] () MD5=6C975A51BA60882F1DEF5EA487E9429C -- C:\Windows\assembly\tmp\L12BX9NM\Microsoft.Office.Interop.Access.dll
  2656. [2012/03/25 17:56:15 | 008,007,680 | ---- | M] () MD5=5440EE9CD44616D60CDE57EBDB286E95 -- C:\Windows\assembly\tmp\L56RCK08\Microsoft.mshtml.dll
  2657. [2012/03/25 18:24:10 | 000,077,824 | ---- | M] () MD5=64BC955B1C9DF3E7FF0453379915922D -- C:\Windows\assembly\tmp\L5NDZOTH\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.dll
  2658. [2012/03/25 18:23:39 | 000,077,824 | ---- | M] () MD5=DC553264A749613C331C8B989A1A9B2A -- C:\Windows\assembly\tmp\L8QZ5F7F\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll
  2659. [2012/03/25 17:11:17 | 000,169,856 | ---- | M] () MD5=3B7CC62A9BD6F75BD6636B6E777F139C -- C:\Windows\assembly\tmp\LASQJ2LO\Microsoft.Office.BusinessApplications.Tools.Intl.dll
  2660. [2012/03/25 17:11:38 | 000,448,360 | ---- | M] () MD5=2D53B9BDBB63C6D7003A1717C9AE7346 -- C:\Windows\assembly\tmp\LBNJFJ9P\OFFICE.DLL
  2661. [2012/03/25 17:56:21 | 000,907,120 | ---- | M] () MD5=271D2874EE8021B10D6DF89307F9D463 -- C:\Windows\assembly\tmp\LEPYL96N\Microsoft.Office.Interop.Word.dll
  2662. [2012/03/25 17:11:29 | 000,140,200 | ---- | M] () MD5=07C649EDCCEB97CBAF976053D2392CC8 -- C:\Windows\assembly\tmp\LHCBLENS\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
  2663. [2012/03/25 13:31:10 | 000,045,056 | ---- | M] () MD5=0EBF536E40253273365C3C26A37D57EF -- C:\Windows\assembly\tmp\LI2HV66D\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.dll
  2664. [2012/03/25 17:11:36 | 000,081,920 | ---- | M] () MD5=A7278626DFE2AAFDDBA6B8B82AA94CEF -- C:\Windows\assembly\tmp\LIVMER0K\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll
  2665. [2012/03/25 17:11:37 | 000,011,664 | ---- | M] () MD5=4E0D9A85155F91CF8B9B66991C273301 -- C:\Windows\assembly\tmp\LLOK7DFS\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
  2666. [2012/03/25 17:11:18 | 000,000,904 | ---- | M] () MD5=4F7AB727B60621BB36E47B682F4BFE23 -- C:\Windows\assembly\tmp\LLOK7DFS\PUSGKN7L
  2667. [2012/03/25 18:23:26 | 000,086,016 | ---- | M] () MD5=F2116B93B569552FA9964ECF0090CF00 -- C:\Windows\assembly\tmp\LT03Y34X\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll
  2668. [2012/03/25 18:23:37 | 000,206,720 | ---- | M] () MD5=D42F1D676FE013CB02087394B57EAA16 -- C:\Windows\assembly\tmp\LT1G6TML\Microsoft.SharePoint.BusinessData.Administration.Client.Intl.dll
  2669. [2012/03/25 17:11:13 | 000,087,936 | ---- | M] () MD5=171E5A171FADDCA58EF97EBD26837863 -- C:\Windows\assembly\tmp\LVTHH3PX\Microsoft.Office.Interop.InfoPath.Xml.dll
  2670. [2012/03/25 17:11:18 | 000,019,320 | ---- | M] () MD5=2320EAD15BF728EC8FF5C9075B4A7B1F -- C:\Windows\assembly\tmp\LW27E6WG\Microsoft.Office.Interop.SmartTag.dll
  2671. [2012/03/25 17:56:13 | 000,096,128 | ---- | M] () MD5=DEC87A5053CE125612D0ECD22CE8A7CC -- C:\Windows\assembly\tmp\M0M7MU2S\microsoft.office.businessapplications.diagnostics.dll
  2672. [2012/03/25 18:23:19 | 000,011,656 | ---- | M] () MD5=E922699AE3647B38A0D3E3982043A9F8 -- C:\Windows\assembly\tmp\M0MJ8JQQ\Policy.12.0.Microsoft.Office.Interop.Access.dll
  2673. [2012/03/25 18:23:21 | 000,116,632 | ---- | M] () MD5=0A37EC78BC05BC953676829C46C2D00F -- C:\Windows\assembly\tmp\M6W366MY\Microsoft.BusinessData.dll
  2674. [2012/03/25 17:55:55 | 000,036,864 | ---- | M] () MD5=0C5700ED83D92BBB5E6F70AB89C26F04 -- C:\Windows\assembly\tmp\MJCPJ8RT\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll
  2675. [2012/03/25 13:31:22 | 000,028,672 | ---- | M] () MD5=4C0E0A5A2D17F67E7DA61822EAE226F4 -- C:\Windows\assembly\tmp\MPMQUW59\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll
  2676. [2012/03/25 17:11:10 | 000,210,848 | ---- | M] () MD5=2E57C4C703D80B484CDDE2C13BA27BF1 -- C:\Windows\assembly\tmp\MQOXVLUW\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
  2677. [2012/03/25 13:31:14 | 000,972,664 | ---- | M] () MD5=D56157EC631B91BB9E439FDC597F0E36 -- C:\Windows\assembly\tmp\MT6ST5OP\Microsoft.Office.Interop.Outlook.dll
  2678. [2012/03/25 13:31:10 | 000,374,640 | ---- | M] () MD5=786BABFD5E40B254EE46F3EEE81C36F4 -- C:\Windows\assembly\tmp\MV40B3Z7\Microsoft.Vbe.Interop.Forms.dll
  2679. [2012/03/25 17:11:17 | 000,045,056 | ---- | M] () MD5=8510E5F664F1C9136E73A13B0C8E5357 -- C:\Windows\assembly\tmp\MVUHAM3B\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll
  2680. [2012/03/25 13:31:24 | 000,040,960 | ---- | M] () MD5=8C4B96CB6644CC8914C44EA2193959B0 -- C:\Windows\assembly\tmp\MY9HVM45\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll
  2681. [2012/03/25 17:11:10 | 000,086,016 | ---- | M] () MD5=F2116B93B569552FA9964ECF0090CF00 -- C:\Windows\assembly\tmp\N0D4GBW5\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll
  2682. [2012/03/25 13:31:10 | 000,045,056 | ---- | M] () MD5=DE2E0DF8A33183053017C1724E30E5DC -- C:\Windows\assembly\tmp\N1J1K5AB\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.dll
  2683. [2012/03/25 18:23:24 | 000,038,832 | ---- | M] () MD5=CC5ECB09FFDD2A7915E3E98A15DF262E -- C:\Windows\assembly\tmp\N27PZGSC\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
  2684. [2012/03/25 18:23:24 | 000,210,848 | ---- | M] () MD5=2E57C4C703D80B484CDDE2C13BA27BF1 -- C:\Windows\assembly\tmp\N2TJC3KV\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
  2685. [2012/03/25 17:55:49 | 000,011,664 | ---- | M] () MD5=D6971FC530C07B6B7DFD3AC9DF8695EE -- C:\Windows\assembly\tmp\N8KUZHS1\Policy.12.0.Microsoft.Office.InfoPath.Permission.dll
  2686. [2012/03/25 18:24:20 | 000,386,944 | ---- | M] () MD5=2FC5B525EA23A3E1B26B5F4996894A6B -- C:\Windows\assembly\tmp\NIN96ZOU\Microsoft.Office.Interop.PowerPoint.dll
  2687. [2012/03/25 18:23:39 | 000,079,744 | ---- | M] () MD5=F883843E31FAE60536A76DE8908DA097 -- C:\Windows\assembly\tmp\NMY5RRHI\Microsoft.Office.BusinessApplications.RuntimeUi.Intl.dll
  2688. [2012/03/25 17:55:46 | 000,038,744 | ---- | M] () MD5=7137B00CD3C6AD6AAAC4D7EE614137D5 -- C:\Windows\assembly\tmp\NQDXF944\System.AddIn.dll
  2689. [2012/03/25 13:31:23 | 000,086,016 | ---- | M] () MD5=F2116B93B569552FA9964ECF0090CF00 -- C:\Windows\assembly\tmp\NV8C09GX\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll
  2690. [2012/03/25 18:23:22 | 000,011,656 | ---- | M] () MD5=879AA1B9EB9923C303737F9A9684E654 -- C:\Windows\assembly\tmp\NWOG0GT0\Policy.11.0.Microsoft.Office.Interop.Excel.dll
  2691. [2012/03/25 13:31:10 | 000,356,352 | ---- | M] () MD5=0A8FCA67378EC92E2F304E6750DD9FD1 -- C:\Windows\assembly\tmp\O26IZKM0\Microsoft.Office.Tools.Common.v9.0.dll
  2692. [2012/03/25 13:31:22 | 000,004,608 | ---- | M] () MD5=F8D11C60B70ACD2EC9154EE676F615BA -- C:\Windows\assembly\tmp\O5ZWBWKZ\extensibility.dll
  2693. [2012/03/25 18:24:19 | 000,448,360 | ---- | M] () MD5=2D53B9BDBB63C6D7003A1717C9AE7346 -- C:\Windows\assembly\tmp\O7S97EZV\OFFICE.DLL
  2694. [2012/03/25 13:31:23 | 000,286,720 | ---- | M] () MD5=F0DA890A63403E2010788FDBC1801FA7 -- C:\Windows\assembly\tmp\O98KIJ5K\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll
  2695. [2012/03/25 17:11:41 | 000,907,120 | ---- | M] () MD5=271D2874EE8021B10D6DF89307F9D463 -- C:\Windows\assembly\tmp\OD2BO9OB\Microsoft.Office.Interop.Word.dll
  2696. [2012/03/25 17:11:05 | 000,011,664 | ---- | M] () MD5=84C6457AF1FD3600FCEF8531A9CD325D -- C:\Windows\assembly\tmp\OF73P8J3\Policy.12.0.Microsoft.Office.Interop.Access.Dao.dll
  2697. [2012/03/25 13:31:07 | 000,110,592 | ---- | M] () MD5=7ECB661F50F34A941A44DAC7241F7D08 -- C:\Windows\assembly\tmp\OOW654P5\adodb.dll
  2698. [2012/03/25 17:11:09 | 000,022,016 | ---- | M] () MD5=6581FE75715D9D6FF9BFD2264F825FB0 -- C:\Windows\assembly\tmp\OQXDW5BN\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll
  2699. [2012/03/25 17:55:57 | 000,011,664 | ---- | M] () MD5=89C5F582D77DDDAA775DC7629C35C592 -- C:\Windows\assembly\tmp\OWFSFGCL\Policy.12.0.Microsoft.Office.Interop.Publisher.dll
  2700. [2012/03/25 17:56:20 | 000,000,906 | ---- | M] () MD5=8C6C64A729444CD2E32FC753D71DB76C -- C:\Windows\assembly\tmp\OWFSFGCL\WKZRF8N4
  2701. [2012/03/25 13:31:27 | 000,011,640 | ---- | M] () MD5=96A8D791500D842A026A2A32BDC7BCA6 -- C:\Windows\assembly\tmp\P05W3NJO\Policy.11.0.Microsoft.Vbe.Interop.dll
  2702. [2012/03/25 18:23:35 | 000,011,664 | ---- | M] () MD5=B4285A86FC714CC0574B9070FB0E511F -- C:\Windows\assembly\tmp\P1TWF6NA\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.dll
  2703. [2012/03/25 17:55:55 | 000,065,536 | ---- | M] () MD5=4167FAFE231BE780D7158B0A7E5D337D -- C:\Windows\assembly\tmp\P5LZ9P04\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.dll
  2704. [2012/03/25 18:23:41 | 000,011,664 | ---- | M] () MD5=31237BBFA5730B335B37A15D71623022 -- C:\Windows\assembly\tmp\P6573M9Y\Policy.12.0.Microsoft.Office.Interop.PowerPoint.dll
  2705. [2012/03/25 18:24:20 | 000,000,908 | ---- | M] () MD5=8199AE1C79C0443071D0352D70CE4DAA -- C:\Windows\assembly\tmp\P6573M9Y\SGZCC93X
  2706. [2012/03/25 17:11:17 | 000,077,824 | ---- | M] () MD5=DC553264A749613C331C8B989A1A9B2A -- C:\Windows\assembly\tmp\P6QC3D7N\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll
  2707. [2012/03/25 13:31:12 | 000,960,384 | ---- | M] () MD5=F433BBD7C984E266A518FD567E5F5DB8 -- C:\Windows\assembly\tmp\P9G7Z446\microsoft.office.businessdata.dll
  2708. [2012/03/25 17:56:15 | 000,077,824 | ---- | M] () MD5=64BC955B1C9DF3E7FF0453379915922D -- C:\Windows\assembly\tmp\PDW2VYPH\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.dll
  2709. [2012/03/25 18:23:41 | 000,011,104 | ---- | M] () MD5=BF675629E050915C92D6D66F72B2AEB6 -- C:\Windows\assembly\tmp\PJOCV8R5\Policy.12.0.Office.dll
  2710. [2012/03/25 18:23:42 | 000,011,664 | ---- | M] () MD5=761343B53E834E3587E7517D37FE9D56 -- C:\Windows\assembly\tmp\PK6IYUMF\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
  2711. [2012/03/25 18:24:21 | 000,011,640 | ---- | M] () MD5=375B11B5290424A3C92221235346CF3D -- C:\Windows\assembly\tmp\PM09WIJI\Policy.11.0.Microsoft.Vbe.Interop.dll
  2712. [2012/03/25 18:23:42 | 000,000,880 | ---- | M] () MD5=6CF29BFDC5FA7B2FE06AE04FA0DDB1B2 -- C:\Windows\assembly\tmp\PM09WIJI\YYFQESU6
  2713. [2012/03/25 18:23:54 | 000,030,608 | ---- | M] () MD5=F9260C73E50DF7670237024883F0AF55 -- C:\Windows\assembly\tmp\PVWRP2GN\IPDMCTRL.DLL
  2714. [2012/03/25 17:11:15 | 000,956,288 | ---- | M] () MD5=5F20CC1396134D409FB641CC6F78623C -- C:\Windows\assembly\tmp\PZZQU2YN\microsoft.office.businessdata.dll
  2715. [2012/03/25 17:56:15 | 001,689,472 | ---- | M] () MD5=8EC5FD93F9A500722C02D6D8A9165E3B -- C:\Windows\assembly\tmp\Q0C0L6PZ\Microsoft.Office.BusinessApplications.SyncServices.dll
  2716. [2012/03/25 18:24:02 | 000,096,128 | ---- | M] () MD5=DEC87A5053CE125612D0ECD22CE8A7CC -- C:\Windows\assembly\tmp\QA2DLDNJ\microsoft.office.businessapplications.diagnostics.dll
  2717. [2012/03/25 17:55:52 | 000,051,072 | ---- | M] () MD5=E60068937F2F8DFDAD8474C2058A28C7 -- C:\Windows\assembly\tmp\QADKVKUN\Microsoft.Office.BusinessApplications.Tools.AutoGen.dll
  2718. [2012/03/25 17:55:59 | 000,163,248 | ---- | M] () MD5=595C46715D74E357B7B2E43CE732CE89 -- C:\Windows\assembly\tmp\QASGDGZW\Microsoft.Office.Access.BusinessDataCatalog.DLL
  2719. [2012/03/25 17:56:18 | 000,011,672 | ---- | M] () MD5=6B9BC53BC0A44CABB1F7FED4B0208D58 -- C:\Windows\assembly\tmp\QATH9U33\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2720. [2012/03/25 18:23:37 | 000,051,072 | ---- | M] () MD5=E60068937F2F8DFDAD8474C2058A28C7 -- C:\Windows\assembly\tmp\QBWUUP9M\Microsoft.Office.BusinessApplications.Tools.AutoGen.dll
  2721. [2012/03/25 18:23:43 | 000,163,248 | ---- | M] () MD5=595C46715D74E357B7B2E43CE732CE89 -- C:\Windows\assembly\tmp\QGDWVPKR\Microsoft.Office.Access.BusinessDataCatalog.DLL
  2722. [2012/03/25 17:11:26 | 000,011,656 | ---- | M] () MD5=71D8A3D576F2E236B91D30608B887853 -- C:\Windows\assembly\tmp\QGO038S0\Policy.12.0.Microsoft.Office.Interop.Graph.dll
  2723. [2012/03/25 17:11:39 | 000,386,944 | ---- | M] () MD5=2FC5B525EA23A3E1B26B5F4996894A6B -- C:\Windows\assembly\tmp\QVDUCV03\Microsoft.Office.Interop.PowerPoint.dll
  2724. [2012/03/25 18:24:15 | 000,011,664 | ---- | M] () MD5=4E0D9A85155F91CF8B9B66991C273301 -- C:\Windows\assembly\tmp\RC1QIJ5U\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
  2725. [2012/03/25 18:23:40 | 000,000,904 | ---- | M] () MD5=4F7AB727B60621BB36E47B682F4BFE23 -- C:\Windows\assembly\tmp\RC1QIJ5U\VK2ZYWCG
  2726. [2012/03/25 18:24:02 | 000,206,720 | ---- | M] () MD5=E1C01B2AF154DE8C5FBF322C22929D5B -- C:\Windows\assembly\tmp\REHNL1GI\microsoft.office.businessdata.intl.dll
  2727. [2012/03/25 17:11:40 | 000,016,384 | ---- | M] () MD5=E1EEB7E26AB04075EECC7275239B20B3 -- C:\Windows\assembly\tmp\RF4D8EB5\stdole.dll
  2728. [2012/03/25 17:11:25 | 000,004,608 | ---- | M] () MD5=F8D11C60B70ACD2EC9154EE676F615BA -- C:\Windows\assembly\tmp\RGOULN5A\extensibility.dll
  2729. [2012/03/25 17:56:03 | 000,230,480 | ---- | M] () MD5=915B2E2620D09B0EE7C10DCEB765916C -- C:\Windows\assembly\tmp\RIVAKSTF\System.Data.SqlServerCe.Entity.dll
  2730. [2012/03/25 18:23:51 | 000,115,744 | ---- | M] () MD5=01B68622F7B4A699D52F9A0B5EA5E4EC -- C:\Windows\assembly\tmp\ROBBZK0O\Microsoft.Synchronization.Data.dll
  2731. [2012/03/25 17:56:02 | 000,004,608 | ---- | M] () MD5=F8D11C60B70ACD2EC9154EE676F615BA -- C:\Windows\assembly\tmp\RQW1JK70\extensibility.dll
  2732. [2012/03/25 17:55:45 | 000,329,632 | ---- | M] () MD5=5DDDB6F96BF41B9FE9C4AB0920A0E445 -- C:\Windows\assembly\tmp\RRJOEJUQ\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
  2733. [2012/03/25 18:23:27 | 000,271,440 | ---- | M] () MD5=EE63BE840C77AA9DDDD5BF66BCF98F87 -- C:\Windows\assembly\tmp\RSHSQSZS\System.Data.SqlServerCe.dll
  2734. [2012/03/25 17:56:09 | 000,011,664 | ---- | M] () MD5=01DC8872B977B52FCF94C6B37E2E3EAB -- C:\Windows\assembly\tmp\RSOFVLUH\policy.12.0.Microsoft.Office.Interop.InfoPath.dll
  2735. [2012/03/25 17:56:03 | 000,115,744 | ---- | M] () MD5=01B68622F7B4A699D52F9A0B5EA5E4EC -- C:\Windows\assembly\tmp\RXWSB85E\Microsoft.Synchronization.Data.dll
  2736. [2012/03/25 17:56:02 | 000,356,352 | ---- | M] () MD5=0A8FCA67378EC92E2F304E6750DD9FD1 -- C:\Windows\assembly\tmp\RY7MWIN4\Microsoft.Office.Tools.Common.v9.0.dll
  2737. [2012/03/25 17:11:21 | 000,011,656 | ---- | M] () MD5=A34037B99EBD76FA30D73E6C8503E8BA -- C:\Windows\assembly\tmp\RZ45DTRM\Policy.12.0.Microsoft.Office.Interop.Word.dll
  2738. [2012/03/25 17:56:15 | 000,036,864 | ---- | M] () MD5=AD54FE98130FA82E5A75A1906F7F14A9 -- C:\Windows\assembly\tmp\S1KA5C83\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll
  2739. [2012/03/25 18:23:41 | 000,011,104 | ---- | M] () MD5=FC885793EAC0A87C43C8F5D6EF5B45B2 -- C:\Windows\assembly\tmp\S5AO4Z2H\Policy.11.0.Office.dll
  2740. [2012/03/25 18:23:41 | 000,046,968 | ---- | M] () MD5=475A31C143A723A68B3CBDDB91142650 -- C:\Windows\assembly\tmp\S8FGGKA3\Microsoft.Office.Interop.OneNote.dll
  2741. [2012/03/25 18:23:43 | 000,110,592 | ---- | M] () MD5=7ECB661F50F34A941A44DAC7241F7D08 -- C:\Windows\assembly\tmp\SAWK5ZKK\adodb.dll
  2742. [2012/03/25 17:55:56 | 000,011,104 | ---- | M] () MD5=FC885793EAC0A87C43C8F5D6EF5B45B2 -- C:\Windows\assembly\tmp\SDVGQSFT\Policy.11.0.Office.dll
  2743. [2012/03/25 17:11:19 | 000,011,104 | ---- | M] () MD5=FC885793EAC0A87C43C8F5D6EF5B45B2 -- C:\Windows\assembly\tmp\SL18S4T8\Policy.11.0.Office.dll
  2744. [2012/03/25 13:31:14 | 000,011,664 | ---- | M] () MD5=719B94FFCC629739E2AEC68D70F2F77A -- C:\Windows\assembly\tmp\SL4NI0YB\Policy.12.0.Microsoft.Office.Interop.Publisher.dll
  2745. [2012/03/25 17:55:56 | 000,019,320 | ---- | M] () MD5=2320EAD15BF728EC8FF5C9075B4A7B1F -- C:\Windows\assembly\tmp\SNLDLF7A\Microsoft.Office.Interop.SmartTag.dll
  2746. [2012/03/25 17:56:02 | 000,438,272 | ---- | M] () MD5=409B1D3ED9ECAAB3D7DA66A83E1161A9 -- C:\Windows\assembly\tmp\SP369FK3\Microsoft.Office.Tools.Excel.v9.0.dll
  2747. [2012/03/25 17:11:10 | 000,329,632 | ---- | M] () MD5=5DDDB6F96BF41B9FE9C4AB0920A0E445 -- C:\Windows\assembly\tmp\SPNQS1Q4\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
  2748. [2012/03/25 17:56:16 | 000,004,096 | ---- | M] () MD5=AAA2E20588E154A10747BF1B31B55125 -- C:\Windows\assembly\tmp\SPZX5B4U\msdatasrc.dll
  2749. [2012/03/25 17:56:18 | 000,972,664 | ---- | M] () MD5=D50EA922CCA0943744AB75E016BDE25E -- C:\Windows\assembly\tmp\SRUETNMH\Microsoft.Office.Interop.Outlook.dll
  2750. [2012/03/25 18:24:16 | 000,065,536 | ---- | M] () MD5=81ADD0B914DBF2C534BBAB1F3F4D78FF -- C:\Windows\assembly\tmp\SWWA3NGT\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.dll
  2751. [2012/03/25 17:55:45 | 000,086,016 | ---- | M] () MD5=258BA858D1A21F816B2C7F8B947C9C9D -- C:\Windows\assembly\tmp\T3WM4OC5\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.dll
  2752. [2012/03/25 18:23:37 | 000,956,288 | ---- | M] () MD5=5F20CC1396134D409FB641CC6F78623C -- C:\Windows\assembly\tmp\T71UHED5\microsoft.office.businessdata.dll
  2753. [2012/03/25 13:31:25 | 000,011,664 | ---- | M] () MD5=8D8DBB9C4811EC4255B878D50D06B627 -- C:\Windows\assembly\tmp\T7LCZX92\Policy.12.0.Microsoft.Office.Interop.SmartTag.dll
  2754. [2012/03/25 17:55:39 | 000,011,656 | ---- | M] () MD5=91EA1E932FDFFD3D8E73324C7E957DF8 -- C:\Windows\assembly\tmp\T7QRZMVZ\Policy.11.0.Microsoft.Office.Interop.Access.dll
  2755. [2012/03/25 18:24:11 | 000,036,864 | ---- | M] () MD5=AD54FE98130FA82E5A75A1906F7F14A9 -- C:\Windows\assembly\tmp\TAAN9UW1\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll
  2756. [2012/03/25 13:31:22 | 000,011,656 | ---- | M] () MD5=7EAF6D9700040029FA01375A920B521F -- C:\Windows\assembly\tmp\TL8HY2FR\Policy.11.0.Microsoft.Office.Interop.Excel.dll
  2757. [2012/03/25 18:23:40 | 000,065,536 | ---- | M] () MD5=4167FAFE231BE780D7158B0A7E5D337D -- C:\Windows\assembly\tmp\TMVI7QGY\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.dll
  2758. [2012/03/25 17:11:09 | 000,299,008 | ---- | M] () MD5=8447FB78623AACCCFC609F01D1723935 -- C:\Windows\assembly\tmp\TN17OHOU\Microsoft.Office.Tools.Word.v9.0.dll
  2759. [2012/03/25 17:11:19 | 000,011,664 | ---- | M] () MD5=761343B53E834E3587E7517D37FE9D56 -- C:\Windows\assembly\tmp\TNIFV35W\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
  2760. [2012/03/25 17:11:25 | 000,028,672 | ---- | M] () MD5=6F6421474D6D385A473640A0CA79695C -- C:\Windows\assembly\tmp\TRUD98N0\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll
  2761. [2012/03/25 18:23:43 | 000,011,656 | ---- | M] () MD5=0C560FE70843B466E8364DD2BC878F97 -- C:\Windows\assembly\tmp\TSW5BM6N\Policy.11.0.Microsoft.Office.Interop.Word.dll
  2762. [2012/03/25 13:31:12 | 008,007,680 | ---- | M] () MD5=5440EE9CD44616D60CDE57EBDB286E95 -- C:\Windows\assembly\tmp\TT29NEEX\Microsoft.mshtml.dll
  2763. [2012/03/25 13:31:17 | 000,011,656 | ---- | M] () MD5=2BD0AF3F15E24A3B97E4453357BCAD3E -- C:\Windows\assembly\tmp\TU3YMX0P\Policy.11.0.Microsoft.Office.Interop.Word.dll
  2764. [2012/03/25 13:31:17 | 000,011,656 | ---- | M] () MD5=A7D719DF8AB1D3C9278C279C1D273ACF -- C:\Windows\assembly\tmp\TXQNYYUS\Policy.12.0.Microsoft.Office.Interop.Word.dll
  2765. [2012/03/25 18:23:48 | 000,049,152 | ---- | M] () MD5=77249A017C234EC21BC60DABB8515896 -- C:\Windows\assembly\tmp\U0VO1ITR\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll
  2766. [2012/03/25 18:23:28 | 000,149,368 | ---- | M] () MD5=83018ECFFD3DB34BF89C0CA0D40A214C -- C:\Windows\assembly\tmp\U2LFE4YG\Microsoft.Office.Interop.Graph.dll
  2767. [2012/03/25 17:11:37 | 000,065,536 | ---- | M] () MD5=81ADD0B914DBF2C534BBAB1F3F4D78FF -- C:\Windows\assembly\tmp\U2Z8U54M\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.dll
  2768. [2012/03/25 17:55:55 | 000,077,824 | ---- | M] () MD5=DC553264A749613C331C8B989A1A9B2A -- C:\Windows\assembly\tmp\U358TZGV\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll
  2769. [2012/03/25 13:31:23 | 000,011,656 | ---- | M] () MD5=A5B6A68F5F4075BBCBC287C371972FC2 -- C:\Windows\assembly\tmp\U5V1JNHR\Policy.12.0.Microsoft.Office.Interop.Graph.dll
  2770. [2012/03/25 17:55:52 | 000,206,720 | ---- | M] () MD5=D42F1D676FE013CB02087394B57EAA16 -- C:\Windows\assembly\tmp\U8EU1J7I\Microsoft.SharePoint.BusinessData.Administration.Client.Intl.dll
  2771. [2012/03/25 17:55:45 | 000,022,016 | ---- | M] () MD5=6581FE75715D9D6FF9BFD2264F825FB0 -- C:\Windows\assembly\tmp\UB4W1EK3\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll
  2772. [2012/03/25 17:11:31 | 000,011,664 | ---- | M] () MD5=01DC8872B977B52FCF94C6B37E2E3EAB -- C:\Windows\assembly\tmp\UBHM4JVD\policy.12.0.Microsoft.Office.Interop.InfoPath.dll
  2773. [2012/03/25 18:24:05 | 000,665,472 | ---- | M] () MD5=4BD743C646EE2F47DDFEEAC9393E7033 -- C:\Windows\assembly\tmp\UL5R9099\Microsoft.Office.BusinessApplications.RuntimeUi.dll
  2774. [2012/03/25 17:11:17 | 000,040,960 | ---- | M] () MD5=8C4B96CB6644CC8914C44EA2193959B0 -- C:\Windows\assembly\tmp\UMYO7A4N\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll
  2775. [2012/03/25 17:55:51 | 000,011,664 | ---- | M] () MD5=B4285A86FC714CC0574B9070FB0E511F -- C:\Windows\assembly\tmp\UN9EHK6T\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.dll
  2776. [2012/03/25 17:11:26 | 000,230,480 | ---- | M] () MD5=915B2E2620D09B0EE7C10DCEB765916C -- C:\Windows\assembly\tmp\UOQIHDE1\System.Data.SqlServerCe.Entity.dll
  2777. [2012/03/25 18:23:54 | 000,042,880 | ---- | M] () MD5=CF202A917D36E48FAD6F57115D643536 -- C:\Windows\assembly\tmp\UQUW0BN7\microsoft.office.infopath.formcontrol.dll
  2778. [2012/03/25 17:56:18 | 000,011,672 | ---- | M] () MD5=45EC3053444CA47BB540E7036F50C0BA -- C:\Windows\assembly\tmp\US74AAZ8\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.dll
  2779. [2012/03/25 18:23:51 | 000,095,312 | ---- | M] () MD5=CDB528E57C8B2F62B773E6224CB811DE -- C:\Windows\assembly\tmp\UUI7KNPR\Microsoft.Synchronization.Data.SqlServerCe.dll
  2780. [2012/03/25 17:11:26 | 000,045,056 | ---- | M] () MD5=0EBF536E40253273365C3C26A37D57EF -- C:\Windows\assembly\tmp\UYC9OQFV\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.dll
  2781. [2012/03/25 17:11:10 | 000,149,368 | ---- | M] () MD5=83018ECFFD3DB34BF89C0CA0D40A214C -- C:\Windows\assembly\tmp\V3B2MHD2\Microsoft.Office.Interop.Graph.dll
  2782. [2012/03/25 13:31:10 | 000,028,672 | ---- | M] () MD5=6F6421474D6D385A473640A0CA79695C -- C:\Windows\assembly\tmp\V3ECH47Z\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll
  2783. [2012/03/25 18:23:37 | 000,018,304 | ---- | M] () MD5=3E473BF3BBA2B5A7EE19D47BD7E1BC80 -- C:\Windows\assembly\tmp\V72FIFW1\Microsoft.Office.BusinessApplications.Runtime.Intl.dll
  2784. [2012/03/25 18:24:16 | 000,094,208 | ---- | M] () MD5=CF53CB86A8D49F5CCA58D8FF8AE246A9 -- C:\Windows\assembly\tmp\VE4H9RIE\Microsoft.Office.Tools.v9.0.dll
  2785. [2012/03/25 18:24:20 | 000,247,680 | ---- | M] () MD5=DFC7276D34F4B66518A32F9AF48BA3F9 -- C:\Windows\assembly\tmp\VJKWGSN9\Microsoft.Office.Interop.Publisher.dll
  2786. [2012/03/25 17:55:46 | 000,086,016 | ---- | M] () MD5=F2116B93B569552FA9964ECF0090CF00 -- C:\Windows\assembly\tmp\VOT5LOLH\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll
  2787. [2012/03/25 17:56:07 | 000,140,200 | ---- | M] () MD5=07C649EDCCEB97CBAF976053D2392CC8 -- C:\Windows\assembly\tmp\VQG734U2\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
  2788. [2012/03/25 13:31:26 | 000,016,248 | ---- | M] () MD5=C41AE505E62434EB08F42EBEC6DBEB2C -- C:\Windows\assembly\tmp\VSB7GQS1\Microsoft.Office.Interop.OneNote.dll
  2789. [2012/03/25 17:55:57 | 000,011,656 | ---- | M] () MD5=F09CDD3138E5EFC8662CC948636F53A5 -- C:\Windows\assembly\tmp\VSUY10HW\Policy.12.0.Microsoft.Office.Interop.Outlook.dll
  2790. [2012/03/25 17:56:19 | 000,000,902 | ---- | M] () MD5=44193BB603AD240A860033F7EFC2E7E8 -- C:\Windows\assembly\tmp\VSUY10HW\WPCBGTC8
  2791. [2012/03/25 17:11:36 | 000,053,248 | ---- | M] () MD5=07E7E7818586A3B3F1EC50E5E2511FC0 -- C:\Windows\assembly\tmp\VVAB44OX\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.dll
  2792. [2012/03/25 17:11:10 | 000,038,832 | ---- | M] () MD5=CC5ECB09FFDD2A7915E3E98A15DF262E -- C:\Windows\assembly\tmp\VWKGTQJY\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
  2793. [2012/03/25 17:11:09 | 000,011,656 | ---- | M] () MD5=879AA1B9EB9923C303737F9A9684E654 -- C:\Windows\assembly\tmp\VXD7WEHA\Policy.11.0.Microsoft.Office.Interop.Excel.dll
  2794. [2012/03/25 18:23:27 | 000,115,744 | ---- | M] () MD5=DA5EE020BEF41DC95C3532CBAA1EA8F4 -- C:\Windows\assembly\tmp\W6S1AON2\Microsoft.Synchronization.Data.Server.dll
  2795. [2012/03/25 18:23:25 | 000,385,024 | ---- | M] () MD5=6F6C2FEB15AFB745C8BF7D0277D2DBBF -- C:\Windows\assembly\tmp\W6TU7ABN\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll
  2796. [2012/03/25 17:11:10 | 000,086,016 | ---- | M] () MD5=258BA858D1A21F816B2C7F8B947C9C9D -- C:\Windows\assembly\tmp\W7PIU09V\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.dll
  2797. [2012/03/25 17:11:19 | 000,011,104 | ---- | M] () MD5=BF675629E050915C92D6D66F72B2AEB6 -- C:\Windows\assembly\tmp\W95JUA9W\Policy.12.0.Office.dll
  2798. [2012/03/25 17:11:26 | 000,115,744 | ---- | M] () MD5=01B68622F7B4A699D52F9A0B5EA5E4EC -- C:\Windows\assembly\tmp\WCLJBTR3\Microsoft.Synchronization.Data.dll
  2799. [2012/03/25 13:31:08 | 000,116,632 | ---- | M] () MD5=668818ADBB2240C42567907FC1044E6E -- C:\Windows\assembly\tmp\WEF8JH6R\Microsoft.BusinessData.dll
  2800. [2012/03/25 17:56:18 | 000,448,360 | ---- | M] () MD5=2D53B9BDBB63C6D7003A1717C9AE7346 -- C:\Windows\assembly\tmp\WKMSI3XY\OFFICE.DLL
  2801. [2012/03/25 13:31:18 | 000,136,624 | ---- | M] () MD5=F8330DA53EA42B4080EBBA5D20E40F66 -- C:\Windows\assembly\tmp\WM989SIO\Microsoft.Office.Access.BusinessDataCatalog.DLL
  2802. [2012/03/25 17:55:52 | 000,018,304 | ---- | M] () MD5=3E473BF3BBA2B5A7EE19D47BD7E1BC80 -- C:\Windows\assembly\tmp\WWI6159L\Microsoft.Office.BusinessApplications.Runtime.Intl.dll
  2803. [2012/03/25 17:55:45 | 000,028,672 | ---- | M] () MD5=4C0E0A5A2D17F67E7DA61822EAE226F4 -- C:\Windows\assembly\tmp\X0NOA9V6\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll
  2804. [2012/03/25 17:55:57 | 000,011,664 | ---- | M] () MD5=AA8582B922BF6A110AD1422B40950720 -- C:\Windows\assembly\tmp\X0O9VGGJ\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
  2805. [2012/03/25 17:56:20 | 000,000,906 | ---- | M] () MD5=449F5367C27EBC6CB917460F0DE2B0CB -- C:\Windows\assembly\tmp\X0O9VGGJ\X7YWI92H
  2806. [2012/03/25 17:11:11 | 000,059,248 | ---- | M] () MD5=D45565A49811DD248532076D4374BD43 -- C:\Windows\assembly\tmp\XB0DKCJJ\Microsoft.Office.Infopath.dll
  2807. [2012/03/25 17:56:04 | 000,011,656 | ---- | M] () MD5=71D8A3D576F2E236B91D30608B887853 -- C:\Windows\assembly\tmp\XD7WJRAH\Policy.12.0.Microsoft.Office.Interop.Graph.dll
  2808. [2012/03/25 17:11:11 | 000,011,664 | ---- | M] () MD5=0826CD2CA41B5ACD3DA5164FEEA7022D -- C:\Windows\assembly\tmp\XJV92VEW\policy.12.0.Microsoft.Office.InfoPath.FormControl.dll
  2809. [2012/03/25 17:11:29 | 000,000,912 | ---- | M] () MD5=8178E3FB89E1EE2F91F678D5E13367BF -- C:\Windows\assembly\tmp\XJV92VEW\XBVY4AR6
  2810. [2012/03/25 17:55:55 | 000,040,960 | ---- | M] () MD5=8C4B96CB6644CC8914C44EA2193959B0 -- C:\Windows\assembly\tmp\XKK553CJ\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll
  2811. [2012/03/25 17:56:20 | 000,011,640 | ---- | M] () MD5=7063FF7154582442F6F533F12B3F0F20 -- C:\Windows\assembly\tmp\XP9PXEY6\Policy.12.0.Microsoft.Vbe.Interop.dll
  2812. [2012/03/25 17:55:58 | 000,000,880 | ---- | M] () MD5=C96C6F48979A5F9F131AA9FCB228B0D1 -- C:\Windows\assembly\tmp\XP9PXEY6\ZJWTVW7G
  2813. [2012/03/25 13:31:28 | 000,907,120 | ---- | M] () MD5=386CC49F35BE2A90E2E3339619102BF3 -- C:\Windows\assembly\tmp\XRMHKZVX\Microsoft.Office.Interop.Word.dll
  2814. [2012/03/25 18:23:48 | 000,028,672 | ---- | M] () MD5=6F6421474D6D385A473640A0CA79695C -- C:\Windows\assembly\tmp\XU1IDKM2\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll
  2815. [2012/03/25 17:11:36 | 000,427,904 | ---- | M] () MD5=01223E1CC857F8399368D8A61BAF24B1 -- C:\Windows\assembly\tmp\Y2N3H6I2\Microsoft.Office.BusinessApplications.Tools.dll
  2816. [2012/03/25 18:23:43 | 000,079,744 | ---- | M] () MD5=DC036E7CE4F62CF27D915C3FF3F7DF52 -- C:\Windows\assembly\tmp\Y4E1PR6T\Microsoft.Office.interop.access.dao.dll
  2817. [2012/03/25 13:31:10 | 000,143,360 | ---- | M] () MD5=BF1B6B22209E8126A184BFA2C4FB49BE -- C:\Windows\assembly\tmp\Y59FLBEC\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll
  2818. [2012/03/25 13:31:23 | 000,385,024 | ---- | M] () MD5=6F6C2FEB15AFB745C8BF7D0277D2DBBF -- C:\Windows\assembly\tmp\Y9GDNVJ1\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll
  2819. [2012/03/25 18:23:49 | 000,071,592 | ---- | M] () MD5=5949DF7B1BF7951C55A31803CD4DC6E2 -- C:\Windows\assembly\tmp\Y9NMYFKW\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
  2820. [2012/03/25 17:11:15 | 000,011,664 | ---- | M] () MD5=EA39607C138BBADB76883FBCBD264AC4 -- C:\Windows\assembly\tmp\YHEMA7NR\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
  2821. [2012/03/25 17:55:59 | 000,079,744 | ---- | M] () MD5=DC036E7CE4F62CF27D915C3FF3F7DF52 -- C:\Windows\assembly\tmp\YHSGP30I\Microsoft.Office.interop.access.dao.dll
  2822. [2012/03/25 17:11:19 | 000,011,656 | ---- | M] () MD5=F09CDD3138E5EFC8662CC948636F53A5 -- C:\Windows\assembly\tmp\YX4ARO7Y\Policy.12.0.Microsoft.Office.Interop.Outlook.dll
  2823. [2012/03/25 18:24:21 | 000,016,384 | ---- | M] () MD5=E1EEB7E26AB04075EECC7275239B20B3 -- C:\Windows\assembly\tmp\YZLFKL7A\stdole.dll
  2824. [2012/03/25 17:55:45 | 000,038,832 | ---- | M] () MD5=CC5ECB09FFDD2A7915E3E98A15DF262E -- C:\Windows\assembly\tmp\Z3FCBWRV\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
  2825. [2012/03/25 18:23:54 | 000,407,440 | ---- | M] () MD5=BEEF1231C4AF6BDB0E26497970EE6DDE -- C:\Windows\assembly\tmp\Z3YJ4Y51\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
  2826. [2012/03/25 13:31:27 | 000,011,640 | ---- | M] () MD5=AC9E566B2E1EF289B6B44934CA3CB160 -- C:\Windows\assembly\tmp\Z9C47V1U\Policy.12.0.Microsoft.Vbe.Interop.dll
  2827. [2012/03/25 13:31:16 | 000,000,880 | ---- | M] () MD5=C96C6F48979A5F9F131AA9FCB228B0D1 -- C:\Windows\assembly\tmp\Z9C47V1U\REVAG6EB
  2828. [2012/03/25 17:11:04 | 000,011,656 | ---- | M] () MD5=91EA1E932FDFFD3D8E73324C7E957DF8 -- C:\Windows\assembly\tmp\Z9DARTCT\Policy.11.0.Microsoft.Office.Interop.Access.dll
  2829. [2012/03/25 18:23:30 | 000,546,704 | ---- | M] () MD5=46B44E2EC2A58FD51278CAE5CE1AF801 -- C:\Windows\assembly\tmp\ZAGIGUOI\Microsoft.Office.Infopath.Client.Internal.Host.dll
  2830. [2012/03/25 17:55:45 | 000,011,656 | ---- | M] () MD5=879AA1B9EB9923C303737F9A9684E654 -- C:\Windows\assembly\tmp\ZBUE51U0\Policy.11.0.Microsoft.Office.Interop.Excel.dll
  2831. [2012/03/25 17:56:02 | 000,000,898 | ---- | M] () MD5=E3C1C0D2C327FEC85FB9857E3F899785 -- C:\Windows\assembly\tmp\ZBUE51U0\RL2VSL89
  2832. [2012/03/25 18:24:21 | 000,907,120 | ---- | M] () MD5=271D2874EE8021B10D6DF89307F9D463 -- C:\Windows\assembly\tmp\ZX94RBE0\Microsoft.Office.Interop.Word.dll
  2833.  
  2834. [color=#A23BEC]< %systemroot%\assembly\temp\*.* /S /MD5 >[/color]
  2835.  
  2836. [color=#A23BEC]< %systemroot%\assembly\GAC\*.ini >[/color]
  2837.  
  2838. [color=#A23BEC]< %systemroot%\assembly\GAC_32\*.ini >[/color]
  2839.  
  2840. [color=#A23BEC]< %systemroot%\assembly\GAC_64\*.ini >[/color]
  2841.  
  2842. [color=#A23BEC]< %SystemRoot%\assembly\GAC_MSIL\*.ini >[/color]
  2843.  
  2844. [color=#A23BEC]< wsSystemRoot|l,n,u,@;True;False;True;$,{ /fn >[/color]
  2845.  
  2846. [color=#A23BEC]< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >[/color]
  2847.  
  2848. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color]
  2849. "" = PSFactoryBuffer
  2850. [HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32]
  2851. "" = %systemroot%\system32\wbem\wbemsvc.dll -- [2009/07/13 19:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation)
  2852. "ThreadingModel" = Both
  2853.  
  2854. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color]
  2855.  
  2856. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color]
  2857.  
  2858. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color]
  2859.  
  2860. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color]
  2861. "" = MruPidlList
  2862. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  2863. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  2864. "ThreadingModel" = Apartment
  2865.  
  2866. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} /s >[/color]
  2867. "" = Start Menu Pin
  2868. "ImplementsVerbs" = startpin;startunpin
  2869. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}\InProcServer32]
  2870. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  2871. "ThreadingModel" = Apartment
  2872.  
  2873. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color]
  2874. "" = PSFactoryBuffer
  2875. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32]
  2876. "" = %systemroot%\system32\wbem\wbemsvc.dll -- [2009/07/13 19:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation)
  2877. "ThreadingModel" = Both
  2878.  
  2879. [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color]
  2880. "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper
  2881. [HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32]
  2882. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
  2883. "ThreadingModel" = Free
  2884.  
  2885. [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color]
  2886. "" = ShellFolder for CD Burning
  2887. [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  2888. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  2889. "ThreadingModel" = Apartment
  2890. [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\MergedFolder]
  2891. "Attributes" = 0x0
  2892. "AttributeMask" = 0xffffffff
  2893. "Location" = @shell32.dll,-12591 -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  2894. "ConflictOverlayIcon" = %SystemRoot%\system32\imageres.dll,-169 -- [2009/07/13 19:06:03 | 020,268,032 | ---- | M] (Microsoft Corporation)
  2895.  
  2896. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color]
  2897.  
  2898. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color]
  2899. "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper
  2900. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32]
  2901. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
  2902. "ThreadingModel" = Free
  2903.  
  2904. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\clsid\{12d0253a-7c96-815c-11e0-3034bbd97cc0}] /s >[/color]
  2905.  
  2906. [color=#A23BEC]< HKEY_CURRENT_USER\Software\MSOLoad /s >[/color]
  2907.  
  2908. [color=#A23BEC]< bcdedit /enum all /v >C:\boot.txt /c >[/color]
  2909.  
  2910. [color=#A23BEC]< type c:\diskreport.txt /c >[/color]
  2911. Microsoft DiskPart version 6.1.7601
  2912. Copyright (C) 1999-2008 Microsoft Corporation.
  2913. On computer: HOME-PC
  2914. Volume ### Ltr Label Fs Type Size Status Info
  2915. ---------- --- ----------- ----- ---------- ------- --------- --------
  2916. Volume 0 D DVD-ROM 0 B No Media
  2917. Volume 1 J DVD-ROM 0 B No Media
  2918. Volume 2 RECOVERY NTFS Partition 13 GB Healthy System
  2919. Volume 3 C OS NTFS Partition 917 GB Healthy Boot
  2920. Volume 4 E Removable 0 B No Media
  2921. Volume 5 F Removable 0 B No Media
  2922. Volume 6 G Removable 0 B No Media
  2923. Volume 7 H Removable 0 B No Media
  2924. Volume 8 L My Passport NTFS Partition 465 GB Healthy
  2925.  
  2926. [color=#A23BEC]< MD5 for: AFD.SYS >[/color]
  2927. [2011/12/27 21:59:24 | 000,498,688 | ---- | M] (Microsoft Corporation) MD5=1C7857B62DE5994A75B054A9FD4C3825 -- C:\Windows\SysNative\drivers\afd.sys
  2928. [2011/12/27 21:59:24 | 000,498,688 | ---- | M] (Microsoft Corporation) MD5=1C7857B62DE5994A75B054A9FD4C3825 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17752_none_35e10b89752ee0f5\afd.sys
  2929. [2011/12/27 22:01:36 | 000,498,176 | ---- | M] (Microsoft Corporation) MD5=36A14FD1A23F57046361733B792CA8DB -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21887_none_364f3a028e605345\afd.sys
  2930. [2010/11/20 21:24:08 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=D31DC7A16DEA4A9BAF179F3D6FBDB38C -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_360e4801750ca991\afd.sys
  2931. [2011/04/24 20:34:03 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=D5B031C308A409A0A576BFF4CF083D30 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_3618198975057170\afd.sys
  2932. [2011/04/24 21:09:35 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=F4AD06143EAC303F55D0E86C40802976 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_3695e61e8e2c13d4\afd.sys
  2933.  
  2934. [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
  2935. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
  2936. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
  2937. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
  2938.  
  2939. [color=#A23BEC]< MD5 for: CNGAUDIT.DLL >[/color]
  2940. [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
  2941. [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
  2942. [2009/07/13 19:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
  2943. [2009/07/13 19:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
  2944.  
  2945. [color=#A23BEC]< MD5 for: CSC.SYS >[/color]
  2946. [2010/11/20 21:24:41 | 000,514,560 | ---- | M] (Microsoft Corporation) MD5=54DA3DFD29ED9F1619B6F53F3CE55E49 -- C:\Windows\winsxs\amd64_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7601.17514_none_fc6e4e567286d457\csc.sys
  2947.  
  2948. [color=#A23BEC]< MD5 for: DFSC.SYS >[/color]
  2949. [2010/11/20 21:24:32 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9BB2EF44EAA163B29C4A4587887A0FE4 -- C:\Windows\SysNative\drivers\dfsc.sys
  2950. [2010/11/20 21:24:32 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9BB2EF44EAA163B29C4A4587887A0FE4 -- C:\Windows\winsxs\amd64_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7601.17514_none_e5c0334cfcbb6f1f\dfsc.sys
  2951.  
  2952. [color=#A23BEC]< MD5 for: DISK.SYS >[/color]
  2953. [2009/07/13 19:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\drivers\disk.sys
  2954. [2009/07/13 19:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\DriverStore\FileRepository\disk.inf_amd64_neutral_10ce25bbc5a9cc43\disk.sys
  2955. [2009/07/13 19:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_55bb738b8ddd8a01\disk.sys
  2956.  
  2957. [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
  2958. [2011/02/25 23:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
  2959. [2011/02/25 00:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
  2960. [2011/02/25 00:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
  2961. [2011/02/26 00:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
  2962. [2010/11/20 21:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
  2963. [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
  2964. [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
  2965. [2010/11/20 21:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
  2966.  
  2967. [color=#A23BEC]< MD5 for: I8042PRT.SYS >[/color]
  2968. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\drivers\i8042prt.sys
  2969. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\i8042prt.sys
  2970. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_neutral_7a5f47d3150cc0eb\i8042prt.sys
  2971. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_f5747347ef9876bf\i8042prt.sys
  2972. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_aa28fd23ec0c39f9\i8042prt.sys
  2973.  
  2974. [color=#A23BEC]< MD5 for: LSASS.EXE >[/color]
  2975. [2009/07/13 19:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
  2976. [2011/11/17 00:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
  2977. [2012/08/24 11:43:36 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=77119F1F9B492B260030C34F9BE327FA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22099_none_04a88ce28cc4eb33\lsass.exe
  2978. [2012/06/04 01:51:10 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=79C908CAA6F43021EB05F4C733A927D1 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_04f609a88c8c279c\lsass.exe
  2979. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\SysNative\lsass.exe
  2980. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
  2981. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_044756c773895c5e\lsass.exe
  2982. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17940_none_044c26dd7386a58a\lsass.exe
  2983.  
  2984. [color=#A23BEC]< MD5 for: NETBT.SYS >[/color]
  2985. [2010/11/20 21:23:51 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=09594D1089C523423B32A4229263F068 -- C:\Windows\SysNative\drivers\netbt.sys
  2986. [2010/11/20 21:23:51 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=09594D1089C523423B32A4229263F068 -- C:\Windows\winsxs\amd64_microsoft-windows-netbt_31bf3856ad364e35_6.1.7601.17514_none_be8acdd10de3b1a6\netbt.sys
  2987.  
  2988. [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
  2989. [2010/11/20 21:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
  2990. [2010/11/20 21:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
  2991. [2010/11/20 21:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
  2992. [2010/11/20 21:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
  2993.  
  2994. [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
  2995. [2010/11/20 21:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
  2996. [2010/11/20 21:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
  2997. [2010/11/20 21:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
  2998. [2010/11/20 21:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
  2999.  
  3000. [color=#A23BEC]< MD5 for: SERIAL.SYS >[/color]
  3001. [2009/07/13 18:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\SysNative\drivers\serial.sys
  3002. [2009/07/13 18:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\SysNative\DriverStore\FileRepository\msports.inf_amd64_neutral_fdcfb86ce78678d1\serial.sys
  3003. [2009/07/13 18:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\winsxs\amd64_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_548ca258d20f4ada\serial.sys
  3004.  
  3005. [color=#A23BEC]< MD5 for: SERVICES.EXE >[/color]
  3006. [2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
  3007. [2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
  3008.  
  3009. [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
  3010. [2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
  3011. [2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
  3012. [2012/09/29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
  3013. [2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
  3014. [2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
  3015.  
  3016. [color=#A23BEC]< MD5 for: TCPIP.SYS >[/color]
  3017. [2012/10/03 11:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\SysNative\drivers\tcpip.sys
  3018. [2012/10/03 11:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
  3019. [2011/09/29 11:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
  3020. [2010/11/20 21:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
  3021. [2012/08/22 12:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
  3022. [2012/03/30 04:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
  3023. [2011/04/24 23:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
  3024. [2011/06/21 00:20:30 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
  3025. [2012/03/30 05:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
  3026. [2011/04/25 00:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
  3027. [2011/06/02 20:45:32 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
  3028. [2012/10/03 11:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
  3029. [2011/06/02 20:45:32 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
  3030. [2011/06/21 00:34:00 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
  3031. [2012/08/22 12:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
  3032. [2011/09/29 10:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
  3033.  
  3034. [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
  3035. [2010/11/20 21:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
  3036. [2010/11/20 21:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
  3037. [2010/11/20 21:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
  3038. [2010/11/20 21:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
  3039.  
  3040. [color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color]
  3041. [2010/11/20 21:23:47 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\SysNative\drivers\volsnap.sys
  3042. [2010/11/20 21:23:47 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_neutral_df8bea40ac96ca21\volsnap.sys
  3043. [2010/11/20 21:23:47 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7601.17514_none_73dcbcf012b4850e\volsnap.sys
  3044.  
  3045. [color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
  3046. [2009/07/13 19:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
  3047. [2009/07/13 19:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
  3048. [2009/07/13 19:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
  3049. [2009/07/13 19:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
  3050.  
  3051. [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
  3052. [2010/11/20 21:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
  3053. [2010/11/20 21:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
  3054. [2012/09/29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
  3055.  
  3056. [color=#E56717]========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[/color]
  3057. [C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3058. [C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
  3059. [C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3060. [C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
  3061. [C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3062. [C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
  3063. [C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
  3064. [C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
  3065. [C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3066. [C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
  3067. [C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3068. [C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3069. [C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3070. [C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3071. [C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3072. [C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3073. [C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3074. [C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
  3075. [C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3076. [C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
  3077. [C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3078. [C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
  3079. [C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
  3080. [C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
  3081. [C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3082. [C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
  3083. [C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3084. [C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3085. [C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3086. [C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3087. [C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3088. [C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3089.  
  3090. [color=#E56717]========== Alternate Data Streams ==========[/color]
  3091.  
  3092. @Alternate Data Stream - 240 bytes -> C:\ProgramData\Temp:1E17A249
  3093. @Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:EFBD4447
  3094. @Alternate Data Stream - 218 bytes -> C:\ProgramData\Temp:C9CDDE5E
  3095. @Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:DFC3B090
  3096.  
  3097. < End of report >
Add Comment
Please, Sign In to add comment