toxictexan

TT_OTL

Dec 10th, 2012
51
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 193.19 KB | None | 0 0
  1. OTL logfile created on: 12/10/2012 12:23:55 AM - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deanne\Desktop
  3. 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.0.8112.16421)
  5. Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
  6.  
  7. 3.75 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 53.96% Memory free
  8. 7.50 Gb Paging File | 5.42 Gb Available in Paging File | 72.28% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 916.38 Gb Total Space | 761.51 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
  13. Drive D: | 15.03 Gb Total Space | 1.86 Gb Free Space | 12.37% Space Free | Partition Type: NTFS
  14.  
  15. Computer Name: DEANNE-HP | User Name: Deanne | Logged in as Administrator.
  16. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
  17. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
  18.  
  19. [color=#E56717]========== Processes (SafeList) ==========[/color]
  20.  
  21. PRC - [2012/12/10 00:20:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deanne\Desktop\OTL.scr
  22. PRC - [2012/12/08 11:39:26 | 000,916,960 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  23. PRC - [2012/11/01 08:52:54 | 000,875,728 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\Comodo\GeekBuddy\unit_manager.exe
  24. PRC - [2012/11/01 08:52:52 | 000,877,264 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\Comodo\GeekBuddy\unit.exe
  25. PRC - [2012/11/01 08:52:52 | 000,070,352 | ---- | M] (Comodo Security Solutions Inc.) -- C:\Program Files (x86)\Common Files\Comodo\launcher_service.exe
  26. PRC - [2012/10/31 15:46:38 | 001,467,088 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
  27. PRC - [2012/08/16 09:21:34 | 000,217,088 | ---- | M] (Code 42 Software, Inc.) -- C:\Program Files\CrashPlan\CrashPlanTray.exe
  28. PRC - [2012/07/27 14:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
  29. PRC - [2012/05/24 12:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Deanne\AppData\Roaming\Dropbox\bin\Dropbox.exe
  30. PRC - [2012/02/10 10:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
  31. PRC - [2012/02/10 10:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE
  32. PRC - [2011/01/17 17:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
  33. PRC - [2011/01/17 17:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
  34. PRC - [2010/07/14 09:29:24 | 000,026,168 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
  35. PRC - [2010/07/14 09:28:12 | 000,022,072 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
  36. PRC - [2010/06/23 13:09:36 | 000,125,552 | ---- | M] () -- C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
  37. PRC - [2010/06/18 15:30:46 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
  38. PRC - [2010/06/17 17:59:40 | 001,040,952 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
  39. PRC - [2010/06/12 19:06:08 | 000,400,368 | ---- | M] (CinemaNow, Inc.) -- C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe
  40. PRC - [2010/04/29 17:57:24 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
  41. PRC - [2010/04/16 16:34:34 | 000,109,168 | ---- | M] (Portrait Displays, Inc.) -- C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
  42. PRC - [2009/10/14 16:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe
  43. PRC - [2009/08/24 20:11:16 | 000,656,896 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
  44. PRC - [2008/11/20 11:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
  45. PRC - [2007/07/24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
  46.  
  47.  
  48. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  49.  
  50. MOD - [2012/12/08 11:39:00 | 002,397,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
  51. MOD - [2012/11/25 13:19:40 | 000,037,280 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\HP.ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll
  52. MOD - [2012/06/13 02:34:20 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
  53. MOD - [2012/06/13 02:33:57 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
  54. MOD - [2012/06/13 02:19:34 | 002,906,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\442af6f7c8b447bdec3ad8d23da89c5a\ReachFramework.ni.dll
  55. MOD - [2012/06/13 02:12:27 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll
  56. MOD - [2012/06/13 02:12:24 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
  57. MOD - [2012/06/13 02:12:18 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll
  58. MOD - [2012/06/13 02:12:17 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
  59. MOD - [2012/05/12 12:31:47 | 001,072,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\bd28f26b18b8ffeee1a0fbaa98f5810e\System.IdentityModel.ni.dll
  60. MOD - [2012/05/12 12:31:46 | 018,058,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll
  61. MOD - [2012/05/12 12:30:06 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\79ac99fe5274fb82ffcff2c15f71854c\System.Runtime.DurableInstancing.ni.dll
  62. MOD - [2012/05/12 12:30:06 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\bb97517e4ca64e02282fca24612ce8ad\SMDiagnostics.ni.dll
  63. MOD - [2012/05/12 12:30:05 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
  64. MOD - [2012/05/12 12:26:07 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
  65. MOD - [2012/05/12 12:23:59 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
  66. MOD - [2012/05/12 12:23:45 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
  67. MOD - [2012/05/12 12:23:44 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
  68. MOD - [2012/05/12 12:23:08 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
  69. MOD - [2012/05/12 12:23:03 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
  70. MOD - [2012/05/12 12:23:00 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
  71. MOD - [2012/05/12 12:22:59 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
  72. MOD - [2012/05/12 12:22:50 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
  73. MOD - [2012/05/09 22:25:31 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
  74. MOD - [2012/05/09 22:25:28 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
  75. MOD - [2012/05/09 22:25:26 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
  76. MOD - [2012/05/09 22:25:22 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
  77. MOD - [2012/05/09 22:25:17 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
  78. MOD - [2012/02/20 20:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
  79. MOD - [2012/02/20 20:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
  80. MOD - [2011/08/25 21:55:24 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
  81. MOD - [2011/03/16 23:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
  82. MOD - [2010/11/04 19:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
  83. MOD - [2010/10/20 14:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
  84. MOD - [2010/06/17 18:11:58 | 001,699,384 | ---- | M] () -- C:\Users\Deanne\AppData\Roaming\PictureMover\EN-US\Presentation.dll
  85. MOD - [2010/06/17 18:00:10 | 012,286,520 | ---- | M] () -- C:\Users\Deanne\AppData\Roaming\PictureMover\Bin\Core.dll
  86. MOD - [2010/02/09 19:58:30 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
  87. MOD - [2010/02/09 19:58:28 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll
  88. MOD - [2010/02/09 19:58:24 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingServer.dll
  89. MOD - [2010/02/09 19:58:24 | 000,007,680 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\RemotingClient.dll
  90. MOD - [2010/02/09 19:58:22 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingClients.dll
  91. MOD - [2010/02/09 19:58:22 | 000,005,632 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingInterface.dll
  92. MOD - [2010/02/09 19:58:18 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingMessages.dll
  93. MOD - [2010/02/09 19:58:14 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll
  94. MOD - [2009/07/13 19:15:45 | 000,364,544 | ---- | M] () -- C:\Windows\SysWOW64\msjetoledb40.dll
  95.  
  96.  
  97. [color=#E56717]========== Services (SafeList) ==========[/color]
  98.  
  99. SRV:[b]64bit:[/b] - [2012/11/07 17:37:39 | 002,828,408 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
  100. SRV:[b]64bit:[/b] - [2012/08/16 09:23:17 | 000,222,720 | ---- | M] (CrashPlan) [Auto | Running] -- C:\Program Files\CrashPlan\CrashPlanService.exe -- (CrashPlanService)
  101. SRV:[b]64bit:[/b] - [2012/03/26 17:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
  102. SRV:[b]64bit:[/b] - [2012/03/26 17:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
  103. SRV:[b]64bit:[/b] - [2010/05/12 00:16:12 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
  104. SRV:[b]64bit:[/b] - [2010/04/29 17:57:24 | 000,944,928 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
  105. SRV:[b]64bit:[/b] - [2009/11/17 05:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
  106. SRV - [2012/12/08 11:39:25 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
  107. SRV - [2012/11/01 08:52:52 | 000,070,352 | ---- | M] (Comodo Security Solutions Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Comodo\launcher_service.exe -- (CLPSLauncher)
  108. SRV - [2012/10/31 15:46:38 | 001,467,088 | ---- | M] (Comodo Security Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe -- (GeekBuddyRSP)
  109. SRV - [2012/09/27 11:55:16 | 000,086,528 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
  110. SRV - [2012/07/27 14:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
  111. SRV - [2012/02/10 10:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE -- (BBUpdate)
  112. SRV - [2012/02/10 10:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE -- (BBSvc)
  113. SRV - [2010/10/22 12:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\Hp\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
  114. SRV - [2010/07/14 09:28:12 | 000,022,072 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe -- (CalendarSynchService)
  115. SRV - [2010/06/23 13:09:36 | 000,125,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
  116. SRV - [2010/06/12 19:06:08 | 000,400,368 | ---- | M] (CinemaNow, Inc.) [Auto | Running] -- C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe -- (CinemaNow Service)
  117. SRV - [2010/06/01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
  118. SRV - [2010/04/16 16:34:34 | 000,109,168 | ---- | M] (Portrait Displays, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe -- (PdiService)
  119. SRV - [2010/04/03 17:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
  120. SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
  121. SRV - [2009/10/14 16:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
  122. SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  123. SRV - [2007/07/24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
  124.  
  125.  
  126. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  127.  
  128. DRV:[b]64bit:[/b] - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
  129. DRV:[b]64bit:[/b] - [2012/07/09 12:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
  130. DRV:[b]64bit:[/b] - [2012/03/20 19:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
  131. DRV:[b]64bit:[/b] - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  132. DRV:[b]64bit:[/b] - [2011/03/18 12:46:20 | 000,074,376 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ftdibus.sys -- (FTDIBUS)
  133. DRV:[b]64bit:[/b] - [2011/03/18 12:46:06 | 000,085,384 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ftser2k.sys -- (FTSER2K)
  134. DRV:[b]64bit:[/b] - [2010/11/20 07:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  135. DRV:[b]64bit:[/b] - [2010/11/20 05:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  136. DRV:[b]64bit:[/b] - [2010/11/11 03:01:20 | 001,212,416 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVerAVF2.sys -- (AVerAVF2)
  137. DRV:[b]64bit:[/b] - [2010/09/24 02:38:49 | 003,060,800 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
  138. DRV:[b]64bit:[/b] - [2010/07/13 18:57:08 | 000,069,736 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\itecir.sys -- (itecir)
  139. DRV:[b]64bit:[/b] - [2010/06/18 15:31:30 | 000,032,880 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
  140. DRV:[b]64bit:[/b] - [2010/05/12 00:46:18 | 006,790,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
  141. DRV:[b]64bit:[/b] - [2010/05/11 23:24:20 | 000,221,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
  142. DRV:[b]64bit:[/b] - [2010/05/03 16:44:02 | 000,331,880 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
  143. DRV:[b]64bit:[/b] - [2010/04/29 20:01:24 | 000,340,520 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
  144. DRV:[b]64bit:[/b] - [2010/04/29 20:00:36 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
  145. DRV:[b]64bit:[/b] - [2010/04/29 20:00:34 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
  146. DRV:[b]64bit:[/b] - [2010/04/29 20:00:34 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
  147. DRV:[b]64bit:[/b] - [2010/04/29 20:00:32 | 000,102,440 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
  148. DRV:[b]64bit:[/b] - [2010/03/10 09:33:52 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
  149. DRV:[b]64bit:[/b] - [2010/02/05 22:04:06 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  150. DRV:[b]64bit:[/b] - [2010/02/05 22:04:04 | 000,070,712 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  151. DRV:[b]64bit:[/b] - [2009/12/22 03:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
  152. DRV:[b]64bit:[/b] - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  153. DRV:[b]64bit:[/b] - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  154. DRV:[b]64bit:[/b] - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  155. DRV:[b]64bit:[/b] - [2009/07/13 18:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
  156. DRV:[b]64bit:[/b] - [2009/07/13 18:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
  157. DRV:[b]64bit:[/b] - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  158. DRV:[b]64bit:[/b] - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  159. DRV:[b]64bit:[/b] - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  160. DRV:[b]64bit:[/b] - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  161. DRV - [2012/12/04 02:41:28 | 000,037,976 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | System | Stopped] -- C:\Windows\SysWOW64\drivers\CFRMD.sys -- (CFRMD)
  162. DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  163.  
  164.  
  165. [color=#E56717]========== Standard Registry (All) ==========[/color]
  166.  
  167.  
  168. [color=#E56717]========== Internet Explorer ==========[/color]
  169.  
  170. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
  171. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  172. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  173. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  174. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
  175. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  176. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  177. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
  178. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {08F9ECC3-87ED-4AF0-BF15-1EF962D2816F}
  179. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{08F9ECC3-87ED-4AF0-BF15-1EF962D2816F}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
  180. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{A418DB94-2828-4D1B-87FF-CB70BE11BDBA}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
  181. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{B75B229E-5675-4670-B9BE-2394AE993282}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
  182. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{FCFE2D47-2199-40BA-99EA-7B2AE9848DAC}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
  183. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
  184. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  185. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  186. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  187. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  188. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  189. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  190. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
  191. IE - HKLM\..\SearchScopes,DefaultScope = {08F9ECC3-87ED-4AF0-BF15-1EF962D2816F}
  192. IE - HKLM\..\SearchScopes\{08F9ECC3-87ED-4AF0-BF15-1EF962D2816F}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
  193. IE - HKLM\..\SearchScopes\{A418DB94-2828-4D1B-87FF-CB70BE11BDBA}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
  194. IE - HKLM\..\SearchScopes\{B75B229E-5675-4670-B9BE-2394AE993282}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
  195. IE - HKLM\..\SearchScopes\{FCFE2D47-2199-40BA-99EA-7B2AE9848DAC}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
  196.  
  197.  
  198. IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {08F9ECC3-87ED-4AF0-BF15-1EF962D2816F}
  199. IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  200.  
  201. IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {08F9ECC3-87ED-4AF0-BF15-1EF962D2816F}
  202. IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  203.  
  204. IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  205.  
  206. IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  207.  
  208. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9MSE&PC=UP09
  209. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
  210. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  211. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=OIE9MSE&PC=UP09
  212. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  213. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\SearchScopes,DefaultScope = {5918AFB6-FA37-46B9-9617-F6B212E32575}
  214. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\SearchScopes\{5918AFB6-FA37-46B9-9617-F6B212E32575}: "URL" = http://www.bing.com/search?FORM=UP09DF&PC=UP09&q={searchTerms}&src=IE-SearchBox
  215. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\SearchScopes\{A418DB94-2828-4D1B-87FF-CB70BE11BDBA}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
  216. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\SearchScopes\{B75B229E-5675-4670-B9BE-2394AE993282}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
  217. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\SearchScopes\{E10B9092-8EDA-4C8A-B542-E6EA08210D5F}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
  218. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\SearchScopes\{FCFE2D47-2199-40BA-99EA-7B2AE9848DAC}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
  219. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  220. IE - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  221.  
  222. [color=#E56717]========== FireFox ==========[/color]
  223.  
  224. FF - prefs.js..extensions.enabledAddons: %7B37fa1426-b82d-11db-8314-0800200c9a66%7D:3.0.3
  225. FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
  226. FF - user.js - File not found
  227.  
  228. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
  229. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  230. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  231. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: c:\Program Files (x86)\Virtual Earth 3D\ [2010/09/24 02:48:43 | 000,000,000 | ---D | M]
  232. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
  233. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
  234. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
  235. FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
  236. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
  237. FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  238. FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
  239. FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  240. FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  241. FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: c:\Program Files (x86)\Virtual Earth 3D\ [2010/09/24 02:48:43 | 000,000,000 | ---D | M]
  242. FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
  243. FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  244. FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()
  245.  
  246. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/08/18 22:30:38 | 000,000,000 | ---D | M]
  247. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/08 11:39:26 | 000,000,000 | ---D | M]
  248. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
  249. FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/08/18 22:30:38 | 000,000,000 | ---D | M]
  250. FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/08 11:39:26 | 000,000,000 | ---D | M]
  251. FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
  252.  
  253. [2011/06/11 09:58:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deanne\AppData\Roaming\Mozilla\Extensions
  254. [2012/12/09 15:56:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deanne\AppData\Roaming\Mozilla\Firefox\Profiles\fuav0843.default\extensions
  255. [2012/12/09 15:56:49 | 000,194,065 | ---- | M] () (No name found) -- C:\Users\Deanne\AppData\Roaming\Mozilla\Firefox\Profiles\fuav0843.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
  256. [2012/12/08 11:38:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
  257. [2012/12/08 11:39:26 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
  258. [2012/12/08 11:39:26 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
  259. [2012/09/16 09:44:57 | 000,001,607 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
  260. [2012/09/16 09:44:57 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
  261. [2012/09/16 09:44:57 | 000,001,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
  262. [2012/09/16 09:44:57 | 000,003,581 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
  263. [2012/10/14 13:41:32 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
  264. [2012/09/16 09:44:57 | 000,001,391 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
  265. [2012/09/16 09:44:57 | 000,001,309 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
  266.  
  267. O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  268. O2:[b]64bit:[/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  269. O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
  270. O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  271. O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\Hp\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
  272. O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
  273. O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
  274. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  275. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
  276. O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
  277. O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
  278. O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
  279. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
  280. O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
  281. O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
  282. O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
  283. O3 - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
  284. O4:[b]64bit:[/b] - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
  285. O4:[b]64bit:[/b] - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
  286. O4:[b]64bit:[/b] - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
  287. O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
  288. O4 - HKLM..\Run: [] File not found
  289. O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
  290. O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
  291. O4 - HKLM..\Run: [BCSSync] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
  292. O4 - HKLM..\Run: [DT HPO] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe ()
  293. O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
  294. O4 - HKLM..\Run: [HP Software Update] c:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
  295. O4 - HKLM..\Run: [hpqSRMon] C:\Program Files (x86)\Hp\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
  296. O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
  297. O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
  298. O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
  299. O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
  300. O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
  301. O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
  302. O4 - HKLM..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe" -controlservice -slave File not found
  303. O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  304. O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  305. O4 - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe ()
  306. O4 - HKU\S-1-5-21-1580667454-1155120739-2748471355-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe File not found
  307. O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  308. O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  309. O4 - Startup: C:\Users\Deanne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Deanne\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
  310. O4 - Startup: C:\Users\Deanne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
  311. O4 - Startup: C:\Users\DH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
  312. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  313. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  314. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
  315. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
  316. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  317. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
  318. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
  319. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
  320. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
  321. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
  322. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
  323. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
  324. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
  325. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
  326. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
  327. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
  328. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
  329. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
  330. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
  331. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
  332. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
  333. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
  334. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
  335. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
  336. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
  337. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
  338. O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
  339. O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  340. O8:[b]64bit:[/b] - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
  341. O8:[b]64bit:[/b] - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
  342. O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
  343. O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  344. O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
  345. O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
  346. O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  347. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  348. O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  349. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  350. O9:[b]64bit:[/b] - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
  351. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
  352. O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
  353. O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
  354. O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
  355. O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
  356. O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  357. O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
  358. O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  359. O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  360. O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
  361. O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
  362. O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
  363. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  364. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
  365. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  366. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  367. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
  368. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
  369. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
  370. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  371. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
  372. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
  373. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  374. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  375. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  376. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  377. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  378. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  379. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  380. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  381. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  382. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  383. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  384. O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
  385. O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
  386. O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  387. O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  388. O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
  389. O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
  390. O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
  391. O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Windows\SysWow64\mswsock.dll (Microsoft Corporation)
  392. O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
  393. O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
  394. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  395. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  396. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  397. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  398. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  399. O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  400. O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  401. O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  402. O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  403. O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  404. O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  405. O13[b]64bit:[/b] - gopher Prefix: missing
  406. O13 - gopher Prefix: missing
  407. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Reg Error: Value error.)
  408. O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
  409. O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
  410. O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 10.9.2)
  411. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
  412. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC042F7A-E9A8-44C4-9462-27ACA4114008}: DhcpNameServer = 192.168.1.254
  413. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC042F7A-E9A8-44C4-9462-27ACA4114008}: NameServer = 8.26.56.26,156.154.70.22
  414. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E37C8F73-7085-44AF-97DA-15E2DB28BC7A}: DhcpNameServer = 192.168.1.254
  415. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E37C8F73-7085-44AF-97DA-15E2DB28BC7A}: NameServer = 8.26.56.26,156.154.70.22
  416. O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  417. O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  418. O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  419. O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  420. O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  421. O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  422. O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  423. O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  424. O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  425. O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
  426. O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  427. O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  428. O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
  429. O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  430. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
  431. O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  432. O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
  433. O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  434. O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  435. O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  436. O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
  437. O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  438. O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  439. O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  440. O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  441. O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  442. O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  443. O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  444. O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  445. O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  446. O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
  447. O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  448. O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  449. O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
  450. O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  451. O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
  452. O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  453. O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
  454. O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  455. O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  456. O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  457. O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
  458. O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  459. O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  460. O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  461. O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
  462. O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  463. O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  464. O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  465. O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
  466. O20:[b]64bit:[/b] - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
  467. O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) - C:\Windows\SysWOW64\guard32.dll (COMODO)
  468. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  469. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  470. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  471. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  472. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  473. O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
  474. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  475. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  476. O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  477. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
  478. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  479. O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  480. O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  481. O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  482. O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
  483. O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  484. O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
  485. O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
  486. O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
  487. O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
  488. O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corporation)
  489. O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
  490. O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  491. O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
  492. O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
  493. O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
  494. O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
  495. O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corporation)
  496. O31 - SafeBoot: AlternateShell - cmd.exe
  497. O32 - HKLM CDRom: AutoRun - 1
  498. O34 - HKLM BootExecute: (autocheck autochk *)
  499. O34 - HKLM BootExecute: (MACHINE BootExecut)
  500. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  501. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  502. O35 - HKLM\..comfile [open] -- "%1" %*
  503. O35 - HKLM\..exefile [open] -- "%1" %*
  504. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  505. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  506. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  507. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  508. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  509. O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
  510. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  511.  
  512.  
  513.  
  514. SafeBootMin:[b]64bit:[/b] 66842018.sys - Driver
  515. SafeBootMin:[b]64bit:[/b] AppMgmt - Service
  516. SafeBootMin:[b]64bit:[/b] Base - Driver Group
  517. SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
  518. SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
  519. SafeBootMin:[b]64bit:[/b] File system - Driver Group
  520. SafeBootMin:[b]64bit:[/b] Filter - Driver Group
  521. SafeBootMin:[b]64bit:[/b] HelpSvc - Service
  522. SafeBootMin:[b]64bit:[/b] MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
  523. SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
  524. SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
  525. SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
  526. SafeBootMin:[b]64bit:[/b] sacsvr - Service
  527. SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
  528. SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
  529. SafeBootMin:[b]64bit:[/b] vmms - Service
  530. SafeBootMin:[b]64bit:[/b] WinDefend - Service
  531. SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  532. SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  533. SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  534. SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  535. SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  536. SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  537. SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  538. SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  539. SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  540. SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  541. SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  542. SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  543. SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  544. SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  545. SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  546. SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  547. SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  548. SafeBootMin: 66842018.sys - Driver
  549. SafeBootMin: AppMgmt - Service
  550. SafeBootMin: Base - Driver Group
  551. SafeBootMin: Boot Bus Extender - Driver Group
  552. SafeBootMin: Boot file system - Driver Group
  553. SafeBootMin: File system - Driver Group
  554. SafeBootMin: Filter - Driver Group
  555. SafeBootMin: HelpSvc - Service
  556. SafeBootMin: PCI Configuration - Driver Group
  557. SafeBootMin: PNP Filter - Driver Group
  558. SafeBootMin: Primary disk - Driver Group
  559. SafeBootMin: sacsvr - Service
  560. SafeBootMin: SCSI Class - Driver Group
  561. SafeBootMin: System Bus Extender - Driver Group
  562. SafeBootMin: vmms - Service
  563. SafeBootMin: WinDefend - Service
  564. SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  565. SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  566. SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  567. SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  568. SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  569. SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  570. SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  571. SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  572. SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  573. SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  574. SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  575. SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  576. SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  577. SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  578. SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  579. SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  580. SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  581.  
  582. SafeBootNet:[b]64bit:[/b] 66842018.sys - Driver
  583. SafeBootNet:[b]64bit:[/b] AppMgmt - Service
  584. SafeBootNet:[b]64bit:[/b] Base - Driver Group
  585. SafeBootNet:[b]64bit:[/b] BFE - Service
  586. SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
  587. SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
  588. SafeBootNet:[b]64bit:[/b] File system - Driver Group
  589. SafeBootNet:[b]64bit:[/b] Filter - Driver Group
  590. SafeBootNet:[b]64bit:[/b] HelpSvc - Service
  591. SafeBootNet:[b]64bit:[/b] Messenger - Service
  592. SafeBootNet:[b]64bit:[/b] MPSSvc - Service
  593. SafeBootNet:[b]64bit:[/b] MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
  594. SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
  595. SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
  596. SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
  597. SafeBootNet:[b]64bit:[/b] Network - Driver Group
  598. SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
  599. SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
  600. SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
  601. SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
  602. SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
  603. SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
  604. SafeBootNet:[b]64bit:[/b] sacsvr - Service
  605. SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
  606. SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
  607. SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
  608. SafeBootNet:[b]64bit:[/b] TDI - Driver Group
  609. SafeBootNet:[b]64bit:[/b] vmms - Service
  610. SafeBootNet:[b]64bit:[/b] WinDefend - Service
  611. SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
  612. SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  613. SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  614. SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  615. SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  616. SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  617. SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  618. SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  619. SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
  620. SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
  621. SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
  622. SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
  623. SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  624. SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  625. SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  626. SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  627. SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
  628. SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  629. SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  630. SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  631. SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  632. SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  633. SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  634. SafeBootNet: 66842018.sys - Driver
  635. SafeBootNet: AppMgmt - Service
  636. SafeBootNet: Base - Driver Group
  637. SafeBootNet: BFE - Service
  638. SafeBootNet: Boot Bus Extender - Driver Group
  639. SafeBootNet: Boot file system - Driver Group
  640. SafeBootNet: File system - Driver Group
  641. SafeBootNet: Filter - Driver Group
  642. SafeBootNet: HelpSvc - Service
  643. SafeBootNet: Messenger - Service
  644. SafeBootNet: MPSSvc - Service
  645. SafeBootNet: NDIS Wrapper - Driver Group
  646. SafeBootNet: NetBIOSGroup - Driver Group
  647. SafeBootNet: NetDDEGroup - Driver Group
  648. SafeBootNet: Network - Driver Group
  649. SafeBootNet: NetworkProvider - Driver Group
  650. SafeBootNet: PCI Configuration - Driver Group
  651. SafeBootNet: PNP Filter - Driver Group
  652. SafeBootNet: PNP_TDI - Driver Group
  653. SafeBootNet: Primary disk - Driver Group
  654. SafeBootNet: rdsessmgr - Service
  655. SafeBootNet: sacsvr - Service
  656. SafeBootNet: SCSI Class - Driver Group
  657. SafeBootNet: Streams Drivers - Driver Group
  658. SafeBootNet: System Bus Extender - Driver Group
  659. SafeBootNet: TDI - Driver Group
  660. SafeBootNet: vmms - Service
  661. SafeBootNet: WinDefend - Service
  662. SafeBootNet: WudfUsbccidDriver - Driver
  663. SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  664. SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  665. SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  666. SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  667. SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  668. SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  669. SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  670. SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
  671. SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
  672. SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
  673. SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
  674. SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  675. SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  676. SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  677. SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  678. SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
  679. SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  680. SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  681. SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  682. SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  683. SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  684. SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  685.  
  686. ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
  687. ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
  688. ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
  689. ActiveX:[b]64bit:[/b] {3CE02F38-C912-44CF-B02E-60F7964E61FF} - BingPack
  690. ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
  691. ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
  692. ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
  693. ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
  694. ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
  695. ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
  696. ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
  697. ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
  698. ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
  699. ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
  700. ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
  701. ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
  702. ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
  703. ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
  704. ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
  705. ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
  706. ActiveX:[b]64bit:[/b] {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
  707. ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
  708. ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
  709. ActiveX:[b]64bit:[/b] >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
  710. ActiveX:[b]64bit:[/b] >{707b55c2-84be-42f0-9864-d04b805cc107} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
  711. ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
  712. ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
  713. ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
  714. ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
  715. ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
  716. ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
  717. ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
  718. ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
  719. ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
  720. ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
  721. ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
  722. ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
  723. ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
  724. ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
  725. ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
  726. ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
  727. ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
  728. ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
  729. ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
  730. ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
  731. ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
  732. ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
  733. ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
  734. ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
  735. ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
  736.  
  737. Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  738. Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  739. Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
  740.  
  741. [color=#E56717]========== Files/Folders - Created Within 90 Days ==========[/color]
  742.  
  743. [2012/12/10 00:20:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Deanne\Desktop\OTL.scr
  744. [2012/12/09 16:05:53 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
  745. [2012/12/08 19:40:27 | 000,000,000 | ---D | C] -- C:\Users\Deanne\Desktop\RK_Quarantine
  746. [2012/12/08 19:06:45 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Deanne\Desktop\tdsskiller.exe
  747. [2012/12/08 18:14:37 | 000,000,000 | ---D | C] -- C:\Users\Deanne\Desktop\mine
  748. [2012/12/08 11:38:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
  749. [2012/12/04 02:41:28 | 000,037,976 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysWow64\drivers\CFRMD.sys
  750. [2012/11/25 13:19:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
  751. [2012/11/25 13:17:48 | 000,000,000 | ---D | C] -- C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
  752. [2012/11/13 20:01:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Comodo
  753. [2012/11/04 14:29:33 | 000,000,000 | ---D | C] -- C:\Users\Deanne\Documents\Cell phone Back up
  754. [2012/10/31 00:15:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
  755. [2012/10/31 00:15:03 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
  756. [2012/10/31 00:14:54 | 000,095,208 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
  757. [2012/10/30 21:31:53 | 000,000,000 | ---D | C] -- C:\Users\Deanne\AppData\Roaming\Softland
  758. [2012/10/30 21:31:52 | 000,025,480 | ---- | C] (Softland) -- C:\Windows\SysNative\dopdfmn7.dll
  759. [2012/10/30 21:31:52 | 000,020,872 | ---- | C] (Softland) -- C:\Windows\SysNative\dopdfmi7.dll
  760. [2012/10/30 21:31:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\doPDF 7
  761. [2012/10/30 21:31:51 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GdiPlus.dll
  762. [2012/10/30 21:31:50 | 000,000,000 | ---D | C] -- C:\Program Files\Softland
  763. [2012/10/30 21:31:05 | 004,240,488 | ---- | C] (Softland ) -- C:\Users\Deanne\Documents\dopdf-7.exe
  764. [2012/10/23 20:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
  765. [2012/10/23 20:45:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
  766. [2012/10/23 20:45:21 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
  767. [2012/10/23 20:44:30 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
  768. [2012/10/23 20:44:29 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
  769. [2012/10/23 20:44:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
  770. [2012/10/23 20:44:29 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
  771. [2012/10/18 22:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\CrashPlan
  772. [2012/10/18 22:28:28 | 000,000,000 | ---D | C] -- C:\Program Files\CrashPlan
  773. [2012/10/18 22:28:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrashPlan
  774. [2012/10/18 22:27:09 | 000,000,000 | ---D | C] -- C:\Users\Deanne\AppData\Roaming\CrashPlan
  775. [2012/10/09 21:55:10 | 000,000,000 | ---D | C] -- C:\Users\Deanne\AppData\Roaming\MusicBrainz
  776. [2012/10/09 21:54:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MusicBrainz Picard
  777. [2012/09/17 21:24:47 | 000,000,000 | ---D | C] -- C:\Users\Deanne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JFAS
  778. [2012/09/17 21:24:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JFAS
  779. [2012/09/17 21:24:46 | 000,355,384 | ---- | C] (Data Dynamics) -- C:\Windows\SysWow64\exclexpt.dll
  780. [2012/09/17 21:24:45 | 001,827,384 | ---- | C] (Data Dynamics) -- C:\Windows\SysWow64\arpro2.dll
  781. [2012/09/17 21:24:45 | 000,604,728 | ---- | C] (Data Dynamics) -- C:\Windows\SysWow64\Arview2.ocx
  782. [2012/09/17 21:24:45 | 000,375,864 | ---- | C] (Data Dynamics) -- C:\Windows\SysWow64\pdfexpt.dll
  783. [2012/09/17 21:24:45 | 000,130,104 | ---- | C] (Data Dynamics) -- C:\Windows\SysWow64\textexpt.dll
  784. [2012/09/17 21:24:44 | 001,287,592 | ---- | C] (FarPoint Technologies, Inc.) -- C:\Windows\SysWow64\EDT32X30.OCX
  785. [2012/09/17 21:24:44 | 000,688,128 | ---- | C] (DevPower Solutions) -- C:\Windows\SysWow64\ButtonBar.ocx
  786. [2012/09/17 21:24:44 | 000,488,448 | ---- | C] (Janus Systems SA de CV) -- C:\Windows\SysWow64\GridEX20.ocx
  787. [2012/09/17 21:24:44 | 000,440,016 | ---- | C] (FarPoint Technologies, Inc.) -- C:\Windows\SysWow64\TAB32X30.OCX
  788. [2012/09/17 21:24:44 | 000,178,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMask32.ocx
  789. [2012/09/17 21:24:44 | 000,129,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSSTDFMT.DLL
  790. [2012/09/17 21:24:44 | 000,119,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mscomm32.ocx
  791. [2012/09/17 21:24:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2005
  792. [2012/09/17 21:21:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
  793. [2012/09/17 21:21:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
  794. [2012/09/17 21:21:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Jazzercise
  795. [2012/09/17 21:21:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Jazzercise
  796. [2012/09/17 21:20:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
  797. [2012/09/17 19:31:14 | 000,000,000 | ---D | C] -- C:\Users\Deanne\AppData\Roaming\pdf995
  798. [2012/09/17 19:30:26 | 000,314,368 | ---- | C] (TODO: <Company name>) -- C:\Windows\SysNative\pdfmona64.dll
  799. [2012/09/17 19:30:26 | 000,000,000 | ---D | C] -- C:\ProgramData\pdf995
  800. [2012/09/17 19:30:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software995
  801. [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  802.  
  803. [color=#E56717]========== Files - Modified Within 90 Days ==========[/color]
  804.  
  805. [2012/12/10 00:20:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deanne\Desktop\OTL.scr
  806. [2012/12/10 00:18:54 | 000,000,204 | ---- | M] () -- C:\Users\Deanne\Desktop\Fix.reg
  807. [2012/12/10 00:10:32 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  808. [2012/12/10 00:10:32 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  809. [2012/12/10 00:07:58 | 000,849,048 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  810. [2012/12/10 00:07:58 | 000,709,534 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  811. [2012/12/10 00:07:58 | 000,140,176 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  812. [2012/12/10 00:03:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  813. [2012/12/10 00:03:07 | 3019,345,920 | -HS- | M] () -- C:\hiberfil.sys
  814. [2012/12/08 19:39:55 | 000,753,152 | ---- | M] () -- C:\Users\Deanne\Desktop\RogueKiller.exe
  815. [2012/12/08 19:06:48 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Deanne\Desktop\tdsskiller.exe
  816. [2012/12/08 16:56:05 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
  817. [2012/12/08 16:56:05 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
  818. [2012/12/04 02:41:28 | 000,037,976 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysWow64\drivers\CFRMD.sys
  819. [2012/11/26 18:59:32 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForDeanne.job
  820. [2012/11/25 13:19:55 | 000,002,187 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
  821. [2012/11/13 20:01:36 | 000,002,049 | ---- | M] () -- C:\Users\Public\Desktop\AntiError.lnk
  822. [2012/11/13 20:01:36 | 000,002,045 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
  823. [2012/11/13 20:01:36 | 000,002,045 | ---- | M] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
  824. [2012/11/07 17:37:57 | 000,022,736 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\cmderd.sys
  825. [2012/11/07 17:37:36 | 000,041,240 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdcsr.dll
  826. [2012/11/07 17:37:34 | 000,301,264 | ---- | M] (COMODO) -- C:\Windows\SysWow64\guard32.dll
  827. [2012/11/07 17:37:31 | 000,390,392 | ---- | M] (COMODO) -- C:\Windows\SysNative\guard64.dll
  828. [2012/10/31 00:14:50 | 000,095,208 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
  829. [2012/10/31 00:14:48 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
  830. [2012/10/31 00:14:48 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
  831. [2012/10/31 00:14:48 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
  832. [2012/10/31 00:14:47 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npdeployJava1.dll
  833. [2012/10/31 00:14:47 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
  834. [2012/10/30 21:45:25 | 000,673,375 | ---- | M] () -- C:\Users\Deanne\Documents\Back of - Insert for halloween-two lower.pdf
  835. [2012/10/30 21:34:01 | 000,673,391 | ---- | M] () -- C:\Users\Deanne\Documents\Back of - Insert for halloween.pdf
  836. [2012/10/30 21:31:09 | 004,240,488 | ---- | M] (Softland ) -- C:\Users\Deanne\Documents\dopdf-7.exe
  837. [2012/10/23 20:45:35 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
  838. [2012/10/18 22:28:57 | 000,001,843 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CrashPlan Tray.lnk
  839. [2012/10/18 18:08:37 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  840. [2012/10/03 11:50:18 | 000,025,480 | ---- | M] (Softland) -- C:\Windows\SysNative\dopdfmn7.dll
  841. [2012/10/03 11:50:16 | 000,020,872 | ---- | M] (Softland) -- C:\Windows\SysNative\dopdfmi7.dll
  842. [2012/09/29 18:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
  843. [2012/09/17 21:24:47 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\JFAS.lnk
  844. [2012/09/17 21:24:26 | 000,799,190 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  845. [2012/09/17 19:30:26 | 000,047,616 | ---- | M] () -- C:\Windows\SysWow64\pdf995mon64.dll
  846. [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  847.  
  848. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  849.  
  850. [2012/12/10 00:18:54 | 000,000,204 | ---- | C] () -- C:\Users\Deanne\Desktop\Fix.reg
  851. [2012/12/08 19:39:46 | 000,753,152 | ---- | C] () -- C:\Users\Deanne\Desktop\RogueKiller.exe
  852. [2012/11/25 13:29:33 | 000,000,336 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForDeanne.job
  853. [2012/11/25 13:19:55 | 000,002,187 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
  854. [2012/10/30 21:45:23 | 000,673,375 | ---- | C] () -- C:\Users\Deanne\Documents\Back of - Insert for halloween-two lower.pdf
  855. [2012/10/30 21:33:59 | 000,673,391 | ---- | C] () -- C:\Users\Deanne\Documents\Back of - Insert for halloween.pdf
  856. [2012/10/30 21:31:52 | 000,007,549 | ---- | C] () -- C:\Windows\SysNative\dopdf7.ctm
  857. [2012/10/23 20:45:35 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
  858. [2012/10/18 22:28:57 | 000,001,843 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CrashPlan Tray.lnk
  859. [2012/10/09 21:54:57 | 000,001,177 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBrainz Picard.lnk
  860. [2012/09/17 21:24:47 | 000,001,024 | ---- | C] () -- C:\Users\Public\Desktop\JFAS.lnk
  861. [2012/09/17 19:30:26 | 000,047,616 | ---- | C] () -- C:\Windows\SysWow64\pdf995mon64.dll
  862. [2012/09/17 19:30:26 | 000,047,616 | ---- | C] () -- C:\Windows\SysNative\pdf995mon64.dll
  863. [2012/09/17 19:30:26 | 000,011,264 | ---- | C] () -- C:\Windows\SysNative\pdf995mon64ui.dll
  864. [2012/09/17 19:30:26 | 000,000,142 | ---- | C] () -- C:\Windows\wpd99.drv
  865. [2012/08/18 21:30:30 | 000,129,024 | ---- | C] () -- C:\Windows\RegBootClean64.exe
  866. [2012/08/18 21:30:30 | 000,021,520 | ---- | C] () -- C:\Windows\DCEBoot64.exe
  867. [2012/08/18 13:22:37 | 007,277,148 | ---- | C] () -- C:\Users\Deanne\AppData\Local\census.cache
  868. [2012/08/18 13:22:28 | 000,114,857 | ---- | C] () -- C:\Users\Deanne\AppData\Local\ars.cache
  869. [2012/08/18 13:13:40 | 000,000,036 | ---- | C] () -- C:\Users\Deanne\AppData\Local\housecall.guid.cache
  870. [2011/08/18 22:13:45 | 000,226,406 | ---- | C] () -- C:\Windows\hpwins20.dat
  871. [2011/08/14 13:20:45 | 000,001,360 | ---- | C] () -- C:\Windows\hpwmdl20.dat.temp
  872.  
  873. [color=#E56717]========== ZeroAccess Check ==========[/color]
  874.  
  875. [2011/12/22 14:43:58 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-1580667454-1155120739-2748471355-1001\$RYZOCYK\Noah_And_The_Whale\L.I.F.E.G.O.E.S.O.N
  876. [2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
  877.  
  878. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  879.  
  880. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  881.  
  882. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  883.  
  884. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  885.  
  886. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  887. "" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 23:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
  888. "ThreadingModel" = Apartment
  889.  
  890. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  891. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  892. "ThreadingModel" = Apartment
  893.  
  894. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  895. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
  896. "ThreadingModel" = Free
  897.  
  898. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  899. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
  900. "ThreadingModel" = Free
  901.  
  902. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  903. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
  904. "ThreadingModel" = Both
  905.  
  906. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  907.  
  908. [color=#E56717]========== LOP Check ==========[/color]
  909.  
  910. [2012/06/26 21:53:59 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\com.amazon.music.uploader
  911. [2012/10/18 22:28:56 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\CrashPlan
  912. [2011/06/10 20:30:30 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\DisplayTune
  913. [2012/12/10 00:06:33 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Dropbox
  914. [2012/11/03 10:04:31 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\HandBrake
  915. [2012/10/09 21:55:10 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\MusicBrainz
  916. [2011/08/25 22:01:01 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\OpenOffice.org
  917. [2011/07/18 06:29:19 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\OverDrive
  918. [2012/09/17 19:31:16 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\pdf995
  919. [2011/06/10 20:28:55 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\PictureMover
  920. [2012/05/30 07:15:11 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\SharePod
  921. [2012/10/30 21:31:53 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Softland
  922. [2012/09/17 19:29:55 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\TaxCut
  923. [2011/06/16 18:51:58 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\TP
  924. [2012/03/04 17:28:53 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\WinBatch
  925. [2012/10/31 00:13:39 | 000,000,000 | ---D | M] -- C:\Users\DH\AppData\Roaming\CrashPlan
  926. [2011/08/25 21:59:40 | 000,000,000 | ---D | M] -- C:\Users\DH\AppData\Roaming\OpenOffice.org
  927. [2011/06/10 20:44:56 | 000,000,000 | ---D | M] -- C:\Users\DH\AppData\Roaming\PictureMover
  928. [2011/08/25 21:25:20 | 000,000,000 | ---D | M] -- C:\Users\DH\AppData\Roaming\WinBatch
  929. [2011/06/23 23:08:20 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\PictureMover
  930.  
  931. [color=#E56717]========== Purity Check ==========[/color]
  932.  
  933.  
  934.  
  935. [color=#E56717]========== Custom Scans ==========[/color]
  936.  
  937. [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
  938. [2009/07/24 13:22:29 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
  939. [2012/12/10 00:03:07 | 3019,345,920 | -HS- | M] () -- C:\hiberfil.sys
  940. [2012/10/04 22:00:11 | 000,000,040 | ---- | M] () -- C:\log.txt
  941. [2010/09/24 04:31:55 | 000,000,000 | RHS- | M] () -- C:\OS
  942. [2012/12/10 00:03:08 | 4025,794,560 | -HS- | M] () -- C:\pagefile.sys
  943. [2012/12/08 19:08:15 | 000,004,046 | ---- | M] () -- C:\TDSSKiller.2.8.15.0_08.12.2012_19.07.04_log.txt
  944. [2012/12/08 19:40:08 | 000,669,858 | ---- | M] () -- C:\TDSSKiller.2.8.15.0_08.12.2012_19.31.25_log.txt
  945. [2012/12/09 16:19:38 | 000,884,286 | ---- | M] () -- C:\TDSSKiller.2.8.15.0_09.12.2012_16.03.54_log.txt
  946.  
  947. [color=#A23BEC]< %USERPROFILE%\*.* >[/color]
  948. [2012/12/10 00:33:08 | 005,242,880 | -HS- | M] () -- C:\Users\Deanne\NTUSER.DAT
  949. [2012/12/10 00:33:08 | 000,262,144 | -HS- | M] () -- C:\Users\Deanne\ntuser.dat.LOG1
  950. [2011/06/10 20:19:38 | 000,000,000 | -HS- | M] () -- C:\Users\Deanne\ntuser.dat.LOG2
  951. [2011/06/10 20:43:07 | 000,065,536 | -HS- | M] () -- C:\Users\Deanne\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
  952. [2011/06/10 20:43:07 | 000,524,288 | -HS- | M] () -- C:\Users\Deanne\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
  953. [2011/06/10 20:43:07 | 000,524,288 | -HS- | M] () -- C:\Users\Deanne\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
  954. [2011/06/10 20:19:38 | 000,000,020 | -HS- | M] () -- C:\Users\Deanne\ntuser.ini
  955.  
  956. [color=#A23BEC]< %USERPROFILE%\temp\*.exe >[/color]
  957.  
  958. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*.* >[/color]
  959. [2012/08/19 13:20:27 | 000,114,857 | ---- | M] () -- C:\Users\Deanne\AppData\Local\ars.cache
  960. [2012/08/19 13:27:29 | 007,277,148 | ---- | M] () -- C:\Users\Deanne\AppData\Local\census.cache
  961. [2012/04/17 22:42:47 | 000,121,512 | ---- | M] () -- C:\Users\Deanne\AppData\Local\GDIPFONTCACHEV1.DAT
  962. [2012/08/18 13:13:40 | 000,000,036 | ---- | M] () -- C:\Users\Deanne\AppData\Local\housecall.guid.cache
  963. [2012/12/09 23:56:10 | 001,337,241 | -H-- | M] () -- C:\Users\Deanne\AppData\Local\IconCache.db
  964.  
  965. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*. >[/color]
  966. [2012/06/26 21:52:40 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Adobe
  967. [2011/08/03 21:35:38 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Apple
  968. [2011/08/03 21:50:44 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Apple Computer
  969. [2011/06/10 20:19:38 | 000,000,000 | -HSD | M] -- C:\Users\Deanne\AppData\Local\Application Data
  970. [2011/06/10 20:28:50 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\ATI
  971. [2011/06/10 20:27:54 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Broadcom
  972. [2012/08/20 06:29:52 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Comodo
  973. [2012/11/04 15:31:49 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\CrashDumps
  974. [2011/12/28 08:18:40 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Diagnostics
  975. [2012/12/05 22:46:57 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\ElevatedDiagnostics
  976. [2012/02/28 19:56:12 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\FreeScreenSharing
  977. [2012/05/18 21:48:10 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Hewlett-Packard
  978. [2011/06/10 20:19:38 | 000,000,000 | -HSD | M] -- C:\Users\Deanne\AppData\Local\History
  979. [2011/06/16 19:22:29 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\HP
  980. [2010/09/24 03:09:26 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\HuluDesktop
  981. [2011/06/10 20:32:28 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\IsolatedStorage
  982. [2012/06/16 18:45:47 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Macromedia
  983. [2012/10/09 21:43:53 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Microsoft
  984. [2011/09/13 19:53:52 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Microsoft Help
  985. [2011/06/11 09:14:44 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Mozilla
  986. [2012/10/29 22:15:32 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\PDFC
  987. [2012/12/10 00:24:30 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\Temp
  988. [2011/06/10 20:19:38 | 000,000,000 | -HSD | M] -- C:\Users\Deanne\AppData\Local\Temporary Internet Files
  989. [2011/06/10 20:20:02 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\TouchSmartData
  990. [2011/08/31 20:52:49 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Local\VirtualStore
  991.  
  992. [color=#A23BEC]< %USERPROFILE%\AppData\Local\temp\*.exe >[/color]
  993. [2012/05/18 21:48:03 | 000,465,920 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Deanne\AppData\Local\temp\COMAP.EXE
  994. [2011/08/25 22:00:33 | 003,127,456 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Deanne\AppData\Local\temp\FlashPlayerUpdate.exe
  995. [2009/07/17 19:12:26 | 001,957,206 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Deanne\AppData\Local\temp\FP_AX_MSI_INSTALLER.exe
  996. [2010/05/21 17:38:56 | 000,074,808 | ---- | M] (Hewlett-Packard) -- C:\Users\Deanne\AppData\Local\temp\HPHelpUpdater.exe
  997. [2011/06/16 19:52:03 | 000,004,608 | ---- | M] () -- C:\Users\Deanne\AppData\Local\temp\i4jdel0.exe
  998. [2011/11/14 15:08:04 | 000,909,088 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\Deanne\AppData\Local\temp\jre-6u30-windows-i586-iftw-rv.exe
  999. [2010/03/16 08:11:59 | 000,149,352 | R--- | M] (Microsoft Corporation) -- C:\Users\Deanne\AppData\Local\temp\ose00000.exe
  1000. [2010/09/14 15:05:54 | 000,036,920 | ---- | M] (Hewlett-Packard Company) -- C:\Users\Deanne\AppData\Local\temp\Resource.exe
  1001. [2011/11/15 23:16:48 | 005,590,528 | ---- | M] (Jeffrey Harris) -- C:\Users\Deanne\AppData\Local\temp\sharepod-eject.exe
  1002. [2012/03/04 17:28:16 | 057,826,304 | ---- | M] (Hewlett-Packard Development Company, L.P. ) -- C:\Users\Deanne\AppData\Local\temp\sp54931.exe
  1003. [2012/11/25 13:16:22 | 041,580,520 | ---- | M] (Hewlett-Packard ) -- C:\Users\Deanne\AppData\Local\temp\sp58915.exe
  1004. [2012/09/27 13:44:36 | 000,114,080 | ---- | M] (Hewlett-Packard Company) -- C:\Users\Deanne\AppData\Local\temp\UninstallHPSA.exe
  1005. [405 C:\Users\Deanne\AppData\Local\temp\*.tmp files -> C:\Users\Deanne\AppData\Local\temp\*.tmp -> ]
  1006.  
  1007. [color=#A23BEC]< %USERPROFILE%\AppData\Roaming\*.* >[/color]
  1008.  
  1009. [color=#A23BEC]< %USERPROFILE%\AppData\Roaming\*. >[/color]
  1010. [2012/06/26 21:53:34 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Adobe
  1011. [2012/06/14 21:52:51 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Apple Computer
  1012. [2011/06/10 20:28:50 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\ATI
  1013. [2012/06/26 21:53:59 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\com.amazon.music.uploader
  1014. [2012/10/18 22:28:56 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\CrashPlan
  1015. [2012/05/18 21:48:02 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\CyberLink
  1016. [2011/06/10 20:30:30 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\DisplayTune
  1017. [2012/12/10 00:06:33 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Dropbox
  1018. [2012/11/03 10:04:31 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\HandBrake
  1019. [2011/06/11 10:54:11 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Hewlett-Packard
  1020. [2011/07/04 12:14:22 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\HP
  1021. [2012/08/05 19:10:37 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\HP Support Assistant
  1022. [2012/11/25 13:18:39 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\hpqLog
  1023. [2012/08/05 19:10:37 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\HpUpdate
  1024. [2011/06/10 20:27:31 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Identities
  1025. [2010/09/24 03:14:49 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Macromedia
  1026. [2012/08/19 13:33:28 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Malwarebytes
  1027. [2009/07/14 01:44:38 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Media Center Programs
  1028. [2012/11/04 14:39:44 | 000,000,000 | --SD | M] -- C:\Users\Deanne\AppData\Roaming\Microsoft
  1029. [2011/06/11 09:58:32 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Mozilla
  1030. [2012/10/09 21:55:10 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\MusicBrainz
  1031. [2011/08/25 22:01:01 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\OpenOffice.org
  1032. [2011/07/18 06:29:19 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\OverDrive
  1033. [2012/09/17 19:31:16 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\pdf995
  1034. [2011/06/10 20:28:55 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\PictureMover
  1035. [2012/05/30 07:15:11 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\SharePod
  1036. [2012/10/30 21:31:53 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\Softland
  1037. [2012/09/17 19:29:55 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\TaxCut
  1038. [2011/06/16 18:51:58 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\TP
  1039. [2012/03/04 17:28:53 | 000,000,000 | ---D | M] -- C:\Users\Deanne\AppData\Roaming\WinBatch
  1040.  
  1041. [color=#A23BEC]< %Public%\Documents\Fonts\*.exe >[/color]
  1042.  
  1043. [color=#A23BEC]< %Public%\Documents\Config\*.exe >[/color]
  1044.  
  1045. [color=#A23BEC]< %Public%\Documents\*.* >[/color]
  1046. [2009/07/13 22:54:24 | 000,000,278 | -HS- | M] () -- C:\Users\Public\Documents\desktop.ini
  1047.  
  1048. [color=#A23BEC]< %ProgramData%\*.* >[/color]
  1049. [2011/08/18 22:47:04 | 000,011,801 | ---- | M] () -- C:\ProgramData\hpzinstall.log
  1050.  
  1051. [color=#A23BEC]< %ProgramData%\*. >[/color]
  1052. [2012/10/23 20:45:20 | 000,000,000 | ---D | M] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
  1053. [2012/12/08 17:10:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe
  1054. [2011/06/10 21:57:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple
  1055. [2011/06/10 21:46:06 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple Computer
  1056. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
  1057. [2010/09/24 02:49:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications
  1058. [2010/09/24 02:39:44 | 000,000,000 | ---D | M] -- C:\ProgramData\ATI
  1059. [2011/06/10 21:15:40 | 000,000,000 | ---D | M] -- C:\ProgramData\CinemaNow
  1060. [2012/08/28 05:58:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Comodo
  1061. [2010/09/24 03:08:05 | 000,000,000 | ---D | M] -- C:\ProgramData\Corel
  1062. [2012/08/31 21:56:09 | 000,000,000 | ---D | M] -- C:\ProgramData\CPA_VA
  1063. [2012/10/18 22:28:49 | 000,000,000 | ---D | M] -- C:\ProgramData\CrashPlan
  1064. [2010/09/24 02:58:47 | 000,000,000 | ---D | M] -- C:\ProgramData\CyberLink
  1065. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
  1066. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
  1067. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
  1068. [2011/08/25 21:21:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Hewlett-Packard
  1069. [2011/08/18 22:30:08 | 000,000,000 | ---D | M] -- C:\ProgramData\HP
  1070. [2011/08/18 22:29:53 | 000,000,000 | ---D | M] -- C:\ProgramData\HP Product Assistant
  1071. [2012/09/17 21:27:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Jazzercise
  1072. [2010/09/24 02:51:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Macrovision
  1073. [2012/08/19 13:33:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes
  1074. [2012/08/19 16:28:27 | 000,000,000 | ---D | M] -- C:\ProgramData\McAfee
  1075. [2012/05/15 19:35:11 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft
  1076. [2012/07/10 22:22:50 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help
  1077. [2012/05/14 19:18:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla
  1078. [2010/09/24 03:14:59 | 000,000,000 | ---D | M] -- C:\ProgramData\NewspaperDirect
  1079. [2011/08/25 20:48:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Norton
  1080. [2010/09/24 03:22:51 | 000,000,000 | ---D | M] -- C:\ProgramData\NortonInstaller
  1081. [2012/12/01 23:42:55 | 000,000,000 | ---D | M] -- C:\ProgramData\pdf995
  1082. [2012/12/04 00:18:59 | 000,000,000 | ---D | M] -- C:\ProgramData\PDFC
  1083. [2010/09/24 02:59:40 | 000,000,000 | ---D | M] -- C:\ProgramData\PictureMover
  1084. [2012/12/08 21:24:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Recovery
  1085. [2010/09/24 02:51:19 | 000,000,000 | ---D | M] -- C:\ProgramData\Sonic
  1086. [2010/09/24 02:25:30 | 000,000,000 | ---D | M] -- C:\ProgramData\SonicFocus
  1087. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
  1088. [2011/07/07 21:10:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun
  1089. [2010/09/24 02:59:28 | 000,000,000 | ---D | M] -- C:\ProgramData\Symantec
  1090. [2012/04/16 17:35:04 | 000,000,000 | ---D | M] -- C:\ProgramData\TaxCut
  1091. [2010/09/24 02:58:10 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp
  1092. [2009/07/13 23:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
  1093. [2010/09/24 03:15:40 | 000,000,000 | ---D | M] -- C:\ProgramData\TouchSmartData
  1094. [2010/09/24 02:51:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
  1095. [2011/06/16 19:24:13 | 000,000,000 | ---D | M] -- C:\ProgramData\WEBREG
  1096. [2010/09/24 03:13:23 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent
  1097. [2010/09/24 02:59:15 | 000,000,000 | -H-D | M] -- C:\ProgramData\{0D9D262D-4BA2-4BC3-9CD3-4D1A9AE63E18}
  1098. [2011/06/10 21:46:18 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
  1099. [2012/11/25 13:17:48 | 000,000,000 | ---D | M] -- C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
  1100.  
  1101. [color=#A23BEC]< %CommonProgramFiles%\*.* >[/color]
  1102.  
  1103. [color=#A23BEC]< %CommonProgramFiles%\ComObjects*.exe >[/color]
  1104.  
  1105. [color=#A23BEC]< %commonprogramfiles(x86)%\*.* >[/color]
  1106.  
  1107. [color=#A23BEC]< %ProgramFiles%\*.* >[/color]
  1108. [2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  1109.  
  1110. [color=#A23BEC]< %ProgramFiles%\*. >[/color]
  1111. [2012/06/26 21:53:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
  1112. [2012/06/26 21:53:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Amazon
  1113. [2011/06/10 21:44:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
  1114. [2010/09/24 02:38:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI Technologies
  1115. [2010/09/24 02:35:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AVerMedia
  1116. [2012/05/28 22:38:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
  1117. [2010/09/24 02:51:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CinemaNow
  1118. [2010/09/24 02:39:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cisco
  1119. [2012/11/13 20:01:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
  1120. [2012/08/31 21:56:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Comodo
  1121. [2011/07/09 19:35:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cricut Software
  1122. [2010/09/24 02:48:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
  1123. [2012/11/25 13:19:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hewlett-Packard
  1124. [2011/08/18 22:29:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hp
  1125. [2010/09/24 03:13:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP Games
  1126. [2012/04/16 17:36:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HRBlock2011
  1127. [2012/11/25 13:28:28 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
  1128. [2012/08/20 22:10:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
  1129. [2010/09/24 02:37:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ITE
  1130. [2012/10/23 20:45:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
  1131. [2012/10/31 00:14:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
  1132. [2012/09/17 21:21:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jazzercise
  1133. [2010/09/24 03:15:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Kobo
  1134. [2012/10/18 18:08:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
  1135. [2012/08/20 22:04:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
  1136. [2011/09/13 19:24:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Analysis Services
  1137. [2011/09/13 19:27:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
  1138. [2012/08/20 21:27:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Security Client
  1139. [2012/05/09 22:19:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
  1140. [2012/09/17 21:23:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server
  1141. [2011/09/13 19:27:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
  1142. [2011/09/13 19:27:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Sync Framework
  1143. [2011/09/13 19:27:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Synchronization Services
  1144. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Touch Pack for Windows 7
  1145. [2011/09/13 19:25:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8
  1146. [2010/09/24 02:51:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft WSE
  1147. [2010/09/24 02:48:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft XNA
  1148. [2012/09/17 21:23:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
  1149. [2012/12/08 11:39:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
  1150. [2012/12/08 17:41:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
  1151. [2011/09/13 19:28:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
  1152. [2011/06/14 13:05:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
  1153. [2012/10/09 21:54:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MusicBrainz Picard
  1154. [2011/06/16 19:44:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\My Digital Studio
  1155. [2010/09/24 03:14:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NewspaperDirect
  1156. [2011/06/10 20:23:27 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Online Services
  1157. [2011/08/25 21:54:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice.org 3
  1158. [2012/08/19 16:30:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Oracle
  1159. [2011/07/13 22:26:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OverDrive Media Console
  1160. [2010/09/24 02:35:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PDF Complete
  1161. [2012/09/17 19:30:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PDF995
  1162. [2010/09/24 02:59:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PictureMover
  1163. [2011/06/10 21:45:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
  1164. [2010/09/24 02:36:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
  1165. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
  1166. [2010/09/24 02:59:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Symantec
  1167. [2010/09/24 02:36:47 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
  1168. [2009/07/13 22:57:06 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
  1169. [2010/09/24 02:48:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Virtual Earth 3D
  1170. [2009/07/13 23:37:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
  1171. [2011/06/10 20:23:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
  1172. [2011/06/10 20:21:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live SkyDrive
  1173. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
  1174. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
  1175. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
  1176. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
  1177. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
  1178. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
  1179. [2010/09/24 03:14:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Zinio Reader 4
  1180.  
  1181. [color=#A23BEC]< %ProgramFiles(x86)%\*.* >[/color]
  1182. [2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  1183.  
  1184. [color=#A23BEC]< %ProgramFiles(x86)%\*. >[/color]
  1185. [2012/06/26 21:53:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
  1186. [2012/06/26 21:53:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Amazon
  1187. [2011/06/10 21:44:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
  1188. [2010/09/24 02:38:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI Technologies
  1189. [2010/09/24 02:35:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AVerMedia
  1190. [2012/05/28 22:38:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
  1191. [2010/09/24 02:51:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CinemaNow
  1192. [2010/09/24 02:39:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cisco
  1193. [2012/11/13 20:01:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
  1194. [2012/08/31 21:56:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Comodo
  1195. [2011/07/09 19:35:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cricut Software
  1196. [2010/09/24 02:48:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
  1197. [2012/11/25 13:19:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hewlett-Packard
  1198. [2011/08/18 22:29:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hp
  1199. [2010/09/24 03:13:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP Games
  1200. [2012/04/16 17:36:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HRBlock2011
  1201. [2012/11/25 13:28:28 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
  1202. [2012/08/20 22:10:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
  1203. [2010/09/24 02:37:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ITE
  1204. [2012/10/23 20:45:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
  1205. [2012/10/31 00:14:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
  1206. [2012/09/17 21:21:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jazzercise
  1207. [2010/09/24 03:15:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Kobo
  1208. [2012/10/18 18:08:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
  1209. [2012/08/20 22:04:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
  1210. [2011/09/13 19:24:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Analysis Services
  1211. [2011/09/13 19:27:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
  1212. [2012/08/20 21:27:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Security Client
  1213. [2012/05/09 22:19:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
  1214. [2012/09/17 21:23:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server
  1215. [2011/09/13 19:27:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
  1216. [2011/09/13 19:27:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Sync Framework
  1217. [2011/09/13 19:27:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Synchronization Services
  1218. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Touch Pack for Windows 7
  1219. [2011/09/13 19:25:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8
  1220. [2010/09/24 02:51:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft WSE
  1221. [2010/09/24 02:48:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft XNA
  1222. [2012/09/17 21:23:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
  1223. [2012/12/08 11:39:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
  1224. [2012/12/08 17:41:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
  1225. [2011/09/13 19:28:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
  1226. [2011/06/14 13:05:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
  1227. [2012/10/09 21:54:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MusicBrainz Picard
  1228. [2011/06/16 19:44:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\My Digital Studio
  1229. [2010/09/24 03:14:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NewspaperDirect
  1230. [2011/06/10 20:23:27 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Online Services
  1231. [2011/08/25 21:54:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice.org 3
  1232. [2012/08/19 16:30:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Oracle
  1233. [2011/07/13 22:26:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OverDrive Media Console
  1234. [2010/09/24 02:35:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PDF Complete
  1235. [2012/09/17 19:30:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PDF995
  1236. [2010/09/24 02:59:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PictureMover
  1237. [2011/06/10 21:45:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
  1238. [2010/09/24 02:36:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
  1239. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
  1240. [2010/09/24 02:59:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Symantec
  1241. [2010/09/24 02:36:47 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
  1242. [2009/07/13 22:57:06 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
  1243. [2010/09/24 02:48:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Virtual Earth 3D
  1244. [2009/07/13 23:37:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
  1245. [2011/06/10 20:23:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
  1246. [2011/06/10 20:21:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live SkyDrive
  1247. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
  1248. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
  1249. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
  1250. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
  1251. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
  1252. [2011/06/16 18:33:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
  1253. [2010/09/24 03:14:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Zinio Reader 4
  1254.  
  1255. [color=#A23BEC]< %programdata%\Microsoft\Windows\DRM\*.tmp >[/color]
  1256.  
  1257. [color=#A23BEC]< %programdata%\Microsoft\Windows\DRM\*.tmp >[/color]
  1258.  
  1259. [color=#A23BEC]< %AllUsersProfile%\Microsoft\Windows\DRM\*.tmp >[/color]
  1260.  
  1261. [color=#A23BEC]< %AllUsersProfile%\Microsoft\Windows\DRM\*.tmp >[/color]
  1262.  
  1263. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Local\*.* >[/color]
  1264.  
  1265. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Roaming\*.* >[/color]
  1266.  
  1267. [color=#A23BEC]< %windir%\SysWOW64\config\systemprofile\AppData\Local\*.* >[/color]
  1268.  
  1269. [color=#A23BEC]< %windir%\SysWOW64\config\systemprofile\AppData\Roaming\*.* >[/color]
  1270.  
  1271. [color=#A23BEC]< %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.tlb >[/color]
  1272.  
  1273. [color=#A23BEC]< %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tlb >[/color]
  1274.  
  1275. [color=#A23BEC]< %windir%\temp\*.exe >[/color]
  1276.  
  1277. [color=#A23BEC]< %windir%\*. >[/color]
  1278. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\addins
  1279. [2009/07/13 21:20:08 | 000,000,000 | ---D | M] -- C:\Windows\AppCompat
  1280. [2011/08/16 20:54:09 | 000,000,000 | ---D | M] -- C:\Windows\AppPatch
  1281. [2012/11/25 13:21:15 | 000,000,000 | R-SD | M] -- C:\Windows\assembly
  1282. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Boot
  1283. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Branding
  1284. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\Cursors
  1285. [2012/08/20 21:56:54 | 000,000,000 | ---D | M] -- C:\Windows\debug
  1286. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\diagnostics
  1287. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\DigitalLocker
  1288. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\Downloaded Program Files
  1289. [2010/09/24 02:35:54 | 000,000,000 | ---D | M] -- C:\Windows\Driver Cache
  1290. [2012/01/14 03:11:46 | 000,000,000 | ---D | M] -- C:\Windows\ehome
  1291. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\en-US
  1292. [2012/04/16 17:36:33 | 000,000,000 | R-SD | M] -- C:\Windows\Fonts
  1293. [2009/07/14 01:50:14 | 000,000,000 | ---D | M] -- C:\Windows\Globalization
  1294. [2012/11/25 13:28:00 | 000,000,000 | ---D | M] -- C:\Windows\Help
  1295. [2011/06/16 18:50:04 | 000,000,000 | ---D | M] -- C:\Windows\hpojj4600
  1296. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\IME
  1297. [2012/12/10 00:07:58 | 000,000,000 | ---D | M] -- C:\Windows\inf
  1298. [2012/11/25 13:21:18 | 000,000,000 | -HSD | M] -- C:\Windows\Installer
  1299. [2009/07/13 23:32:39 | 000,000,000 | ---D | M] -- C:\Windows\L2Schemas
  1300. [2009/07/13 20:34:24 | 000,000,000 | ---D | M] -- C:\Windows\LiveKernelReports
  1301. [2011/06/14 13:18:02 | 000,000,000 | ---D | M] -- C:\Windows\Logs
  1302. [2009/07/13 23:32:40 | 000,000,000 | R-SD | M] -- C:\Windows\Media
  1303. [2012/06/13 02:42:00 | 000,000,000 | ---D | M] -- C:\Windows\Microsoft.NET
  1304. [2012/12/08 19:30:34 | 000,000,000 | ---D | M] -- C:\Windows\Minidump
  1305. [2009/07/13 20:34:34 | 000,000,000 | ---D | M] -- C:\Windows\ModemLogs
  1306. [2012/08/20 22:10:21 | 000,000,000 | -H-D | M] -- C:\Windows\msdownld.tmp
  1307. [2009/07/13 23:32:40 | 000,000,000 | ---D | M] -- C:\Windows\Offline Web Pages
  1308. [2011/06/10 20:19:26 | 000,000,000 | ---D | M] -- C:\Windows\Panther
  1309. [2011/06/10 20:21:06 | 000,000,000 | ---D | M] -- C:\Windows\PCHEALTH
  1310. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Performance
  1311. [2009/07/13 21:20:10 | 000,000,000 | ---D | M] -- C:\Windows\PLA
  1312. [2011/06/14 13:19:14 | 000,000,000 | ---D | M] -- C:\Windows\PolicyDefinitions
  1313. [2012/12/10 00:21:41 | 000,000,000 | ---D | M] -- C:\Windows\Prefetch
  1314. [2010/09/24 03:15:07 | 000,000,000 | ---D | M] -- C:\Windows\PRIndex
  1315. [2012/09/17 21:22:21 | 000,000,000 | ---D | M] -- C:\Windows\Registration
  1316. [2012/07/12 20:12:46 | 000,000,000 | ---D | M] -- C:\Windows\rescache
  1317. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Resources
  1318. [2009/07/13 20:35:47 | 000,000,000 | ---D | M] -- C:\Windows\SchCache
  1319. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\schemas
  1320. [2009/07/13 21:20:10 | 000,000,000 | ---D | M] -- C:\Windows\security
  1321. [2009/07/13 22:45:47 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles
  1322. [2011/06/16 18:33:36 | 000,000,000 | ---D | M] -- C:\Windows\servicing
  1323. [2009/07/24 13:36:12 | 000,000,000 | ---D | M] -- C:\Windows\Setup
  1324. [2011/09/13 19:28:18 | 000,000,000 | ---D | M] -- C:\Windows\ShellNew
  1325. [2011/06/14 11:53:02 | 000,000,000 | ---D | M] -- C:\Windows\SoftwareDistribution
  1326. [2009/07/13 23:37:44 | 000,000,000 | ---D | M] -- C:\Windows\Speech
  1327. [2012/08/09 18:27:37 | 000,000,000 | ---D | M] -- C:\Windows\Sun
  1328. [2009/07/13 20:36:55 | 000,000,000 | ---D | M] -- C:\Windows\system
  1329. [2012/12/10 00:07:58 | 000,000,000 | ---D | M] -- C:\Windows\System32
  1330. [2012/11/26 18:59:21 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64
  1331. [2009/07/13 22:57:13 | 000,000,000 | ---D | M] -- C:\Windows\TAPI
  1332. [2012/11/25 13:29:33 | 000,000,000 | ---D | M] -- C:\Windows\Tasks
  1333. [2012/12/10 00:20:47 | 000,000,000 | ---D | M] -- C:\Windows\Temp
  1334. [2009/07/13 20:34:33 | 000,000,000 | ---D | M] -- C:\Windows\tracing
  1335. [2011/08/25 21:33:04 | 000,000,000 | ---D | M] -- C:\Windows\twain_32
  1336. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\Vss
  1337. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Web
  1338. [2012/11/25 13:27:35 | 000,000,000 | ---D | M] -- C:\Windows\winsxs
  1339.  
  1340. [color=#A23BEC]< %windir%\installer\*. >[/color]
  1341. [2010/09/24 02:37:29 | 000,000,000 | -HSD | M] -- C:\Windows\installer\$PatchCache$
  1342. [2010/09/24 02:57:07 | 000,000,000 | ---D | M] -- C:\Windows\installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D}
  1343. [2010/09/24 03:08:23 | 000,000,000 | ---D | M] -- C:\Windows\installer\{02EABF5D-E535-4A0F-8658-C1F4BF25850C}
  1344. [2010/09/24 03:08:58 | 000,000,000 | ---D | M] -- C:\Windows\installer\{053BC793-EB2F-48B6-AB61-6B76CCCCB041}
  1345. [2010/09/24 02:38:30 | 000,000,000 | ---D | M] -- C:\Windows\installer\{05CA9AF2-E06D-3991-887C-FC5822D5468A}
  1346. [2010/09/24 03:08:27 | 000,000,000 | ---D | M] -- C:\Windows\installer\{06A1431C-C951-4A9B-8732-04827497BF25}
  1347. [2010/09/24 02:38:14 | 000,000,000 | ---D | M] -- C:\Windows\installer\{07BF9DB6-69AE-4070-EFBC-44C5BB3E10D2}
  1348. [2012/03/04 17:34:02 | 000,000,000 | ---D | M] -- C:\Windows\installer\{07FA4960-B038-49EB-891B-9F95930AA544}
  1349. [2010/09/24 03:08:29 | 000,000,000 | ---D | M] -- C:\Windows\installer\{0ACB0830-631B-4C84-81CD-0B33E8129964}
  1350. [2010/09/24 03:08:25 | 000,000,000 | ---D | M] -- C:\Windows\installer\{0C49FC5B-B846-4430-83BA-4F5DD481DC53}
  1351. [2010/09/24 02:37:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{104BEA41-8EC0-B483-04AA-FAB143CBBCAE}
  1352. [2010/09/24 03:07:35 | 000,000,000 | ---D | M] -- C:\Windows\installer\{11070051-3806-4F34-8F1D-A7874ADC296C}
  1353. [2012/08/19 16:30:06 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1111706F-666A-4037-7777-211328764D10}
  1354. [2010/09/24 02:51:04 | 000,000,000 | ---D | M] -- C:\Windows\installer\{120262A6-7A4B-4889-AE85-F5E5688D3683}
  1355. [2012/10/23 20:45:35 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}
  1356. [2010/09/24 03:08:35 | 000,000,000 | ---D | M] -- C:\Windows\installer\{157A2E65-1D59-4BE2-BBD4-D16A14EEF959}
  1357. [2011/06/10 20:23:06 | 000,000,000 | ---D | M] -- C:\Windows\installer\{178832DE-9DE0-4C87-9F82-9315A9B03985}
  1358. [2010/09/24 02:52:22 | 000,000,000 | ---D | M] -- C:\Windows\installer\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}
  1359. [2010/09/24 02:38:08 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1D4B453A-6C34-FEDF-4B69-C026E2E58655}
  1360. [2011/08/18 22:27:10 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}
  1361. [2010/09/24 03:03:13 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1F99BAFA-2FD1-42D6-BE19-97144103D758}
  1362. [2010/09/24 02:45:25 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}
  1363. [2011/06/10 20:21:39 | 000,000,000 | ---D | M] -- C:\Windows\installer\{205C6BDD-7B73-42DE-8505-9A093F35A238}
  1364. [2010/09/24 02:37:58 | 000,000,000 | ---D | M] -- C:\Windows\installer\{22139F5D-9405-455A-BDEB-658B1A4E4861}
  1365. [2010/09/24 03:08:50 | 000,000,000 | ---D | M] -- C:\Windows\installer\{22CD5AA1-C28D-458A-AC3D-FB30F74111F9}
  1366. [2010/09/24 02:59:40 | 000,000,000 | ---D | M] -- C:\Windows\installer\{264FE20A-757B-492a-B0C3-4009E2997D8A}
  1367. [2012/04/29 15:22:46 | 000,000,000 | ---D | M] -- C:\Windows\installer\{26A24AE4-039D-4CA4-87B4-2F83216032FF}
  1368. [2010/09/24 03:08:54 | 000,000,000 | ---D | M] -- C:\Windows\installer\{29CE5C81-B7F9-40EA-997E-606C09F515A6}
  1369. [2010/09/24 03:09:02 | 000,000,000 | ---D | M] -- C:\Windows\installer\{29F19C52-0B82-4741-8015-8D46E28638EC}
  1370. [2012/09/17 21:24:27 | 000,000,000 | ---D | M] -- C:\Windows\installer\{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
  1371. [2010/09/24 02:45:01 | 000,000,000 | ---D | M] -- C:\Windows\installer\{3023EBDA-BF1B-4831-B347-E5018555F26E}
  1372. [2010/09/24 02:35:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\{32A2B967-279F-457D-B767-76352DA2F108}
  1373. [2010/09/24 02:38:07 | 000,000,000 | ---D | M] -- C:\Windows\installer\{338556DF-B61E-26A0-4DF9-F95658B3454B}
  1374. [2010/09/24 02:38:01 | 000,000,000 | ---D | M] -- C:\Windows\installer\{37220538-53F8-728A-C7EA-92ABD78CA94B}
  1375. [2010/09/24 02:48:38 | 000,000,000 | ---D | M] -- C:\Windows\installer\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}
  1376. [2010/09/24 03:08:09 | 000,000,000 | ---D | M] -- C:\Windows\installer\{3C19AEEC-7779-4FA5-A1DA-AEB93E674294}
  1377. [2010/09/24 02:38:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{3DAB1C09-2B6C-4FEE-2B95-EABAAF7002FB}
  1378. [2011/08/25 21:55:10 | 000,000,000 | ---D | M] -- C:\Windows\installer\{3E171899-0175-47CC-84C4-562ACDD4C021}
  1379. [2010/09/24 02:59:28 | 000,000,000 | ---D | M] -- C:\Windows\installer\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}
  1380. [2010/09/24 02:47:50 | 000,000,000 | ---D | M] -- C:\Windows\installer\{40BF1E83-20EB-11D8-97C5-0009C5020658}
  1381. [2010/09/24 03:06:42 | 000,000,000 | ---D | M] -- C:\Windows\installer\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}
  1382. [2010/09/24 03:16:09 | 000,000,000 | ---D | M] -- C:\Windows\installer\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}
  1383. [2010/09/24 02:40:48 | 000,000,000 | ---D | M] -- C:\Windows\installer\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}
  1384. [2010/09/24 02:38:20 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4513B67A-61E4-D7BF-6381-657581C9097C}
  1385. [2010/09/24 03:00:45 | 000,000,000 | ---D | M] -- C:\Windows\installer\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}
  1386. [2012/10/23 20:49:05 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4BC310C4-B898-46E2-B5FB-B85A30AA7142}
  1387. [2012/11/22 11:17:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4EAB2511-0135-48CA-A47B-CE1E6836793A}
  1388. [2010/09/24 02:38:33 | 000,000,000 | ---D | M] -- C:\Windows\installer\{5031851B-1BC3-EAB0-AC16-7D5FF880502C}
  1389. [2012/09/17 21:22:10 | 000,000,000 | ---D | M] -- C:\Windows\installer\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
  1390. [2011/06/10 21:45:10 | 000,000,000 | ---D | M] -- C:\Windows\installer\{57752979-A1C9-4C02-856B-FBB27AC4E02C}
  1391. [2010/09/24 02:38:05 | 000,000,000 | ---D | M] -- C:\Windows\installer\{5924CA2E-D145-87A2-CB65-39313C0D825C}
  1392. [2010/09/24 03:08:14 | 000,000,000 | ---D | M] -- C:\Windows\installer\{5932A032-0BD3-4EEA-9FC3-5E4C98B770C5}
  1393. [2010/09/24 03:08:41 | 000,000,000 | ---D | M] -- C:\Windows\installer\{5A9DADC3-6C03-4C83-8622-60405126D1E0}
  1394. [2010/09/24 03:08:19 | 000,000,000 | ---D | M] -- C:\Windows\installer\{5CBE8F58-049D-49FE-B4E3-A23CF3194771}
  1395. [2012/10/23 20:33:35 | 000,000,000 | ---D | M] -- C:\Windows\installer\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}
  1396. [2011/06/10 20:22:30 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6412CECE-8172-4BE5-935B-6CECACD2CA87}
  1397. [2010/09/24 02:58:44 | 000,000,000 | ---D | M] -- C:\Windows\installer\{67626E09-5366-4480-8F1E-93FADF50CA15}
  1398. [2010/09/24 02:38:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\{67AAEC8B-9A0C-154E-21F8-0AEF4A05E98D}
  1399. [2010/09/24 03:07:58 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6807F13C-A925-4DD8-80C0-24D93A6FFE83}
  1400. [2010/09/24 02:48:44 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}
  1401. [2010/09/24 02:51:28 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6C122441-1861-4CD7-B1C5-A163A6984E12}
  1402. [2012/05/28 22:38:25 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}
  1403. [2012/11/25 13:21:15 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F}
  1404. [2010/09/24 02:38:09 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6FA22C59-53A4-6C24-4E2B-8024838F1016}
  1405. [2010/09/24 02:38:15 | 000,000,000 | ---D | M] -- C:\Windows\installer\{713578E2-16BA-B3C5-A1D3-147F4BD6CE14}
  1406. [2012/10/23 20:41:26 | 000,000,000 | ---D | M] -- C:\Windows\installer\{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}
  1407. [2010/09/24 03:08:20 | 000,000,000 | ---D | M] -- C:\Windows\installer\{766486B3-441B-4376-A5F8-0AE2E4BDFB3C}
  1408. [2010/09/24 03:08:28 | 000,000,000 | ---D | M] -- C:\Windows\installer\{769FA062-69D1-4456-8624-13EC3880787E}
  1409. [2010/09/24 02:38:12 | 000,000,000 | ---D | M] -- C:\Windows\installer\{777E6DA6-2487-4A56-0FAB-07C9F82B9C18}
  1410. [2010/09/24 03:08:13 | 000,000,000 | ---D | M] -- C:\Windows\installer\{77B559D7-CBF8-43FE-90BB-BDB6A30E9B61}
  1411. [2011/06/10 20:22:48 | 000,000,000 | ---D | M] -- C:\Windows\installer\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}
  1412. [2010/09/24 02:38:13 | 000,000,000 | ---D | M] -- C:\Windows\installer\{858CA5A0-9A7E-3D84-679F-5934B22255A8}
  1413. [2011/06/14 13:05:38 | 000,000,000 | ---D | M] -- C:\Windows\installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
  1414. [2010/09/24 03:08:16 | 000,000,000 | ---D | M] -- C:\Windows\installer\{864BC409-6229-452C-B1FD-FA960D13F824}
  1415. [2010/09/24 02:38:34 | 000,000,000 | ---D | M] -- C:\Windows\installer\{88B6E7E4-2D44-9C8D-1B7E-1131C8B0D111}
  1416. [2010/09/24 02:38:03 | 000,000,000 | ---D | M] -- C:\Windows\installer\{88E2586F-E0D5-A3E3-B84F-4CC6E86F4D23}
  1417. [2010/09/24 03:08:45 | 000,000,000 | ---D | M] -- C:\Windows\installer\{89DE8F46-0495-46F7-94EB-DC6AA71BD3EE}
  1418. [2012/05/09 22:20:17 | 000,000,000 | ---D | M] -- C:\Windows\installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
  1419. [2012/12/09 16:01:11 | 000,000,000 | -HSD | M] -- C:\Windows\installer\{8ab922df-6a75-fa7b-8ace-d21af1b25ed3}
  1420. [2010/09/24 03:09:16 | 000,000,000 | ---D | M] -- C:\Windows\installer\{8ABB6A99-E2D5-47E4-905A-2FD4657D235E}
  1421. [2010/09/24 02:38:04 | 000,000,000 | ---D | M] -- C:\Windows\installer\{8D016DB5-8672-0757-F228-32BF04278665}
  1422. [2010/09/24 03:15:30 | 000,000,000 | ---D | M] -- C:\Windows\installer\{8DB462BD-8372-47F1-9356-210BE357B1A8}
  1423. [2010/09/24 02:50:43 | 000,000,000 | ---D | M] -- C:\Windows\installer\{8FF90DB8-6DED-44A3-B182-244FEC09012F}
  1424. [2011/09/13 19:26:19 | 000,000,000 | ---D | M] -- C:\Windows\installer\{90140000-002A-0000-1000-0000000FF1CE}
  1425. [2011/11/10 03:04:17 | 000,000,000 | ---D | M] -- C:\Windows\installer\{90140000-006E-0409-0000-0000000FF1CE}
  1426. [2012/07/10 22:22:48 | 000,000,000 | ---D | M] -- C:\Windows\installer\{91140000-0011-0000-0000-0000000FF1CE}
  1427. [2010/09/24 03:15:02 | 000,000,000 | ---D | M] -- C:\Windows\installer\{912CED74-88D3-4C5B-ACB0-13231864975D}
  1428. [2010/09/24 02:55:57 | 000,000,000 | ---D | M] -- C:\Windows\installer\{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}
  1429. [2011/08/18 22:28:17 | 000,000,000 | ---D | M] -- C:\Windows\installer\{92A51949-EE4C-466D-AAF0-99E74A49A63F}
  1430. [2010/09/24 02:43:46 | 000,000,000 | ---D | M] -- C:\Windows\installer\{95140000-0070-0000-0000-0000000FF1CE}
  1431. [2010/09/24 02:38:19 | 000,000,000 | ---D | M] -- C:\Windows\installer\{95251A23-7B7A-BFA7-C812-9A0E4EC04120}
  1432. [2012/09/17 21:21:56 | 000,000,000 | ---D | M] -- C:\Windows\installer\{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}
  1433. [2010/09/24 03:18:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\{9B48B0AC-C813-4174-9042-476A887592C7}
  1434. [2010/09/24 02:38:21 | 000,000,000 | ---D | M] -- C:\Windows\installer\{9B51638F-A1F3-05B5-46A1-B54A025766E1}
  1435. [2010/09/24 03:08:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{9CEE002F-22B8-4335-8D55-A1EE852C8072}
  1436. [2012/08/20 21:27:58 | 000,000,000 | ---D | M] -- C:\Windows\installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}
  1437. [2010/09/24 03:15:43 | 000,000,000 | ---D | M] -- C:\Windows\installer\{A1CE6220-A44F-4B0B-B445-738ACB55C25D}
  1438. [2010/09/24 02:38:18 | 000,000,000 | ---D | M] -- C:\Windows\installer\{A6D0B261-9CF1-1C7E-5A5C-6D42EE9AE9E6}
  1439. [2011/06/10 20:22:06 | 000,000,000 | ---D | M] -- C:\Windows\installer\{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
  1440. [2010/09/24 02:38:29 | 000,000,000 | ---D | M] -- C:\Windows\installer\{AB92BB15-CF56-0490-64D9-06DD82522CC5}
  1441. [2012/08/20 06:27:26 | 000,000,000 | ---D | M] -- C:\Windows\installer\{AC76BA86-7AD7-1033-7B44-AA1000000001}
  1442. [2010/09/24 02:38:28 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B1588559-57A0-5948-0A3F-F768AC350F29}
  1443. [2010/09/24 02:38:36 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B191C95B-7E4A-6419-F332-307810CE4FA5}
  1444. [2010/09/24 02:38:22 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B4DFE240-836F-3EA4-B764-BE778EB7B86B}
  1445. [2012/09/17 21:22:39 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B636C9B9-A3F2-4DCE-ADCC-72E095018385}
  1446. [2010/09/24 03:08:00 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B770307B-2E7E-4BAD-BF75-1511A76AD277}
  1447. [2010/09/24 02:38:26 | 000,000,000 | ---D | M] -- C:\Windows\installer\{BD30FF0E-FFD3-8200-68F1-7772F0C091DD}
  1448. [2010/09/24 03:09:22 | 000,000,000 | ---D | M] -- C:\Windows\installer\{BDDA1E1E-204E-4368-B0C2-737F16B76307}
  1449. [2010/09/24 03:08:12 | 000,000,000 | ---D | M] -- C:\Windows\installer\{BFA6DE67-F8EF-427B-B962-D03ADAF56734}
  1450. [2010/09/24 02:38:10 | 000,000,000 | ---D | M] -- C:\Windows\installer\{C1441CC5-D9DC-C781-F5FC-B7CA0FBA0914}
  1451. [2010/09/24 02:48:23 | 000,000,000 | ---D | M] -- C:\Windows\installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}
  1452. [2012/04/16 21:29:56 | 000,000,000 | ---D | M] -- C:\Windows\installer\{C6006AED-E5A7-4F77-BAD5-95AC43DE04F3}
  1453. [2011/06/10 21:44:53 | 000,000,000 | ---D | M] -- C:\Windows\installer\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}
  1454. [2010/09/24 02:53:42 | 000,000,000 | ---D | M] -- C:\Windows\installer\{C9DCE03F-8CB7-4146-A99C-0612D75177EA}
  1455. [2010/09/24 02:46:41 | 000,000,000 | ---D | M] -- C:\Windows\installer\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}
  1456. [2010/09/24 02:37:42 | 000,000,000 | ---D | M] -- C:\Windows\installer\{CBF9CADC-3F81-44E4-3B0F-B0E288D0FBEC}
  1457. [2012/11/22 11:17:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{CC6B1BB4-4E06-4A5B-A166-B371B551324B}
  1458. [2010/09/24 02:46:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D36DD326-7280-11D8-97C8-000129760CBE}
  1459. [2012/10/18 22:28:45 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D377B43D-DF58-4D54-A809-781D4F576FE6}
  1460. [2011/07/13 22:26:55 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}
  1461. [2012/11/22 11:17:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}
  1462. [2012/05/15 19:35:55 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}
  1463. [2011/06/10 20:22:58 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}
  1464. [2011/08/18 22:26:25 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D79113E7-274C-470B-BD46-01B10219DF6A}
  1465. [2010/09/24 03:22:44 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D79A02E9-6713-4335-9668-AAC7474C0C0E}
  1466. [2010/09/24 03:08:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\{DBE1BE19-6D8E-4623-83B1-EE017908A8B7}
  1467. [2011/08/18 22:30:44 | 000,000,000 | ---D | M] -- C:\Windows\installer\{DC635845-46D3-404B-BCB1-FC4A91091AFA}
  1468. [2010/09/24 02:57:57 | 000,000,000 | ---D | M] -- C:\Windows\installer\{DCCAD079-F92C-44DA-B258-624FC6517A5A}
  1469. [2010/09/24 03:14:38 | 000,000,000 | ---D | M] -- C:\Windows\installer\{DE665CEA-0968-4211-B0B0-2A917CE9EC7E}
  1470. [2010/09/24 02:42:40 | 000,000,000 | ---D | M] -- C:\Windows\installer\{DE77FE3F-A33D-499A-87AD-5FC406617B40}
  1471. [2010/09/24 03:08:02 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E1FD99EF-7312-426E-A9BD-92ECD2093B4A}
  1472. [2012/11/13 20:01:36 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E21161DD-05A2-42ED-A0EC-9C1393F51A64}
  1473. [2010/09/24 02:37:44 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E2D662AD-3FE3-26C5-5540-90E4974EF412}
  1474. [2012/11/22 11:17:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E62381A7-B1C1-4121-8262-84D38C77786C}
  1475. [2010/09/24 02:38:16 | 000,000,000 | ---D | M] -- C:\Windows\installer\{EB235F08-D1FC-D35F-BD8A-84C232184AF2}
  1476. [2010/09/24 02:38:23 | 000,000,000 | ---D | M] -- C:\Windows\installer\{EB69F7A5-778B-2F95-1FFD-949157FB94CA}
  1477. [2012/11/25 13:19:55 | 000,000,000 | ---D | M] -- C:\Windows\installer\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}
  1478. [2010/09/24 02:55:04 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F04BFADD-C8CA-4C86-8F20-B1D7F4F8C66C}
  1479. [2011/06/10 20:22:38 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
  1480. [2010/09/24 03:08:21 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F33B9785-B646-4564-849B-BEE3A1700694}
  1481. [2011/06/14 13:06:21 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
  1482. [2010/09/24 02:38:27 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F6A4B871-A06A-0EB2-DA8F-BD26CA4B7D90}
  1483. [2011/06/10 20:21:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
  1484. [2010/09/24 03:08:17 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F9A36074-25AD-4F2E-969E-AEDF452DC57B}
  1485. [2010/09/24 02:52:15 | 000,000,000 | ---D | M] -- C:\Windows\installer\{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}
  1486. [2012/11/22 11:17:59 | 000,000,000 | ---D | M] -- C:\Windows\installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}
  1487.  
  1488. [color=#A23BEC]< %windir%\system32\*. >[/color]
  1489. [2012/08/09 18:34:38 | 000,000,000 | -HSD | M] -- C:\Windows\system32\%APPDATA%
  1490. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\0409
  1491. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\AdvancedInstallers
  1492. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\ar-SA
  1493. [2010/09/24 02:49:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\bg
  1494. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\bg-BG
  1495. [2009/07/13 20:35:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\catroot
  1496. [2009/07/13 20:35:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\catroot2
  1497. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\com
  1498. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\config
  1499. [2010/09/24 02:49:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\cs
  1500. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\cs-CZ
  1501. [2010/09/24 02:49:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\da
  1502. [2011/06/16 18:33:31 | 000,000,000 | ---D | M] -- C:\Windows\system32\da-DK
  1503. [2010/09/24 02:49:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\de
  1504. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\de-DE
  1505. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\Dism
  1506. [2012/12/05 21:33:49 | 000,000,000 | ---D | M] -- C:\Windows\system32\drivers
  1507. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\DriverStore
  1508. [2010/09/24 02:49:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\el
  1509. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\el-GR
  1510. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\en
  1511. [2012/06/13 02:28:59 | 000,000,000 | ---D | M] -- C:\Windows\system32\en-US
  1512. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\es
  1513. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\es-ES
  1514. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\et-EE
  1515. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\fi
  1516. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\fi-FI
  1517. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\fr
  1518. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\fr-FR
  1519. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\FxsTmp
  1520. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\GroupPolicy
  1521. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\GroupPolicyUsers
  1522. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\he-IL
  1523. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\hr-HR
  1524. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\hu
  1525. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\hu-HU
  1526. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\icsxml
  1527. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\IME
  1528. [2009/07/13 20:36:55 | 000,000,000 | ---D | M] -- C:\Windows\system32\inetsrv
  1529. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\InstallShield
  1530. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\it
  1531. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\it-IT
  1532. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ja
  1533. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ja-JP
  1534. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ko
  1535. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ko-KR
  1536. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\LogFiles
  1537. [2009/07/13 21:20:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\lt-LT
  1538. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\lv-LV
  1539. [2010/09/24 02:35:06 | 000,000,000 | ---D | M] -- C:\Windows\system32\Macromed
  1540. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\manifeststore
  1541. [2012/07/12 19:43:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\migration
  1542. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\migwiz
  1543. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\Msdtc
  1544. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\MUI
  1545. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\nb-NO
  1546. [2009/07/13 20:34:31 | 000,000,000 | ---D | M] -- C:\Windows\system32\NDF
  1547. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\NetworkList
  1548. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\nl
  1549. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\nl-NL
  1550. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\no
  1551. [2011/06/16 18:33:30 | 000,000,000 | ---D | M] -- C:\Windows\system32\oobe
  1552. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\pl
  1553. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\pl-PL
  1554. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\Printing_Admin_Scripts
  1555. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt
  1556. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt-BR
  1557. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt-PT
  1558. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\ras
  1559. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\Recovery
  1560. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\restore
  1561. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ro
  1562. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\ro-RO
  1563. [2010/09/24 02:36:18 | 000,000,000 | ---D | M] -- C:\Windows\system32\RTCOM
  1564. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\ru
  1565. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\ru-RU
  1566. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\Setup
  1567. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\sk
  1568. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sk-SK
  1569. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sl-SI
  1570. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\slmgr
  1571. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\Speech
  1572. [2011/08/18 22:27:52 | 000,000,000 | ---D | M] -- C:\Windows\system32\spool
  1573. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\spp
  1574. [2011/06/16 18:33:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\sppui
  1575. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sr-Latn-CS
  1576. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\sv
  1577. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\sv-SE
  1578. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\sysprep
  1579. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\Tasks
  1580. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\th-TH
  1581. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\tr
  1582. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\tr-TR
  1583. [2009/07/13 21:20:19 | 000,000,000 | ---D | M] -- C:\Windows\system32\uk-UA
  1584. [2011/06/14 13:12:53 | 000,000,000 | ---D | M] -- C:\Windows\system32\Wat
  1585. [2012/09/17 19:29:55 | 000,000,000 | ---D | M] -- C:\Windows\system32\wbem
  1586. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\WCN
  1587. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\wdi
  1588. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\WindowsPowerShell
  1589. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\winrm
  1590. [2010/09/24 02:49:17 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-CHS
  1591. [2010/09/24 02:49:16 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-CHT
  1592. [2009/07/13 21:20:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-CN
  1593. [2009/07/13 21:20:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-HK
  1594. [2009/07/13 21:20:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-TW
  1595.  
  1596. [color=#A23BEC]< %windir%\sysnative\*. >[/color]
  1597. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\0409
  1598. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\AdvancedInstallers
  1599. [2010/09/24 02:38:54 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ar-SA
  1600. [2010/09/24 02:38:54 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\bg-BG
  1601. [2011/06/16 18:32:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Boot
  1602. [2012/10/23 22:35:01 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\catroot
  1603. [2012/11/01 14:01:21 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\catroot2
  1604. [2010/09/24 02:36:48 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\CodeIntegrity
  1605. [2009/07/13 23:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\com
  1606. [2012/12/02 20:30:12 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\config
  1607. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\cs-CZ
  1608. [2011/06/16 18:33:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\da-DK
  1609. [2010/09/24 02:38:54 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\de-DE
  1610. [2011/06/16 18:33:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Dism
  1611. [2012/12/09 16:03:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\drivers
  1612. [2012/10/23 20:41:25 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\DriverStore
  1613. [2012/10/23 20:45:21 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\DRVSTORE
  1614. [2010/09/24 02:38:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\el-GR
  1615. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\en
  1616. [2012/07/12 19:43:12 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\en-US
  1617. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\es-ES
  1618. [2010/09/24 02:38:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\et-EE
  1619. [2011/06/16 18:06:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\EventProviders
  1620. [2010/09/24 02:38:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\fi-FI
  1621. [2010/09/24 02:38:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\fr-FR
  1622. [2011/11/21 22:46:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\FxsTmp
  1623. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\GroupPolicy
  1624. [2009/07/13 20:34:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\GroupPolicyUsers
  1625. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\he-IL
  1626. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\hr-HR
  1627. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\hu-HU
  1628. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ias
  1629. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\icsxml
  1630. [2009/07/13 21:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\IME
  1631. [2009/07/13 20:36:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\inetsrv
  1632. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\it-IT
  1633. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ja-JP
  1634. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ko-KR
  1635. [2012/12/08 21:10:50 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\LogFiles
  1636. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\lt-LT
  1637. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\lv-LV
  1638. [2011/11/28 21:21:08 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Macromed
  1639. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\manifeststore
  1640. [2010/09/24 03:16:29 | 000,000,000 | --SD | M] -- C:\Windows\sysnative\Microsoft
  1641. [2012/07/12 19:43:09 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\migration
  1642. [2011/06/16 18:33:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\migwiz
  1643. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Msdtc
  1644. [2009/07/13 23:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\MUI
  1645. [2010/09/24 02:38:56 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\nb-NO
  1646. [2012/08/20 21:23:51 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\NDF
  1647. [2009/07/13 21:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\NetworkList
  1648. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\nl-NL
  1649. [2009/07/24 13:22:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\OEM
  1650. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\oobe
  1651. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pl-PL
  1652. [2009/07/13 23:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Printing_Admin_Scripts
  1653. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pt-BR
  1654. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pt-PT
  1655. [2009/07/13 21:20:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ras
  1656. [2010/09/24 03:10:33 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Recovery
  1657. [2011/06/10 20:26:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\restore
  1658. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ro-RO
  1659. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ru-RU
  1660. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Setup
  1661. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sk-SK
  1662. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sl-SI
  1663. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\slmgr
  1664. [2009/07/13 21:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\SMI
  1665. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Speech
  1666. [2009/07/13 22:53:31 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\spool
  1667. [2009/07/13 21:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\spp
  1668. [2011/06/16 18:33:15 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sppui
  1669. [2011/06/16 18:08:25 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\SPReview
  1670. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sr-Latn-CS
  1671. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sv-SE
  1672. [2010/09/24 05:20:48 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sysprep
  1673. [2012/11/25 13:29:33 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Tasks
  1674. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\th-TH
  1675. [2010/09/24 02:38:57 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\tr-TR
  1676. [2009/07/13 21:20:16 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\uk-UA
  1677. [2011/06/14 13:12:53 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Wat
  1678. [2011/06/16 18:33:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wbem
  1679. [2009/07/13 23:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WCN
  1680. [2011/06/10 23:10:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wdi
  1681. [2009/07/13 23:09:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wfp
  1682. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WinBioDatabase
  1683. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WinBioPlugIns
  1684. [2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WindowsPowerShell
  1685. [2009/07/13 21:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\winevt
  1686. [2009/07/13 23:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\winrm
  1687. [2010/09/24 02:38:58 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-CN
  1688. [2010/09/24 02:38:58 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-HK
  1689. [2010/09/24 02:38:58 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-TW
  1690.  
  1691. [color=#A23BEC]< %Temp%\smtmp\1\*.* >[/color]
  1692.  
  1693. [color=#A23BEC]< %Temp%\smtmp\2\*.* >[/color]
  1694.  
  1695. [color=#A23BEC]< %Temp%\smtmp\3\*.* >[/color]
  1696.  
  1697. [color=#A23BEC]< %Temp%\smtmp\4\*.* >[/color]
  1698.  
  1699. [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
  1700.  
  1701. [color=#A23BEC]< %systemroot%\syswow64\*.dll /lockedfiles >[/color]
  1702.  
  1703. [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]
  1704.  
  1705. [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /90 >[/color]
  1706. [2012/12/04 02:41:28 | 000,037,976 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Windows\system32\drivers\CFRMD.sys
  1707.  
  1708. [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
  1709.  
  1710. [color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /90 >[/color]
  1711. [2012/12/04 02:41:28 | 000,037,976 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Windows\syswow64\drivers\CFRMD.sys
  1712.  
  1713. [color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /lockedfiles >[/color]
  1714.  
  1715. [color=#A23BEC]< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >[/color]
  1716.  
  1717. [color=#A23BEC]< %systemroot%\*. /rp /s >[/color]
  1718.  
  1719. [color=#A23BEC]< %systemroot%\assembly\tmp\*.* /S /MD5 >[/color]
  1720.  
  1721. [color=#A23BEC]< %systemroot%\assembly\temp\*.* /S /MD5 >[/color]
  1722. [2012/03/04 17:32:28 | 000,022,584 | ---- | M] () MD5=BD1DF0D6DB26F210CE52DA48A59F96C4 -- C:\Windows\assembly\temp\O8JWJO715P\HP.SupportFramework.Communicator.dll
  1723.  
  1724. [color=#A23BEC]< %systemroot%\assembly\GAC\*.ini >[/color]
  1725.  
  1726. [color=#A23BEC]< %systemroot%\assembly\GAC_32\*.ini >[/color]
  1727.  
  1728. [color=#A23BEC]< %systemroot%\assembly\GAC_64\*.ini >[/color]
  1729.  
  1730. [color=#A23BEC]< %SystemRoot%\assembly\GAC_MSIL\*.ini >[/color]
  1731.  
  1732. [color=#A23BEC]< wsSystemRoot|l,n,u,@;True;False;True;$,{ /fn >[/color]
  1733.  
  1734. [color=#A23BEC]< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >[/color]
  1735.  
  1736. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color]
  1737. "" = PSFactoryBuffer
  1738. [HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32]
  1739. "" = %systemroot%\system32\wbem\wbemsvc.dll -- [2009/07/13 19:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation)
  1740. "ThreadingModel" = Both
  1741.  
  1742. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color]
  1743.  
  1744. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color]
  1745.  
  1746. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color]
  1747.  
  1748. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color]
  1749. "" = MruPidlList
  1750. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  1751. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  1752. "ThreadingModel" = Apartment
  1753.  
  1754. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} /s >[/color]
  1755. "" = Start Menu Pin
  1756. "ImplementsVerbs" = startpin;startunpin
  1757. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}\InProcServer32]
  1758. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  1759. "ThreadingModel" = Apartment
  1760.  
  1761. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color]
  1762. "" = PSFactoryBuffer
  1763. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32]
  1764. "" = %systemroot%\system32\wbem\wbemsvc.dll -- [2009/07/13 19:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation)
  1765. "ThreadingModel" = Both
  1766.  
  1767. [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color]
  1768. "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper
  1769. [HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32]
  1770. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
  1771. "ThreadingModel" = Free
  1772.  
  1773. [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color]
  1774. "" = ShellFolder for CD Burning
  1775. [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  1776. "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  1777. "ThreadingModel" = Apartment
  1778. [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\MergedFolder]
  1779. "Attributes" = 0x0
  1780. "AttributeMask" = 0xffffffff
  1781. "Location" = @shell32.dll,-12591 -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
  1782. "ConflictOverlayIcon" = %SystemRoot%\system32\imageres.dll,-169 -- [2009/07/13 19:06:03 | 020,268,032 | ---- | M] (Microsoft Corporation)
  1783.  
  1784. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color]
  1785.  
  1786. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color]
  1787. "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper
  1788. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32]
  1789. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
  1790. "ThreadingModel" = Free
  1791.  
  1792. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\clsid\{12d0253a-7c96-815c-11e0-3034bbd97cc0}] /s >[/color]
  1793.  
  1794. [color=#A23BEC]< HKEY_CURRENT_USER\Software\MSOLoad /s >[/color]
  1795.  
  1796. [color=#A23BEC]< bcdedit /enum all /v >C:\boot.txt /c >[/color]
  1797.  
  1798. [color=#A23BEC]< type c:\diskreport.txt /c >[/color]
  1799. Microsoft DiskPart version 6.1.7601
  1800. Copyright (C) 1999-2008 Microsoft Corporation.
  1801. On computer: DEANNE-HP
  1802. Volume ### Ltr Label Fs Type Size Status Info
  1803. ---------- --- ----------- ----- ---------- ------- --------- --------
  1804. Volume 0 E DVD-ROM 0 B No Media
  1805. Volume 1 SYSTEM NTFS Partition 100 MB Healthy System
  1806. Volume 2 C OS NTFS Partition 916 GB Healthy Boot
  1807. Volume 3 D HP_RECOVERY NTFS Partition 15 GB Healthy
  1808. Volume 4 G Removable 0 B No Media
  1809.  
  1810. [color=#A23BEC]< MD5 for: AFD.SYS >[/color]
  1811. [2011/12/27 21:59:24 | 000,498,688 | ---- | M] (Microsoft Corporation) MD5=1C7857B62DE5994A75B054A9FD4C3825 -- C:\Windows\SysNative\drivers\afd.sys
  1812. [2011/12/27 21:59:24 | 000,498,688 | ---- | M] (Microsoft Corporation) MD5=1C7857B62DE5994A75B054A9FD4C3825 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17752_none_35e10b89752ee0f5\afd.sys
  1813. [2011/12/27 22:01:36 | 000,498,176 | ---- | M] (Microsoft Corporation) MD5=36A14FD1A23F57046361733B792CA8DB -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21887_none_364f3a028e605345\afd.sys
  1814. [2011/04/24 20:44:02 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=6EF20DDF3172E97D69F596FB90602F29 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_3430bc3977dfec2d\afd.sys
  1815. [2009/07/13 17:21:42 | 000,500,224 | ---- | M] (Microsoft Corporation) MD5=B9384E03479D2506BC924C16A3DB87BC -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_33dd3439781e25f7\afd.sys
  1816. [2011/12/27 22:01:12 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=CCA39961E76B491DDF44B1E90FC8971D -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.21115_none_34b263fe91032456\afd.sys
  1817. [2010/11/20 03:23:34 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=D31DC7A16DEA4A9BAF179F3D6FBDB38C -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_360e4801750ca991\afd.sys
  1818. [2011/04/24 20:34:03 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=D5B031C308A409A0A576BFF4CF083D30 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_3618198975057170\afd.sys
  1819. [2011/12/27 21:59:11 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=DB9D6C6B2CD95A9CA414D045B627422E -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16937_none_34154fcd77f3bbda\afd.sys
  1820. [2011/04/24 21:09:35 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=F4AD06143EAC303F55D0E86C40802976 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_3695e61e8e2c13d4\afd.sys
  1821. [2011/04/24 20:44:27 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=FBFF8B7C9D116229E9208A0D1CAEB49B -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_3483491e9126fe55\afd.sys
  1822.  
  1823. [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
  1824. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
  1825. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
  1826. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
  1827. [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
  1828.  
  1829. [color=#A23BEC]< MD5 for: CNGAUDIT.DLL >[/color]
  1830. [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
  1831. [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
  1832. [2009/07/13 19:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
  1833. [2009/07/13 19:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
  1834.  
  1835. [color=#A23BEC]< MD5 for: CSC.SYS >[/color]
  1836. [2009/07/13 17:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) MD5=4A6173C2279B498CD8F57CAE504564CB -- C:\Windows\winsxs\amd64_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7600.16385_none_fa3d3a8e759850bd\csc.sys
  1837. [2010/11/20 03:27:13 | 000,514,560 | ---- | M] (Microsoft Corporation) MD5=54DA3DFD29ED9F1619B6F53F3CE55E49 -- C:\Windows\winsxs\amd64_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7601.17514_none_fc6e4e567286d457\csc.sys
  1838.  
  1839. [color=#A23BEC]< MD5 for: DFSC.SYS >[/color]
  1840. [2009/07/13 17:23:44 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=3F1DC527070ACB87E40AFE46EF6DA749 -- C:\Windows\winsxs\amd64_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7600.16385_none_e38f1f84ffcceb85\dfsc.sys
  1841. [2011/04/26 20:45:11 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=59E1C75E5DDBB70BF5A9C6A34D31B4AC -- C:\Windows\winsxs\amd64_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7600.20953_none_e43734fe18d3f691\dfsc.sys
  1842. [2010/11/20 03:26:32 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9BB2EF44EAA163B29C4A4587887A0FE4 -- C:\Windows\SysNative\drivers\dfsc.sys
  1843. [2010/11/20 03:26:32 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9BB2EF44EAA163B29C4A4587887A0FE4 -- C:\Windows\winsxs\amd64_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7601.17514_none_e5c0334cfcbb6f1f\dfsc.sys
  1844. [2011/04/26 20:57:40 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9C253CE7311CA60FC11C774692A13208 -- C:\Windows\winsxs\amd64_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7600.16804_none_e3e4a818ff8ce469\dfsc.sys
  1845.  
  1846. [color=#A23BEC]< MD5 for: DISK.SYS >[/color]
  1847. [2009/07/13 19:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\drivers\disk.sys
  1848. [2009/07/13 19:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\DriverStore\FileRepository\disk.inf_amd64_neutral_10ce25bbc5a9cc43\disk.sys
  1849. [2009/07/13 19:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_55bb738b8ddd8a01\disk.sys
  1850.  
  1851. [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
  1852. [2008/06/06 15:03:52 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
  1853.  
  1854. [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
  1855. [2010/09/24 03:13:58 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
  1856. [2011/02/26 00:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
  1857. [2011/02/25 23:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
  1858. [2009/07/13 19:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
  1859. [2011/02/25 23:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
  1860. [2010/09/24 03:15:36 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
  1861. [2011/02/25 23:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
  1862. [2011/02/25 00:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
  1863. [2011/02/25 00:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
  1864. [2011/02/26 00:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
  1865. [2010/11/20 06:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
  1866. [2010/09/24 03:13:58 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
  1867. [2010/09/24 03:12:25 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
  1868. [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
  1869. [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
  1870. [2010/09/24 03:15:36 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
  1871. [2010/09/24 03:12:25 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
  1872. [2010/11/20 07:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
  1873. [2010/09/24 03:15:36 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
  1874. [2010/09/24 03:12:25 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
  1875. [2009/07/13 19:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
  1876. [2010/09/24 03:15:36 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
  1877. [2010/09/24 03:13:58 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
  1878. [2011/02/26 00:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
  1879. [2010/09/24 03:12:25 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
  1880. [2010/09/24 03:13:58 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe
  1881.  
  1882. [color=#A23BEC]< MD5 for: I8042PRT.SYS >[/color]
  1883. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\drivers\i8042prt.sys
  1884. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\i8042prt.sys
  1885. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_neutral_7a5f47d3150cc0eb\i8042prt.sys
  1886. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.1.7600.16385_none_f3435f7ff2a9f325\i8042prt.sys
  1887. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_f5747347ef9876bf\i8042prt.sys
  1888. [2009/07/13 17:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_aa28fd23ec0c39f9\i8042prt.sys
  1889.  
  1890. [color=#A23BEC]< MD5 for: LSASS.EXE >[/color]
  1891. [2009/07/13 19:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_023f7c69767c3edd\lsass.exe
  1892. [2009/07/13 19:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_023e7e05767d22ad\lsass.exe
  1893. [2009/07/13 19:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_02bd4ae48fa2de68\lsass.exe
  1894. [2009/07/13 19:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
  1895. [2011/11/17 00:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
  1896. [2011/11/17 01:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=156F6159457D0AA7E59B62681B56EB90 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16915_none_028b374176436a30\lsass.exe
  1897. [2011/11/17 01:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=156F6159457D0AA7E59B62681B56EB90 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.17035_none_02756f8b7653d554\lsass.exe
  1898. [2012/06/04 01:51:10 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=79C908CAA6F43021EB05F4C733A927D1 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_04f609a88c8c279c\lsass.exe
  1899. [2012/06/01 23:30:31 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=BF63CE11A25F3509129888710D5111FC -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21225_none_0309de288f695654\lsass.exe
  1900. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\SysNative\lsass.exe
  1901. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
  1902. [2011/11/17 00:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_044756c773895c5e\lsass.exe
  1903. [2011/11/17 00:42:52 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D21BD47E528CD62E79311FB5DF0150E6 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21092_none_02bb2a0a8fa4d398\lsass.exe
  1904.  
  1905. [color=#A23BEC]< MD5 for: NETBT.SYS >[/color]
  1906. [2010/11/20 03:23:20 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=09594D1089C523423B32A4229263F068 -- C:\Windows\SysNative\drivers\netbt.sys
  1907. [2010/11/20 03:23:20 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=09594D1089C523423B32A4229263F068 -- C:\Windows\winsxs\amd64_microsoft-windows-netbt_31bf3856ad364e35_6.1.7601.17514_none_be8acdd10de3b1a6\netbt.sys
  1908. [2009/07/13 17:21:29 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=9162B273A44AB9DCE5B44362731D062A -- C:\Windows\winsxs\amd64_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_bc59ba0910f52e0c\netbt.sys
  1909.  
  1910. [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
  1911. [2009/07/13 19:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
  1912. [2010/11/20 07:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
  1913. [2010/11/20 07:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
  1914. [2010/11/20 06:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
  1915. [2010/11/20 06:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
  1916. [2009/07/13 19:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
  1917.  
  1918. [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
  1919. [2009/07/13 19:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
  1920. [2009/07/13 19:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
  1921. [2010/11/20 06:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
  1922. [2010/11/20 06:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
  1923. [2010/11/20 07:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
  1924. [2010/11/20 07:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
  1925.  
  1926. [color=#A23BEC]< MD5 for: SERIAL.SYS >[/color]
  1927. [2009/07/13 18:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\SysNative\drivers\serial.sys
  1928. [2009/07/13 18:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\SysNative\DriverStore\FileRepository\msports.inf_amd64_neutral_fdcfb86ce78678d1\serial.sys
  1929. [2009/07/13 18:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\winsxs\amd64_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_548ca258d20f4ada\serial.sys
  1930.  
  1931. [color=#A23BEC]< MD5 for: SERVICES.EXE >[/color]
  1932. [2012/08/19 16:56:01 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
  1933. [2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
  1934.  
  1935. [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
  1936. [2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
  1937. [2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
  1938. [2012/09/29 18:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
  1939. [2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
  1940. [2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
  1941.  
  1942. [color=#A23BEC]< MD5 for: TCPIP.SYS >[/color]
  1943. [2011/04/24 23:28:24 | 001,893,248 | ---- | M] (Microsoft Corporation) MD5=1F748D5439B65E0BEBD92F65048F030D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_0fb918de99201ffb\tcpip.sys
  1944. [2011/09/29 11:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
  1945. [2010/11/20 07:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
  1946. [2011/06/21 00:16:55 | 001,888,128 | ---- | M] (Microsoft Corporation) MD5=5279D4DD69C7C71524B8E7A5746D15CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_0f8ed978993fa916\tcpip.sys
  1947. [2012/03/30 04:19:17 | 001,877,872 | ---- | M] (Microsoft Corporation) MD5=5EFD096DEF47F8B88EF591DA92143440 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21178_none_0faa5514992a39a7\tcpip.sys
  1948. [2011/04/24 23:32:22 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=61DC720BB065D607D5823F13D2A64321 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_0f668bf97fd90dd3\tcpip.sys
  1949. [2012/03/30 05:09:53 | 001,895,280 | ---- | M] (Microsoft Corporation) MD5=624C5B3AA4C99B3184BB922D9ECE3FF0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_0f140fa780164fde\tcpip.sys
  1950. [2012/03/30 04:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
  1951. [2009/07/13 19:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
  1952. [2011/04/24 23:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
  1953. [2011/06/21 00:20:30 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
  1954. [2011/09/29 10:17:51 | 001,886,064 | ---- | M] (Microsoft Corporation) MD5=AC3E29880DB5659532A1AA3439304A43 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_0fad20ca992955d7\tcpip.sys
  1955. [2012/03/30 05:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\SysNative\drivers\tcpip.sys
  1956. [2012/03/30 05:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
  1957. [2011/04/25 00:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
  1958. [2011/06/21 00:27:14 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=B9D87C7707F058AC652A398CD28DE14B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_0f4d1e3b7feb1307\tcpip.sys
  1959. [2011/06/21 00:34:00 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
  1960. [2011/09/29 10:24:44 | 001,897,328 | ---- | M] (Microsoft Corporation) MD5=F18F56EFC0BFB9C87BA01C37B27F4DA5 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_0f170e9f80139ebc\tcpip.sys
  1961. [2011/09/29 10:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
  1962.  
  1963. [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
  1964. [2010/11/20 06:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
  1965. [2010/11/20 06:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
  1966. [2009/07/13 19:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
  1967. [2009/07/13 19:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
  1968. [2010/11/20 07:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
  1969. [2010/11/20 07:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
  1970.  
  1971. [color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color]
  1972. [2010/11/20 07:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\SysNative\drivers\volsnap.sys
  1973. [2010/11/20 07:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_neutral_df8bea40ac96ca21\volsnap.sys
  1974. [2010/11/20 07:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7601.17514_none_73dcbcf012b4850e\volsnap.sys
  1975. [2009/07/13 19:45:55 | 000,294,992 | ---- | M] (Microsoft Corporation) MD5=58F82EED8CA24B461441F9C3E4F0BF5C -- C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7600.16385_none_71aba92815c60174\volsnap.sys
  1976.  
  1977. [color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
  1978. [2009/07/13 19:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
  1979. [2009/07/13 19:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
  1980. [2009/07/13 19:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
  1981. [2009/07/13 19:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
  1982.  
  1983. [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
  1984. [2010/11/20 07:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
  1985. [2010/11/20 07:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
  1986. [2009/07/13 19:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
  1987. [2012/09/29 18:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
  1988. [2010/09/24 03:15:36 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
  1989. [2010/09/24 03:15:36 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
  1990.  
  1991. < End of report >
Add Comment
Please, Sign In to add comment