Mazz

OTL

Dec 5th, 2013
574
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 422.12 KB | None | 0 0
  1. OTL logfile created on: 05/12/2013 20:47:06 - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marion\Desktop
  3. 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.11.9600.16428)
  5. Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
  6.  
  7. 5.99 Gb Total Physical Memory | 3.87 Gb Available Physical Memory | 64.62% Memory free
  8. 11.99 Gb Paging File | 9.48 Gb Available in Paging File | 79.07% Paging File free
  9. Paging file location(s): C:\pagefile.sys 6142 6142F:\pagef [Binary data over 200 bytes]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 596.07 Gb Total Space | 481.35 Gb Free Space | 80.75% Space Free | Partition Type: NTFS
  13. Drive F: | 298.09 Gb Total Space | 9.14 Gb Free Space | 3.07% Space Free | Partition Type: NTFS
  14.  
  15. Computer Name: MARION-PC | User Name: Marion | Logged in as Administrator.
  16. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
  17. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
  18.  
  19. [color=#E56717]========== Processes (SafeList) ==========[/color]
  20.  
  21. PRC - [2013/12/05 20:44:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marion\Desktop\OTL (1).scr
  22. PRC - [2013/11/14 11:29:33 | 000,863,184 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  23. PRC - [2013/11/09 02:51:36 | 029,770,248 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\AppData\Roaming\Dropbox\bin\Dropbox.exe
  24. PRC - [2013/11/06 01:55:46 | 000,845,168 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
  25. PRC - [2013/11/06 01:55:38 | 001,564,528 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
  26. PRC - [2013/10/14 23:03:48 | 000,237,960 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
  27. PRC - [2013/10/06 03:27:28 | 000,129,424 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe
  28. PRC - [2013/05/11 10:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
  29. PRC - [2013/02/19 21:32:20 | 001,259,296 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
  30.  
  31.  
  32. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  33.  
  34. MOD - [2013/11/14 11:29:31 | 000,399,312 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppgooglenaclpluginchrome.dll
  35. MOD - [2013/11/14 11:29:29 | 004,055,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll
  36. MOD - [2013/11/14 11:28:37 | 000,702,416 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
  37. MOD - [2013/11/14 11:28:36 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll
  38. MOD - [2013/11/14 11:28:34 | 001,619,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
  39. MOD - [2013/11/09 02:50:34 | 003,558,400 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
  40. MOD - [2013/10/18 23:55:02 | 025,100,288 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Dropbox\bin\libcef.dll
  41. MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
  42. MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
  43.  
  44.  
  45. [color=#E56717]========== Services (SafeList) ==========[/color]
  46.  
  47. SRV:[b]64bit:[/b] - [2013/11/12 08:51:33 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
  48. SRV:[b]64bit:[/b] - [2013/09/06 16:32:06 | 000,288,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe -- (McComponentHostService)
  49. SRV:[b]64bit:[/b] - [2013/05/27 05:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
  50. SRV:[b]64bit:[/b] - [2013/02/19 13:56:14 | 000,182,752 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe -- (mfevtp)
  51. SRV:[b]64bit:[/b] - [2013/02/19 13:53:32 | 000,218,760 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
  52. SRV:[b]64bit:[/b] - [2013/02/19 13:51:54 | 000,241,456 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
  53. SRV:[b]64bit:[/b] - [2012/11/16 21:10:22 | 000,383,608 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
  54. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (MSK80Service)
  55. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
  56. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
  57. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
  58. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
  59. SRV:[b]64bit:[/b] - [2012/08/31 12:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
  60. SRV:[b]64bit:[/b] - [2011/10/26 02:00:58 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
  61. SRV - [2013/11/13 10:42:36 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
  62. SRV - [2013/10/06 03:27:28 | 000,129,424 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe -- (NCO)
  63. SRV - [2013/10/02 16:05:08 | 000,121,616 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe -- (McAfee SiteAdvisor Service)
  64. SRV - [2013/05/11 10:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
  65. SRV - [2013/02/19 21:32:20 | 001,259,296 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
  66. SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
  67. SRV - [2009/06/10 21:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  68.  
  69.  
  70. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  71.  
  72. DRV:[b]64bit:[/b] - [2013/11/13 08:35:22 | 000,016,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SWDUMon.sys -- (SWDUMon)
  73. DRV:[b]64bit:[/b] - [2013/10/02 07:50:58 | 000,067,808 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mozy.sys -- (mozyFilter)
  74. DRV:[b]64bit:[/b] - [2013/09/27 19:23:26 | 000,162,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.sys -- (ccSet_NST)
  75. DRV:[b]64bit:[/b] - [2013/09/11 23:26:40 | 000,036,096 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd)
  76. DRV:[b]64bit:[/b] - [2013/08/21 04:31:40 | 000,204,568 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
  77. DRV:[b]64bit:[/b] - [2013/08/21 04:31:40 | 000,103,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
  78. DRV:[b]64bit:[/b] - [2013/08/13 00:54:29 | 001,907,440 | ---- | M] (Hauppauge Computer Works) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HCW85BDA.sys -- (HCW85BDA)
  79. DRV:[b]64bit:[/b] - [2013/04/27 07:56:54 | 000,021,600 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdkmafd.sys -- (amdkmafd)
  80. DRV:[b]64bit:[/b] - [2013/04/12 08:20:15 | 000,015,344 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomrouterfilter.sys -- (wacomrouterfilter)
  81. DRV:[b]64bit:[/b] - [2013/04/06 11:23:03 | 000,302,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y62x64.sys -- (e1yexpress)
  82. DRV:[b]64bit:[/b] - [2013/04/06 11:02:53 | 000,020,464 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
  83. DRV:[b]64bit:[/b] - [2013/02/19 13:59:06 | 000,070,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
  84. DRV:[b]64bit:[/b] - [2013/02/19 13:56:26 | 000,340,216 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
  85. DRV:[b]64bit:[/b] - [2013/02/19 13:55:14 | 000,106,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
  86. DRV:[b]64bit:[/b] - [2013/02/19 13:54:32 | 000,771,536 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
  87. DRV:[b]64bit:[/b] - [2013/02/19 13:53:42 | 000,515,968 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
  88. DRV:[b]64bit:[/b] - [2013/02/19 13:53:02 | 000,309,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
  89. DRV:[b]64bit:[/b] - [2013/02/19 13:52:44 | 000,179,280 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
  90. DRV:[b]64bit:[/b] - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
  91. DRV:[b]64bit:[/b] - [2012/12/10 14:48:02 | 000,044,544 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
  92. DRV:[b]64bit:[/b] - [2012/08/23 14:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
  93. DRV:[b]64bit:[/b] - [2012/08/23 14:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  94. DRV:[b]64bit:[/b] - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
  95. DRV:[b]64bit:[/b] - [2012/08/04 14:19:22 | 000,018,832 | ---- | M] (PenMount) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pmkbdfltr.sys -- (pmkbdfltr)
  96. DRV:[b]64bit:[/b] - [2012/04/20 15:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)
  97. DRV:[b]64bit:[/b] - [2012/03/01 06:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  98. DRV:[b]64bit:[/b] - [2011/10/26 03:05:10 | 010,496,512 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
  99. DRV:[b]64bit:[/b] - [2011/10/26 03:05:10 | 010,496,512 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
  100. DRV:[b]64bit:[/b] - [2011/10/26 01:21:58 | 000,326,656 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
  101. DRV:[b]64bit:[/b] - [2011/06/06 22:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
  102. DRV:[b]64bit:[/b] - [2011/03/11 06:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  103. DRV:[b]64bit:[/b] - [2011/03/11 06:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  104. DRV:[b]64bit:[/b] - [2010/11/20 13:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  105. DRV:[b]64bit:[/b] - [2010/05/06 09:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
  106. DRV:[b]64bit:[/b] - [2009/12/30 11:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
  107. DRV:[b]64bit:[/b] - [2009/07/14 01:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  108. DRV:[b]64bit:[/b] - [2009/07/14 01:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  109. DRV:[b]64bit:[/b] - [2009/07/14 01:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  110. DRV:[b]64bit:[/b] - [2009/07/14 00:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
  111. DRV:[b]64bit:[/b] - [2009/06/10 20:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  112. DRV:[b]64bit:[/b] - [2009/06/10 20:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  113. DRV:[b]64bit:[/b] - [2009/06/10 20:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  114. DRV:[b]64bit:[/b] - [2009/06/10 20:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  115. DRV - [2009/07/14 01:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  116. DRV - [2006/07/19 12:04:00 | 000,014,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\dell\drivers\R267410\atillk64.sys -- (atillk64)
  117.  
  118.  
  119. [color=#E56717]========== Standard Registry (All) ==========[/color]
  120.  
  121.  
  122. [color=#E56717]========== Internet Explorer ==========[/color]
  123.  
  124. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
  125. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  126. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  127. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  128. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  129. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  130. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
  131. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
  132. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  133. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
  134. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
  135. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  136. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  137. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  138. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  139. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  140. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
  141. IE - HKLM\..\SearchScopes,DefaultScope =
  142. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  143. IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
  144.  
  145.  
  146. IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
  147. IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  148. IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  149.  
  150. IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
  151. IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  152. IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  153.  
  154. IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  155. IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
  156.  
  157. IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  158. IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
  159.  
  160. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
  161. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
  162. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
  163. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://virginmedia.com/
  164. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
  165. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
  166. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 54 7E 92 81 C3 73 CB 01 [binary data]
  167. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  168. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  169. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
  170. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
  171. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\SearchScopes\{452B4F5D-18DD-42C7-809A-34754EB5172C}: "URL" = http://uk.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20110937,16938,0,8,0
  172. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_en
  173. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\SearchScopes\{A753159B-7604-4426-AF07-A8153F3B1107}: "URL" = http://uk.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
  174. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=IDSS&chn=retail&geo=GB&ver=2014&locale=en_GB&gct=kwd&qsrc=2869
  175. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  176. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
  177.  
  178. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.virginmedia.com/
  179. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://www.virginmedia.com/
  180. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
  181. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
  182. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
  183. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
  184. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
  185. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 54 7E 92 81 C3 73 CB 01 [binary data]
  186. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  187. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
  188. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\URLSearchHook: {9427041a-a8dc-4d06-9a68-93873486e957} - No CLSID value found
  189. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  190. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\URLSearchHook: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - No CLSID value found
  191. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\URLSearchHook: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - No CLSID value found
  192. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
  193. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
  194. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes,DefaultScope =
  195. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
  196. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{087a7792-10bb-455d-bd55-427d589addf5}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YN^xdm085^YY^gb&si=google_figsdfitness&ptb=22759277-C892-4A15-B599-019125E73BF2&ind=2013051011&n=77fcb883&psa=&st=sb&searchfor={searchTerms}
  197. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{10B4E706-0FB5-43BE-88B2-C3CC5CCFECC8}: "URL" = http://search.surfcanyon.com/search?f=sb&q={searchTerms}
  198. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{452B4F5D-18DD-42C7-809A-34754EB5172C}: "URL" = http://uk.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20110937,16938,0,8,0
  199. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_en
  200. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{A753159B-7604-4426-AF07-A8153F3B1107}: "URL" = http://uk.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
  201. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\SearchScopes\{B16D4423-A93F-4EF2-BE8E-4E6CFEC23362}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_UK&apn_ptnrs=U3&apn_dtid=OSJ000YYGB&apn_uid=3C52A9ED-8439-407D-804D-435BE12E48F3&apn_sauid=F11A3E81-7B62-483D-8B95-DCB3C87540C5&
  202. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  203. IE - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  204.  
  205.  
  206. [color=#E56717]========== FireFox ==========[/color]
  207.  
  208. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
  209. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  210. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
  211. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
  212. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
  213. FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
  214. FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
  215. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
  216. FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
  217. FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
  218. FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
  219. FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
  220. FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  221. FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
  222. FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
  223. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
  224. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
  225. FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  226.  
  227. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2013/10/04 21:40:25 | 000,000,000 | ---D | M]
  228. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F04D2D30-776C-4d02-8627-8E4385ECA58D}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.6.0.27\coFFPlgn\ [2013/12/05 17:10:09 | 000,000,000 | ---D | M]
  229. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2013/11/21 08:32:02 | 000,000,000 | ---D | M]
  230. FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\McAfee\MSK [2013/08/14 18:53:52 | 000,000,000 | ---D | M]
  231.  
  232. [2012/09/20 20:42:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
  233.  
  234. [color=#E56717]========== Chrome ==========[/color]
  235.  
  236. CHR - default_search_provider: Google (Enabled)
  237. CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
  238. CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
  239. CHR - homepage: http://www.virginmedia.com/
  240. CHR - Extension: Google Docs = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1\
  241. CHR - Extension: Google Drive = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
  242. CHR - Extension: YouTube = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
  243. CHR - Extension: Google Search = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
  244. CHR - Extension: Google Wallet = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1\
  245. CHR - Extension: Norton Identity Protection = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\nppllibpnmahfaklnpggkibhkapjkeob\2014.6.0.27_0\
  246. CHR - Extension: Gmail = C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
  247.  
  248. O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  249. O2:[b]64bit:[/b] - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - Reg Error: Value error. File not found
  250. O2:[b]64bit:[/b] - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20131121002211.dll (McAfee, Inc.)
  251. O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
  252. O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
  253. O2:[b]64bit:[/b] - BHO: (Norton Identity Protection) - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.6.0.27\CoIEPlg.dll (Symantec Corporation)
  254. O2:[b]64bit:[/b] - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  255. O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
  256. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
  257. O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20131121002212.dll (McAfee, Inc.)
  258. O2 - BHO: (Norton Identity Protection) - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\CoIEPlg.dll (Symantec Corporation)
  259. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
  260. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  261. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
  262. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.6.0.27\CoIEPlg.dll (Symantec Corporation)
  263. O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  264. O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
  265. O3 - HKLM\..\Toolbar: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\CoIEPlg.dll (Symantec Corporation)
  266. O3:[b]64bit:[/b] - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
  267. O3 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
  268. O3:[b]64bit:[/b] - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\Toolbar\WebBrowser: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.6.0.27\CoIEPlg.dll (Symantec Corporation)
  269. O3 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..\Toolbar\WebBrowser: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\CoIEPlg.dll (Symantec Corporation)
  270. O3 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
  271. O3:[b]64bit:[/b] - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
  272. O3 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
  273. O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
  274. O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  275. O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  276. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
  277. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
  278. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [Consumer Input Update] C:\Program Files (x86)\Consumer Input\dca-ua.exe File not found
  279. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [Driver Whiz] C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe /applicationMode:systemTray /showWelcome:false File not found
  280. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [iTunes Sync] "C:\Users\Marion\AppData\Local\Apps\2.0\H0T3JGL3.JGK\BMB4RVJK.XV3\itun..tion_e05fb8e279c30af8_0001.0000_76d6a1fc3fa61adf\iTunesSync.exe" File not found
  281. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe File not found
  282. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
  283. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [PowerSuite] "C:\PROGRA~2\Uniblue\POWERS~1\launcher.exe" delay 20000 -m File not found
  284. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
  285. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
  286. O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  287. O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  288. O4 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
  289. O4 - Startup: C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Marion\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
  290. O4 - Startup: C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
  291. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  292. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
  293. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
  294. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
  295. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
  296. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
  297. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  298. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
  299. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
  300. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
  301. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
  302. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
  303. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
  304. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
  305. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
  306. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
  307. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
  308. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
  309. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
  310. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
  311. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
  312. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
  313. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
  314. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
  315. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
  316. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
  317. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
  318. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
  319. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
  320. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
  321. O7 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
  322. O7 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
  323. O7 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
  324. O7 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
  325. O7 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
  326. O7 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
  327. O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
  328. O8:[b]64bit:[/b] - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
  329. O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
  330. O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
  331. O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
  332. O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
  333. O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
  334. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
  335. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
  336. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  337. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  338. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  339. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
  340. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  341. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  342. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
  343. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  344. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  345. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  346. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  347. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  348. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  349. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  350. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  351. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  352. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  353. O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
  354. O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
  355. O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  356. O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  357. O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  358. O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
  359. O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  360. O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
  361. O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
  362. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  363. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  364. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  365. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  366. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  367. O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  368. O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  369. O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  370. O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  371. O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  372. O13[b]64bit:[/b] - gopher Prefix: missing
  373. O13 - gopher Prefix: missing
  374. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..Trusted Domains: dell.com ([]* in Trusted sites)
  375. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..Trusted Domains: internet ([]about in Trusted sites)
  376. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..Trusted Domains: mcafee.com ([]http in Trusted sites)
  377. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..Trusted Domains: mcafee.com ([]https in Trusted sites)
  378. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1001\..Trusted Domains: pheonixviewer.com ([]https in Trusted sites)
  379. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..Trusted Domains: dell.com ([]* in Trusted sites)
  380. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..Trusted Domains: internet ([]about in Trusted sites)
  381. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..Trusted Domains: mcafee.com ([]http in Trusted sites)
  382. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..Trusted Domains: mcafee.com ([]https in Trusted sites)
  383. O15 - HKU\S-1-5-21-1013639583-4134777893-1337409647-1005\..Trusted Domains: pheonixviewer.com ([]https in Trusted sites)
  384. O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab (Microsoft Office Template and Media Control)
  385. O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
  386. O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (Reg Error: Key error.)
  387. O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
  388. O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
  389. O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (Reg Error: Key error.)
  390. O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553570000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Reg Error: Key error.)
  391. O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
  392. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
  393. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{243E26F8-19B7-40F0-B85D-57EF616299DD}: DhcpNameServer = 194.168.4.100 194.168.8.100
  394. O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  395. O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  396. O18:[b]64bit:[/b] - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  397. O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  398. O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  399. O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  400. O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  401. O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  402. O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  403. O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  404. O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
  405. O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  406. O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  407. O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
  408. O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  409. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
  410. O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  411. O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
  412. O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  413. O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
  414. O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  415. O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  416. O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
  417. O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  418. O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  419. O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  420. O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  421. O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  422. O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  423. O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  424. O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  425. O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  426. O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  427. O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
  428. O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  429. O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  430. O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
  431. O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  432. O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
  433. O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  434. O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
  435. O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  436. O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
  437. O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  438. O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  439. O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
  440. O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  441. O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  442. O18:[b]64bit:[/b] - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
  443. O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  444. O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
  445. O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  446. O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  447. O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
  448. O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
  449. O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
  450. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  451. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  452. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  453. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  454. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  455. O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
  456. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  457. O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
  458. O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  459. O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  460. O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
  461. O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  462. O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
  463. O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
  464. O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
  465. O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
  466. O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
  467. O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
  468. O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  469. O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
  470. O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
  471. O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
  472. O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
  473. O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
  474. O31 - SafeBoot: AlternateShell - cmd.exe
  475. O32 - HKLM CDRom: AutoRun - 1
  476. O32 - AutoRun File - [2013/11/03 01:37:03 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
  477. O33 - MountPoints2\{1548efea-ee06-11e2-92cc-00219b1c2f23}\Shell - "" = AutoRun
  478. O34 - HKLM BootExecute: (autocheck autochk *)
  479. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  480. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  481. O35 - HKLM\..comfile [open] -- "%1" %*
  482. O35 - HKLM\..exefile [open] -- "%1" %*
  483. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  484. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  485. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  486. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  487. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  488. O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
  489. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  490.  
  491.  
  492. MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^MozyHome Status.lnk - C:\Program Files\MozyHome\mozystat.exe - (Mozy, Inc.)
  493. MsConfig:64bit - StartUpReg: [b]Akamai NetSession Interface[/b] - hkey= - key= - C:\Users\Marion\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
  494. MsConfig:64bit - StartUpReg: [b]AppleSyncNotifier[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
  495. MsConfig:64bit - StartUpReg: [b]APSDaemon[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
  496. MsConfig:64bit - StartUpReg: [b]ATICustomerCare[/b] - hkey= - key= - C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
  497. MsConfig:64bit - StartUpReg: [b]EverioService[/b] - hkey= - key= - C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
  498. MsConfig:64bit - StartUpReg: [b]KiesAirMessage[/b] - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics)
  499. MsConfig:64bit - StartUpReg: [b]KiesPreload[/b] - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
  500. MsConfig:64bit - StartUpReg: [b]KiesTrayAgent[/b] - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
  501. MsConfig:64bit - StartUpReg: [b]mcui_exe[/b] - hkey= - key= - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
  502. MsConfig:64bit - StartUpReg: [b]Rim.DesktopHelper.exe[/b] - hkey= - key= - File not found
  503. MsConfig:64bit - StartUpReg: [b]RIMBBLaunchAgent.exe[/b] - hkey= - key= - File not found
  504. MsConfig:64bit - StartUpReg: [b]SunJavaUpdateSched[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Oracle Corporation)
  505. MsConfig:64bit - State: "startup" - Reg Error: Key error.
  506.  
  507. SafeBootMin:[b]64bit:[/b] AppMgmt - Service
  508. SafeBootMin:[b]64bit:[/b] Base - Driver Group
  509. SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
  510. SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
  511. SafeBootMin:[b]64bit:[/b] File system - Driver Group
  512. SafeBootMin:[b]64bit:[/b] Filter - Driver Group
  513. SafeBootMin:[b]64bit:[/b] HelpSvc - Service
  514. SafeBootMin:[b]64bit:[/b] hitmanpro37 - Reg Error: Value error.
  515. SafeBootMin:[b]64bit:[/b] hitmanpro37.sys - Reg Error: Value error.
  516. SafeBootMin:[b]64bit:[/b] mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
  517. SafeBootMin:[b]64bit:[/b] MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
  518. SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
  519. SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
  520. SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
  521. SafeBootMin:[b]64bit:[/b] sacsvr - Service
  522. SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
  523. SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
  524. SafeBootMin:[b]64bit:[/b] vmms - Service
  525. SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
  526. SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  527. SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  528. SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  529. SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  530. SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  531. SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  532. SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  533. SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  534. SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  535. SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  536. SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  537. SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  538. SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  539. SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  540. SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  541. SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  542. SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  543. SafeBootMin: AppMgmt - Service
  544. SafeBootMin: Base - Driver Group
  545. SafeBootMin: Boot Bus Extender - Driver Group
  546. SafeBootMin: Boot file system - Driver Group
  547. SafeBootMin: File system - Driver Group
  548. SafeBootMin: Filter - Driver Group
  549. SafeBootMin: HelpSvc - Service
  550. SafeBootMin: hitmanpro37 - Reg Error: Value error.
  551. SafeBootMin: hitmanpro37.sys - Reg Error: Value error.
  552. SafeBootMin: PCI Configuration - Driver Group
  553. SafeBootMin: PNP Filter - Driver Group
  554. SafeBootMin: Primary disk - Driver Group
  555. SafeBootMin: sacsvr - Service
  556. SafeBootMin: SCSI Class - Driver Group
  557. SafeBootMin: System Bus Extender - Driver Group
  558. SafeBootMin: vmms - Service
  559. SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  560. SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  561. SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  562. SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  563. SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  564. SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  565. SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  566. SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  567. SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  568. SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  569. SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  570. SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  571. SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  572. SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  573. SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  574. SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  575. SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  576.  
  577. SafeBootNet:[b]64bit:[/b] AppMgmt - Service
  578. SafeBootNet:[b]64bit:[/b] Base - Driver Group
  579. SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
  580. SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
  581. SafeBootNet:[b]64bit:[/b] File system - Driver Group
  582. SafeBootNet:[b]64bit:[/b] Filter - Driver Group
  583. SafeBootNet:[b]64bit:[/b] HelpSvc - Service
  584. SafeBootNet:[b]64bit:[/b] hitmanpro37 - Reg Error: Value error.
  585. SafeBootNet:[b]64bit:[/b] hitmanpro37.sys - Reg Error: Value error.
  586. SafeBootNet:[b]64bit:[/b] McMPFSvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
  587. SafeBootNet:[b]64bit:[/b] mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
  588. SafeBootNet:[b]64bit:[/b] MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
  589. SafeBootNet:[b]64bit:[/b] Messenger - Service
  590. SafeBootNet:[b]64bit:[/b] mfefire - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
  591. SafeBootNet:[b]64bit:[/b] mfefirek - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
  592. SafeBootNet:[b]64bit:[/b] mfefirek.sys - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
  593. SafeBootNet:[b]64bit:[/b] mfehidk - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
  594. SafeBootNet:[b]64bit:[/b] mfehidk.sys - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
  595. SafeBootNet:[b]64bit:[/b] mfevtp - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
  596. SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
  597. SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
  598. SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
  599. SafeBootNet:[b]64bit:[/b] Network - Driver Group
  600. SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
  601. SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
  602. SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
  603. SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
  604. SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
  605. SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
  606. SafeBootNet:[b]64bit:[/b] sacsvr - Service
  607. SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
  608. SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
  609. SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
  610. SafeBootNet:[b]64bit:[/b] TDI - Driver Group
  611. SafeBootNet:[b]64bit:[/b] vmms - Service
  612. SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
  613. SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
  614. SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  615. SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  616. SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  617. SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  618. SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  619. SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  620. SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  621. SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
  622. SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
  623. SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
  624. SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
  625. SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  626. SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  627. SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  628. SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  629. SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
  630. SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  631. SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  632. SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  633. SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  634. SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  635. SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  636. SafeBootNet: AppMgmt - Service
  637. SafeBootNet: Base - Driver Group
  638. SafeBootNet: Boot Bus Extender - Driver Group
  639. SafeBootNet: Boot file system - Driver Group
  640. SafeBootNet: File system - Driver Group
  641. SafeBootNet: Filter - Driver Group
  642. SafeBootNet: HelpSvc - Service
  643. SafeBootNet: hitmanpro37 - Reg Error: Value error.
  644. SafeBootNet: hitmanpro37.sys - Reg Error: Value error.
  645. SafeBootNet: Messenger - Service
  646. SafeBootNet: NDIS Wrapper - Driver Group
  647. SafeBootNet: NetBIOSGroup - Driver Group
  648. SafeBootNet: NetDDEGroup - Driver Group
  649. SafeBootNet: Network - Driver Group
  650. SafeBootNet: NetworkProvider - Driver Group
  651. SafeBootNet: PCI Configuration - Driver Group
  652. SafeBootNet: PNP Filter - Driver Group
  653. SafeBootNet: PNP_TDI - Driver Group
  654. SafeBootNet: Primary disk - Driver Group
  655. SafeBootNet: rdsessmgr - Service
  656. SafeBootNet: sacsvr - Service
  657. SafeBootNet: SCSI Class - Driver Group
  658. SafeBootNet: Streams Drivers - Driver Group
  659. SafeBootNet: System Bus Extender - Driver Group
  660. SafeBootNet: TDI - Driver Group
  661. SafeBootNet: vmms - Service
  662. SafeBootNet: WudfUsbccidDriver - Driver
  663. SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
  664. SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
  665. SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
  666. SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
  667. SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
  668. SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
  669. SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
  670. SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
  671. SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
  672. SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
  673. SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
  674. SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
  675. SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
  676. SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
  677. SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
  678. SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
  679. SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
  680. SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
  681. SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
  682. SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
  683. SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
  684. SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
  685.  
  686. ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
  687. ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
  688. ActiveX:[b]64bit:[/b] {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
  689. ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
  690. ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
  691. ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
  692. ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
  693. ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
  694. ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
  695. ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
  696. ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
  697. ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
  698. ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
  699. ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
  700. ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
  701. ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
  702. ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
  703. ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
  704. ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
  705. ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
  706. ActiveX:[b]64bit:[/b] {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
  707. ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
  708. ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
  709. ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
  710. ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
  711. ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
  712. ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
  713. ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
  714. ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
  715. ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
  716. ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
  717. ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
  718. ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
  719. ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
  720. ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
  721. ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
  722. ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
  723. ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
  724. ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
  725. ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
  726. ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
  727. ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
  728. ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
  729. ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
  730. ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
  731. ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
  732. ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
  733. ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
  734. ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
  735. ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
  736.  
  737. Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  738. Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  739. Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
  740.  
  741. [color=#E56717]========== Files/Folders - Created Within 90 Days ==========[/color]
  742.  
  743. [2013/12/05 20:44:40 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Marion\Desktop\OTL (1).scr
  744. [2013/12/05 17:16:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
  745. [2013/11/29 12:42:33 | 000,286,720 | ---- | C] (SteelWerX) -- C:\Windows\swreg.exe
  746. [2013/11/29 12:20:10 | 000,286,720 | ---- | C] (SteelWerX) -- C:\Users\Marion\Desktop\swreg.exe
  747. [2013/11/29 11:54:44 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
  748. [2013/11/29 08:14:53 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozyHome
  749. [2013/11/29 08:14:49 | 000,067,808 | ---- | C] (Mozy, Inc.) -- C:\Windows\SysNative\drivers\mozy.sys
  750. [2013/11/29 06:57:43 | 000,000,000 | ---D | C] -- C:\Users\Marion\Desktop\Revo Uninstaller
  751. [2013/11/29 06:50:01 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Research In Motion
  752. [2013/11/29 06:41:05 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Mozy Restore Manager
  753. [2013/11/29 06:41:03 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozy
  754. [2013/11/29 06:41:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozy
  755. [2013/11/28 18:30:44 | 000,387,776 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\PsExec.exe
  756. [2013/11/28 17:38:01 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\{E0669A64-556C-40F3-BD00-25C15A9466F1}
  757. [2013/11/27 16:56:13 | 000,000,000 | ---D | C] -- C:\ProgramData\CDB
  758. [2013/11/23 09:50:20 | 000,000,000 | R--D | C] -- C:\Users\Marion\Dropbox
  759. [2013/11/23 09:42:23 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
  760. [2013/11/23 09:41:34 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Dropbox
  761. [2013/11/23 02:17:48 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Bit_Studio
  762. [2013/11/23 02:15:01 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\SyncTunesDesktop
  763. [2013/11/23 02:14:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Bit Studio
  764. [2013/11/23 02:14:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synctunes Desktop
  765. [2013/11/22 16:26:38 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Downloaded Installations
  766. [2013/11/22 16:26:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
  767. [2013/11/22 16:26:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyFree Codec
  768. [2013/11/22 16:24:28 | 000,204,568 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudmdm.sys
  769. [2013/11/22 16:24:28 | 000,103,576 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
  770. [2013/11/22 16:22:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
  771. [2013/11/22 16:21:17 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NativeFus_Log
  772. [2013/11/22 16:21:17 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
  773. [2013/11/22 16:05:05 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG
  774. [2013/11/21 14:19:59 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\{20884471-0E7E-4940-A053-1F0B12FF9589}
  775. [2013/11/21 13:52:12 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
  776. [2013/11/21 11:56:58 | 000,000,000 | ---D | C] -- C:\Users\Marion\Documents\OneNote Notebooks
  777. [2013/11/20 22:38:53 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\{DB584E07-379E-41CB-9996-243B7BE00B07}
  778. [2013/11/20 19:37:59 | 000,000,000 | ---D | C] -- C:\FRST
  779. [2013/11/20 19:02:04 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\VS Revo Group
  780. [2013/11/20 19:02:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
  781. [2013/11/20 19:02:00 | 000,031,800 | ---- | C] (VS Revo Group) -- C:\Windows\SysNative\drivers\revoflt.sys
  782. [2013/11/20 19:02:00 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
  783. [2013/11/20 19:01:58 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
  784. [2013/11/20 18:49:35 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
  785. [2013/11/20 15:35:11 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\CrashDumps
  786. [2013/11/17 16:41:44 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\KeePass
  787. [2013/11/17 16:31:33 | 000,162,392 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.sys
  788. [2013/11/17 16:31:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSTx64
  789. [2013/11/17 16:31:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B
  790. [2013/11/17 16:31:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe
  791. [2013/11/17 16:31:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Identity Safe
  792. [2013/11/17 16:31:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
  793. [2013/11/17 16:31:14 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
  794. [2013/11/17 16:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
  795. [2013/11/17 16:13:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe
  796. [2013/11/17 14:40:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
  797. [2013/11/17 14:40:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
  798. [2013/11/17 14:39:28 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
  799. [2013/11/17 14:39:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
  800. [2013/11/17 14:39:21 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
  801. [2013/11/17 14:39:21 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
  802. [2013/11/17 14:39:21 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
  803. [2013/11/17 14:39:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
  804. [2013/11/17 14:06:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
  805. [2013/11/17 12:17:55 | 000,000,000 | ---D | C] -- C:\RegBackup
  806. [2013/11/15 16:22:19 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
  807. [2013/11/15 16:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
  808. [2013/11/15 15:40:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
  809. [2013/11/14 14:09:44 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Malwarebytes
  810. [2013/11/14 14:09:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
  811. [2013/11/14 14:07:45 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Programs
  812. [2013/11/14 00:21:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diego`s Dinosaur Adventure
  813. [2013/11/14 00:21:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diego`s Dinosaur Adventure
  814. [2013/11/13 08:50:26 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
  815. [2013/11/13 08:49:37 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
  816. [2013/11/13 08:49:36 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
  817. [2013/11/13 08:49:36 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
  818. [2013/11/13 08:49:36 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
  819. [2013/11/13 08:49:35 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
  820. [2013/11/13 08:48:57 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
  821. [2013/11/13 08:48:57 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
  822. [2013/11/13 08:48:56 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
  823. [2013/11/13 08:48:56 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
  824. [2013/11/13 08:48:55 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
  825. [2013/11/13 08:48:39 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
  826. [2013/11/13 08:48:34 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
  827. [2013/11/13 08:48:33 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
  828. [2013/11/13 08:48:33 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
  829. [2013/11/13 08:48:33 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
  830. [2013/11/12 08:54:02 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
  831. [2013/11/12 08:51:53 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
  832. [2013/11/12 08:51:53 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
  833. [2013/11/12 08:51:38 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
  834. [2013/11/12 08:51:38 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
  835. [2013/11/12 08:51:38 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
  836. [2013/11/12 08:51:38 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
  837. [2013/11/12 08:51:38 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
  838. [2013/11/12 08:51:38 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
  839. [2013/11/12 08:51:38 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
  840. [2013/11/12 08:51:38 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
  841. [2013/11/12 08:51:37 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
  842. [2013/11/12 08:51:37 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
  843. [2013/11/12 08:51:37 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
  844. [2013/11/12 08:51:37 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
  845. [2013/11/12 08:51:37 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
  846. [2013/11/12 08:51:37 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
  847. [2013/11/12 08:51:37 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
  848. [2013/11/12 08:51:37 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
  849. [2013/11/12 08:51:37 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
  850. [2013/11/12 08:51:37 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
  851. [2013/11/12 08:51:37 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
  852. [2013/11/12 08:51:37 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
  853. [2013/11/12 08:51:37 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
  854. [2013/11/12 08:51:37 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
  855. [2013/11/12 08:51:37 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
  856. [2013/11/12 08:51:37 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
  857. [2013/11/12 08:51:37 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
  858. [2013/11/12 08:51:36 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
  859. [2013/11/12 08:51:36 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
  860. [2013/11/12 08:51:36 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
  861. [2013/11/12 08:51:36 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
  862. [2013/11/12 08:51:36 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
  863. [2013/11/12 08:51:36 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
  864. [2013/11/12 08:51:36 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
  865. [2013/11/12 08:51:36 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
  866. [2013/11/12 08:51:36 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
  867. [2013/11/12 08:51:35 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
  868. [2013/11/12 08:51:35 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
  869. [2013/11/12 08:51:35 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
  870. [2013/11/12 08:51:35 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
  871. [2013/11/12 08:51:34 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
  872. [2013/11/12 08:51:34 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
  873. [2013/11/12 08:51:34 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
  874. [2013/11/12 08:51:34 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
  875. [2013/11/12 08:51:34 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
  876. [2013/11/12 08:51:34 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
  877. [2013/11/12 08:51:34 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
  878. [2013/11/12 08:51:34 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
  879. [2013/11/12 08:51:34 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
  880. [2013/11/12 08:51:34 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
  881. [2013/11/12 08:51:34 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
  882. [2013/11/12 08:51:34 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
  883. [2013/11/12 08:51:34 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
  884. [2013/11/12 08:51:34 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
  885. [2013/11/12 08:51:34 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
  886. [2013/11/12 08:51:34 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
  887. [2013/11/12 08:51:34 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
  888. [2013/11/12 08:51:34 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
  889. [2013/11/12 08:51:34 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
  890. [2013/11/12 08:51:34 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
  891. [2013/11/12 08:51:33 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
  892. [2013/11/12 08:51:33 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
  893. [2013/11/12 08:51:33 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
  894. [2013/11/12 08:51:33 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
  895. [2013/11/12 08:51:33 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
  896. [2013/11/12 08:51:33 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
  897. [2013/11/12 08:51:33 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
  898. [2013/11/12 08:51:33 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
  899. [2013/11/12 08:51:33 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
  900. [2013/11/12 08:51:33 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
  901. [2013/11/12 08:51:33 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
  902. [2013/11/12 08:51:33 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
  903. [2013/11/12 08:51:33 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
  904. [2013/11/12 08:51:33 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
  905. [2013/11/12 08:51:33 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
  906. [2013/11/12 08:51:33 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
  907. [2013/11/12 08:51:33 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
  908. [2013/11/12 08:51:33 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
  909. [2013/11/12 08:51:33 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
  910. [2013/11/12 08:51:32 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
  911. [2013/11/12 00:24:43 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Deployment
  912. [2013/11/11 12:08:32 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Picsoft
  913. [2013/11/11 11:58:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peggle Deluxe
  914. [2013/11/11 11:58:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Peggle Deluxe
  915. [2013/11/11 11:45:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
  916. [2013/11/11 11:44:10 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
  917. [2013/11/11 11:44:09 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
  918. [2013/11/11 11:44:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
  919. [2013/11/10 09:44:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Innovative Solutions
  920. [2013/11/10 09:44:17 | 000,000,000 | ---D | C] -- C:\Windows\Fonts\AdvUninstal
  921. [2013/11/10 09:44:12 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\Innovative Solutions
  922. [2013/11/10 09:44:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO
  923. [2013/11/10 09:44:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Innovative Solutions
  924. [2013/11/10 09:44:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Innovative Solutions
  925. [2013/11/10 09:42:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Common Files
  926. [2013/11/03 01:36:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
  927. [2013/11/02 12:06:12 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Local\NativeMessaging
  928. [2013/11/01 23:43:39 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drawn - Dark Flight
  929. [2013/11/01 23:43:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drawn - Dark Flight
  930. [2013/11/01 23:43:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Drawn - Dark Flight
  931. [2013/10/27 19:51:27 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Pengu Wars
  932. [2013/10/27 19:46:36 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Melesta
  933. [2013/10/27 19:21:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpongeBob SquarePants Obstacle Odyssey
  934. [2013/10/27 19:20:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpongeBob SquarePants Obstacle Odyssey
  935. [2013/10/27 19:20:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nick Jr. Bingo
  936. [2013/10/27 19:20:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nick Jr. Bingo
  937. [2013/10/27 19:11:17 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_5.dll
  938. [2013/10/27 19:11:17 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll
  939. [2013/10/27 19:11:16 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll
  940. [2013/10/27 19:11:16 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_7.dll
  941. [2013/10/27 19:11:13 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll
  942. [2013/10/27 19:11:13 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_7.dll
  943. [2013/10/27 19:11:10 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll
  944. [2013/10/27 19:11:06 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_43.dll
  945. [2013/10/27 19:11:06 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll
  946. [2013/10/27 19:11:04 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll
  947. [2013/10/27 19:11:04 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll
  948. [2013/10/27 19:11:02 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_43.dll
  949. [2013/10/27 19:11:02 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll
  950. [2013/10/27 19:10:56 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_43.dll
  951. [2013/10/27 19:09:20 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dark Manor - A Hidden Object Mystery
  952. [2013/10/27 19:09:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dark Manor - A Hidden Object Mystery
  953. [2013/10/27 19:09:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dark Manor - A Hidden Object Mystery
  954. [2013/10/27 19:09:10 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Nimbus Games
  955. [2013/10/27 19:08:27 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Putt-Putt Saves the Zoo
  956. [2013/10/27 19:08:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Putt-Putt Saves the Zoo
  957. [2013/10/27 19:08:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Putt-Putt Saves the Zoo
  958. [2013/10/24 19:10:26 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\The Witch and The Warrior
  959. [2013/10/24 18:44:42 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Skyborn
  960. [2013/10/23 11:38:46 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\viking_saga_bfg_en
  961. [2013/10/23 11:36:03 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viking Saga
  962. [2013/10/23 11:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Viking Saga
  963. [2013/10/23 11:36:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Viking Saga
  964. [2013/10/22 13:52:28 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\kidoz
  965. [2013/10/22 08:59:34 | 000,387,776 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Marion\Desktop\PsExec.exe
  966. [2013/10/19 10:59:04 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\InstallShield
  967. [2013/10/18 19:15:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
  968. [2013/10/18 19:15:51 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
  969. [2013/10/18 19:14:56 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
  970. [2013/10/18 19:14:56 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
  971. [2013/10/18 19:14:46 | 002,797,128 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
  972. [2013/10/18 19:14:45 | 000,331,880 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
  973. [2013/10/18 19:14:38 | 000,149,608 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
  974. [2013/10/18 19:14:38 | 000,014,952 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCoLDR64.dll
  975. [2013/10/18 19:14:35 | 003,693,128 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
  976. [2013/10/18 19:14:35 | 000,991,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
  977. [2013/10/18 19:14:35 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
  978. [2013/10/18 19:14:34 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
  979. [2013/10/18 19:14:34 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
  980. [2013/10/18 19:14:34 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
  981. [2013/10/18 19:14:33 | 000,613,448 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtDataProc64.dll
  982. [2013/10/18 19:14:31 | 001,284,680 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
  983. [2013/10/18 19:14:30 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
  984. [2013/10/18 19:14:30 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
  985. [2013/10/18 19:14:19 | 000,135,240 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInstII64.dll
  986. [2013/10/18 19:14:11 | 000,083,072 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBWrp64.dll
  987. [2013/10/18 19:14:10 | 000,897,152 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBAPO64.dll
  988. [2013/10/18 19:14:10 | 000,065,112 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBppld64.dll
  989. [2013/10/18 19:14:10 | 000,060,504 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBPPCn64.dll
  990. [2013/10/18 19:14:09 | 000,753,280 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysWow64\MBAPO32.dll
  991. [2013/10/18 19:13:33 | 002,734,624 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
  992. [2013/10/18 19:13:26 | 000,110,592 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
  993. [2013/10/18 19:13:22 | 000,208,072 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAC64.dll
  994. [2013/10/18 19:13:22 | 000,108,640 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAR64.dll
  995. [2013/10/18 19:05:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
  996. [2013/10/18 19:00:31 | 002,079,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
  997. [2013/10/18 18:58:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP260 series
  998. [2013/10/18 18:30:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Driver Whiz
  999. [2013/10/18 18:28:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Whiz
  1000. [2013/10/18 18:18:03 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Foresight Software
  1001. [2013/10/18 18:17:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Foresight Software
  1002. [2013/10/18 16:35:59 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows
  1003. [2013/10/18 16:35:58 | 000,000,000 | ---D | C] -- C:\Program Files\Dell Support Center
  1004. [2013/10/18 13:22:32 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
  1005. [2013/10/17 00:12:18 | 000,044,544 | ---- | C] (Research in Motion Ltd) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys
  1006. [2013/10/11 23:29:41 | 000,000,000 | ---D | C] -- C:\Users\Marion\Desktop\FITNESS
  1007. [2013/10/11 17:04:46 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
  1008. [2013/10/11 17:04:21 | 005,549,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
  1009. [2013/10/11 17:04:21 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
  1010. [2013/10/11 17:04:20 | 003,969,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
  1011. [2013/10/11 17:04:20 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
  1012. [2013/10/11 17:04:20 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
  1013. [2013/10/11 17:04:19 | 000,619,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
  1014. [2013/10/11 17:04:18 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
  1015. [2013/10/11 17:04:16 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
  1016. [2013/10/11 17:04:08 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
  1017. [2013/10/11 17:04:08 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
  1018. [2013/10/11 17:04:08 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
  1019. [2013/10/11 17:04:07 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
  1020. [2013/10/11 17:04:07 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
  1021. [2013/10/11 17:03:10 | 000,461,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll
  1022. [2013/10/11 17:02:11 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll
  1023. [2013/10/11 17:01:59 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
  1024. [2013/10/11 17:01:58 | 000,032,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys
  1025. [2013/10/11 17:01:45 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
  1026. [2013/10/11 17:01:45 | 000,007,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys
  1027. [2013/10/11 17:01:25 | 000,368,128 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
  1028. [2013/10/11 17:01:25 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
  1029. [2013/10/11 17:01:25 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
  1030. [2013/10/11 17:01:25 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
  1031. [2013/10/11 17:01:24 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
  1032. [2013/10/11 17:01:24 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
  1033. [2013/10/11 17:01:23 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
  1034. [2013/10/11 17:01:23 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
  1035. [2013/10/11 17:00:13 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
  1036. [2013/10/11 17:00:13 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
  1037. [2013/10/11 13:35:32 | 000,000,000 | ---D | C] -- C:\Users\Marion\Desktop\KIDS WORK
  1038. [2013/09/29 17:02:44 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\FixCleaner
  1039. [2013/09/29 17:02:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixCleaner
  1040. [2013/09/29 16:38:54 | 000,000,000 | ---D | C] -- C:\teac
  1041. [2013/09/26 15:58:06 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\PlayFirst
  1042. [2013/09/26 15:57:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpongeBob SquarePants Diner Dash
  1043. [2013/09/26 15:57:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpongeBob SquarePants Diner Dash
  1044. [2013/09/24 22:21:25 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\BBB
  1045. [2013/09/17 19:43:00 | 000,274,944 | ---- | C] (SingularLabs) -- C:\Users\Marion\Desktop\JavaRa.exe
  1046. [2013/09/13 22:02:14 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\DarkManor
  1047. [2013/09/13 17:38:41 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
  1048. [2013/09/13 17:38:33 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll
  1049. [2013/09/13 17:34:36 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Puppetshow - Return to Joyville
  1050. [2013/09/13 17:34:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puppetshow - Return to Joyville
  1051. [2013/09/13 17:34:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Puppetshow - Return to Joyville
  1052. [2013/09/13 07:42:45 | 000,155,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys
  1053. [2013/09/13 07:42:14 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
  1054. [2013/09/13 07:42:12 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
  1055. [2013/09/13 07:42:11 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
  1056. [2013/09/13 07:42:11 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
  1057. [2013/09/13 07:42:11 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
  1058. [2013/09/13 07:42:11 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
  1059. [2013/09/13 07:42:09 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
  1060. [2013/09/13 07:42:09 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
  1061. [2013/09/13 07:42:09 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
  1062. [2013/09/13 07:42:08 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
  1063. [2013/09/13 07:42:08 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
  1064. [2013/09/13 07:42:08 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
  1065. [2013/09/13 07:42:07 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
  1066. [2013/09/13 07:42:07 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
  1067. [2013/09/13 07:42:06 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
  1068. [2013/09/13 07:42:06 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
  1069. [2013/09/13 07:42:06 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
  1070. [2013/09/13 07:42:05 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
  1071. [2013/09/13 07:42:05 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
  1072. [2013/09/13 07:42:05 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
  1073. [2013/09/13 07:42:04 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
  1074. [2013/09/13 07:42:04 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
  1075. [2013/09/13 07:42:04 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
  1076. [2013/09/13 07:42:04 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
  1077. [2013/09/13 07:42:03 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
  1078. [2013/09/13 07:42:03 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
  1079. [2013/09/13 07:42:03 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
  1080. [2013/09/13 07:42:03 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
  1081. [2013/09/13 07:42:02 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
  1082. [2013/09/13 07:42:02 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
  1083. [2013/09/13 07:42:02 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
  1084. [2013/09/13 07:42:01 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
  1085. [2013/09/13 07:42:01 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
  1086. [2013/09/13 07:42:01 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
  1087. [2013/09/13 07:42:01 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
  1088. [2013/09/13 07:42:00 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
  1089. [2013/09/13 07:42:00 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
  1090. [2013/09/13 07:42:00 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
  1091. [2013/09/13 07:42:00 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
  1092. [2013/09/13 07:41:59 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
  1093. [2013/09/13 07:41:59 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
  1094. [2013/09/13 07:41:59 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
  1095. [2013/09/13 07:41:58 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
  1096. [2013/09/13 07:41:58 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
  1097. [2013/09/13 07:41:58 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
  1098. [2013/09/13 07:41:58 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
  1099. [2013/09/13 07:41:57 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
  1100. [2013/09/13 07:41:57 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
  1101. [2013/09/13 07:41:57 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
  1102. [2013/09/13 07:41:57 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
  1103. [2013/09/13 07:41:56 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
  1104. [2013/09/13 07:41:56 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
  1105. [2013/09/13 07:41:56 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
  1106. [2013/09/13 07:41:55 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
  1107. [2013/09/13 07:41:55 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
  1108. [2013/09/13 07:41:55 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
  1109. [2013/09/13 07:41:54 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
  1110. [2013/09/13 07:41:54 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
  1111. [2013/09/13 07:41:53 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
  1112. [2013/09/13 07:41:53 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
  1113. [2013/09/13 07:41:52 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
  1114. [2013/09/13 07:41:52 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
  1115. [2013/09/13 07:41:51 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
  1116. [2013/09/13 07:41:51 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
  1117. [2013/09/13 07:41:31 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
  1118. [2013/09/11 23:26:40 | 000,036,096 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\amdkmpfd.sys
  1119. [2013/09/10 23:34:58 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plants vs Zombies
  1120. [2013/09/10 23:34:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plants vs Zombies
  1121. [2013/09/10 23:34:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Plants vs Zombies
  1122. [2013/09/10 22:56:58 | 000,000,000 | ---D | C] -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jar of Marbles II - Journey to the West
  1123. [2013/09/10 22:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jar of Marbles II - Journey to the West
  1124. [2013/09/10 22:56:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Jar of Marbles II - Journey to the West
  1125. [2013/08/13 09:54:30 | 000,889,416 | ---- | C] (Microsoft Corporation) -- C:\Users\Marion\AppData\Roaming\dotNetFx40_Full_setup.exe
  1126. [2012/09/07 11:47:45 | 000,940,544 | ---- | C] (Apache Software Foundation) -- C:\Users\Marion\AppData\Local\log4cxx.dll
  1127. [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  1128. [1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
  1129. [1 C:\Users\Marion\Documents\*.tmp files -> C:\Users\Marion\Documents\*.tmp -> ]
  1130.  
  1131. [color=#E56717]========== Files - Modified Within 90 Days ==========[/color]
  1132.  
  1133. [2013/12/05 20:44:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marion\Desktop\OTL (1).scr
  1134. [2013/12/05 20:30:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
  1135. [2013/12/05 20:09:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  1136. [2013/12/05 18:03:38 | 000,005,030 | ---- | M] () -- C:\Windows\mozy.blk
  1137. [2013/12/05 18:03:37 | 000,005,050 | ---- | M] () -- C:\Windows\mozy.flt
  1138. [2013/12/05 17:17:33 | 000,014,832 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  1139. [2013/12/05 17:17:33 | 000,014,832 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  1140. [2013/12/05 17:09:55 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat
  1141. [2013/12/05 17:09:48 | 529,932,287 | -HS- | M] () -- C:\hiberfil.sys
  1142. [2013/12/03 10:27:07 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  1143. [2013/12/02 10:42:34 | 000,012,067 | ---- | M] () -- C:\Users\Marion\Documents\Capture.PNG
  1144. [2013/12/02 10:34:38 | 000,000,000 | ---- | M] () -- C:\Users\Marion\chkdsk
  1145. [2013/12/02 10:22:13 | 000,793,338 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  1146. [2013/12/02 10:22:13 | 000,669,552 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  1147. [2013/12/02 10:22:13 | 000,125,738 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  1148. [2013/11/29 12:20:12 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Windows\swreg.exe
  1149. [2013/11/29 12:20:12 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Users\Marion\Desktop\swreg.exe
  1150. [2013/11/29 11:54:52 | 000,001,743 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
  1151. [2013/11/29 08:14:53 | 000,000,873 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MozyHome Status.lnk
  1152. [2013/11/28 18:28:59 | 000,387,776 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\Marion\Desktop\PsExec.exe
  1153. [2013/11/28 18:28:59 | 000,387,776 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\PsExec.exe
  1154. [2013/11/28 18:25:24 | 000,000,856 | ---- | M] () -- C:\Users\Public\Desktop\Resume Reimage Repair Installation.lnk
  1155. [2013/11/28 18:25:19 | 000,000,179 | ---- | M] () -- C:\Windows\Reimage.ini
  1156. [2013/11/28 17:39:45 | 000,052,729 | ---- | M] () -- C:\Users\Marion\Desktop\FindTracks.vbs
  1157. [2013/11/27 17:47:22 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\reimage.rep
  1158. [2013/11/27 17:19:23 | 000,009,728 | ---- | M] () -- C:\Windows\SysNative\Native.exe
  1159. [2013/11/24 19:34:44 | 704,825,013 | ---- | M] () -- C:\Windows\MEMORY.DMP
  1160. [2013/11/23 09:50:20 | 000,001,041 | ---- | M] () -- C:\Users\Marion\Desktop\Dropbox.lnk
  1161. [2013/11/23 09:48:13 | 000,001,051 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
  1162. [2013/11/23 02:14:50 | 000,002,627 | ---- | M] () -- C:\Users\Public\Desktop\Synctunes.lnk
  1163. [2013/11/22 16:27:42 | 000,002,124 | ---- | M] () -- C:\Users\Marion\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Story Album Viewer.lnk
  1164. [2013/11/22 16:24:48 | 000,001,966 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
  1165. [2013/11/21 11:56:57 | 000,001,270 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
  1166. [2013/11/21 00:13:25 | 000,005,120 | ---- | M] () -- C:\Users\Marion\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
  1167. [2013/11/20 19:29:08 | 000,165,376 | ---- | M] () -- C:\Users\Marion\Desktop\SystemLook_x64.exe
  1168. [2013/11/18 23:46:22 | 000,451,928 | ---- | M] () -- C:\Users\Marion\Desktop\JavaRa.def
  1169. [2013/11/18 23:46:18 | 000,274,944 | ---- | M] (SingularLabs) -- C:\Users\Marion\Desktop\JavaRa.exe
  1170. [2013/11/17 20:22:50 | 000,003,228 | ---- | M] () -- C:\Users\Marion\Documents\Database.kdb
  1171. [2013/11/17 16:31:40 | 000,002,487 | ---- | M] () -- C:\Users\Public\Desktop\Norton Identity Safe.LNK
  1172. [2013/11/17 16:13:56 | 000,001,055 | ---- | M] () -- C:\Users\Marion\Desktop\KeePass.lnk
  1173. [2013/11/17 14:39:08 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
  1174. [2013/11/17 14:39:05 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
  1175. [2013/11/17 14:39:05 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
  1176. [2013/11/17 14:39:05 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
  1177. [2013/11/17 14:14:29 | 000,000,093 | ---- | M] () -- C:\Windows\SysWow64\Configurations.plist.signed
  1178. [2013/11/17 14:11:08 | 000,000,863 | ---- | M] () -- C:\MARION-PC.rtf
  1179. [2013/11/17 14:06:29 | 000,002,248 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
  1180. [2013/11/17 12:20:36 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-MARION-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
  1181. [2013/11/14 00:21:42 | 000,001,282 | ---- | M] () -- C:\Users\Public\Desktop\More Great Games.lnk
  1182. [2013/11/13 10:42:36 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
  1183. [2013/11/13 10:42:36 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
  1184. [2013/11/13 08:35:22 | 000,016,152 | ---- | M] () -- C:\Windows\SysNative\drivers\SWDUMon.sys
  1185. [2013/11/12 08:51:53 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
  1186. [2013/11/12 08:51:53 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
  1187. [2013/11/12 08:51:38 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
  1188. [2013/11/12 08:51:38 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
  1189. [2013/11/12 08:51:38 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
  1190. [2013/11/12 08:51:38 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
  1191. [2013/11/12 08:51:38 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
  1192. [2013/11/12 08:51:38 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
  1193. [2013/11/12 08:51:38 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
  1194. [2013/11/12 08:51:38 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
  1195. [2013/11/12 08:51:37 | 001,926,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
  1196. [2013/11/12 08:51:37 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
  1197. [2013/11/12 08:51:37 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
  1198. [2013/11/12 08:51:37 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
  1199. [2013/11/12 08:51:37 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
  1200. [2013/11/12 08:51:37 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
  1201. [2013/11/12 08:51:37 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
  1202. [2013/11/12 08:51:37 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
  1203. [2013/11/12 08:51:37 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
  1204. [2013/11/12 08:51:37 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
  1205. [2013/11/12 08:51:37 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
  1206. [2013/11/12 08:51:37 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
  1207. [2013/11/12 08:51:37 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
  1208. [2013/11/12 08:51:37 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
  1209. [2013/11/12 08:51:37 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
  1210. [2013/11/12 08:51:37 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
  1211. [2013/11/12 08:51:37 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
  1212. [2013/11/12 08:51:37 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
  1213. [2013/11/12 08:51:36 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
  1214. [2013/11/12 08:51:36 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
  1215. [2013/11/12 08:51:36 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
  1216. [2013/11/12 08:51:36 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
  1217. [2013/11/12 08:51:36 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
  1218. [2013/11/12 08:51:36 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
  1219. [2013/11/12 08:51:36 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
  1220. [2013/11/12 08:51:36 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
  1221. [2013/11/12 08:51:36 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
  1222. [2013/11/12 08:51:35 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
  1223. [2013/11/12 08:51:35 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
  1224. [2013/11/12 08:51:35 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
  1225. [2013/11/12 08:51:35 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
  1226. [2013/11/12 08:51:34 | 005,765,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
  1227. [2013/11/12 08:51:34 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
  1228. [2013/11/12 08:51:34 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
  1229. [2013/11/12 08:51:34 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
  1230. [2013/11/12 08:51:34 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
  1231. [2013/11/12 08:51:34 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
  1232. [2013/11/12 08:51:34 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
  1233. [2013/11/12 08:51:34 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
  1234. [2013/11/12 08:51:34 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
  1235. [2013/11/12 08:51:34 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
  1236. [2013/11/12 08:51:34 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
  1237. [2013/11/12 08:51:34 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
  1238. [2013/11/12 08:51:34 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
  1239. [2013/11/12 08:51:34 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
  1240. [2013/11/12 08:51:34 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
  1241. [2013/11/12 08:51:34 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
  1242. [2013/11/12 08:51:34 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
  1243. [2013/11/12 08:51:34 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
  1244. [2013/11/12 08:51:34 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
  1245. [2013/11/12 08:51:34 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
  1246. [2013/11/12 08:51:34 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
  1247. [2013/11/12 08:51:33 | 001,993,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
  1248. [2013/11/12 08:51:33 | 001,228,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
  1249. [2013/11/12 08:51:33 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
  1250. [2013/11/12 08:51:33 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
  1251. [2013/11/12 08:51:33 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
  1252. [2013/11/12 08:51:33 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
  1253. [2013/11/12 08:51:33 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
  1254. [2013/11/12 08:51:33 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
  1255. [2013/11/12 08:51:33 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
  1256. [2013/11/12 08:51:33 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
  1257. [2013/11/12 08:51:33 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
  1258. [2013/11/12 08:51:33 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
  1259. [2013/11/12 08:51:33 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
  1260. [2013/11/12 08:51:33 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
  1261. [2013/11/12 08:51:33 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
  1262. [2013/11/12 08:51:33 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
  1263. [2013/11/12 08:51:33 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
  1264. [2013/11/12 08:51:33 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
  1265. [2013/11/12 08:51:33 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
  1266. [2013/11/12 08:51:32 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
  1267. [2013/11/11 17:52:11 | 000,001,411 | ---- | M] () -- C:\Users\Marion\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
  1268. [2013/11/03 01:37:03 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
  1269. [2013/11/03 01:34:05 | 000,002,243 | ---- | M] () -- C:\Users\Marion\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
  1270. [2013/10/18 16:14:03 | 000,000,629 | ---- | M] () -- C:\Windows\SysNative\mapisvc.inf
  1271. [2013/10/18 13:22:34 | 000,001,929 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
  1272. [2013/10/18 13:22:34 | 000,001,929 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
  1273. [2013/10/14 18:00:00 | 000,028,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
  1274. [2013/10/12 02:30:42 | 000,830,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
  1275. [2013/10/12 02:29:08 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
  1276. [2013/10/12 02:03:08 | 000,656,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
  1277. [2013/10/12 02:01:25 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
  1278. [2013/10/11 17:28:58 | 000,310,896 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  1279. [2013/10/11 08:09:07 | 000,786,910 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  1280. [2013/10/06 03:27:19 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\isolate.ini
  1281. [2013/10/05 20:25:35 | 001,474,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
  1282. [2013/10/04 02:28:31 | 000,190,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
  1283. [2013/10/04 02:25:17 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
  1284. [2013/10/04 02:24:49 | 001,930,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
  1285. [2013/10/04 01:58:50 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
  1286. [2013/10/04 01:56:00 | 001,796,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
  1287. [2013/10/03 02:23:48 | 000,404,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
  1288. [2013/10/02 07:50:58 | 000,067,808 | ---- | M] (Mozy, Inc.) -- C:\Windows\SysNative\drivers\mozy.sys
  1289. [2013/09/27 19:30:07 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.inf
  1290. [2013/09/27 19:23:26 | 000,162,392 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.sys
  1291. [2013/09/27 19:23:15 | 000,008,202 | ---- | M] () -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.cat
  1292. [2013/09/25 02:23:33 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
  1293. [2013/09/25 02:23:33 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
  1294. [2013/09/25 02:23:01 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
  1295. [2013/09/25 02:21:50 | 000,307,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
  1296. [2013/09/25 02:21:07 | 001,447,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
  1297. [2013/09/11 23:26:40 | 000,036,096 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\amdkmpfd.sys
  1298. [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  1299. [1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
  1300. [1 C:\Users\Marion\Documents\*.tmp files -> C:\Users\Marion\Documents\*.tmp -> ]
  1301.  
  1302. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  1303.  
  1304. [2013/12/02 10:58:09 | 000,012,067 | ---- | C] () -- C:\Users\Marion\Documents\Capture.PNG
  1305. [2013/12/02 10:34:38 | 000,000,000 | ---- | C] () -- C:\Users\Marion\chkdsk
  1306. [2013/11/29 08:14:53 | 000,000,873 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MozyHome Status.lnk
  1307. [2013/11/28 18:25:17 | 000,000,856 | ---- | C] () -- C:\Users\Public\Desktop\Resume Reimage Repair Installation.lnk
  1308. [2013/11/28 17:39:45 | 000,052,729 | ---- | C] () -- C:\Users\Marion\Desktop\FindTracks.vbs
  1309. [2013/11/27 17:47:22 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\reimage.rep
  1310. [2013/11/27 17:19:23 | 000,009,728 | ---- | C] () -- C:\Windows\SysNative\Native.exe
  1311. [2013/11/27 16:54:42 | 000,000,179 | ---- | C] () -- C:\Windows\Reimage.ini
  1312. [2013/11/23 09:50:20 | 000,001,041 | ---- | C] () -- C:\Users\Marion\Desktop\Dropbox.lnk
  1313. [2013/11/23 09:42:51 | 000,001,051 | ---- | C] () -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
  1314. [2013/11/23 02:14:50 | 000,002,627 | ---- | C] () -- C:\Users\Public\Desktop\Synctunes.lnk
  1315. [2013/11/22 16:27:42 | 000,002,124 | ---- | C] () -- C:\Users\Marion\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Story Album Viewer.lnk
  1316. [2013/11/22 16:24:48 | 000,001,966 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
  1317. [2013/11/21 13:51:59 | 704,825,013 | ---- | C] () -- C:\Windows\MEMORY.DMP
  1318. [2013/11/21 11:56:57 | 000,001,270 | ---- | C] () -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
  1319. [2013/11/20 19:29:07 | 000,165,376 | ---- | C] () -- C:\Users\Marion\Desktop\SystemLook_x64.exe
  1320. [2013/11/17 17:10:33 | 000,003,228 | ---- | C] () -- C:\Users\Marion\Documents\Database.kdb
  1321. [2013/11/17 16:31:40 | 000,002,487 | ---- | C] () -- C:\Users\Public\Desktop\Norton Identity Safe.LNK
  1322. [2013/11/17 16:31:28 | 000,000,855 | ---- | C] () -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.inf
  1323. [2013/11/17 16:31:25 | 000,008,202 | ---- | C] () -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\ccSetx64.cat
  1324. [2013/11/17 16:31:25 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NSTx64\7DE06000.01B\isolate.ini
  1325. [2013/11/17 16:13:56 | 000,001,067 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass.lnk
  1326. [2013/11/17 16:13:56 | 000,001,055 | ---- | C] () -- C:\Users\Marion\Desktop\KeePass.lnk
  1327. [2013/11/17 14:14:27 | 000,000,093 | ---- | C] () -- C:\Windows\SysWow64\Configurations.plist.signed
  1328. [2013/11/17 14:06:35 | 000,000,863 | ---- | C] () -- C:\MARION-PC.rtf
  1329. [2013/11/17 14:06:29 | 000,002,248 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
  1330. [2013/11/17 12:20:36 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-MARION-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
  1331. [2013/11/12 08:51:37 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
  1332. [2013/11/12 08:51:34 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
  1333. [2013/11/11 17:52:11 | 000,001,417 | ---- | C] () -- C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
  1334. [2013/11/11 17:52:11 | 000,001,411 | ---- | C] () -- C:\Users\Marion\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
  1335. [2013/11/11 12:08:21 | 000,001,282 | ---- | C] () -- C:\Users\Public\Desktop\More Great Games.lnk
  1336. [2013/11/11 11:45:13 | 000,001,743 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
  1337. [2013/11/10 09:44:12 | 000,002,283 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO 11.lnk
  1338. [2013/11/10 09:44:07 | 000,042,496 | ---- | C] () -- C:\Windows\SysWow64\AdvUninstCPL.cpl
  1339. [2013/11/03 01:37:03 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
  1340. [2013/10/18 19:14:30 | 000,449,481 | ---- | C] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT
  1341. [2013/10/02 07:51:14 | 000,005,050 | ---- | C] () -- C:\Windows\mozy.flt
  1342. [2013/10/02 07:51:14 | 000,005,030 | ---- | C] () -- C:\Windows\mozy.blk
  1343. [2013/09/12 20:29:06 | 000,451,928 | ---- | C] () -- C:\Users\Marion\Desktop\JavaRa.def
  1344. [2013/04/18 18:07:00 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
  1345. [2013/04/18 18:06:46 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
  1346. [2013/04/18 18:06:46 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
  1347. [2013/04/18 18:06:46 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
  1348. [2013/04/18 18:06:46 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
  1349. [2013/04/06 19:58:16 | 000,074,703 | ---- | C] () -- C:\Windows\SysWow64\mfc45.dat
  1350. [2013/03/20 02:50:28 | 000,000,036 | ---- | C] () -- C:\Windows\Tiny_Run.ini
  1351. [2012/11/09 00:27:01 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
  1352. [2012/09/07 11:47:49 | 000,196,608 | ---- | C] () -- C:\Users\Marion\AppData\Local\common_functions.dll
  1353. [2011/08/25 17:18:10 | 000,000,129 | ---- | C] () -- C:\Users\Marion\jagex_runescape_preferences2.dat
  1354. [2011/08/25 17:18:10 | 000,000,129 | ---- | C] () -- C:\Users\Marion\jagex_runescape_preferences2 (2).dat
  1355. [2011/08/25 17:18:10 | 000,000,129 | ---- | C] () -- C:\Users\Marion\jagex_runescape_preferences2 (1).dat
  1356. [2011/08/25 17:17:33 | 000,000,035 | ---- | C] () -- C:\Users\Marion\jagex_runescape_preferences.dat
  1357. [2011/08/25 17:17:33 | 000,000,035 | ---- | C] () -- C:\Users\Marion\jagex_runescape_preferences (2).dat
  1358. [2011/08/25 17:17:33 | 000,000,035 | ---- | C] () -- C:\Users\Marion\jagex_runescape_preferences (1).dat
  1359. [2011/04/09 14:21:18 | 000,005,120 | ---- | C] () -- C:\Users\Marion\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
  1360. [2010/08/14 08:55:32 | 000,000,094 | ---- | C] () -- C:\Users\Marion\AppData\Local\fusioncache.dat
  1361. [2010/04/16 09:09:00 | 000,007,623 | ---- | C] () -- C:\Users\Marion\AppData\Local\Resmon.ResmonCfg
  1362. [2010/04/12 08:38:46 | 000,061,224 | ---- | C] () -- C:\Users\Marion\GoToAssistDownloadHelper.exe
  1363. [2010/04/12 08:38:46 | 000,061,224 | ---- | C] () -- C:\Users\Marion\GoToAssistDownloadHelper (2).exe
  1364. [2010/04/12 08:38:46 | 000,061,224 | ---- | C] () -- C:\Users\Marion\GoToAssistDownloadHelper (1).exe
  1365. [2010/04/12 07:40:20 | 007,864,320 | ---- | C] () -- C:\Users\Marion\ntuser (2).dat
  1366. [2010/04/12 07:40:20 | 007,864,320 | ---- | C] () -- C:\Users\Marion\ntuser (1).dat
  1367. [2010/04/12 07:40:20 | 000,000,020 | ---- | C] () -- C:\Users\Marion\ntuser (2).ini
  1368. [2010/04/12 07:40:20 | 000,000,020 | ---- | C] () -- C:\Users\Marion\ntuser (1).ini
  1369.  
  1370. [color=#E56717]========== ZeroAccess Check ==========[/color]
  1371.  
  1372. [2013/09/29 11:52:56 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
  1373.  
  1374. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  1375.  
  1376. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  1377.  
  1378. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  1379.  
  1380. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  1381.  
  1382. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  1383. "" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 02:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
  1384. "ThreadingModel" = Apartment
  1385.  
  1386. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  1387. "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 01:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
  1388. "ThreadingModel" = Apartment
  1389.  
  1390. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  1391. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 01:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
  1392. "ThreadingModel" = Free
  1393.  
  1394. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  1395. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 12:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
  1396. "ThreadingModel" = Free
  1397.  
  1398. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  1399. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 01:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
  1400. "ThreadingModel" = Both
  1401.  
  1402. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  1403.  
  1404. [color=#E56717]========== LOP Check ==========[/color]
  1405.  
  1406. [2010/07/17 02:19:16 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Trusteer
  1407. [2010/07/17 02:19:16 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Trusteer
  1408. [2013/11/02 01:33:39 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\AlawarEntertainment
  1409. [2012/08/19 12:38:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\aliasworlds
  1410. [2010/06/03 10:27:43 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Amazon
  1411. [2013/11/10 09:56:30 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Ancient Quest of Saqqarah__bfg
  1412. [2012/08/31 13:41:45 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Anuman
  1413. [2010/12/22 23:11:16 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Awem
  1414. [2013/09/24 22:21:25 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\BBB
  1415. [2013/06/28 09:02:43 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Be a King 2
  1416. [2013/11/01 19:27:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Big Fish Games
  1417. [2012/08/24 17:49:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Boolat Games
  1418. [2013/06/28 09:03:15 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Boomzap
  1419. [2010/04/17 15:36:29 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Braintonik
  1420. [2013/12/02 20:49:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Clip Art Collection
  1421. [2013/09/13 22:02:21 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\DarkManor
  1422. [2013/06/28 09:11:38 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Deadly Sin
  1423. [2011/09/09 16:26:22 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\DriverFinder
  1424. [2013/12/05 17:10:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Dropbox
  1425. [2012/08/09 09:37:18 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\EdAlive
  1426. [2013/02/04 15:51:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Elephant Games
  1427. [2013/09/29 08:25:30 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\ERS Game Studios
  1428. [2013/06/28 09:17:08 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Faerie Solitaire
  1429. [2013/10/13 11:12:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\FixCleaner
  1430. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Foresight Software
  1431. [2013/06/28 09:17:09 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\ForrestGump
  1432. [2012/11/09 00:32:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\funkitron
  1433. [2010/04/28 17:59:55 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\G-HeadGames
  1434. [2012/04/05 10:51:14 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\GAMESHASTRA
  1435. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\GirlsDateChat
  1436. [2010/04/18 07:09:26 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\GOA
  1437. [2013/09/06 00:31:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Inertia Game Studios
  1438. [2012/08/23 11:48:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\InWorldz
  1439. [2013/11/17 16:41:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\KeePass
  1440. [2013/10/22 13:52:28 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\kidoz
  1441. [2012/08/31 15:15:41 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\LegacyGames
  1442. [2013/03/20 00:57:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Liam games
  1443. [2013/10/27 19:46:36 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Melesta
  1444. [2013/10/27 19:09:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Nimbus Games
  1445. [2012/10/03 12:25:45 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Oberon Media
  1446. [2013/01/14 14:54:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\OpenClipArtLibraryPackages
  1447. [2010/05/17 22:11:18 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Orneon
  1448. [2013/08/13 10:00:37 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\PCDr
  1449. [2013/11/10 09:57:08 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Pengu Wars
  1450. [2013/11/11 12:08:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Picsoft
  1451. [2013/09/26 15:58:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\PlayFirst
  1452. [2013/02/04 13:35:56 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Publisher
  1453. [2010/05/24 15:32:17 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\QB9
  1454. [2013/11/29 06:54:40 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Research In Motion
  1455. [2013/11/22 16:21:13 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Samsung
  1456. [2012/05/16 18:51:11 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\SecondLife
  1457. [2013/10/24 18:44:56 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Skyborn
  1458. [2013/06/28 10:02:03 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Super-Cow
  1459. [2013/11/25 02:54:40 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\SyncTunesDesktop
  1460. [2010/04/13 14:42:02 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\System Tweaker
  1461. [2013/10/24 19:22:42 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\The Witch and The Warrior
  1462. [2010/06/12 19:35:04 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Trusteer
  1463. [2013/06/28 10:03:23 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Turbine
  1464. [2013/11/13 09:30:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Uniblue
  1465. [2013/11/10 09:57:21 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\vcards
  1466. [2013/10/23 12:06:34 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\viking_saga_bfg_en
  1467. [2013/06/28 10:07:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Virtual City
  1468. [2012/04/21 19:15:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\WendigoStudios
  1469. [2013/10/03 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\when_in_rome_bfg
  1470. [2013/07/14 19:16:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Windows Live Writer
  1471. [2010/07/17 02:19:16 | 000,000,000 | ---D | M] -- C:\Users\UpdatusUser\AppData\Roaming\Trusteer
  1472.  
  1473. [color=#E56717]========== Purity Check ==========[/color]
  1474.  
  1475.  
  1476.  
  1477. [color=#E56717]========== Custom Scans ==========[/color]
  1478.  
  1479. [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
  1480. [2013/04/30 11:13:04 | 000,021,494 | ---- | M] () -- C:\0x0409.ini
  1481. [2013/04/30 11:13:05 | 000,003,584 | ---- | M] () -- C:\1033.MST
  1482. [2013/11/03 01:37:03 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
  1483. [2013/11/17 15:27:04 | 000,001,566 | ---- | M] () -- C:\DelFix.txt
  1484. [2013/04/30 11:35:12 | 000,000,058 | ---- | M] () -- C:\DUMPA.WAV
  1485. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
  1486. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
  1487. [2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
  1488. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
  1489. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
  1490. [2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
  1491. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
  1492. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
  1493. [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
  1494. [2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
  1495. [2013/12/05 17:09:48 | 529,932,287 | -HS- | M] () -- C:\hiberfil.sys
  1496. [2007/11/07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
  1497. [2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
  1498. [2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
  1499. [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
  1500. [2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
  1501. [2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
  1502. [2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
  1503. [2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
  1504. [2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
  1505. [2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
  1506. [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
  1507. [2013/11/17 14:11:08 | 000,000,863 | ---- | M] () -- C:\MARION-PC.rtf
  1508. [2013/12/05 17:09:54 | 2145,386,495 | -HS- | M] () -- C:\pagefile.sys
  1509. [2013/11/28 18:28:59 | 000,387,776 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\PsExec.exe
  1510. [2013/09/29 19:24:44 | 000,001,790 | ---- | M] () -- C:\RHDSetup.log
  1511. [2013/04/30 11:13:16 | 069,073,836 | ---- | M] () -- C:\Samsung Kies.msi
  1512. [2012/09/20 20:42:43 | 000,001,806 | ---- | M] () -- C:\user.js
  1513. [2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
  1514. [2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
  1515. [2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
  1516.  
  1517. [color=#A23BEC]< %SYSTEMDRIVE%\*. >[/color]
  1518. [2010/04/12 07:40:27 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin
  1519. [2011/08/25 17:17:33 | 000,000,000 | ---D | M] -- C:\.jagex_cache_32
  1520. [2013/04/11 20:16:44 | 000,000,000 | ---D | M] -- C:\00000000d34f
  1521. [2013/11/10 10:06:22 | 000,000,000 | ---D | M] -- C:\AI_RecycleBin
  1522. [2010/08/11 14:08:28 | 000,000,000 | ---D | M] -- C:\ATI
  1523. [2013/11/14 15:57:03 | 000,000,000 | ---D | M] -- C:\BigFishCache
  1524. [2013/11/10 09:54:03 | 000,000,000 | ---D | M] -- C:\BigFishGamesCache
  1525. [2013/11/29 11:54:55 | 000,000,000 | ---D | M] -- C:\Config.Msi
  1526. [2010/08/11 14:26:13 | 000,000,000 | ---D | M] -- C:\dell
  1527. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings
  1528. [2012/01/29 16:42:45 | 000,000,000 | ---D | M] -- C:\found.000
  1529. [2013/11/25 19:24:28 | 000,000,000 | ---D | M] -- C:\FRST
  1530. [2010/08/11 14:21:13 | 000,000,000 | ---D | M] -- C:\Intel
  1531. [2013/02/01 10:35:58 | 000,000,000 | ---D | M] -- C:\KA
  1532. [2013/04/12 10:44:33 | 000,000,000 | ---D | M] -- C:\Kids Videos
  1533. [2013/11/19 00:23:09 | 000,000,000 | ---D | M] -- C:\MATS
  1534. [2013/03/12 18:54:38 | 000,000,000 | RH-D | M] -- C:\MSOCache
  1535. [2012/01/30 09:06:47 | 000,000,000 | ---D | M] -- C:\NVIDIA
  1536. [2013/11/10 11:25:16 | 000,000,000 | ---D | M] -- C:\PerfLogs
  1537. [2013/11/27 18:38:31 | 000,000,000 | ---D | M] -- C:\Program Files
  1538. [2013/11/29 06:41:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)
  1539. [2013/11/29 11:54:44 | 000,000,000 | ---D | M] -- C:\ProgramData
  1540. [2010/04/12 07:40:09 | 000,000,000 | ---D | M] -- C:\Recovery
  1541. [2013/11/17 12:17:55 | 000,000,000 | ---D | M] -- C:\RegBackup
  1542. [2013/12/05 18:13:05 | 000,000,000 | ---D | M] -- C:\System Volume Information
  1543. [2013/11/10 09:54:15 | 000,000,000 | ---D | M] -- C:\teac
  1544. [2013/08/14 18:55:11 | 000,000,000 | ---D | M] -- C:\Users
  1545. [2013/12/05 18:03:38 | 000,000,000 | ---D | M] -- C:\Windows
  1546.  
  1547. [color=#A23BEC]< %USERPROFILE%\*.* >[/color]
  1548. [2013/12/02 10:34:38 | 000,000,000 | ---- | M] () -- C:\Users\Marion\chkdsk
  1549. [2010/04/12 08:38:47 | 000,061,224 | ---- | M] () -- C:\Users\Marion\GoToAssistDownloadHelper (1).exe
  1550. [2010/04/12 08:38:47 | 000,061,224 | ---- | M] () -- C:\Users\Marion\GoToAssistDownloadHelper (2).exe
  1551. [2010/04/12 08:38:47 | 000,061,224 | ---- | M] () -- C:\Users\Marion\GoToAssistDownloadHelper.exe
  1552. [2011/08/25 17:18:29 | 000,000,035 | ---- | M] () -- C:\Users\Marion\jagex_runescape_preferences (1).dat
  1553. [2011/08/25 17:18:29 | 000,000,035 | ---- | M] () -- C:\Users\Marion\jagex_runescape_preferences (2).dat
  1554. [2011/08/25 17:18:29 | 000,000,035 | ---- | M] () -- C:\Users\Marion\jagex_runescape_preferences.dat
  1555. [2011/08/25 17:19:11 | 000,000,129 | ---- | M] () -- C:\Users\Marion\jagex_runescape_preferences2 (1).dat
  1556. [2011/08/25 17:19:11 | 000,000,129 | ---- | M] () -- C:\Users\Marion\jagex_runescape_preferences2 (2).dat
  1557. [2011/08/25 17:19:11 | 000,000,129 | ---- | M] () -- C:\Users\Marion\jagex_runescape_preferences2.dat
  1558. [2013/05/29 22:27:12 | 007,864,320 | ---- | M] () -- C:\Users\Marion\ntuser (1).dat
  1559. [2010/04/12 07:40:20 | 000,000,020 | ---- | M] () -- C:\Users\Marion\ntuser (1).ini
  1560. [2013/05/29 22:27:12 | 007,864,320 | ---- | M] () -- C:\Users\Marion\ntuser (2).dat
  1561. [2010/04/12 07:40:20 | 000,000,020 | ---- | M] () -- C:\Users\Marion\ntuser (2).ini
  1562. [2013/12/05 20:48:53 | 008,912,896 | ---- | M] () -- C:\Users\Marion\ntuser.dat
  1563. [2013/05/29 22:27:12 | 000,262,144 | ---- | M] () -- C:\Users\Marion\ntuser.dat (1).LOG1
  1564. [2010/04/12 07:40:20 | 000,000,000 | ---- | M] () -- C:\Users\Marion\ntuser.dat (1).LOG2
  1565. [2013/05/29 22:27:12 | 000,262,144 | ---- | M] () -- C:\Users\Marion\ntuser.dat (2).LOG1
  1566. [2010/04/12 07:40:20 | 000,000,000 | ---- | M] () -- C:\Users\Marion\ntuser.dat (2).LOG2
  1567. [2013/12/05 20:48:53 | 000,262,144 | ---- | M] () -- C:\Users\Marion\ntuser.dat.LOG1
  1568. [2010/04/12 07:40:20 | 000,000,000 | ---- | M] () -- C:\Users\Marion\ntuser.dat.LOG2
  1569. [2010/04/12 21:55:15 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM (1).blf
  1570. [2010/04/12 21:55:15 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM (2).blf
  1571. [2010/04/12 21:55:15 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
  1572. [2010/04/12 21:55:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001 (1).regtrans-ms
  1573. [2010/04/12 21:55:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001 (2).regtrans-ms
  1574. [2010/04/12 21:55:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
  1575. [2010/04/12 21:55:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002 (1).regtrans-ms
  1576. [2010/04/12 21:55:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002 (2).regtrans-ms
  1577. [2010/04/12 21:55:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
  1578. [2012/04/09 22:27:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TM (1).blf
  1579. [2012/04/09 22:27:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TM (2).blf
  1580. [2012/04/09 22:27:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TM.blf
  1581. [2012/04/09 22:27:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1582. [2012/04/09 22:27:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1583. [2012/04/09 22:27:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1584. [2012/04/09 22:27:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1585. [2012/04/09 22:27:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1586. [2012/04/09 22:27:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{03a38bfc-7772-11e1-bb39-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1587. [2010/04/15 12:28:26 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TM (1).blf
  1588. [2010/04/15 12:28:26 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TM (2).blf
  1589. [2010/04/15 12:28:26 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TM.blf
  1590. [2010/04/15 12:28:26 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1591. [2010/04/15 12:28:26 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1592. [2010/04/15 12:28:26 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1593. [2010/04/15 12:28:26 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1594. [2010/04/15 12:28:26 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1595. [2010/04/15 12:28:26 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{042e7f84-486c-11df-80ae-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1596. [2012/11/10 00:26:38 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TM (1).blf
  1597. [2012/11/10 00:26:38 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TM (2).blf
  1598. [2012/11/10 00:26:38 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TM.blf
  1599. [2012/11/10 00:26:38 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1600. [2012/11/10 00:26:38 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1601. [2012/11/10 00:26:38 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1602. [2012/11/10 00:26:38 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1603. [2012/11/10 00:26:38 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1604. [2012/11/10 00:26:38 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{05661d81-2a84-11e2-8932-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1605. [2013/03/10 23:45:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TM (1).blf
  1606. [2013/03/10 23:45:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TM (2).blf
  1607. [2013/03/10 23:45:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TM.blf
  1608. [2013/03/10 23:45:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1609. [2013/03/10 23:45:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1610. [2013/03/10 23:45:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1611. [2013/03/10 23:45:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1612. [2013/03/10 23:45:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1613. [2013/03/10 23:45:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{0e3f3bde-8953-11e2-930f-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1614. [2012/01/13 13:47:48 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TM (1).blf
  1615. [2012/01/13 13:47:48 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TM (2).blf
  1616. [2012/01/13 13:47:48 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TM.blf
  1617. [2012/01/13 13:47:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1618. [2012/01/13 13:47:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1619. [2012/01/13 13:47:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1620. [2012/01/13 13:47:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1621. [2012/01/13 13:47:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1622. [2012/01/13 13:47:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{168709f4-313d-11e1-b840-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1623. [2013/05/20 21:06:12 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TM (1).blf
  1624. [2013/05/20 21:06:12 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TM (2).blf
  1625. [2013/05/20 21:06:12 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TM.blf
  1626. [2013/05/20 21:06:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1627. [2013/05/20 21:06:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1628. [2013/05/20 21:06:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1629. [2013/05/20 21:06:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1630. [2013/05/20 21:06:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1631. [2013/05/20 21:06:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{18f1efc4-c15d-11e2-847a-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1632. [2013/05/18 22:04:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TM (1).blf
  1633. [2013/05/18 22:04:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TM (2).blf
  1634. [2013/05/18 22:04:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TM.blf
  1635. [2013/05/18 22:04:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1636. [2013/05/18 22:04:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1637. [2013/05/18 22:04:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1638. [2013/05/18 22:04:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1639. [2013/05/18 22:04:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1640. [2013/05/18 22:04:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1b750d8e-bfd4-11e2-99c5-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1641. [2012/02/04 18:07:10 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TM (1).blf
  1642. [2012/02/04 18:07:10 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TM (2).blf
  1643. [2012/02/04 18:07:10 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TM.blf
  1644. [2012/02/04 18:07:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1645. [2012/02/04 18:07:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1646. [2012/02/04 18:07:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1647. [2012/02/04 18:07:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1648. [2012/02/04 18:07:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1649. [2012/02/04 18:07:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fd4c860-4e9d-11e1-aaca-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1650. [2013/09/12 07:26:07 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fee42c9-1b3a-11e3-a824-00219b1c2f23}.TM.blf
  1651. [2013/09/12 07:26:07 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fee42c9-1b3a-11e3-a824-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1652. [2013/09/12 07:26:07 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{1fee42c9-1b3a-11e3-a824-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1653. [2012/09/25 22:20:27 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TM (1).blf
  1654. [2012/09/25 22:20:27 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TM (2).blf
  1655. [2012/09/25 22:20:27 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TM.blf
  1656. [2012/09/25 22:20:27 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1657. [2012/09/25 22:20:27 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1658. [2012/09/25 22:20:27 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1659. [2012/09/25 22:20:27 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1660. [2012/09/25 22:20:27 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1661. [2012/09/25 22:20:27 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2a43f013-055e-11e2-9f95-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1662. [2012/03/20 11:59:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TM (1).blf
  1663. [2012/03/20 11:59:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TM (2).blf
  1664. [2012/03/20 11:59:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TM.blf
  1665. [2012/03/20 11:59:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1666. [2012/03/20 11:59:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1667. [2012/03/20 11:59:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1668. [2012/03/20 11:59:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1669. [2012/03/20 11:59:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1670. [2012/03/20 11:59:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2b381aee-702f-11e1-a922-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1671. [2011/12/14 13:57:41 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TM (1).blf
  1672. [2011/12/14 13:57:41 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TM (2).blf
  1673. [2011/12/14 13:57:41 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TM.blf
  1674. [2011/12/14 13:57:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1675. [2011/12/14 13:57:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1676. [2011/12/14 13:57:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1677. [2011/12/14 13:57:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1678. [2011/12/14 13:57:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1679. [2011/12/14 13:57:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{2c8357d5-2647-11e1-b348-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1680. [2012/01/13 19:20:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TM (1).blf
  1681. [2012/01/13 19:20:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TM (2).blf
  1682. [2012/01/13 19:20:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TM.blf
  1683. [2012/01/13 19:20:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1684. [2012/01/13 19:20:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1685. [2012/01/13 19:20:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1686. [2012/01/13 19:20:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1687. [2012/01/13 19:20:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1688. [2012/01/13 19:20:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{3256672a-3df3-11e1-8e17-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1689. [2013/08/14 22:57:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{41b4cfdd-04bb-11e3-8fee-00219b1c2f23}.TM.blf
  1690. [2013/08/14 22:57:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{41b4cfdd-04bb-11e3-8fee-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1691. [2013/08/14 22:57:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{41b4cfdd-04bb-11e3-8fee-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1692. [2010/04/13 14:51:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TM (1).blf
  1693. [2010/04/13 14:51:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TM (2).blf
  1694. [2010/04/13 14:51:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TM.blf
  1695. [2010/04/13 14:51:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1696. [2010/04/13 14:51:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1697. [2010/04/13 14:51:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1698. [2010/04/13 14:51:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1699. [2010/04/13 14:51:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1700. [2010/04/13 14:51:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{4243960b-46c3-11df-8e03-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1701. [2012/07/12 02:21:20 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TM (1).blf
  1702. [2012/07/12 02:21:20 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TM (2).blf
  1703. [2012/07/12 02:21:20 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TM.blf
  1704. [2012/07/12 02:21:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1705. [2012/07/12 02:21:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1706. [2012/07/12 02:21:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1707. [2012/07/12 02:21:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1708. [2012/07/12 02:21:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1709. [2012/07/12 02:21:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{4e27ae8c-ca71-11e1-8c5c-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1710. [2012/05/13 23:08:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TM (1).blf
  1711. [2012/05/13 23:08:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TM (2).blf
  1712. [2012/05/13 23:08:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TM.blf
  1713. [2012/05/13 23:08:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1714. [2012/05/13 23:08:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1715. [2012/05/13 23:08:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1716. [2012/05/13 23:08:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1717. [2012/05/13 23:08:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1718. [2012/05/13 23:08:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5b3256c1-9ce9-11e1-8f34-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1719. [2012/05/01 08:52:53 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TM (1).blf
  1720. [2012/05/01 08:52:53 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TM (2).blf
  1721. [2012/05/01 08:52:53 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TM.blf
  1722. [2012/05/01 08:52:53 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1723. [2012/05/01 08:52:53 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1724. [2012/05/01 08:52:53 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1725. [2012/05/01 08:52:53 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1726. [2012/05/01 08:52:53 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1727. [2012/05/01 08:52:53 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{5fae0cdf-9065-11e1-8db5-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1728. [2010/04/17 21:35:43 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TM (1).blf
  1729. [2010/04/17 21:35:43 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TM (2).blf
  1730. [2010/04/17 21:35:43 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TM.blf
  1731. [2010/04/17 21:35:43 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1732. [2010/04/17 21:35:43 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1733. [2010/04/17 21:35:43 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1734. [2010/04/17 21:35:43 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1735. [2010/04/17 21:35:43 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1736. [2010/04/17 21:35:43 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{6452f106-49f0-11df-9e42-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1737. [2012/01/28 11:53:12 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TM (1).blf
  1738. [2012/01/28 11:53:12 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TM (2).blf
  1739. [2012/01/28 11:53:12 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TM.blf
  1740. [2012/01/28 11:53:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1741. [2012/01/28 11:53:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1742. [2012/01/28 11:53:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1743. [2012/01/28 11:53:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1744. [2012/01/28 11:53:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1745. [2012/01/28 11:53:12 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{678fb743-49a6-11e1-a7df-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1746. [2013/05/28 08:06:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TM (1).blf
  1747. [2013/05/28 08:06:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TM (2).blf
  1748. [2013/05/28 08:06:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TM.blf
  1749. [2013/05/28 08:06:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1750. [2013/05/28 08:06:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1751. [2013/05/28 08:06:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1752. [2013/05/28 08:06:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1753. [2013/05/28 08:06:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1754. [2013/05/28 08:06:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{74c60549-c769-11e2-8cd3-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1755. [2013/10/26 03:31:35 | 000,065,536 | -HS- | M] () -- C:\Users\Marion\ntuser.dat{7dc60bcc-3dc7-11e3-9998-00219b1c2f23}.TM.blf
  1756. [2013/10/26 03:31:35 | 000,524,288 | -HS- | M] () -- C:\Users\Marion\ntuser.dat{7dc60bcc-3dc7-11e3-9998-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1757. [2013/10/26 03:31:35 | 000,524,288 | -HS- | M] () -- C:\Users\Marion\ntuser.dat{7dc60bcc-3dc7-11e3-9998-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1758. [2013/04/05 00:18:41 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TM (1).blf
  1759. [2013/04/05 00:18:41 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TM (2).blf
  1760. [2013/04/05 00:18:41 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TM.blf
  1761. [2013/04/05 00:18:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1762. [2013/04/05 00:18:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1763. [2013/04/05 00:18:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1764. [2013/04/05 00:18:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1765. [2013/04/05 00:18:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1766. [2013/04/05 00:18:41 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{7eb12626-9d2d-11e2-8165-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1767. [2013/09/29 11:42:46 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8b7c597b-28d8-11e3-a62e-00219b1c2f23}.TM.blf
  1768. [2013/09/29 11:42:46 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8b7c597b-28d8-11e3-a62e-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1769. [2013/09/29 11:42:46 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8b7c597b-28d8-11e3-a62e-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1770. [2013/01/21 23:24:01 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TM (1).blf
  1771. [2013/01/21 23:24:01 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TM (2).blf
  1772. [2013/01/21 23:24:01 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TM.blf
  1773. [2013/01/21 23:24:01 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1774. [2013/01/21 23:24:01 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1775. [2013/01/21 23:24:01 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1776. [2013/01/21 23:24:01 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1777. [2013/01/21 23:24:01 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1778. [2013/01/21 23:24:01 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8bf40fc4-62f7-11e2-8d4c-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1779. [2012/08/04 21:33:09 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TM (1).blf
  1780. [2012/08/04 21:33:09 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TM (2).blf
  1781. [2012/08/04 21:33:09 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TM.blf
  1782. [2012/08/04 21:33:09 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1783. [2012/08/04 21:33:09 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1784. [2012/08/04 21:33:09 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1785. [2012/08/04 21:33:09 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1786. [2012/08/04 21:33:09 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1787. [2012/08/04 21:33:09 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{8d0beaf2-de39-11e1-aa7a-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1788. [2013/05/28 07:36:54 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TM (1).blf
  1789. [2013/05/28 07:36:54 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TM (2).blf
  1790. [2013/05/28 07:36:54 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TM.blf
  1791. [2013/05/28 07:36:54 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1792. [2013/05/28 07:36:54 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1793. [2013/05/28 07:36:54 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1794. [2013/05/28 07:36:54 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1795. [2013/05/28 07:36:54 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1796. [2013/05/28 07:36:54 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{938e5069-c701-11e2-870b-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1797. [2011/12/11 11:03:03 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TM (1).blf
  1798. [2011/12/11 11:03:03 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TM (2).blf
  1799. [2011/12/11 11:03:03 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TM.blf
  1800. [2011/12/11 11:03:03 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1801. [2011/12/11 11:03:03 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1802. [2011/12/11 11:03:03 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1803. [2011/12/11 11:03:03 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1804. [2011/12/11 11:03:03 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1805. [2011/12/11 11:03:03 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{94cf3b11-23e7-11e1-bf2e-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1806. [2013/04/06 11:04:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TM (1).blf
  1807. [2013/04/06 11:04:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TM (2).blf
  1808. [2013/04/06 11:04:13 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TM.blf
  1809. [2013/04/06 11:04:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1810. [2013/04/06 11:04:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1811. [2013/04/06 11:04:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1812. [2013/04/06 11:04:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1813. [2013/04/06 11:04:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1814. [2013/04/06 11:04:13 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{95f121bc-9dc8-11e2-9831-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1815. [2013/10/18 17:29:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{9f2a2a20-37cb-11e3-abbb-00219b1c2f23}.TM.blf
  1816. [2013/10/18 17:29:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{9f2a2a20-37cb-11e3-abbb-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1817. [2013/10/18 17:29:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{9f2a2a20-37cb-11e3-abbb-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1818. [2013/05/28 07:40:20 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TM (1).blf
  1819. [2013/05/28 07:40:20 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TM (2).blf
  1820. [2013/05/28 07:40:20 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TM.blf
  1821. [2013/05/28 07:40:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1822. [2013/05/28 07:40:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1823. [2013/05/28 07:40:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1824. [2013/05/28 07:40:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1825. [2013/05/28 07:40:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1826. [2013/05/28 07:40:20 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a330e9e7-c743-11e2-95f9-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1827. [2013/01/10 15:28:48 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TM (1).blf
  1828. [2013/01/10 15:28:48 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TM (2).blf
  1829. [2013/01/10 15:28:48 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TM.blf
  1830. [2013/01/10 15:28:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1831. [2013/01/10 15:28:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1832. [2013/01/10 15:28:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1833. [2013/01/10 15:28:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1834. [2013/01/10 15:28:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1835. [2013/01/10 15:28:48 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{a6756125-5b25-11e2-8d64-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1836. [2012/10/06 21:19:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TM (1).blf
  1837. [2012/10/06 21:19:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TM (2).blf
  1838. [2012/10/06 21:19:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TM.blf
  1839. [2012/10/06 21:19:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1840. [2012/10/06 21:19:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1841. [2012/10/06 21:19:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1842. [2012/10/06 21:19:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1843. [2012/10/06 21:19:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1844. [2012/10/06 21:19:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{aa6d1014-0f81-11e2-855f-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1845. [2013/08/13 13:36:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b23fe0a9-03ea-11e3-8d22-00219b1c2f23}.TM.blf
  1846. [2013/08/13 13:36:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b23fe0a9-03ea-11e3-8d22-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1847. [2013/08/13 13:36:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b23fe0a9-03ea-11e3-8d22-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1848. [2010/05/11 09:16:18 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TM (1).blf
  1849. [2010/05/11 09:16:18 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TM (2).blf
  1850. [2010/05/11 09:16:18 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TM.blf
  1851. [2010/05/11 09:16:18 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1852. [2010/05/11 09:16:18 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1853. [2010/05/11 09:16:18 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1854. [2010/05/11 09:16:18 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1855. [2010/05/11 09:16:18 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1856. [2010/05/11 09:16:18 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{b7148580-5cdc-11df-9d3e-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1857. [2013/02/12 23:59:16 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TM (1).blf
  1858. [2013/02/12 23:59:16 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TM (2).blf
  1859. [2013/02/12 23:59:16 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TM.blf
  1860. [2013/02/12 23:59:16 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1861. [2013/02/12 23:59:16 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1862. [2013/02/12 23:59:16 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1863. [2013/02/12 23:59:16 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1864. [2013/02/12 23:59:16 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1865. [2013/02/12 23:59:16 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{bf968272-716a-11e2-9745-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1866. [2013/04/06 12:16:15 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TM (1).blf
  1867. [2013/04/06 12:16:15 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TM (2).blf
  1868. [2013/04/06 12:16:15 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TM.blf
  1869. [2013/04/06 12:16:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1870. [2013/04/06 12:16:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1871. [2013/04/06 12:16:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1872. [2013/04/06 12:16:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1873. [2013/04/06 12:16:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1874. [2013/04/06 12:16:15 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c317ffaf-9eae-11e2-947c-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1875. [2012/06/12 11:20:51 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TM (1).blf
  1876. [2012/06/12 11:20:51 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TM (2).blf
  1877. [2012/06/12 11:20:51 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TM.blf
  1878. [2012/06/12 11:20:51 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1879. [2012/06/12 11:20:51 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1880. [2012/06/12 11:20:51 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1881. [2012/06/12 11:20:51 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1882. [2012/06/12 11:20:51 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1883. [2012/06/12 11:20:51 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{c47e7f70-b341-11e1-aac9-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1884. [2013/03/12 20:26:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TM (1).blf
  1885. [2013/03/12 20:26:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TM (2).blf
  1886. [2013/03/12 20:26:42 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TM.blf
  1887. [2013/03/12 20:26:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1888. [2013/03/12 20:26:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1889. [2013/03/12 20:26:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1890. [2013/03/12 20:26:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1891. [2013/03/12 20:26:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1892. [2013/03/12 20:26:42 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{cf16146f-8b27-11e2-ad6d-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1893. [2012/09/17 11:44:45 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TM (1).blf
  1894. [2012/09/17 11:44:45 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TM (2).blf
  1895. [2012/09/17 11:44:45 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TM.blf
  1896. [2012/09/17 11:44:45 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1897. [2012/09/17 11:44:45 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1898. [2012/09/17 11:44:45 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1899. [2012/09/17 11:44:45 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1900. [2012/09/17 11:44:45 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1901. [2012/09/17 11:44:45 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{dcb5cd9b-ffd0-11e1-8a99-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1902. [2011/12/12 23:14:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TM (1).blf
  1903. [2011/12/12 23:14:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TM (2).blf
  1904. [2011/12/12 23:14:21 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TM.blf
  1905. [2011/12/12 23:14:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1906. [2011/12/12 23:14:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1907. [2011/12/12 23:14:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1908. [2011/12/12 23:14:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1909. [2011/12/12 23:14:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1910. [2011/12/12 23:14:21 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e311fbcf-24d2-11e1-b7c2-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1911. [2013/07/12 23:55:10 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e4226979-eb0b-11e2-9441-00219b1c2f23}.TM.blf
  1912. [2013/07/12 23:55:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e4226979-eb0b-11e2-9441-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1913. [2013/07/12 23:55:10 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{e4226979-eb0b-11e2-9441-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1914. [2010/04/13 18:51:50 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TM (1).blf
  1915. [2010/04/13 18:51:50 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TM (2).blf
  1916. [2010/04/13 18:51:50 | 000,065,536 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TM.blf
  1917. [2010/04/13 18:51:50 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1918. [2010/04/13 18:51:50 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1919. [2010/04/13 18:51:50 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1920. [2010/04/13 18:51:50 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1921. [2010/04/13 18:51:50 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1922. [2010/04/13 18:51:50 | 000,524,288 | ---- | M] () -- C:\Users\Marion\NTUSER.DAT{e8116b11-470b-11df-bce6-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1923. [2013/04/27 16:01:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TM (1).blf
  1924. [2013/04/27 16:01:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TM (2).blf
  1925. [2013/04/27 16:01:36 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TM.blf
  1926. [2013/04/27 16:01:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1927. [2013/04/27 16:01:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1928. [2013/04/27 16:01:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1929. [2013/04/27 16:01:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1930. [2013/04/27 16:01:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1931. [2013/04/27 16:01:36 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{ead6b020-af0a-11e2-84ef-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1932. [2013/02/28 23:28:49 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TM (1).blf
  1933. [2013/02/28 23:28:49 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TM (2).blf
  1934. [2013/02/28 23:28:49 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TM.blf
  1935. [2013/02/28 23:28:49 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1936. [2013/02/28 23:28:49 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1937. [2013/02/28 23:28:49 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1938. [2013/02/28 23:28:49 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1939. [2013/02/28 23:28:49 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1940. [2013/02/28 23:28:49 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f352ce25-80b8-11e2-8d50-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1941. [2011/12/11 11:55:44 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TM (1).blf
  1942. [2011/12/11 11:55:44 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TM (2).blf
  1943. [2011/12/11 11:55:44 | 000,065,536 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TM.blf
  1944. [2011/12/11 11:55:44 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TMContainer00000000000000000001 (1).regtrans-ms
  1945. [2011/12/11 11:55:44 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TMContainer00000000000000000001 (2).regtrans-ms
  1946. [2011/12/11 11:55:44 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  1947. [2011/12/11 11:55:44 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TMContainer00000000000000000002 (1).regtrans-ms
  1948. [2011/12/11 11:55:44 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TMContainer00000000000000000002 (2).regtrans-ms
  1949. [2011/12/11 11:55:44 | 000,524,288 | ---- | M] () -- C:\Users\Marion\ntuser.dat{f94429f2-23ee-11e1-a7c3-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  1950. [2010/04/12 07:40:20 | 000,000,020 | -HS- | M] () -- C:\Users\Marion\ntuser.ini
  1951.  
  1952. [color=#A23BEC]< %USERPROFILE%\*. >[/color]
  1953. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData
  1954. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\Application Data
  1955. [2013/11/29 07:00:01 | 000,000,000 | ---D | M] -- C:\Users\Marion\Contacts
  1956. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\Cookies
  1957. [2013/12/05 20:44:58 | 000,000,000 | R--D | M] -- C:\Users\Marion\Desktop
  1958. [2013/12/02 20:55:07 | 000,000,000 | ---D | M] -- C:\Users\Marion\Documents
  1959. [2013/12/05 20:44:58 | 000,000,000 | ---D | M] -- C:\Users\Marion\Downloads
  1960. [2013/12/05 17:10:42 | 000,000,000 | R--D | M] -- C:\Users\Marion\Dropbox
  1961. [2013/11/17 20:27:16 | 000,000,000 | ---D | M] -- C:\Users\Marion\Favorites
  1962. [2013/11/27 18:33:55 | 000,000,000 | ---D | M] -- C:\Users\Marion\Links
  1963. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\Local Settings
  1964. [2013/11/22 17:09:51 | 000,000,000 | ---D | M] -- C:\Users\Marion\Music
  1965. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\My Documents
  1966. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\NetHood
  1967. [2013/12/02 10:42:34 | 000,000,000 | ---D | M] -- C:\Users\Marion\Pictures
  1968. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\PrintHood
  1969. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\Recent
  1970. [2013/11/17 20:27:16 | 000,000,000 | ---D | M] -- C:\Users\Marion\Saved Games
  1971. [2013/11/21 12:08:07 | 000,000,000 | ---D | M] -- C:\Users\Marion\Searches
  1972. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\SendTo
  1973. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\Start Menu
  1974. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\Templates
  1975. [2013/11/10 09:58:14 | 000,000,000 | ---D | M] -- C:\Users\Marion\Tracing
  1976. [2013/11/10 09:58:14 | 000,000,000 | ---D | M] -- C:\Users\Marion\Videos
  1977.  
  1978. [color=#A23BEC]< %USERPROFILE%\*.exe /s >[/color]
  1979. [2010/04/12 08:38:47 | 000,061,224 | ---- | M] () -- C:\Users\Marion\GoToAssistDownloadHelper (1).exe
  1980. [2010/04/12 08:38:47 | 000,061,224 | ---- | M] () -- C:\Users\Marion\GoToAssistDownloadHelper (2).exe
  1981. [2010/04/12 08:38:47 | 000,061,224 | ---- | M] () -- C:\Users\Marion\GoToAssistDownloadHelper.exe
  1982. [2013/06/04 23:47:02 | 000,142,576 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\admintool.exe
  1983. [2013/06/05 00:55:50 | 004,415,736 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\ControlPanel.exe
  1984. [2013/11/03 01:19:10 | 010,028,936 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\installer_no_upload_silent.exe
  1985. [2013/06/05 01:01:52 | 004,489,472 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\netsession_win.exe
  1986. [2013/06/05 01:01:50 | 006,339,816 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\rswinui.exe
  1987. [2013/06/05 01:01:50 | 002,244,336 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\uninstall.exe
  1988. [2013/01/26 06:02:32 | 004,415,736 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Marion\AppData\Local\Akamai\ControlPanel.old\ControlPanel.exe
  1989. [2013/11/11 11:39:50 | 000,077,136 | ---- | M] (Apple Inc.) -- C:\Users\Marion\AppData\Local\Apple\Apple Software Update\SetupAdmin.exe
  1990. [2010/04/12 08:38:44 | 000,038,912 | ---- | M] (Citrix Online) -- C:\Users\Marion\AppData\Local\Apps\2.0\H0T3JGL3.JGK\BMB4RVJK.XV3\citr..rter_1f7b1ea3a3243e4a_0001.0000_0b3e9c346e6aaa9f\AppCore.exe
  1991. [2010/04/12 08:38:51 | 001,106,728 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) -- C:\Users\Marion\AppData\Local\Citrix\GoToAssist\GoToAssist_chat2way_service_514_en.exe
  1992. [2012/04/13 10:50:42 | 001,287,528 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\AppData\Local\Microsoft\Windows Live\Installer\Catalog\wlsetup.exe
  1993. [1623/03/26 06:11:20 | 000,375,072 | ---- | M] (Conduit Ltd.) -- C:\Users\Marion\AppData\Local\NativeMessaging\CT3292715\1_0_0_2\TBMessagingHost.exe
  1994. [2013/09/29 17:02:27 | 000,821,568 | ---- | M] (SlimWare Utilities, Inc.) -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\FC-setup.exe
  1995. [2013/09/29 16:38:36 | 000,549,091 | ---- | M] () -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Downloads\00D9E9A9052F01F386A3E962111EBDBAF700000000000860E3.exe
  1996. [2013/09/29 19:08:49 | 059,632,525 | ---- | M] () -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Downloads\00DC1251C27AFD94F23B0F5666E988B5C100000000038DEB8D.exe
  1997. [2013/09/29 16:34:58 | 026,129,808 | ---- | M] () -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Downloads\00E7864BFCBB3C8586EDD1E2C540F5374900000000018EB590.exe
  1998. [2013/09/01 11:58:28 | 000,488,960 | ---- | M] () -- C:\Users\Marion\AppData\Local\Temp\sqlite3.exe
  1999. [8 C:\Users\Marion\AppData\Local\Temp\*.tmp files -> C:\Users\Marion\AppData\Local\Temp\*.tmp -> ]
  2000. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\0g73u2ek\na3z0zgb (1).exe
  2001. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\0g73u2ek\na3z0zgb (2).exe
  2002. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\0g73u2ek\na3z0zgb.exe
  2003. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\df3u7m23\bk29k0qq (1).exe
  2004. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\df3u7m23\bk29k0qq (2).exe
  2005. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\df3u7m23\bk29k0qq.exe
  2006. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\tlngbbrx\sa8my2rg (1).exe
  2007. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\tlngbbrx\sa8my2rg (2).exe
  2008. [2012/04/15 09:40:03 | 000,065,896 | ---- | M] () -- C:\Users\Marion\AppData\LocalLow\Microsoft\Windows Live\Setup\tmp\tlngbbrx\sa8my2rg.exe
  2009. [2013/08/13 09:54:31 | 000,889,416 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\AppData\Roaming\dotNetFx40_Full_setup.exe
  2010. [2009/05/12 04:35:30 | 000,118,784 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atibtmon (1).exe
  2011. [2009/05/12 04:35:30 | 000,118,784 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atibtmon (2).exe
  2012. [2009/05/12 04:35:30 | 000,118,784 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atibtmon.exe
  2013. [2009/08/18 09:36:54 | 000,420,352 | ---- | M] (AMD) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atieclxx (1).exe
  2014. [2009/08/18 09:36:54 | 000,420,352 | ---- | M] (AMD) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atieclxx (2).exe
  2015. [2009/08/18 09:36:54 | 000,420,352 | ---- | M] (AMD) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atieclxx.exe
  2016. [2009/08/18 09:36:20 | 000,203,264 | ---- | M] (AMD) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atiesrxx (1).exe
  2017. [2009/08/18 09:36:20 | 000,203,264 | ---- | M] (AMD) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atiesrxx (2).exe
  2018. [2009/08/18 09:36:20 | 000,203,264 | ---- | M] (AMD) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\atiesrxx.exe
  2019. [2009/02/04 03:52:08 | 000,051,200 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\ATIODCLI (1).exe
  2020. [2009/02/04 03:52:08 | 000,051,200 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\ATIODCLI (2).exe
  2021. [2009/02/04 03:52:08 | 000,051,200 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\ATIODCLI.exe
  2022. [2009/02/19 00:55:24 | 000,332,288 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\ATIODE (1).exe
  2023. [2009/02/19 00:55:24 | 000,332,288 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\ATIODE (2).exe
  2024. [2009/02/19 00:55:24 | 000,332,288 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\ATI Radeon HD 4800 Series - 8.632.1.2000\ATIODE.exe
  2025. [2009/11/17 17:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\AERTSr64 (1).exe
  2026. [2009/11/17 17:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\AERTSr64 (2).exe
  2027. [2009/11/17 17:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\AERTSr64.exe
  2028. [2010/07/06 17:31:12 | 002,103,912 | ---- | M] (Realtek Semiconductor) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RAVBg64 (1).exe
  2029. [2010/07/06 17:31:12 | 002,103,912 | ---- | M] (Realtek Semiconductor) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RAVBg64 (2).exe
  2030. [2010/07/06 17:31:12 | 002,103,912 | ---- | M] (Realtek Semiconductor) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RAVBg64.exe
  2031. [2010/07/06 17:31:18 | 011,057,768 | ---- | M] (Realtek Semiconductor) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RAVCpl64 (1).exe
  2032. [2010/07/06 17:31:18 | 011,057,768 | ---- | M] (Realtek Semiconductor) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RAVCpl64 (2).exe
  2033. [2010/07/06 17:31:18 | 011,057,768 | ---- | M] (Realtek Semiconductor) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RAVCpl64.exe
  2034. [2010/07/06 17:31:36 | 001,679,976 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RtlUpd64 (1).exe
  2035. [2010/07/06 17:31:36 | 001,679,976 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RtlUpd64 (2).exe
  2036. [2010/07/06 17:31:36 | 001,679,976 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6151\RtlUpd64.exe
  2037. [2010/11/25 01:01:47 | 080,984,908 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\104139\Vista_Win7_R254 (1).exe
  2038. [2010/11/25 01:01:47 | 080,984,908 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\104139\Vista_Win7_R254 (2).exe
  2039. [2010/11/25 01:01:47 | 080,984,908 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\104139\Vista_Win7_R254.exe
  2040. [2010/07/31 08:29:25 | 000,136,848 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\65252\DELL_S2309W-MONITOR_A00-00_R222241 (1).exe
  2041. [2010/07/31 08:29:25 | 000,136,848 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\65252\DELL_S2309W-MONITOR_A00-00_R222241 (2).exe
  2042. [2010/07/31 08:29:25 | 000,136,848 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\65252\DELL_S2309W-MONITOR_A00-00_R222241.exe
  2043. [2010/07/31 08:30:21 | 020,719,880 | ---- | M] (Intel ) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\75961\Intel-PROWinx64 (1).exe
  2044. [2010/07/31 08:30:21 | 020,719,880 | ---- | M] (Intel ) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\75961\Intel-PROWinx64 (2).exe
  2045. [2010/07/31 08:30:21 | 020,719,880 | ---- | M] (Intel ) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\75961\Intel-PROWinx64.exe
  2046. [2010/07/31 08:27:52 | 076,127,344 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\80017\10-6_vista64_win7_64_dd_ccc_enu (1).exe
  2047. [2010/07/31 08:27:52 | 076,127,344 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\80017\10-6_vista64_win7_64_dd_ccc_enu (2).exe
  2048. [2010/07/31 08:27:52 | 076,127,344 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\80017\10-6_vista64_win7_64_dd_ccc_enu.exe
  2049. [2010/07/31 08:30:35 | 002,869,784 | ---- | M] (Intel Corporation) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\81823\INF_allOS_9.1.2.1007_PV (1).exe
  2050. [2010/07/31 08:30:35 | 002,869,784 | ---- | M] (Intel Corporation) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\81823\INF_allOS_9.1.2.1007_PV (2).exe
  2051. [2010/07/31 08:30:35 | 002,869,784 | ---- | M] (Intel Corporation) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\81823\INF_allOS_9.1.2.1007_PV.exe
  2052. [2010/07/31 08:29:23 | 041,623,735 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\82036\Vista_Win7_R250_x64 (1).exe
  2053. [2010/07/31 08:29:23 | 041,623,735 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\82036\Vista_Win7_R250_x64 (2).exe
  2054. [2010/07/31 08:29:23 | 041,623,735 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\AppData\Roaming\DriverFinder\Download\82036\Vista_Win7_R250_x64.exe
  2055. [2013/11/09 02:51:36 | 029,770,248 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\AppData\Roaming\Dropbox\bin\Dropbox.exe
  2056. [2013/11/09 02:51:50 | 000,229,288 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
  2057. [2013/11/09 02:51:40 | 000,919,016 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
  2058. [2013/11/03 01:36:38 | 000,110,080 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Microsoft\Installer\{72AAF455-1E54-475B-B0AB-5413C78D0E63}\Icon1226A4C5.exe
  2059. [2012/10/12 23:54:32 | 000,565,760 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\OpenClipArtLibraryPackages\UninstallPackages\Uninstall (1).exe
  2060. [2012/10/12 23:54:32 | 000,565,760 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\OpenClipArtLibraryPackages\UninstallPackages\Uninstall (2).exe
  2061. [2012/10/12 23:54:32 | 000,565,760 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\OpenClipArtLibraryPackages\UninstallPackages\Uninstall.exe
  2062. [2013/11/15 10:44:59 | 015,412,488 | ---- | M] (Dell Inc) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Binaries\patch_dsc_630828to636148_64_02.exe
  2063. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\1ab4c4c1-e3a5-4613-aac4-f8faa9eddda6\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2064. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\1ba6a1b8-59b1-457e-b230-fae7dc3fbd76\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2065. [2012/07/05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\24a729b3-e675-452d-b208-37709b433f7d\appupdaterrules_dell\AddCertificate.exe
  2066. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\4fdc8fde-9d58-45d4-9132-936ffee177a4\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2067. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\52c6edd0-ff38-42b9-b7ef-0932dc1f5a4c\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2068. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\5b3d0243-64e0-44d1-b022-cce092b408c3\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2069. [2012/07/05 12:51:46 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\8b7d5cd4-c303-42c1-91ae-fc18c6770a2e\appupdaterrules_dell\AddCertificate.exe
  2070. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\8e6330c1-6c63-4c12-8369-3080b5851cd3\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2071. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\a1048767-7d0f-4734-a32d-4f71d6cb599d\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2072. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\bcc6f796-514a-4b4e-a836-61472d9b94d8\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2073. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\d3e63b9a-a865-4b0e-8400-891923e520af\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2074. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\d52bfeb8-b3c9-4cbf-b5a7-7ccab666143d\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2075. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\f184a63b-362f-4564-a883-1e98b3a1704b\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2076. [2013/07/24 20:54:48 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Marion\AppData\Roaming\PCDr\Update\Rules\f4c37d52-012a-4c52-a9aa-59e50aa0005b\PCDoctor_6219.34_windows_appupdaterrules_dell\AddCertificate.exe
  2077. [2013/03/07 19:22:20 | 002,959,376 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\AppData\Roaming\Research In Motion\BlackBerry Desktop\Updates\33484803-750F-4154-A0A3-C0474F3BE1BE\dotnetfx35setup.exe
  2078. [2013/10/17 00:10:38 | 116,383,248 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Research In Motion\BlackBerry Desktop\Updates\33484803-750F-4154-A0A3-C0474F3BE1BE\Extractor.exe
  2079. [2013/03/07 19:22:20 | 000,128,472 | ---- | M] (Macrovision Corporation) -- C:\Users\Marion\AppData\Roaming\Research In Motion\BlackBerry Desktop\Updates\33484803-750F-4154-A0A3-C0474F3BE1BE\Helper.exe
  2080. [2013/03/07 19:22:20 | 004,216,840 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\AppData\Roaming\Research In Motion\BlackBerry Desktop\Updates\33484803-750F-4154-A0A3-C0474F3BE1BE\vcredist_x86.exe
  2081. [2013/03/07 19:22:20 | 000,424,976 | ---- | M] (Research In Motion Limited) -- C:\Users\Marion\AppData\Roaming\Research In Motion\BlackBerry Desktop\Updates\33484803-750F-4154-A0A3-C0474F3BE1BE\InstallerUtils\InstallerUtils.exe
  2082. [2013/03/07 19:22:20 | 000,083,472 | ---- | M] (Research In Motion Limited) -- C:\Users\Marion\AppData\Roaming\Research In Motion\BlackBerry Desktop\Updates\33484803-750F-4154-A0A3-C0474F3BE1BE\InstallerUtils\Setup.exe
  2083. [2013/05/10 13:08:04 | 000,061,328 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AdminDelegator (1).exe
  2084. [2013/05/10 13:08:04 | 000,061,328 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AdminDelegator (2).exe
  2085. [2013/05/10 13:08:04 | 000,061,328 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AdminDelegator.exe
  2086. [2013/05/10 13:08:04 | 000,088,464 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller (1).exe
  2087. [2013/05/10 13:08:04 | 000,088,464 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller (2).exe
  2088. [2013/05/10 13:08:04 | 000,088,464 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller.exe
  2089. [2013/05/10 13:08:05 | 000,077,704 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate (1).exe
  2090. [2013/05/10 13:08:05 | 000,077,704 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate (2).exe
  2091. [2013/05/10 13:08:05 | 000,077,704 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate.exe
  2092. [2013/05/10 13:08:06 | 000,844,168 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR (1).exe
  2093. [2013/05/10 13:08:06 | 000,844,168 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR (2).exe
  2094. [2013/05/10 13:08:06 | 000,844,168 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR.exe
  2095. [2013/04/23 12:48:12 | 001,561,968 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Kies.exe
  2096. [2013/04/23 12:48:14 | 000,559,984 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesAgent.exe
  2097. [2013/04/23 12:48:16 | 000,277,872 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesDriverInstaller.exe
  2098. [2013/04/23 12:48:16 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesTrayAgent.exe
  2099. [2013/04/23 12:36:02 | 000,173,568 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\ConnectionManager.exe
  2100. [2013/04/23 12:38:58 | 000,344,576 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\DeviceDataService.exe
  2101. [2013/04/23 12:36:54 | 000,692,224 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\DeviceManager.exe
  2102. [2013/04/23 12:48:18 | 000,067,952 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\Kies_Tutorial.exe
  2103. [2013/04/23 12:48:24 | 000,065,904 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\RegisterCOM.exe
  2104. [2013/05/10 13:08:04 | 000,061,328 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AdminDelegator.exe
  2105. [2013/05/10 13:08:04 | 000,088,464 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentInstaller.exe
  2106. [2013/05/10 13:08:05 | 000,077,704 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentUpdate.exe
  2107. [2013/05/10 13:08:06 | 000,844,168 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\KiesPDLR.exe
  2108. [2013/04/23 03:48:22 | 003,768,712 | ---- | M] (Freeware) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\MediaModules\MyFreeCodecPack.exe
  2109. [2013/04/23 12:48:22 | 000,602,992 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Updater\Kies.Update.exe
  2110. [2013/04/03 07:16:34 | 015,359,912 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
  2111. [2013/11/06 01:55:38 | 001,564,528 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Kies.exe
  2112. [2013/11/06 01:55:40 | 000,559,984 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAgent.exe
  2113. [2013/11/06 01:55:42 | 000,277,872 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesDriverInstaller.exe
  2114. [2013/11/06 01:55:40 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesTrayAgent.exe
  2115. [2013/11/06 01:42:10 | 000,173,568 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\ConnectionManager.exe
  2116. [2013/11/06 01:44:58 | 000,351,232 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceDataService.exe
  2117. [2013/11/06 01:43:48 | 000,693,760 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceManager.exe
  2118. [2013/11/06 01:55:44 | 000,067,952 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\Kies_Tutorial.exe
  2119. [2013/11/06 01:55:50 | 000,065,904 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\RegisterCOM.exe
  2120. [2013/10/30 03:12:52 | 000,061,840 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AdminDelegator.exe
  2121. [2013/10/30 03:12:52 | 000,088,464 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentInstaller.exe
  2122. [2013/10/30 03:12:56 | 000,078,216 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentUpdate.exe
  2123. [2013/11/06 01:55:46 | 000,845,168 | ---- | M] (Samsung) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\KiesPDLR.exe
  2124. [2013/10/30 03:12:54 | 000,017,408 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\Uncompress.exe
  2125. [2013/11/06 01:55:48 | 003,835,088 | ---- | M] (Freeware) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\MediaModules\MyFreeCodecPack.exe
  2126. [2013/10/30 03:06:58 | 000,061,440 | ---- | M] ((주)마크애니) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\MaAgent.exe
  2127. [2013/10/30 03:06:58 | 000,032,768 | ---- | M] (MarkAny Co, Ltd) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\MaCSMgr.exe
  2128. [2013/10/30 03:06:58 | 000,065,536 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\MAWebControl.exe
  2129. [2013/10/30 03:06:58 | 000,401,056 | ---- | M] (Marktek Inc.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\MPXBox.exe
  2130. [2013/10/30 03:06:54 | 000,020,480 | ---- | M] ( ) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe
  2131. [2013/10/30 03:06:54 | 000,057,344 | ---- | M] ((주)마크애니) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe
  2132. [2013/10/30 03:06:54 | 000,126,976 | ---- | M] ((주)마크애니) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Program Files\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe
  2133. [2013/10/30 03:09:20 | 025,591,752 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\StoryAlbumViewer\StoryAlbumViewer_setup.exe
  2134. [2013/11/06 01:55:48 | 000,623,984 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Updater\Kies.Update.exe
  2135. [2013/10/30 04:45:28 | 015,369,584 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
  2136. [2013/04/23 12:48:22 | 000,602,992 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update (1).exe
  2137. [2013/04/23 12:48:22 | 000,602,992 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update (2).exe
  2138. [2013/04/23 12:48:22 | 000,602,992 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
  2139. [2013/04/23 12:48:22 | 000,602,992 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update (1).exe
  2140. [2013/04/23 12:48:22 | 000,602,992 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update (2).exe
  2141. [2013/11/06 01:55:48 | 000,623,984 | ---- | M] (ml) -- C:\Users\Marion\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
  2142. [2005/06/06 09:29:14 | 000,110,592 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\U3\03715B60F0A018D9\cleanup.exe
  2143. [2006/03/30 10:34:56 | 002,592,768 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\U3\03715B60F0A018D9\LaunchPad.exe
  2144. [2013/11/18 23:46:18 | 000,274,944 | ---- | M] (SingularLabs) -- C:\Users\Marion\Desktop\JavaRa.exe
  2145. [2013/11/28 18:28:59 | 000,387,776 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\Marion\Desktop\PsExec.exe
  2146. [2013/11/29 12:20:12 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Users\Marion\Desktop\swreg.exe
  2147. [2013/11/20 19:29:08 | 000,165,376 | ---- | M] () -- C:\Users\Marion\Desktop\SystemLook_x64.exe
  2148. [2013/11/25 19:19:01 | 001,958,474 | ---- | M] (Farbar) -- C:\Users\Marion\Desktop\Maintainence\FRST64 (1).exe
  2149. [2013/11/18 23:46:18 | 000,274,944 | ---- | M] (SingularLabs) -- C:\Users\Marion\Desktop\Maintainence\JavaRa.exe
  2150. [2009/12/22 04:16:20 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Marion\Desktop\Maintainence\Adobe Reader 9 Installer\Setup (1).exe
  2151. [2009/12/22 04:16:20 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Marion\Desktop\Maintainence\Adobe Reader 9 Installer\Setup (2).exe
  2152. [2009/12/22 04:16:20 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Marion\Desktop\Maintainence\Adobe Reader 9 Installer\Setup.exe
  2153. [2013/07/03 11:47:30 | 003,161,648 | ---- | M] (VS Revo Group) -- C:\Users\Marion\Desktop\Maintainence\Revo Uninstaller\Revouninstaller.exe
  2154. [2013/11/20 18:49:36 | 000,087,550 | ---- | M] (VS Revo Group Ltd.) -- C:\Users\Marion\Desktop\Maintainence\Revo Uninstaller\uninst.exe
  2155. [2013/07/03 11:47:30 | 003,161,648 | ---- | M] (VS Revo Group) -- C:\Users\Marion\Desktop\Revo Uninstaller\Revouninstaller.exe
  2156. [2013/04/06 20:05:16 | 004,137,976 | ---- | M] () -- C:\Users\Marion\Documents\CW1356A1.exe
  2157. [1 C:\Users\Marion\Documents\*.tmp files -> C:\Users\Marion\Documents\*.tmp -> ]
  2158. [2013/10/18 19:43:19 | 154,092,488 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\Downloads\13-1-legacy_vista_win7_win8_64_dd_ccc.exe
  2159. [2012/03/17 17:36:42 | 155,182,440 | ---- | M] (NVIDIA Corporation) -- C:\Users\Marion\Downloads\285.62-desktop-win7-winvista-64bit-english-whql.exe
  2160. [2012/04/25 13:29:08 | 122,601,808 | ---- | M] () -- C:\Users\Marion\Downloads\610_b038_multilanguage (1).exe
  2161. [2012/04/25 13:39:15 | 122,601,808 | ---- | M] () -- C:\Users\Marion\Downloads\610_b038_multilanguage (2).exe
  2162. [2012/03/17 17:45:08 | 122,601,808 | ---- | M] () -- C:\Users\Marion\Downloads\610_b038_multilanguage.exe
  2163. [2013/11/10 09:40:12 | 021,548,944 | ---- | M] (Innovative Solutions ) -- C:\Users\Marion\Downloads\Advanced_Uninstaller11.exe
  2164. [2013/11/03 01:33:17 | 000,819,208 | ---- | M] (Google Inc.) -- C:\Users\Marion\Downloads\ChromeSetup.exe
  2165. [2013/10/18 18:24:25 | 001,998,248 | ---- | M] (Driver Whiz) -- C:\Users\Marion\Downloads\Driverwhiz.exe
  2166. [2013/11/23 09:46:13 | 035,334,016 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\Downloads\Dropbox 2.4.7 (1).exe
  2167. [2013/11/23 09:41:22 | 035,334,016 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\Downloads\Dropbox 2.4.7.exe
  2168. [2013/11/20 19:37:42 | 001,957,964 | ---- | M] (Farbar) -- C:\Users\Marion\Downloads\FRST64.exe
  2169. [2013/11/12 00:14:39 | 023,960,472 | ---- | M] (NVIDIA Corporation) -- C:\Users\Marion\Downloads\GeForce_Experience_v1.7.0.0.exe
  2170. [2013/11/15 16:03:37 | 010,264,904 | ---- | M] (SurfRight B.V.) -- C:\Users\Marion\Downloads\HitmanPro_x64.exe
  2171. [2013/11/29 11:51:43 | 100,400,976 | ---- | M] (Apple Inc.) -- C:\Users\Marion\Downloads\iTunes64Setup (1).exe
  2172. [2013/10/12 12:15:32 | 097,206,096 | ---- | M] (Apple Inc.) -- C:\Users\Marion\Downloads\iTunes64Setup.exe
  2173. [2013/11/17 14:36:48 | 029,040,552 | ---- | M] (Oracle Corporation) -- C:\Users\Marion\Downloads\jre-7u45-windows-i586 (1).exe
  2174. [2013/11/17 13:07:38 | 029,040,552 | ---- | M] (Oracle Corporation) -- C:\Users\Marion\Downloads\jre-7u45-windows-i586.exe
  2175. [2013/11/17 16:12:32 | 001,850,306 | ---- | M] (Dominik Reichl ) -- C:\Users\Marion\Downloads\KeePass-1.26-Setup (1).exe
  2176. [2013/11/17 16:12:02 | 001,850,306 | ---- | M] (Dominik Reichl ) -- C:\Users\Marion\Downloads\KeePass-1.26-Setup.exe
  2177. [2013/11/14 14:07:35 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Marion\Downloads\mbam-setup-1.75.0.1300.exe
  2178. [2013/11/19 00:21:08 | 000,347,304 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.31308247663186633.1.1.Run.exe
  2179. [2013/11/18 23:55:26 | 000,347,304 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.63308246104186734.1.1.Run.exe
  2180. [2013/11/29 07:56:20 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\Marion\Downloads\mozysetup (1).exe
  2181. [2013/11/29 08:03:03 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\Marion\Downloads\mozysetup (2).exe
  2182. [2013/11/29 07:07:05 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\Marion\Downloads\mozysetup.exe
  2183. [2013/11/21 00:31:53 | 000,578,640 | ---- | M] (McAfee, Inc.) -- C:\Users\Marion\Downloads\MVTInstaller (1).exe
  2184. [2013/11/21 00:30:22 | 000,578,640 | ---- | M] (McAfee, Inc.) -- C:\Users\Marion\Downloads\MVTInstaller.exe
  2185. [2013/11/17 16:31:06 | 029,515,104 | ---- | M] (Symantec Corporation) -- C:\Users\Marion\Downloads\NortonIdentitySafe-EN-v1.exe
  2186. [2013/11/21 11:40:02 | 000,482,896 | ---- | M] (www.patchmypc.net) -- C:\Users\Marion\Downloads\PatchMyPC (1).exe
  2187. [2013/11/17 14:04:03 | 000,482,896 | ---- | M] (www.patchmypc.net) -- C:\Users\Marion\Downloads\PatchMyPC.exe
  2188. [2013/11/11 11:53:21 | 000,236,648 | ---- | M] (Big Fish Games) -- C:\Users\Marion\Downloads\peggle_s1_l1_gF1465T1L1_d2194852066.exe
  2189. [2013/10/31 22:57:36 | 001,520,376 | ---- | M] (Uniblue Systems Limited ) -- C:\Users\Marion\Downloads\powersuite.exe
  2190. [2013/10/21 12:33:07 | 002,712,592 | ---- | M] () -- C:\Users\Marion\Downloads\R199967.exe
  2191. [2013/10/19 09:46:06 | 000,571,728 | ---- | M] () -- C:\Users\Marion\Downloads\R205900.exe
  2192. [2013/10/19 09:46:40 | 002,445,208 | ---- | M] () -- C:\Users\Marion\Downloads\R213714.EXE
  2193. [2013/10/19 09:45:18 | 110,976,048 | ---- | M] () -- C:\Users\Marion\Downloads\R227524.exe
  2194. [2013/11/05 07:43:39 | 000,272,664 | ---- | M] (Trusteer Ltd.) -- C:\Users\Marion\Downloads\RapportSetup.exe
  2195. [2013/11/27 16:54:30 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (1).exe
  2196. [2013/11/27 17:03:15 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (2).exe
  2197. [2013/11/27 17:06:08 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (3).exe
  2198. [2013/11/28 18:24:42 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (4).exe
  2199. [2013/11/28 18:24:53 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (5).exe
  2200. [2013/11/27 16:51:14 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair.exe
  2201. [2013/11/20 18:49:07 | 002,623,656 | ---- | M] (VS Revo Group Ltd.) -- C:\Users\Marion\Downloads\revosetup.exe
  2202. [2013/11/20 18:50:07 | 010,031,224 | ---- | M] (VS Revo Group ) -- C:\Users\Marion\Downloads\RevoUninProSetup.exe
  2203. [2013/10/12 09:37:44 | 000,272,664 | ---- | M] (Trusteer Ltd.) -- C:\Users\Marion\Downloads\RpprtSetup.exe
  2204. [2013/11/28 18:32:54 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Users\Marion\Downloads\swreg (1).exe
  2205. [2013/11/29 12:15:19 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Users\Marion\Downloads\swreg (2).exe
  2206. [2013/11/29 12:50:08 | 000,165,376 | ---- | M] () -- C:\Users\Marion\Downloads\SystemLook_x64 (1).exe
  2207. [2013/11/17 12:14:31 | 003,927,696 | ---- | M] () -- C:\Users\Marion\Downloads\tweaking.com_registry_backup_setup.exe
  2208. [2013/10/23 11:34:56 | 000,236,648 | ---- | M] (Big Fish Games) -- C:\Users\Marion\Downloads\viking-saga_s1_l1_gF7645T1L1_d2182559580.exe
  2209. [2013/11/11 18:38:39 | 000,661,184 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\Marion\Downloads\Autoruns\autoruns.exe
  2210. [2013/11/11 18:38:39 | 000,579,264 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\Marion\Downloads\Autoruns\autorunsc.exe
  2211. [2013/10/18 20:00:20 | 081,891,861 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\Downloads\Driver Whiz\Driver Whiz\64bit_Vista_Win7_Win8_R271.exe
  2212. [2013/11/05 14:26:56 | 107,949,327 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Marion\Downloads\Driver Whiz\Driver Whiz\64bit_Win7_Win8_Win81_R272.exe
  2213. [2013/10/18 18:57:49 | 026,129,808 | ---- | M] () -- C:\Users\Marion\Downloads\Driver Whiz\Driver Whiz\md64-win-mp260-1_02-ea24.exe
  2214.  
  2215. [color=#A23BEC]< %USERPROFILE%\Documents\*.* >[/color]
  2216. [2013/01/28 16:56:43 | 000,013,046 | ---- | M] () -- C:\Users\Marion\Documents\154 C Chicken Soup.docx
  2217. [2011/10/28 14:27:06 | 000,014,859 | ---- | M] () -- C:\Users\Marion\Documents\Apple Crumble Recipe.docx
  2218. [2010/10/01 20:07:21 | 000,134,163 | ---- | M] () -- C:\Users\Marion\Documents\Ashton letters.docx
  2219. [2010/10/05 16:14:09 | 000,108,856 | ---- | M] () -- C:\Users\Marion\Documents\Ashton name.docx
  2220. [2012/02/06 18:27:53 | 000,673,654 | ---- | M] () -- C:\Users\Marion\Documents\ashton questions.docx
  2221. [2013/06/28 10:51:28 | 000,673,656 | ---- | M] () -- C:\Users\Marion\Documents\ashton questions.docx.518b.part
  2222. [2010/10/02 12:12:40 | 000,012,932 | ---- | M] () -- C:\Users\Marion\Documents\Ashton.docx
  2223. [2013/06/28 13:56:01 | 000,050,303 | ---- | M] () -- C:\Users\Marion\Documents\bell (2).docx
  2224. [2013/06/28 10:51:29 | 000,050,304 | ---- | M] () -- C:\Users\Marion\Documents\bell.docx.52be.part
  2225. [2013/12/02 10:42:34 | 000,012,067 | ---- | M] () -- C:\Users\Marion\Documents\Capture.PNG
  2226. [2013/06/28 13:56:01 | 000,013,500 | ---- | M] () -- C:\Users\Marion\Documents\cinema tickets (2).docx
  2227. [2013/06/28 10:51:29 | 000,013,504 | ---- | M] () -- C:\Users\Marion\Documents\cinema tickets.docx.5456.part
  2228. [2013/04/06 20:08:44 | 004,202,393 | ---- | M] () -- C:\Users\Marion\Documents\CL1356A1.bin
  2229. [2013/04/06 20:05:16 | 004,137,976 | ---- | M] () -- C:\Users\Marion\Documents\CW1356A1.exe
  2230. [2013/11/17 20:22:50 | 000,003,228 | ---- | M] () -- C:\Users\Marion\Documents\Database.kdb
  2231. [2012/06/19 17:13:48 | 000,658,201 | ---- | M] () -- C:\Users\Marion\Documents\Dear Ashton.docx
  2232. [2012/07/12 08:29:59 | 000,000,402 | ---- | M] () -- C:\Users\Marion\Documents\desktop (1).ini
  2233. [2013/06/28 13:56:02 | 000,000,402 | ---- | M] () -- C:\Users\Marion\Documents\desktop (2).ini
  2234. [2013/09/14 10:15:55 | 000,000,402 | -HS- | M] () -- C:\Users\Marion\Documents\desktop.ini
  2235. [2013/06/28 10:51:32 | 000,000,408 | ---- | M] () -- C:\Users\Marion\Documents\desktop.ini.01b6.part
  2236. [2013/08/09 17:10:51 | 000,055,444 | ---- | M] () -- C:\Users\Marion\Documents\Doc2.docx
  2237. [2012/02/05 11:42:40 | 000,031,118 | ---- | M] () -- C:\Users\Marion\Documents\DOG POO.docx
  2238. [2013/06/28 13:56:02 | 000,000,756 | ---- | M] () -- C:\Users\Marion\Documents\downloads (2).txt
  2239. [2013/06/28 10:51:47 | 000,000,760 | ---- | M] () -- C:\Users\Marion\Documents\downloads.txt.39f9.part
  2240. [2013/06/28 10:51:47 | 000,096,984 | ---- | M] () -- C:\Users\Marion\Documents\fatface.docx.3bc6.part
  2241. [2013/04/27 15:57:35 | 000,023,229 | ---- | M] () -- C:\Users\Marion\Documents\Global Sleepover Letter 1 April 2013v2.docx
  2242. [2011/09/09 16:54:59 | 000,043,258 | ---- | M] () -- C:\Users\Marion\Documents\Great_Fire.docx
  2243. [2011/05/18 20:19:44 | 000,026,027 | ---- | M] () -- C:\Users\Marion\Documents\HAPPY.docx
  2244. [2012/01/02 13:27:22 | 000,010,972 | ---- | M] () -- C:\Users\Marion\Documents\Institute of Health and Wellbeing.docx
  2245. [2013/06/28 13:56:03 | 000,000,552 | ---- | M] () -- C:\Users\Marion\Documents\iTunes (2).txt
  2246. [2013/06/28 13:56:02 | 000,004,164 | ---- | M] () -- C:\Users\Marion\Documents\iTunes Diagnostics (2).rtf
  2247. [2013/06/28 13:56:03 | 000,042,354 | ---- | M] () -- C:\Users\Marion\Documents\iTunes Diagnostics (2).spx
  2248. [2013/06/28 10:51:47 | 000,004,168 | ---- | M] () -- C:\Users\Marion\Documents\iTunes Diagnostics.rtf.3d8f.part
  2249. [2013/06/28 10:51:47 | 000,042,360 | ---- | M] () -- C:\Users\Marion\Documents\iTunes Diagnostics.spx.3f27.part
  2250. [2013/06/28 10:51:47 | 000,000,560 | ---- | M] () -- C:\Users\Marion\Documents\iTunes.txt.40f0.part
  2251. [2013/03/10 07:45:37 | 000,017,741 | ---- | M] () -- C:\Users\Marion\Documents\Kidderminster-Gym-Timetable.pdf
  2252. [2011/05/19 09:13:17 | 000,011,685 | ---- | M] () -- C:\Users\Marion\Documents\LEAH.docx
  2253. [2012/07/06 00:19:37 | 000,105,703 | ---- | M] () -- C:\Users\Marion\Documents\Nick and Lou 2.jpg
  2254. [2013/06/28 13:56:04 | 000,011,113 | ---- | M] () -- C:\Users\Marion\Documents\overpayment letter (2).docx
  2255. [2013/06/28 10:51:47 | 000,011,120 | ---- | M] () -- C:\Users\Marion\Documents\overpayment letter.docx.4223.part
  2256. [2010/12/27 19:01:43 | 000,015,442 | ---- | M] () -- C:\Users\Marion\Documents\Pension complaint letter.docx
  2257. [2013/06/28 13:56:04 | 000,011,061 | ---- | M] () -- C:\Users\Marion\Documents\pension proposal (2).docx
  2258. [2013/06/28 10:51:47 | 000,011,064 | ---- | M] () -- C:\Users\Marion\Documents\pension proposal.docx.4387.part
  2259. [2013/06/28 13:56:04 | 000,026,964 | ---- | M] () -- C:\Users\Marion\Documents\quote_108617 (2).pdf
  2260. [2013/06/28 10:51:48 | 000,026,968 | ---- | M] () -- C:\Users\Marion\Documents\quote_108617.pdf.44eb.part
  2261. [2011/10/28 14:22:00 | 000,015,339 | ---- | M] () -- C:\Users\Marion\Documents\Recipes.docx
  2262. [2013/06/28 10:51:48 | 000,166,872 | ---- | M] () -- C:\Users\Marion\Documents\request.pdf.46b8.part
  2263. [2011/10/28 10:42:59 | 000,012,156 | ---- | M] () -- C:\Users\Marion\Documents\Rock Cakes Recipe.docx
  2264. [2010/10/05 12:46:40 | 000,167,165 | ---- | M] () -- C:\Users\Marion\Documents\satpin.docx
  2265. [2011/10/27 10:59:08 | 000,035,961 | ---- | M] () -- C:\Users\Marion\Documents\The Victoria Sponge.docx
  2266. [2012/02/05 12:12:09 | 000,010,746 | ---- | M] () -- C:\Users\Marion\Documents\WHERE.docx
  2267. [2010/11/29 12:46:02 | 000,073,176 | ---- | M] () -- C:\Users\Marion\Documents\WOODY.docx
  2268. [2010/10/04 09:25:51 | 000,000,162 | ---- | M] () -- C:\Users\Marion\Documents\~$satpin.docx
  2269. [1 C:\Users\Marion\Documents\*.tmp files -> C:\Users\Marion\Documents\*.tmp -> ]
  2270.  
  2271. [color=#A23BEC]< %USERPROFILE%\Downloads\*.* >[/color]
  2272. [2009/02/15 23:45:17 | 006,190,278 | ---- | M] () -- C:\Users\Marion\Downloads\05 You're The First Time I've Though.m4a
  2273. [2013/10/18 19:43:19 | 154,092,488 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Marion\Downloads\13-1-legacy_vista_win7_win8_64_dd_ccc.exe
  2274. [2013/10/18 19:42:42 | 415,761,013 | ---- | M] () -- C:\Users\Marion\Downloads\13.151-130819a-161838C-EDG_Direct.zip
  2275. [2013/11/02 10:20:10 | 000,124,678 | ---- | M] () -- C:\Users\Marion\Downloads\1729042N (1).pdf
  2276. [2013/11/01 12:45:33 | 000,124,678 | ---- | M] () -- C:\Users\Marion\Downloads\1729042N.pdf
  2277. [2013/11/06 23:14:31 | 003,222,081 | ---- | M] () -- C:\Users\Marion\Downloads\1895973 doc01616820131030171823 (1).pdf
  2278. [2013/11/06 23:13:43 | 003,222,081 | ---- | M] () -- C:\Users\Marion\Downloads\1895973 doc01616820131030171823.pdf
  2279. [2013/01/07 22:04:53 | 000,212,180 | ---- | M] () -- C:\Users\Marion\Downloads\250099_10151102318438859_2018073678_n.jpg
  2280. [2012/03/17 17:36:42 | 155,182,440 | ---- | M] (NVIDIA Corporation) -- C:\Users\Marion\Downloads\285.62-desktop-win7-winvista-64bit-english-whql.exe
  2281. [2012/04/25 13:29:08 | 122,601,808 | ---- | M] () -- C:\Users\Marion\Downloads\610_b038_multilanguage (1).exe
  2282. [2012/04/25 13:39:15 | 122,601,808 | ---- | M] () -- C:\Users\Marion\Downloads\610_b038_multilanguage (2).exe
  2283. [2012/03/17 17:45:08 | 122,601,808 | ---- | M] () -- C:\Users\Marion\Downloads\610_b038_multilanguage.exe
  2284. [2013/11/20 19:39:18 | 000,029,651 | ---- | M] () -- C:\Users\Marion\Downloads\Addition.txt
  2285. [2013/11/10 09:40:12 | 021,548,944 | ---- | M] (Innovative Solutions ) -- C:\Users\Marion\Downloads\Advanced_Uninstaller11.exe
  2286. [2013/10/18 19:37:57 | 217,681,405 | ---- | M] () -- C:\Users\Marion\Downloads\AMD_Catalyst_13.4_Vista_W7_W8_WHQL.zip
  2287. [2013/11/11 18:29:11 | 000,550,371 | ---- | M] () -- C:\Users\Marion\Downloads\Autoruns.zip
  2288. [2013/10/19 09:44:22 | 002,911,266 | ---- | M] () -- C:\Users\Marion\Downloads\BH20N-C106 (1).zip
  2289. [2013/11/03 01:33:17 | 000,819,208 | ---- | M] (Google Inc.) -- C:\Users\Marion\Downloads\ChromeSetup.exe
  2290. [2013/10/21 10:58:28 | 000,027,305 | ---- | M] () -- C:\Users\Marion\Downloads\DellPerformanceDiagnostic (1).diagcab
  2291. [2013/10/21 10:46:24 | 000,027,305 | ---- | M] () -- C:\Users\Marion\Downloads\DellPerformanceDiagnostic.diagcab
  2292. [2013/10/13 11:43:33 | 000,010,591 | ---- | M] () -- C:\Users\Marion\Downloads\dellsystemdetect (1).application
  2293. [2012/07/12 08:29:59 | 000,000,282 | ---- | M] () -- C:\Users\Marion\Downloads\desktop (1).ini
  2294. [2012/07/12 08:29:59 | 000,000,282 | ---- | M] () -- C:\Users\Marion\Downloads\desktop (2).ini
  2295. [2013/11/17 20:27:16 | 000,000,282 | -HS- | M] () -- C:\Users\Marion\Downloads\desktop.ini
  2296. [2013/10/18 18:24:25 | 001,998,248 | ---- | M] (Driver Whiz) -- C:\Users\Marion\Downloads\Driverwhiz.exe
  2297. [2013/11/23 09:46:13 | 035,334,016 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\Downloads\Dropbox 2.4.7 (1).exe
  2298. [2013/11/23 09:41:22 | 035,334,016 | ---- | M] (Dropbox, Inc.) -- C:\Users\Marion\Downloads\Dropbox 2.4.7.exe
  2299. [2013/11/17 13:00:52 | 000,001,450 | ---- | M] () -- C:\Users\Marion\Downloads\fix.reg
  2300. [2013/11/17 14:58:50 | 000,000,060 | ---- | M] () -- C:\Users\Marion\Downloads\fixlist (1).txt
  2301. [2013/11/24 18:58:54 | 000,011,526 | ---- | M] () -- C:\Users\Marion\Downloads\fixlist (2).txt
  2302. [2013/11/25 00:18:58 | 000,011,526 | ---- | M] () -- C:\Users\Marion\Downloads\fixlist (3).txt
  2303. [2013/11/25 09:24:32 | 000,011,526 | ---- | M] () -- C:\Users\Marion\Downloads\fixlist (4).txt
  2304. [2013/11/20 19:39:18 | 000,082,760 | ---- | M] () -- C:\Users\Marion\Downloads\FRST.txt
  2305. [2013/11/20 19:37:42 | 001,957,964 | ---- | M] (Farbar) -- C:\Users\Marion\Downloads\FRST64.exe
  2306. [2013/11/12 00:14:39 | 023,960,472 | ---- | M] (NVIDIA Corporation) -- C:\Users\Marion\Downloads\GeForce_Experience_v1.7.0.0.exe
  2307. [2013/01/13 14:15:45 | 000,001,837 | ---- | M] () -- C:\Users\Marion\Downloads\graph.pdf
  2308. [2013/11/15 16:30:01 | 000,004,626 | ---- | M] () -- C:\Users\Marion\Downloads\HitmanPro_20131115_1629.log
  2309. [2013/11/15 16:03:37 | 010,264,904 | ---- | M] (SurfRight B.V.) -- C:\Users\Marion\Downloads\HitmanPro_x64.exe
  2310. [2013/11/29 11:51:43 | 100,400,976 | ---- | M] (Apple Inc.) -- C:\Users\Marion\Downloads\iTunes64Setup (1).exe
  2311. [2013/10/12 12:15:32 | 097,206,096 | ---- | M] (Apple Inc.) -- C:\Users\Marion\Downloads\iTunes64Setup.exe
  2312. [2013/11/18 23:45:44 | 000,157,265 | ---- | M] () -- C:\Users\Marion\Downloads\JavaRa-2.3.zip
  2313. [2013/11/17 13:24:17 | 029,040,552 | ---- | M] (Oracle Corporation) -- C:\Users\Marion\Downloads\jre-7u45-windows-i586
  2314. [2013/11/17 14:36:48 | 029,040,552 | ---- | M] (Oracle Corporation) -- C:\Users\Marion\Downloads\jre-7u45-windows-i586 (1).exe
  2315. [2013/11/17 13:07:38 | 029,040,552 | ---- | M] (Oracle Corporation) -- C:\Users\Marion\Downloads\jre-7u45-windows-i586.exe
  2316. [2013/11/17 16:12:32 | 001,850,306 | ---- | M] (Dominik Reichl ) -- C:\Users\Marion\Downloads\KeePass-1.26-Setup (1).exe
  2317. [2013/11/17 16:12:02 | 001,850,306 | ---- | M] (Dominik Reichl ) -- C:\Users\Marion\Downloads\KeePass-1.26-Setup.exe
  2318. [2013/11/18 23:44:44 | 000,451,928 | ---- | M] () -- C:\Users\Marion\Downloads\linecount (1).txt
  2319. [2013/11/18 00:19:22 | 000,451,928 | ---- | M] () -- C:\Users\Marion\Downloads\linecount.txt
  2320. [2013/11/19 20:01:31 | 000,000,393 | ---- | M] () -- C:\Users\Marion\Downloads\live-calls-by-topic.csv
  2321. [2012/07/10 14:49:39 | 000,005,323 | ---- | M] () -- C:\Users\Marion\Downloads\lunapic_134193091269708_6.jpg
  2322. [2013/04/14 12:16:27 | 000,031,744 | ---- | M] () -- C:\Users\Marion\Downloads\Marion April 2013.xls
  2323. [2013/11/14 14:07:35 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Marion\Downloads\mbam-setup-1.75.0.1300.exe
  2324. [2013/04/11 21:22:01 | 000,345,515 | ---- | M] () -- C:\Users\Marion\Downloads\ME FAT (1).htm
  2325. [2013/11/19 00:21:08 | 000,347,304 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.31308247663186633.1.1.Run.exe
  2326. [2013/11/18 23:55:26 | 000,347,304 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.63308246104186734.1.1.Run.exe
  2327. [2012/05/20 17:53:24 | 000,000,363 | ---- | M] () -- C:\Users\Marion\Downloads\MOV079.MOI
  2328. [2013/11/29 06:40:28 | 002,394,624 | ---- | M] () -- C:\Users\Marion\Downloads\MozyRestoreManager.msi
  2329. [2013/11/29 07:56:20 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\Marion\Downloads\mozysetup (1).exe
  2330. [2013/11/29 08:03:03 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\Marion\Downloads\mozysetup (2).exe
  2331. [2013/11/29 07:07:05 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\Marion\Downloads\mozysetup.exe
  2332. [2013/10/18 09:00:45 | 001,445,133 | ---- | M] () -- C:\Users\Marion\Downloads\MS STEPIEN.PDF
  2333. [2013/11/11 12:17:32 | 000,987,961 | ---- | M] () -- C:\Users\Marion\Downloads\MS STEPIEN.zip
  2334. [2013/11/21 00:31:53 | 000,578,640 | ---- | M] (McAfee, Inc.) -- C:\Users\Marion\Downloads\MVTInstaller (1).exe
  2335. [2013/11/21 00:30:22 | 000,578,640 | ---- | M] (McAfee, Inc.) -- C:\Users\Marion\Downloads\MVTInstaller.exe
  2336. [2013/11/17 16:31:06 | 029,515,104 | ---- | M] (Symantec Corporation) -- C:\Users\Marion\Downloads\NortonIdentitySafe-EN-v1.exe
  2337. [2013/12/05 20:19:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marion\Downloads\OTL.scr
  2338. [2013/11/14 14:00:47 | 000,001,816 | ---- | M] () -- C:\Users\Marion\Downloads\pastebin_backup_20131114.zip
  2339. [2013/11/21 11:40:02 | 000,482,896 | ---- | M] (www.patchmypc.net) -- C:\Users\Marion\Downloads\PatchMyPC (1).exe
  2340. [2013/11/17 14:04:03 | 000,482,896 | ---- | M] (www.patchmypc.net) -- C:\Users\Marion\Downloads\PatchMyPC.exe
  2341. [2013/11/11 11:53:21 | 000,236,648 | ---- | M] (Big Fish Games) -- C:\Users\Marion\Downloads\peggle_s1_l1_gF1465T1L1_d2194852066.exe
  2342. [2013/02/17 14:53:16 | 000,029,314 | ---- | M] () -- C:\Users\Marion\Downloads\photo 2 (1).JPG
  2343. [2013/01/16 16:51:22 | 000,034,367 | ---- | M] () -- C:\Users\Marion\Downloads\photo 2.JPG
  2344. [2013/10/31 22:57:36 | 001,520,376 | ---- | M] (Uniblue Systems Limited ) -- C:\Users\Marion\Downloads\powersuite.exe
  2345. [2013/11/28 18:27:37 | 001,662,360 | ---- | M] () -- C:\Users\Marion\Downloads\PSTools.zip
  2346. [2013/10/21 12:33:07 | 002,712,592 | ---- | M] () -- C:\Users\Marion\Downloads\R199967.exe
  2347. [2013/10/19 09:46:06 | 000,571,728 | ---- | M] () -- C:\Users\Marion\Downloads\R205900.exe
  2348. [2013/10/19 09:46:40 | 002,445,208 | ---- | M] () -- C:\Users\Marion\Downloads\R213714.EXE
  2349. [2013/10/19 09:45:18 | 110,976,048 | ---- | M] () -- C:\Users\Marion\Downloads\R227524.exe
  2350. [2013/11/05 07:43:39 | 000,272,664 | ---- | M] (Trusteer Ltd.) -- C:\Users\Marion\Downloads\RapportSetup.exe
  2351. [2013/11/27 16:54:30 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (1).exe
  2352. [2013/11/27 17:03:15 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (2).exe
  2353. [2013/11/27 17:06:08 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (3).exe
  2354. [2013/11/28 18:24:42 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (4).exe
  2355. [2013/11/28 18:24:53 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair (5).exe
  2356. [2013/11/27 16:51:14 | 000,767,448 | ---- | M] (Reimage®) -- C:\Users\Marion\Downloads\ReimageRepair.exe
  2357. [2013/11/29 12:43:49 | 000,000,226 | ---- | M] () -- C:\Users\Marion\Downloads\reset (1).bat
  2358. [2013/11/29 06:41:37 | 000,000,170 | ---- | M] () -- C:\Users\Marion\Downloads\restore_2037934.mzd
  2359. [2013/11/20 18:49:07 | 002,623,656 | ---- | M] (VS Revo Group Ltd.) -- C:\Users\Marion\Downloads\revosetup.exe
  2360. [2013/11/20 18:50:07 | 010,031,224 | ---- | M] (VS Revo Group ) -- C:\Users\Marion\Downloads\RevoUninProSetup.exe
  2361. [2013/10/12 09:37:44 | 000,272,664 | ---- | M] (Trusteer Ltd.) -- C:\Users\Marion\Downloads\RpprtSetup.exe
  2362. [2013/11/22 16:53:53 | 002,825,011 | ---- | M] () -- C:\Users\Marion\Downloads\SmartSwitch_1.0.13041_14.zip
  2363. [2013/01/07 22:04:40 | 000,533,342 | ---- | M] () -- C:\Users\Marion\Downloads\Summer 2012 (1).htm
  2364. [2013/11/28 18:32:54 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Users\Marion\Downloads\swreg (1).exe
  2365. [2013/11/29 12:15:19 | 000,286,720 | ---- | M] (SteelWerX) -- C:\Users\Marion\Downloads\swreg (2).exe
  2366. [2013/11/25 00:45:09 | 001,828,864 | ---- | M] () -- C:\Users\Marion\Downloads\synctunes (1).msi
  2367. [2013/11/23 02:13:00 | 001,828,864 | ---- | M] () -- C:\Users\Marion\Downloads\synctunes.msi
  2368. [2013/11/20 19:33:01 | 000,047,676 | ---- | M] () -- C:\Users\Marion\Downloads\SystemLook.txt
  2369. [2013/11/29 12:50:08 | 000,165,376 | ---- | M] () -- C:\Users\Marion\Downloads\SystemLook_x64 (1).exe
  2370. [2013/11/17 12:14:31 | 003,927,696 | ---- | M] () -- C:\Users\Marion\Downloads\tweaking.com_registry_backup_setup.exe
  2371. [2013/10/23 11:34:56 | 000,236,648 | ---- | M] (Big Fish Games) -- C:\Users\Marion\Downloads\viking-saga_s1_l1_gF7645T1L1_d2182559580.exe
  2372. [2013/11/14 13:01:08 | 000,001,017 | ---- | M] () -- C:\Users\Marion\Downloads\XkFYh0gP.txt
  2373.  
  2374. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*.* >[/color]
  2375. [2011/11/29 10:40:00 | 000,196,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\common_functions.dll
  2376. [2013/11/21 00:13:25 | 000,005,120 | ---- | M] () -- C:\Users\Marion\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
  2377. [2010/08/14 08:55:32 | 000,000,094 | ---- | M] () -- C:\Users\Marion\AppData\Local\fusioncache.dat
  2378. [2010/04/19 03:22:53 | 000,068,328 | ---- | M] () -- C:\Users\Marion\AppData\Local\GDIPFONTCACHEV1.DAT
  2379. [2013/12/03 13:53:20 | 008,031,545 | -H-- | M] () -- C:\Users\Marion\AppData\Local\IconCache.db
  2380. [2011/10/25 17:54:06 | 000,940,544 | ---- | M] (Apache Software Foundation) -- C:\Users\Marion\AppData\Local\log4cxx.dll
  2381. [2013/06/24 06:44:53 | 000,007,623 | ---- | M] () -- C:\Users\Marion\AppData\Local\Resmon.ResmonCfg
  2382. [2008/02/05 12:28:20 | 000,000,051 | ---- | M] () -- C:\Users\Marion\AppData\Local\setup.txt
  2383.  
  2384. [color=#A23BEC]< %USERPROFILE%\AppData\Local\*. >[/color]
  2385. [2013/11/22 15:59:50 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Adobe
  2386. [2013/11/03 01:19:30 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Akamai
  2387. [2013/11/10 13:53:03 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Apple
  2388. [2013/11/10 09:55:35 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Apple Computer
  2389. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Application Data
  2390. [2013/03/12 20:05:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\ApplicationHistory
  2391. [2010/04/12 08:38:40 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Apps
  2392. [2010/12/22 22:46:41 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Astar Games
  2393. [2010/08/11 14:13:15 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\ATI
  2394. [2013/09/24 22:21:27 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Big Fish
  2395. [2013/11/23 02:17:48 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Bit_Studio
  2396. [2010/04/12 08:38:47 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Citrix
  2397. [2013/12/05 17:39:18 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\CrashDumps
  2398. [2013/11/12 00:24:48 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Deployment
  2399. [2013/11/24 19:45:01 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Diagnostics
  2400. [2013/11/22 16:33:30 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Downloaded Installations
  2401. [2013/11/29 12:33:59 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\ElevatedDiagnostics
  2402. [2010/11/25 00:45:57 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Emerald
  2403. [2013/11/17 12:01:51 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google
  2404. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\History
  2405. [2013/11/10 09:44:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Innovative Solutions
  2406. [2013/03/12 00:17:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\InWorldz
  2407. [2013/11/21 11:56:58 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Microsoft
  2408. [2013/11/12 16:08:41 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Microsoft Games
  2409. [2013/03/12 20:05:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Microsoft Help
  2410. [2012/09/01 13:08:42 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\MigWiz
  2411. [2013/11/29 07:05:47 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Mozy Restore Manager
  2412. [2013/11/02 12:06:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\NativeMessaging
  2413. [2013/11/10 09:55:50 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\PCM4Everio
  2414. [2011/12/20 17:47:07 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\PhoenixViewer
  2415. [2013/11/14 14:07:45 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Programs
  2416. [2013/01/17 13:50:43 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Research In Motion
  2417. [2013/04/30 11:27:41 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Samsung
  2418. [2013/03/12 01:30:51 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\SecondLife
  2419. [2011/11/12 14:21:08 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc
  2420. [2010/04/27 12:13:47 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\sowhat
  2421. [2013/01/14 14:54:51 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Stronghold_LLC
  2422. [2013/12/05 20:52:18 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Temp
  2423. [2010/04/12 07:40:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Temporary Internet Files
  2424. [2011/03/16 20:37:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Trusteer
  2425. [2013/09/03 11:51:03 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Turtix
  2426. [2013/11/14 18:02:45 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\VirtualStore
  2427. [2013/11/20 19:02:04 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\VS Revo Group
  2428. [2012/08/18 22:34:04 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Windows Live
  2429. [2011/06/08 09:47:16 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Windows Live Writer
  2430. [2013/11/21 14:20:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\{20884471-0E7E-4940-A053-1F0B12FF9589}
  2431. [2013/11/20 22:39:04 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\{DB584E07-379E-41CB-9996-243B7BE00B07}
  2432. [2013/11/28 17:38:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\{E0669A64-556C-40F3-BD00-25C15A9466F1}
  2433.  
  2434. [color=#A23BEC]< %USERPROFILE%\AppData\Local\Google\Chrome\User Data\Default\*.* >[/color]
  2435. [2013/11/10 13:09:27 | 000,114,688 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Archived History
  2436. [2013/04/29 00:15:38 | 000,110,592 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Archived History (1)
  2437. [2013/04/29 00:15:38 | 000,110,592 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Archived History (2)
  2438. [2013/11/10 13:09:27 | 000,008,720 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal
  2439. [2013/04/29 00:15:38 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal (1)
  2440. [2013/04/29 00:15:38 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal (2)
  2441. [2013/11/29 12:40:18 | 000,034,082 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Bookmarks
  2442. [2012/05/11 23:29:12 | 000,001,849 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Bookmarks (1)
  2443. [2012/05/11 23:29:12 | 000,001,849 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Bookmarks (1).bak
  2444. [2012/05/11 23:29:12 | 000,001,849 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Bookmarks (2)
  2445. [2012/05/11 23:29:12 | 000,001,849 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Bookmarks (2).bak
  2446. [2013/11/29 12:40:18 | 000,034,082 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Bookmarks.bak
  2447. [2013/03/12 18:16:09 | 000,083,968 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data (1)
  2448. [2013/03/12 18:16:09 | 000,083,968 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data (2)
  2449. [2013/03/12 23:16:57 | 000,095,836 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences (1)
  2450. [2013/03/12 23:16:57 | 000,095,836 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences (2)
  2451. [2013/12/05 20:52:18 | 000,670,720 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cookies
  2452. [2013/04/29 00:13:47 | 000,068,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cookies (1)
  2453. [2013/04/29 00:13:47 | 000,068,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cookies (2)
  2454. [2013/12/05 20:52:18 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
  2455. [2013/04/29 00:13:47 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal (1)
  2456. [2013/04/29 00:13:47 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal (2)
  2457. [2013/11/11 12:41:40 | 000,670,720 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\cookies_2013-11-11_14-1-14-744
  2458. [2013/12/05 20:45:50 | 000,000,000 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Current Session
  2459. [2013/04/29 00:15:38 | 000,070,934 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Current Session (1)
  2460. [2013/04/29 00:15:38 | 000,070,934 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Current Session (2)
  2461. [2013/12/05 20:45:04 | 000,032,312 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
  2462. [2013/04/29 00:15:38 | 000,013,571 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Current Tabs (1)
  2463. [2013/04/29 00:15:38 | 000,013,571 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Current Tabs (2)
  2464. [2013/11/03 00:06:51 | 000,006,144 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies
  2465. [2013/03/12 18:16:09 | 000,006,144 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies (1)
  2466. [2013/03/12 18:16:09 | 000,006,144 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies (2)
  2467. [2013/11/03 00:06:51 | 000,003,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies-journal
  2468. [2013/03/12 18:16:09 | 000,001,544 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies-journal (1)
  2469. [2013/03/12 18:16:09 | 000,001,544 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies-journal (2)
  2470. [2013/12/05 18:42:18 | 004,517,888 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Favicons
  2471. [2013/04/29 00:13:28 | 000,069,632 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Favicons (1)
  2472. [2013/04/29 00:13:28 | 000,069,632 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Favicons (2)
  2473. [2013/12/05 18:42:18 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
  2474. [2013/04/29 00:13:28 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal (1)
  2475. [2013/04/29 00:13:28 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal (2)
  2476. [2012/04/25 13:37:39 | 000,150,798 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Google Profile (1).ico
  2477. [2012/04/25 13:37:39 | 000,150,798 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Google Profile (2).ico
  2478. [2013/11/17 12:02:09 | 000,181,623 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Google Profile.ico
  2479. [2013/12/05 20:46:14 | 005,414,912 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History
  2480. [2013/04/29 00:15:37 | 000,143,360 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History (1)
  2481. [2013/04/29 00:15:37 | 000,143,360 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History (2)
  2482. [2013/12/05 20:45:04 | 000,516,389 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
  2483. [2013/04/29 00:15:37 | 000,003,231 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache (1)
  2484. [2013/04/29 00:15:37 | 000,003,231 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache (2)
  2485. [2013/12/05 20:46:14 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History-journal
  2486. [2013/04/29 00:15:37 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History-journal (1)
  2487. [2013/04/29 00:15:37 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\History-journal (2)
  2488. [2013/12/05 20:45:05 | 000,345,234 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Last Session
  2489. [2013/03/24 19:22:42 | 000,086,926 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Last Session (1)
  2490. [2013/03/24 19:22:42 | 000,086,926 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Last Session (2)
  2491. [2013/12/05 20:14:47 | 000,087,204 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Last Tabs
  2492. [2013/03/24 19:22:42 | 000,007,619 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Last Tabs (1)
  2493. [2013/03/24 19:22:42 | 000,007,619 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Last Tabs (2)
  2494. [2013/12/05 18:30:19 | 000,030,720 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Login Data
  2495. [2011/08/28 12:51:43 | 000,012,288 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Login Data (1)
  2496. [2011/08/28 12:51:43 | 000,012,288 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Login Data (2)
  2497. [2013/12/05 18:30:19 | 000,008,736 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
  2498. [2013/11/17 10:15:35 | 000,000,008 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings
  2499. [2013/04/29 00:13:25 | 000,000,008 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings (1)
  2500. [2013/04/29 00:13:25 | 000,000,008 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings (2)
  2501. [2013/12/03 12:14:13 | 000,080,896 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor
  2502. [2013/03/12 18:16:08 | 000,013,312 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor (1)
  2503. [2013/03/12 18:16:08 | 000,013,312 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor (2)
  2504. [2013/12/03 12:14:13 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal
  2505. [2013/03/12 18:16:08 | 000,003,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal (1)
  2506. [2013/03/12 18:16:08 | 000,003,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal (2)
  2507. [2013/12/05 18:32:19 | 000,032,768 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs
  2508. [2013/03/24 19:21:58 | 000,007,168 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs (1)
  2509. [2013/03/24 19:21:58 | 000,007,168 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs (2)
  2510. [2013/12/05 18:32:19 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal
  2511. [2013/03/24 19:21:58 | 000,003,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal (1)
  2512. [2013/03/24 19:21:58 | 000,003,608 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal (2)
  2513. [2013/12/05 20:50:07 | 000,087,482 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Preferences
  2514. [2013/04/29 00:15:38 | 000,089,949 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Preferences (1)
  2515. [2013/04/29 00:15:38 | 000,089,949 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Preferences (2)
  2516. [2013/12/02 22:55:06 | 000,013,312 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\QuotaManager
  2517. [2013/03/24 19:16:17 | 000,013,312 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\QuotaManager (1)
  2518. [2013/03/24 19:16:17 | 000,013,312 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\QuotaManager (2)
  2519. [2013/12/02 22:55:06 | 000,008,768 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal
  2520. [2013/03/24 19:16:17 | 000,008,768 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal (1)
  2521. [2013/03/24 19:16:17 | 000,008,768 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal (2)
  2522. [2012/06/11 10:31:19 | 000,000,180 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\README
  2523. [2012/06/11 10:31:19 | 000,000,180 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\README (1)
  2524. [2012/06/11 10:31:19 | 000,000,180 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\README (2)
  2525. [2013/12/03 11:31:58 | 000,024,576 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Shortcuts
  2526. [2012/04/25 13:49:06 | 000,012,288 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Shortcuts (1)
  2527. [2012/04/25 13:49:06 | 000,012,288 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Shortcuts (2)
  2528. [2013/12/03 11:31:58 | 000,012,824 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal
  2529. [2012/04/25 13:49:06 | 000,012,824 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal (1)
  2530. [2012/04/25 13:49:06 | 000,012,824 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal (2)
  2531. [2013/12/05 18:30:00 | 000,176,128 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Top Sites
  2532. [2012/08/03 18:48:01 | 000,110,592 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Top Sites (1)
  2533. [2012/08/03 18:48:01 | 000,110,592 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Top Sites (2)
  2534. [2013/12/05 18:30:00 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
  2535. [2012/08/03 18:48:01 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal (1)
  2536. [2012/08/03 18:48:01 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal (2)
  2537. [2013/12/05 20:46:15 | 000,004,158 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
  2538. [2013/12/05 20:14:47 | 000,262,160 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Visited Links
  2539. [2013/04/29 00:15:38 | 000,131,072 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Visited Links (1)
  2540. [2013/04/29 00:15:38 | 000,131,072 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Visited Links (2)
  2541. [2013/12/05 18:42:06 | 000,129,024 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Web Data
  2542. [2013/04/29 00:13:16 | 000,083,968 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Web Data (1)
  2543. [2013/04/29 00:13:16 | 000,083,968 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Web Data (2)
  2544. [2013/12/05 18:42:06 | 000,016,384 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
  2545. [2013/04/29 00:13:16 | 000,012,848 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal (1)
  2546. [2013/04/29 00:13:16 | 000,012,848 | ---- | M] () -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal (2)
  2547. [17 C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\*.tmp files -> C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\*.tmp -> ]
  2548.  
  2549. [color=#A23BEC]< %USERPROFILE%\AppData\Local\Google\Chrome\User Data\Default\*. >[/color]
  2550. [2013/12/05 20:46:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Cache
  2551. [2013/11/12 01:54:55 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\databases
  2552. [2013/12/05 20:45:47 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension Rules
  2553. [2013/12/05 20:45:49 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extension State
  2554. [2013/11/17 16:47:19 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions
  2555. [2013/11/14 01:18:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\File System
  2556. [2013/11/12 01:55:07 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\GPUCache
  2557. [2013/12/05 20:46:03 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons
  2558. [2013/12/05 20:45:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld
  2559. [2013/11/02 12:07:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings
  2560. [2013/12/05 18:34:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Local Storage
  2561. [2013/11/25 01:01:13 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Media Cache
  2562. [2012/11/23 17:15:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Pepper Data
  2563. [2013/12/05 20:45:48 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Session Storage
  2564. [2013/10/11 18:04:24 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Sync Data
  2565. [2013/06/28 08:53:20 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\User StyleSheets
  2566.  
  2567. [color=#A23BEC]< %USERPROFILE%\AppData\Local\temp\*.exe >[/color]
  2568. [2013/09/01 11:58:28 | 000,488,960 | ---- | M] () -- C:\Users\Marion\AppData\Local\temp\sqlite3.exe
  2569. [8 C:\Users\Marion\AppData\Local\temp\*.tmp files -> C:\Users\Marion\AppData\Local\temp\*.tmp -> ]
  2570.  
  2571. [color=#A23BEC]< %USERPROFILE%\AppData\Roaming\*.* >[/color]
  2572. [2013/08/13 09:54:31 | 000,889,416 | ---- | M] (Microsoft Corporation) -- C:\Users\Marion\AppData\Roaming\dotNetFx40_Full_setup.exe
  2573. [2013/04/12 08:36:32 | 000,001,617 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Desktop.Exception (1).log
  2574. [2013/04/12 08:36:32 | 000,001,617 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Desktop.Exception (2).log
  2575. [2013/11/24 19:17:32 | 000,002,464 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Desktop.Exception.log
  2576. [2013/01/06 10:56:40 | 000,002,257 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Desktop.HttpServerSetup (1).log
  2577. [2013/01/06 10:56:40 | 000,002,257 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Desktop.HttpServerSetup (2).log
  2578. [2013/11/24 19:18:26 | 000,006,437 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
  2579. [2013/02/07 21:08:13 | 000,001,463 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.DesktopHelper.Exception (1).log
  2580. [2013/02/07 21:08:13 | 000,001,463 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.DesktopHelper.Exception (2).log
  2581. [2013/11/20 22:48:21 | 000,001,771 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.DesktopHelper.Exception.log
  2582. [2013/11/24 19:17:32 | 000,000,539 | ---- | M] () -- C:\Users\Marion\AppData\Roaming\Rim.Transcoder.Exception.log
  2583.  
  2584. [color=#A23BEC]< %USERPROFILE%\AppData\Roaming\*. >[/color]
  2585. [2013/11/10 11:21:59 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Adobe
  2586. [2013/11/02 01:33:39 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\AlawarEntertainment
  2587. [2012/08/19 12:38:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\aliasworlds
  2588. [2010/06/03 10:27:43 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Amazon
  2589. [2013/11/10 09:56:30 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Ancient Quest of Saqqarah__bfg
  2590. [2012/08/31 13:41:45 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Anuman
  2591. [2013/01/06 11:57:04 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Apple Computer
  2592. [2013/11/10 09:56:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\ATI
  2593. [2010/12/22 23:11:16 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Awem
  2594. [2013/09/24 22:21:25 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\BBB
  2595. [2013/06/28 09:02:43 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Be a King 2
  2596. [2013/11/01 19:27:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Big Fish Games
  2597. [2013/06/28 09:03:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\BigFish All My Gods
  2598. [2010/04/29 21:22:42 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\BigFishGames
  2599. [2012/08/24 17:49:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Boolat Games
  2600. [2013/06/28 09:03:15 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Boomzap
  2601. [2010/04/17 15:36:29 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Braintonik
  2602. [2013/12/02 20:49:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Clip Art Collection
  2603. [2013/11/10 09:56:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\CyberLink
  2604. [2013/09/13 22:02:21 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\DarkManor
  2605. [2013/06/28 09:11:38 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Deadly Sin
  2606. [2013/08/13 10:02:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Dell
  2607. [2011/09/09 16:26:22 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\DriverFinder
  2608. [2013/12/05 17:10:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Dropbox
  2609. [2012/08/09 09:37:18 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\EdAlive
  2610. [2013/02/04 15:51:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Elephant Games
  2611. [2013/09/29 08:25:30 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\ERS Game Studios
  2612. [2013/06/28 09:17:08 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Faerie Solitaire
  2613. [2013/10/13 11:12:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\FixCleaner
  2614. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Foresight Software
  2615. [2013/06/28 09:17:09 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\ForrestGump
  2616. [2012/11/09 00:32:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\funkitron
  2617. [2010/04/28 17:59:55 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\G-HeadGames
  2618. [2012/04/05 10:51:14 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\GAMESHASTRA
  2619. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\GirlsDateChat
  2620. [2010/04/18 07:09:26 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\GOA
  2621. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Google
  2622. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Identities
  2623. [2013/09/06 00:31:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Inertia Game Studios
  2624. [2013/11/10 09:56:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\InstallShield
  2625. [2012/08/23 11:48:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\InWorldz
  2626. [2013/11/17 16:41:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\KeePass
  2627. [2013/10/22 13:52:28 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\kidoz
  2628. [2012/08/31 15:15:41 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\LegacyGames
  2629. [2013/03/20 00:57:52 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Liam games
  2630. [2013/09/26 15:58:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Macromedia
  2631. [2013/11/14 14:09:44 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Malwarebytes
  2632. [2011/12/12 15:51:40 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\McAfee
  2633. [2013/10/27 19:46:36 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Melesta
  2634. [2013/11/21 11:57:00 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Microsoft
  2635. [2013/10/27 19:09:10 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Nimbus Games
  2636. [2012/02/03 19:44:35 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\NVIDIA
  2637. [2012/10/03 12:25:45 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Oberon Media
  2638. [2013/01/14 14:54:31 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\OpenClipArtLibraryPackages
  2639. [2010/05/17 22:11:18 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Orneon
  2640. [2013/08/13 10:00:37 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\PCDr
  2641. [2013/11/10 09:57:08 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Pengu Wars
  2642. [2013/11/11 12:08:32 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Picsoft
  2643. [2013/09/26 15:58:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\PlayFirst
  2644. [2013/02/04 13:35:56 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Publisher
  2645. [2010/05/24 15:32:17 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\QB9
  2646. [2013/11/29 06:54:40 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Research In Motion
  2647. [2013/11/22 16:21:13 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Samsung
  2648. [2012/05/16 18:51:11 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\SecondLife
  2649. [2013/10/24 18:44:56 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Skyborn
  2650. [2013/06/28 10:02:03 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Super-Cow
  2651. [2013/11/25 02:54:40 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\SyncTunesDesktop
  2652. [2010/04/13 14:42:02 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\System Tweaker
  2653. [2013/10/24 19:22:42 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\The Witch and The Warrior
  2654. [2010/06/12 19:35:04 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Trusteer
  2655. [2013/06/28 10:03:23 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Turbine
  2656. [2013/07/16 15:51:11 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\U3
  2657. [2013/11/13 09:30:12 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Uniblue
  2658. [2013/11/10 09:57:21 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\vcards
  2659. [2013/10/23 12:06:34 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\viking_saga_bfg_en
  2660. [2013/06/28 10:07:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Virtual City
  2661. [2012/04/21 19:15:05 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\WendigoStudios
  2662. [2013/10/03 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\when_in_rome_bfg
  2663. [2013/07/14 19:16:06 | 000,000,000 | ---D | M] -- C:\Users\Marion\AppData\Roaming\Windows Live Writer
  2664.  
  2665. [color=#A23BEC]< %ProgramData%\*.* >[/color]
  2666.  
  2667. [color=#A23BEC]< %ProgramData%\*. >[/color]
  2668. [2012/08/04 12:59:36 | 000,000,000 | ---D | M] -- C:\ProgramData\225932D202D48936DAFC29C6F875F002
  2669. [2013/11/29 11:54:50 | 000,000,000 | ---D | M] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
  2670. [2013/11/10 09:54:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe
  2671. [2011/10/21 09:26:01 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple
  2672. [2010/04/12 15:43:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple Computer
  2673. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Application Data
  2674. [2011/12/12 15:16:02 | 000,000,000 | ---D | M] -- C:\ProgramData\ATI
  2675. [2013/09/13 17:38:50 | 000,000,000 | ---D | M] -- C:\ProgramData\Big Fish
  2676. [2013/11/11 11:59:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Big Fish Games
  2677. [2013/11/13 20:19:59 | 000,000,000 | ---D | M] -- C:\ProgramData\Braintonik
  2678. [2010/04/12 19:31:33 | 000,000,000 | ---D | M] -- C:\ProgramData\CanonBJ
  2679. [2013/11/27 16:56:15 | 000,000,000 | ---D | M] -- C:\ProgramData\CDB
  2680. [2010/04/12 08:39:42 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix
  2681. [2013/11/10 09:42:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Common Files
  2682. [2011/09/09 16:19:24 | 000,000,000 | ---D | M] -- C:\ProgramData\Computer Updater
  2683. [2011/04/09 13:30:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Cyberlink
  2684. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Desktop
  2685. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Documents
  2686. [2013/10/18 18:30:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Driver Whiz
  2687. [2013/11/10 09:54:05 | 000,000,000 | ---D | M] -- C:\ProgramData\Elephant Games
  2688. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Favorites
  2689. [2010/12/27 19:06:26 | 000,000,000 | ---D | M] -- C:\ProgramData\Fenomen Games
  2690. [2012/08/24 18:37:46 | 000,000,000 | ---D | M] -- C:\ProgramData\FireGlow
  2691. [2013/11/10 09:54:05 | 000,000,000 | ---D | M] -- C:\ProgramData\Foresight Software
  2692. [2010/04/23 16:33:23 | 000,000,000 | ---D | M] -- C:\ProgramData\Fugazo
  2693. [2012/04/19 13:25:34 | 000,000,000 | ---D | M] -- C:\ProgramData\Funny Bear Studio
  2694. [2012/04/05 10:51:14 | 000,000,000 | ---D | M] -- C:\ProgramData\GAMESHASTRA
  2695. [2013/11/10 09:54:05 | 000,000,000 | ---D | M] -- C:\ProgramData\GOA
  2696. [2010/04/12 15:31:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Google
  2697. [2013/11/15 16:13:06 | 000,000,000 | ---D | M] -- C:\ProgramData\HitmanPro
  2698. [2013/11/17 23:36:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Innovative Solutions
  2699. [2013/11/14 14:09:27 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes
  2700. [2013/07/12 22:55:21 | 000,000,000 | ---D | M] -- C:\ProgramData\McAfee
  2701. [2013/08/14 18:54:00 | 000,000,000 | ---D | M] -- C:\ProgramData\McAfee Security Scan
  2702. [2013/11/22 15:45:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft
  2703. [2013/11/13 12:52:41 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help
  2704. [2010/04/17 15:41:39 | 000,000,000 | ---D | M] -- C:\ProgramData\MythPeople
  2705. [2013/11/17 16:31:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Norton
  2706. [2013/11/17 16:31:14 | 000,000,000 | ---D | M] -- C:\ProgramData\NortonInstaller
  2707. [2010/04/13 06:25:15 | 000,000,000 | ---D | M] -- C:\ProgramData\NOS
  2708. [2013/11/12 08:49:32 | 000,000,000 | ---D | M] -- C:\ProgramData\NVIDIA
  2709. [2012/01/29 17:04:32 | 000,000,000 | ---D | M] -- C:\ProgramData\NVIDIA Corporation
  2710. [2012/10/03 12:25:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Oberon Media
  2711. [2013/11/17 14:40:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Oracle
  2712. [2013/10/18 16:35:59 | 000,000,000 | ---D | M] -- C:\ProgramData\PC-Doctor for Windows
  2713. [2013/12/03 12:22:48 | 000,000,000 | ---D | M] -- C:\ProgramData\PCDr
  2714. [2010/04/17 16:04:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Playrix Entertainment
  2715. [2013/11/26 17:01:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Publisher
  2716. [2013/04/30 11:24:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Samsung
  2717. [2010/04/12 08:52:30 | 000,000,000 | ---D | M] -- C:\ProgramData\SiteAdvisor
  2718. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Start Menu
  2719. [2010/09/29 10:36:52 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun
  2720. [2013/12/05 17:41:41 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
  2721. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\ProgramData\Templates
  2722. [2010/06/12 19:33:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Trusteer
  2723. [2013/11/10 09:54:10 | 000,000,000 | ---D | M] -- C:\ProgramData\Uniblue
  2724. [2013/11/20 19:02:00 | 000,000,000 | ---D | M] -- C:\ProgramData\VS Revo Group
  2725. [2010/04/12 15:43:58 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
  2726.  
  2727. [color=#A23BEC]< %programdata%\Microsoft\Windows\DRM\*.tmp >[/color]
  2728.  
  2729. [color=#A23BEC]< %programdata%\Microsoft\DRM\*.tmp >[/color]
  2730.  
  2731. [color=#A23BEC]< C:\Users\All Users\*.exe /s >[/color]
  2732. [2012/08/21 13:01:28 | 001,977,816 | ---- | M] (GEAR Software, Inc.) -- C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe
  2733. [2012/08/21 13:01:20 | 000,131,544 | ---- | M] (GEAR Software, Inc.) -- C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DifXInst64.exe
  2734. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\10521\AcrobatUpdater.exe
  2735. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\10521\AdobeARM.exe
  2736. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\10521\ReaderUpdater.exe
  2737. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\13019\AcrobatUpdater.exe
  2738. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\13019\AdobeARM.exe
  2739. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\13019\ReaderUpdater.exe
  2740. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\16958\AcrobatUpdater.exe
  2741. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\16958\AdobeARM.exe
  2742. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\16958\ReaderUpdater.exe
  2743. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\19042\AcrobatUpdater.exe
  2744. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\19042\AdobeARM.exe
  2745. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\19042\ReaderUpdater.exe
  2746. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\19319\AcrobatUpdater.exe
  2747. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\19319\AdobeARM.exe
  2748. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\19319\ReaderUpdater.exe
  2749. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20080\AcrobatUpdater.exe
  2750. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20080\AdobeARM.exe
  2751. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20080\ReaderUpdater.exe
  2752. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20107\AcrobatUpdater.exe
  2753. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20107\AdobeARM.exe
  2754. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20107\ReaderUpdater.exe
  2755. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20474\AcrobatUpdater.exe
  2756. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20474\AdobeARM.exe
  2757. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\20474\ReaderUpdater.exe
  2758. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\28591\AcrobatUpdater.exe
  2759. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\28591\AdobeARM.exe
  2760. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\28591\ReaderUpdater.exe
  2761. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\31115\AcrobatUpdater.exe
  2762. [2012/01/03 07:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\31115\AdobeARM.exe
  2763. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\31115\AdobeARMHelper.exe
  2764. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\31115\ReaderUpdater.exe
  2765. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\6511\AcrobatUpdater.exe
  2766. [2010/09/21 18:37:40 | 000,932,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\6511\AdobeARM.exe
  2767. [2010/09/21 18:37:40 | 000,338,856 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\6511\ReaderUpdater.exe
  2768. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\7379\AcrobatUpdater.exe
  2769. [2012/01/03 07:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\7379\AdobeARM.exe
  2770. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\7379\AdobeARMHelper.exe
  2771. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\7379\ReaderUpdater.exe
  2772. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\8207\AcrobatUpdater.exe
  2773. [2012/01/03 07:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\8207\AdobeARM.exe
  2774. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\8207\AdobeARMHelper.exe
  2775. [2012/01/03 07:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.3\ARM\8207\ReaderUpdater.exe
  2776. [2012/12/03 07:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.5\ARM\12838\AcrobatUpdater.exe
  2777. [2012/12/03 07:35:28 | 000,946,352 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.5\ARM\12838\AdobeARM.exe
  2778. [2012/12/03 07:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.5\ARM\12838\AdobeARMHelper.exe
  2779. [2012/12/03 07:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Reader\9.5\ARM\12838\ReaderUpdater.exe
  2780. [2012/01/03 17:46:15 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-A95000000001}\Setup.exe
  2781. [2012/09/24 03:47:39 | 000,364,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\setup.exe
  2782. [2013/11/11 11:39:50 | 000,077,136 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\iTunes 11.1.3.8\SetupAdmin.exe
  2783. [2010/05/02 19:03:19 | 000,079,144 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
  2784. [2010/11/24 11:53:49 | 000,072,488 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.33.19.4\SetupAdmin.exe
  2785. [2011/03/16 23:21:16 | 000,072,488 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.33.20.27\SetupAdmin.exe
  2786. [2011/05/02 22:52:32 | 000,072,488 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.33.21.1\SetupAdmin.exe
  2787. [2011/08/25 09:50:55 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.34.50.0\SetupAdmin.exe
  2788. [2011/10/21 09:29:47 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.34.51.22\SetupAdmin.exe
  2789. [2011/12/20 17:29:56 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
  2790. [2012/03/26 18:43:08 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.34.54.16\SetupAdmin.exe
  2791. [2012/04/03 12:28:25 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple Computer\Installer Cache\Safari 5.34.55.3\SetupAdmin.exe
  2792. [2011/10/21 13:26:35 | 000,073,576 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 1.0.1.29\SetupAdmin.exe
  2793. [2011/12/20 17:28:46 | 000,073,576 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 1.0.2.17\SetupAdmin.exe
  2794. [2012/03/09 11:24:59 | 000,073,576 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 1.1.0.40\SetupAdmin.exe
  2795. [2012/12/10 17:58:37 | 000,076,688 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 2.1.0.39\SetupAdmin.exe
  2796. [2013/02/04 08:57:09 | 000,077,280 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 2.1.1.3\SetupAdmin.exe
  2797. [2013/05/06 09:59:20 | 000,077,128 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 2.1.2.8\SetupAdmin.exe
  2798. [2013/10/28 13:21:45 | 000,077,128 | ---- | M] (Apple Inc.) -- C:\Users\All Users\Apple\Installer Cache\iCloud Control Panel 3.0.2.163\SetupAdmin.exe
  2799. [2012/11/13 18:29:06 | 001,411,072 | ---- | M] () -- C:\Users\All Users\Big Fish\cef\1.963.439\cefclient.exe
  2800. [2013/08/29 21:59:06 | 002,340,184 | ---- | M] () -- C:\Users\All Users\Big Fish\Game Manager\Addons\gmActivator.exe
  2801. [2013/08/29 21:59:10 | 000,689,152 | ---- | M] () -- C:\Users\All Users\Big Fish\Game Manager\Addons\BFGameLauncher\BFGameLauncher.exe
  2802. [2013/08/29 21:59:12 | 002,340,664 | ---- | M] () -- C:\Users\All Users\Big Fish\Game Manager\Addons\BFGameLauncher\CasinoActivator.exe
  2803. [2012/11/13 18:28:46 | 002,026,496 | ---- | M] () -- C:\Users\All Users\Big Fish\In Game Purchase\1.0.1\bfgbrowser.exe
  2804. [2013/10/24 00:45:22 | 002,027,520 | ---- | M] (Big Fish, Inc.) -- C:\Users\All Users\Big Fish\In Game Purchase\1.0.2\bfgbrowser.exe
  2805. [2011/08/18 17:30:08 | 000,527,024 | ---- | M] (Google Inc.) -- C:\Users\All Users\Google\Google Toolbar\Update\GoogleToolbarInstaller_updater_signed.exe
  2806. [2010/04/12 15:31:17 | 000,086,016 | ---- | M] () -- C:\Users\All Users\NOS\Adobe_Downloads\arh.exe
  2807. [2011/10/15 08:53:00 | 000,195,904 | ---- | M] (NVIDIA Corporation) -- C:\Users\All Users\NVIDIA\Updatus\WLMerger.exe
  2808. [1970/01/01 00:00:00 | 000,118,212 | ---- | M] () -- C:\Users\All Users\NVIDIA\Updatus\Download\8789D51\drsupdate.11403901_RUNASUSER.exe
  2809. [2013/11/12 08:49:55 | 000,125,480 | ---- | M] () -- C:\Users\All Users\NVIDIA\Updatus\Packages\00000000\drsupdate.11403901_RUNASUSER.exe
  2810. [2013/11/13 08:39:40 | 000,353,128 | ---- | M] () -- C:\Users\All Users\NVIDIA\Updatus\Packages\00000eaf\drsupdate.13728286_RUNASUSER.exe
  2811. [2013/09/04 06:16:00 | 000,025,336 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\All Users\PC-Doctor for Windows\startmenu\startmenu-localizer.exe
  2812. [2013/11/18 12:44:31 | 013,294,808 | ---- | M] (Mozy, Inc.) -- C:\Users\All Users\TEMP\mozy-autoupdate-b6ef32f74275da3b7074b1f807e71343.exe
  2813. [2013/08/13 20:26:51 | 013,206,744 | ---- | M] (Mozy, Inc.) -- C:\Users\All Users\TEMP\mozy-manualupdate-b7a98b96ee32dd5287d4d7d58fa788c3.exe
  2814. [2009/07/14 05:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
  2815. [2009/07/14 05:08:49 | 000,032,608 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
  2816. [2010/04/12 15:40:00 | 000,000,894 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
  2817. [2010/04/12 15:40:01 | 000,000,898 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
  2818. [2013/06/28 16:40:01 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
  2819.  
  2820. [color=#A23BEC]< C:\Users\Default\*.exe /s >[/color]
  2821. [2013/11/17 14:05:01 | 000,054,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
  2822.  
  2823. [color=#A23BEC]< C:\Users\Public\*.exe /s >[/color]
  2824.  
  2825. [color=#A23BEC]< %CommonProgramFiles%\*.* >[/color]
  2826.  
  2827. [color=#A23BEC]< %CommonProgramFiles%\*. >[/color]
  2828. [2013/06/28 16:52:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Adobe
  2829. [2013/11/17 14:05:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Adobe AIR
  2830. [2013/11/11 11:44:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Apple
  2831. [2010/08/11 14:10:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\ATI Technologies
  2832. [2013/08/14 18:53:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\DESIGNER
  2833. [2013/11/10 09:44:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Innovative Solutions
  2834. [2011/04/09 13:13:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\InstallShield
  2835. [2013/11/17 14:40:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Java
  2836. [2013/03/12 20:04:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\McAfee
  2837. [2013/07/12 22:54:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\microsoft shared
  2838. [2013/11/24 19:18:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Research In Motion
  2839. [2013/03/12 20:12:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Services
  2840. [2009/07/14 03:20:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\SpeechEngines
  2841. [2013/07/12 22:57:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\System
  2842. [2010/04/12 08:57:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Windows Live
  2843. [2013/11/19 00:17:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
  2844. [2013/11/24 19:19:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\XCPCSync.OEM
  2845.  
  2846. [color=#A23BEC]< %CommonProgramFiles%\ComObjects\*.* >[/color]
  2847.  
  2848. [color=#A23BEC]< %ProgramFiles%\*.* >[/color]
  2849. [2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  2850.  
  2851. [color=#A23BEC]< %ProgramFiles%\*. >[/color]
  2852. [2013/11/17 14:05:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
  2853. [2013/08/14 18:52:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\All My Gods
  2854. [2010/06/03 10:26:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Amazon
  2855. [2011/12/12 15:15:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AMD APP
  2856. [2013/08/14 18:52:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Ancient Quest of Saqqarah
  2857. [2013/08/14 18:52:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
  2858. [2013/11/21 11:43:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI
  2859. [2011/12/12 15:15:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI Technologies
  2860. [2013/08/14 18:52:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Awakening - Moonfell Wood
  2861. [2013/08/14 18:52:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Awakening - The Dreamless Castle
  2862. [2013/09/10 22:56:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\bfgclient
  2863. [2013/08/14 18:52:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
  2864. [2010/04/15 08:01:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Canon
  2865. [2010/04/12 08:39:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Citrix
  2866. [2013/08/14 18:52:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\City of Fools
  2867. [2013/08/14 18:52:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Clip Art Collection
  2868. [2013/11/21 11:49:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Codemasters
  2869. [2013/11/17 14:40:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
  2870. [2011/04/09 13:20:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
  2871. [2013/10/27 19:11:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dark Manor - A Hidden Object Mystery
  2872. [2011/12/11 15:16:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dell
  2873. [2013/11/14 00:21:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Diego`s Dinosaur Adventure
  2874. [2013/07/12 22:54:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Digital Photo Navigator 1.5
  2875. [2013/08/14 18:53:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dora Saves the Crystal Kingdom
  2876. [2013/08/28 17:40:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dora the Explorer - Swiper's Big Adventure!
  2877. [2013/08/14 18:53:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Doras Carnival 2 - At the Boardwalk
  2878. [2013/11/01 23:44:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Drawn - Dark Flight
  2879. [2013/11/13 09:28:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DriverUpdate
  2880. [2013/07/30 11:09:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EdAlive
  2881. [2013/08/14 18:53:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Faerie Solitaire
  2882. [2013/10/15 16:46:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\FixCleaner
  2883. [2013/03/12 20:04:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GirlsDateChat
  2884. [2013/11/17 14:06:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
  2885. [2013/08/14 18:53:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\House of 1000 Doors - The Palm of Zoroaster
  2886. [2013/11/10 09:44:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Innovative Solutions
  2887. [2013/11/22 16:27:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\InstallShield Installation Information
  2888. [2013/10/19 10:59:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
  2889. [2013/11/12 14:04:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
  2890. [2013/07/12 22:54:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\InWorldz
  2891. [2013/11/11 11:45:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
  2892. [2013/09/10 22:57:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jar of Marbles II - Journey to the West
  2893. [2013/11/17 14:39:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
  2894. [2013/08/14 18:53:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jigs@w Puzzle 2
  2895. [2013/11/17 16:13:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\KeePass Password Safe
  2896. [2013/08/14 18:53:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Kingdom Chronicles
  2897. [2013/08/14 18:53:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\La Casa De Dora
  2898. [2013/08/14 18:53:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Legends of Atlantis - Exodus
  2899. [2013/08/14 18:53:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Magic Maze
  2900. [2013/08/28 23:31:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Margrave - The Blacksmiths Daughter
  2901. [2013/11/22 16:22:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MarkAny
  2902. [2012/09/12 11:18:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\McAfee
  2903. [2010/08/28 10:57:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\McAfee.com
  2904. [2013/11/17 16:45:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
  2905. [2011/12/20 21:45:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
  2906. [2013/10/11 12:54:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
  2907. [2013/08/14 18:53:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works
  2908. [2010/09/15 02:01:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
  2909. [2013/10/06 08:10:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
  2910. [2013/11/29 06:41:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozy
  2911. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
  2912. [2011/04/09 16:28:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
  2913. [2013/11/22 16:26:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MyFree Codec
  2914. [2013/10/27 19:20:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Nick Jr. Bingo
  2915. [2013/11/17 16:31:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Norton Identity Safe
  2916. [2013/11/17 16:31:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NortonInstaller
  2917. [2013/04/06 20:23:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
  2918. [2012/10/03 12:25:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Oberon Media SIDR
  2919. [2013/08/14 18:53:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Open Clip Art Library
  2920. [2013/11/11 11:58:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Peggle Deluxe
  2921. [2013/09/10 23:35:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Plants vs Zombies
  2922. [2013/08/14 18:53:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Plumeboom - The First Chapter
  2923. [2013/03/12 20:04:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Pony World 2
  2924. [2013/09/13 17:36:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Puppetshow - Return to Joyville
  2925. [2013/10/27 19:08:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Putt-Putt Saves the Zoo
  2926. [2013/08/14 18:53:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
  2927. [2013/08/14 18:53:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Rangy Lil's Wild West Adventure
  2928. [2013/10/18 19:52:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
  2929. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
  2930. [2013/11/22 16:26:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Samsung
  2931. [2013/08/14 18:53:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SecondLifeViewer
  2932. [2013/11/20 15:36:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SpongeBob SquarePants Diner Dash
  2933. [2013/10/27 19:21:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SpongeBob SquarePants Obstacle Odyssey
  2934. [2013/08/14 18:53:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Strimko
  2935. [2013/03/12 20:04:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Supercow
  2936. [2013/08/14 18:53:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SystemRequirementsLab
  2937. [2013/10/18 19:52:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Temp
  2938. [2013/11/23 02:14:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\The Bit Studio
  2939. [2013/08/14 18:53:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\The Timebuilders - Caveman's Prophecy
  2940. [2013/08/14 18:53:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\The Timebuilders - Pyramid Rising
  2941. [2012/10/03 10:33:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TotalRecipeSearch_14
  2942. [2013/08/14 18:53:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Trial of the Gods - Ariadnes Journey
  2943. [2013/11/13 09:30:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uniblue
  2944. [2009/07/14 04:57:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uninstall Information
  2945. [2013/10/23 11:37:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Viking Saga
  2946. [2013/08/14 18:53:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Virus 3
  2947. [2013/08/28 23:34:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\When_In_Rome
  2948. [2013/07/13 11:25:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
  2949. [2012/06/07 23:14:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
  2950. [2013/07/12 22:57:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
  2951. [2013/08/14 18:55:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
  2952. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
  2953. [2013/07/12 22:57:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
  2954. [2013/03/12 20:10:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
  2955. [2013/07/12 22:57:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
  2956. [2011/09/09 16:29:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Yahoo!
  2957.  
  2958. [color=#A23BEC]< %Public%\Documents\*.* >[/color]
  2959. [2009/07/14 04:54:24 | 000,000,278 | -HS- | M] () -- C:\Users\Public\Documents\desktop.ini
  2960.  
  2961. [color=#A23BEC]< %Public%\Documents\*. >[/color]
  2962. [2013/11/22 16:21:17 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\CrashDump
  2963. [2013/09/29 17:02:32 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\Downloaded Installers
  2964. [2010/04/12 09:05:02 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\microsoft
  2965. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\My Music
  2966. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\My Pictures
  2967. [2009/07/14 05:08:56 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\My Videos
  2968. [2013/11/22 16:21:17 | 000,000,000 | ---D | M] -- C:\Users\Public\Documents\NativeFus_Log
  2969.  
  2970. [color=#A23BEC]< %systemroot%\System32\config\systemprofile\*.exe /s >[/color]
  2971.  
  2972. [color=#A23BEC]< %systemroot%\System32\config\systemprofile\*.* >[/color]
  2973. [2010/08/21 21:48:15 | 000,262,144 | ---- | M] () -- C:\Windows\System32\config\systemprofile\NTUSER.DAT
  2974. [2010/08/21 21:48:15 | 000,005,120 | ---- | M] () -- C:\Windows\System32\config\systemprofile\NTUSER.DAT.LOG1
  2975. [2010/08/21 21:48:15 | 000,000,000 | ---- | M] () -- C:\Windows\System32\config\systemprofile\NTUSER.DAT.LOG2
  2976. [2010/08/21 21:48:15 | 000,065,536 | ---- | M] () -- C:\Windows\System32\config\systemprofile\NTUSER.DAT{b01e5d4d-ad40-11df-b922-00219b1c2f23}.TM.blf
  2977. [2010/08/21 21:48:15 | 000,524,288 | ---- | M] () -- C:\Windows\System32\config\systemprofile\NTUSER.DAT{b01e5d4d-ad40-11df-b922-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  2978. [2010/08/21 21:48:15 | 000,524,288 | ---- | M] () -- C:\Windows\System32\config\systemprofile\NTUSER.DAT{b01e5d4d-ad40-11df-b922-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  2979.  
  2980. [color=#A23BEC]< %systemroot%\System32\config\systemprofile\*. >[/color]
  2981. [2009/07/14 04:55:33 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\AppData
  2982. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Application Data
  2983. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Contacts
  2984. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Cookies
  2985. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Desktop
  2986. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Documents
  2987. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Downloads
  2988. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Favorites
  2989. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Links
  2990. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Local Settings
  2991. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Music
  2992. [2013/10/18 19:12:50 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\My Documents
  2993. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\NetHood
  2994. [2013/10/18 19:12:52 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Pictures
  2995. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\PrintHood
  2996. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Recent
  2997. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Saved Games
  2998. [2013/10/18 19:12:52 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Searches
  2999. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\SendTo
  3000. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Start Menu
  3001. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Templates
  3002. [2013/10/18 19:12:52 | 000,000,000 | ---D | M] -- C:\Windows\System32\config\systemprofile\Videos
  3003.  
  3004. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Local\*.* >[/color]
  3005.  
  3006. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Local\*. >[/color]
  3007. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Application Data
  3008. [2013/08/01 22:01:07 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Google
  3009. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\History
  3010. [2013/10/18 19:12:50 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft
  3011. [2013/10/18 19:12:47 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Programs
  3012. [2010/10/21 10:54:50 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Temp
  3013. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Temporary Internet Files
  3014. [2013/11/02 10:04:55 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\Trusteer
  3015.  
  3016. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Roaming\*.* >[/color]
  3017.  
  3018. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\AppData\Roaming\*. >[/color]
  3019. [2010/11/24 11:55:03 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
  3020. [2011/09/02 13:03:20 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\McAfee
  3021. [2013/10/18 19:12:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft
  3022. [2010/04/12 08:56:07 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Roaming\SACore
  3023.  
  3024. [color=#A23BEC]< %systemroot%\SysWow64\config\systemprofile\*.exe /s >[/color]
  3025.  
  3026. [color=#A23BEC]< %systemroot%\SysWow64\config\systemprofile\*.* >[/color]
  3027. [2010/08/21 21:48:15 | 000,262,144 | ---- | M] () -- C:\Windows\SysWow64\config\systemprofile\NTUSER.DAT
  3028. [2010/08/21 21:48:15 | 000,005,120 | ---- | M] () -- C:\Windows\SysWow64\config\systemprofile\NTUSER.DAT.LOG1
  3029. [2010/08/21 21:48:15 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config\systemprofile\NTUSER.DAT.LOG2
  3030. [2010/08/21 21:48:15 | 000,065,536 | ---- | M] () -- C:\Windows\SysWow64\config\systemprofile\NTUSER.DAT{b01e5d4d-ad40-11df-b922-00219b1c2f23}.TM.blf
  3031. [2010/08/21 21:48:15 | 000,524,288 | ---- | M] () -- C:\Windows\SysWow64\config\systemprofile\NTUSER.DAT{b01e5d4d-ad40-11df-b922-00219b1c2f23}.TMContainer00000000000000000001.regtrans-ms
  3032. [2010/08/21 21:48:15 | 000,524,288 | ---- | M] () -- C:\Windows\SysWow64\config\systemprofile\NTUSER.DAT{b01e5d4d-ad40-11df-b922-00219b1c2f23}.TMContainer00000000000000000002.regtrans-ms
  3033.  
  3034. [color=#A23BEC]< %systemroot%\SysWow64\config\systemprofile\*. >[/color]
  3035. [2009/07/14 04:55:33 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\AppData
  3036. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Application Data
  3037. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Contacts
  3038. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Cookies
  3039. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Desktop
  3040. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Documents
  3041. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Downloads
  3042. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Favorites
  3043. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Links
  3044. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Local Settings
  3045. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Music
  3046. [2013/10/18 19:12:50 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\My Documents
  3047. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\NetHood
  3048. [2013/10/18 19:12:52 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Pictures
  3049. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\PrintHood
  3050. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Recent
  3051. [2013/10/18 19:12:53 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Saved Games
  3052. [2013/10/18 19:12:52 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Searches
  3053. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\SendTo
  3054. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Start Menu
  3055. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Templates
  3056. [2013/10/18 19:12:52 | 000,000,000 | ---D | M] -- C:\Windows\SysWow64\config\systemprofile\Videos
  3057.  
  3058. [color=#A23BEC]< %systemroot%\SysWOW64\config\systemprofile\AppData\Local\*.* >[/color]
  3059.  
  3060. [color=#A23BEC]< %systemroot%\SysWOW64\config\systemprofile\AppData\Local\*. >[/color]
  3061. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data
  3062. [2013/08/01 22:01:07 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google
  3063. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History
  3064. [2013/10/18 19:12:50 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft
  3065. [2013/10/18 19:12:47 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Programs
  3066. [2010/10/21 10:54:50 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temp
  3067. [2013/10/18 19:12:51 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files
  3068. [2013/11/02 10:04:55 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Trusteer
  3069.  
  3070. [color=#A23BEC]< %systemroot%\SysWOW64\config\systemprofile\AppData\Roaming\*.* >[/color]
  3071.  
  3072. [color=#A23BEC]< %systemroot%\SysWOW64\config\systemprofile\AppData\Roaming\*. >[/color]
  3073. [2010/11/24 11:55:03 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Apple Computer
  3074. [2011/09/02 13:03:20 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\McAfee
  3075. [2013/10/18 19:12:46 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft
  3076. [2010/04/12 08:56:07 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SACore
  3077.  
  3078. [color=#A23BEC]< %systemroot%\ServiceProfiles\*.exe /s >[/color]
  3079.  
  3080. [color=#A23BEC]< %systemroot%\ServiceProfiles\LocalService\AppData\Local\*.* >[/color]
  3081. [2012/08/04 13:55:57 | 000,275,836 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
  3082. [2013/03/15 00:04:17 | 002,864,141 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1013639583-4134777893-1337409647-1001-12288.dat
  3083. [2013/03/15 00:04:16 | 045,570,742 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1013639583-4134777893-1337409647-1001-4096.dat
  3084. [2013/03/15 00:04:14 | 009,086,996 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1013639583-4134777893-1337409647-1001-8192.dat
  3085. [2013/11/23 14:37:33 | 005,429,504 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
  3086. [2013/12/05 17:09:56 | 000,002,048 | -HS- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  3087. [2013/12/05 17:09:56 | 000,002,048 | -HS- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  3088. [2013/11/24 19:41:53 | 016,777,216 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-FontFace.dat
  3089. [2013/11/24 19:46:08 | 008,388,608 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-S-1-5-21-1013639583-4134777893-1337409647-1001.dat
  3090. [2013/11/24 19:42:10 | 000,387,652 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-System.dat
  3091.  
  3092. [color=#A23BEC]< %systemroot%\ServiceProfiles\LocalService\AppData\Local\*. >[/color]
  3093. [2009/07/14 04:45:47 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft
  3094. [2010/04/12 07:40:37 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\PnrpSqm
  3095. [2013/09/02 17:30:14 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
  3096.  
  3097. [color=#A23BEC]< %systemroot%\ServiceProfiles\LocalService\AppData\Local\Temp\*.tlb >[/color]
  3098.  
  3099. [color=#A23BEC]< %systemroot%\ServiceProfiles\LocalService\AppData\Roaming\*.* >[/color]
  3100.  
  3101. [color=#A23BEC]< %systemroot%\ServiceProfiles\LocalService\AppData\Roaming\*. >[/color]
  3102. [2010/07/03 16:55:14 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft
  3103. [2013/03/12 20:06:33 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking
  3104.  
  3105. [color=#A23BEC]< %systemroot%\ServiceProfiles\NetworkService\AppData\Local\*.* >[/color]
  3106.  
  3107. [color=#A23BEC]< %systemroot%\ServiceProfiles\NetworkService\AppData\Local\*. >[/color]
  3108. [2010/04/13 06:25:57 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft
  3109. [2013/12/05 20:46:19 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
  3110.  
  3111. [color=#A23BEC]< %systemroot%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tlb >[/color]
  3112.  
  3113. [color=#A23BEC]< %systemroot%\ServiceProfiles\NetworkService\AppData\Roaming\*.* >[/color]
  3114.  
  3115. [color=#A23BEC]< %systemroot%\ServiceProfiles\NetworkService\AppData\Roaming\*. >[/color]
  3116. [2010/04/12 09:29:23 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft
  3117.  
  3118. [color=#A23BEC]< %windir%\temp\*.exe >[/color]
  3119.  
  3120. [color=#A23BEC]< %windir%\*. >[/color]
  3121. [2013/11/13 10:45:36 | 000,000,000 | ---D | M] -- C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
  3122. [2013/03/12 20:12:03 | 000,000,000 | ---D | M] -- C:\Windows\addins
  3123. [2013/08/14 18:54:17 | 000,000,000 | ---D | M] -- C:\Windows\AppCompat
  3124. [2013/10/11 17:25:04 | 000,000,000 | ---D | M] -- C:\Windows\AppPatch
  3125. [2013/11/13 09:22:53 | 000,000,000 | ---D | M] -- C:\Windows\assembly
  3126. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Boot
  3127. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Branding
  3128. [2013/11/20 19:04:10 | 000,000,000 | ---D | M] -- C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
  3129. [2013/08/14 18:55:12 | 000,000,000 | ---D | M] -- C:\Windows\Cursors
  3130. [2013/11/13 12:48:22 | 000,000,000 | ---D | M] -- C:\Windows\debug
  3131. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\diagnostics
  3132. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\DigitalLocker
  3133. [2013/11/10 13:06:15 | 000,000,000 | ---D | M] -- C:\Windows\Downloaded Program Files
  3134. [2013/08/14 18:55:06 | 000,000,000 | ---D | M] -- C:\Windows\ehome
  3135. [2013/07/12 22:57:33 | 000,000,000 | ---D | M] -- C:\Windows\en-US
  3136. [2013/11/10 09:44:17 | 000,000,000 | ---D | M] -- C:\Windows\Fonts
  3137. [2009/07/14 07:50:14 | 000,000,000 | ---D | M] -- C:\Windows\Globalization
  3138. [2012/01/29 17:05:02 | 000,000,000 | ---D | M] -- C:\Windows\Help
  3139. [2013/08/14 18:55:12 | 000,000,000 | ---D | M] -- C:\Windows\IME
  3140. [2013/12/02 10:22:13 | 000,000,000 | ---D | M] -- C:\Windows\inf
  3141. [2013/11/29 11:54:55 | 000,000,000 | -HSD | M] -- C:\Windows\Installer
  3142. [2013/03/12 20:12:04 | 000,000,000 | ---D | M] -- C:\Windows\L2Schemas
  3143. [2010/04/28 18:55:55 | 000,000,000 | ---D | M] -- C:\Windows\LiveKernelReports
  3144. [2013/11/12 08:54:02 | 000,000,000 | ---D | M] -- C:\Windows\Logs
  3145. [2013/08/14 18:55:06 | 000,000,000 | ---D | M] -- C:\Windows\Media
  3146. [2013/11/22 17:35:39 | 000,000,000 | ---D | M] -- C:\Windows\Microsoft.NET
  3147. [2013/11/24 19:34:55 | 000,000,000 | ---D | M] -- C:\Windows\Minidump
  3148. [2012/04/25 13:41:37 | 000,000,000 | ---D | M] -- C:\Windows\ModemLogs
  3149. [2012/03/20 12:07:48 | 000,000,000 | ---D | M] -- C:\Windows\msdownld.tmp
  3150. [2013/03/12 20:12:04 | 000,000,000 | ---D | M] -- C:\Windows\Offline Web Pages
  3151. [2010/04/12 07:40:12 | 000,000,000 | ---D | M] -- C:\Windows\Panther
  3152. [2010/04/12 09:04:12 | 000,000,000 | ---D | M] -- C:\Windows\PCHEALTH
  3153. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Performance
  3154. [2009/07/14 03:20:10 | 000,000,000 | ---D | M] -- C:\Windows\PLA
  3155. [2013/11/12 14:04:52 | 000,000,000 | ---D | M] -- C:\Windows\PolicyDefinitions
  3156. [2013/12/05 20:45:19 | 000,000,000 | ---D | M] -- C:\Windows\Prefetch
  3157. [2013/03/20 02:19:07 | 000,000,000 | ---D | M] -- C:\Windows\Profiles
  3158. [2013/03/12 20:06:33 | 000,000,000 | ---D | M] -- C:\Windows\pss
  3159. [2013/08/14 18:51:20 | 000,000,000 | ---D | M] -- C:\Windows\registration
  3160. [2013/11/13 22:28:02 | 000,000,000 | ---D | M] -- C:\Windows\rescache
  3161. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Resources
  3162. [2009/07/14 02:35:47 | 000,000,000 | ---D | M] -- C:\Windows\SchCache
  3163. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\schemas
  3164. [2009/07/14 03:20:10 | 000,000,000 | ---D | M] -- C:\Windows\security
  3165. [2009/07/14 04:45:47 | 000,000,000 | ---D | M] -- C:\Windows\ServiceProfiles
  3166. [2013/08/14 19:01:02 | 000,000,000 | ---D | M] -- C:\Windows\servicing
  3167. [2009/07/14 04:45:50 | 000,000,000 | ---D | M] -- C:\Windows\Setup
  3168. [2013/03/12 20:11:07 | 000,000,000 | ---D | M] -- C:\Windows\ShellNew
  3169. [2013/08/13 09:55:04 | 000,000,000 | ---D | M] -- C:\Windows\SoftwareDistribution
  3170. [2009/07/14 05:37:44 | 000,000,000 | ---D | M] -- C:\Windows\Speech
  3171. [2011/08/12 10:16:53 | 000,000,000 | ---D | M] -- C:\Windows\Sun
  3172. [2013/03/12 20:07:32 | 000,000,000 | ---D | M] -- C:\Windows\system
  3173. [2013/12/02 10:22:13 | 000,000,000 | ---D | M] -- C:\Windows\System32
  3174. [2013/11/29 11:54:52 | 000,000,000 | ---D | M] -- C:\Windows\SysWOW64
  3175. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\TAPI
  3176. [2013/11/20 19:07:13 | 000,000,000 | ---D | M] -- C:\Windows\Tasks
  3177. [2013/12/05 20:46:49 | 000,000,000 | ---D | M] -- C:\Windows\Temp
  3178. [2009/07/14 02:34:33 | 000,000,000 | ---D | M] -- C:\Windows\tracing
  3179. [2013/10/18 18:42:41 | 000,000,000 | ---D | M] -- C:\Windows\twain_32
  3180. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\Vss
  3181. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\Web
  3182. [2013/11/24 19:29:14 | 000,000,000 | ---D | M] -- C:\Windows\winsxs
  3183.  
  3184. [color=#A23BEC]< %windir%\AppPatch\*.exe /s >[/color]
  3185.  
  3186. [color=#A23BEC]< %windir%\ShellNew\*.* >[/color]
  3187. [2006/09/21 23:25:46 | 000,008,714 | ---- | M] () -- C:\Windows\ShellNew\EXCEL12.XLSX
  3188. [2009/06/10 20:44:28 | 000,004,544 | ---- | M] () -- C:\Windows\ShellNew\Journal.jnt
  3189. [2006/09/21 23:32:50 | 000,027,140 | ---- | M] () -- C:\Windows\ShellNew\PWRPNT12.PPTX
  3190.  
  3191. [color=#A23BEC]< %windir%\installer\*. >[/color]
  3192. [2010/04/12 09:06:15 | 000,000,000 | ---D | M] -- C:\Windows\installer\$PatchCache$
  3193. [2013/01/14 14:54:37 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI3D25.tmp-
  3194. [2013/01/14 14:54:42 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI5495.tmp-
  3195. [2013/01/14 14:54:47 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI5995.tmp-
  3196. [2013/01/14 14:54:47 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI6BCF.tmp-
  3197. [2013/01/14 14:54:50 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI6BDF.tmp-
  3198. [2013/01/18 11:42:13 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI78B2.tmp-
  3199. [2013/01/18 11:42:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSI81A9.tmp-
  3200. [2013/01/18 11:42:30 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSIC0FC.tmp-
  3201. [2013/01/18 11:42:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSIC293.tmp-
  3202. [2013/01/18 11:42:38 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSID0B2.tmp-
  3203. [2013/01/18 11:42:38 | 000,000,000 | ---D | M] -- C:\Windows\installer\MSIE240.tmp-
  3204. [2013/05/20 21:21:58 | 000,000,000 | ---D | M] -- C:\Windows\installer\{0225AD21-F3E2-4916-BFF3-65D3F9052582}
  3205. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}
  3206. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{158104AB-D92E-45BC-8268-5D351C95F6AD}
  3207. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{19A492A0-888F-44A0-9B21-D91700763F62}
  3208. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{1BF82343-8EE6-8B76-90CF-31059B9D1842}
  3209. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{27735B09-9EFE-419F-A377-10AA8111C30A}
  3210. [2013/09/23 08:59:07 | 000,000,000 | ---D | M] -- C:\Windows\installer\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}
  3211. [2013/09/23 08:59:13 | 000,000,000 | ---D | M] -- C:\Windows\installer\{2F72F540-1F60-4266-9506-952B21D6640D}
  3212. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}
  3213. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4286E640-B5FB-11DF-AC4B-005056C00008}
  3214. [2013/08/01 22:01:14 | 000,000,000 | ---D | M] -- C:\Windows\installer\{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}
  3215. [2013/09/23 08:58:28 | 000,000,000 | ---D | M] -- C:\Windows\installer\{46F044A5-CE8B-4196-984E-5BD6525E361D}
  3216. [2013/11/23 02:14:50 | 000,000,000 | ---D | M] -- C:\Windows\installer\{48C16095-BE15-48C7-9F13-FF2242587AEB}
  3217. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4B55F339-396E-29A9-B6D0-24B6D251C90A}
  3218. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4BE9F0B8-FF3D-5CAA-9BF2-CB6F3DF75D3B}
  3219. [2013/11/17 14:06:30 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
  3220. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{4FBB2E98-1A3B-396A-A662-73E17009C076}
  3221. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}
  3222. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{52FB2985-F3AD-DAA7-7645-4E38A5B96E17}
  3223. [2013/03/24 16:44:06 | 000,000,000 | ---D | M] -- C:\Windows\installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}
  3224. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726}
  3225. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6412CECE-8172-4BE5-935B-6CECACD2CA87}
  3226. [2013/11/29 08:14:53 | 000,000,000 | ---D | M] -- C:\Windows\installer\{65F6392F-4967-832D-817B-296E3C673C03}
  3227. [2013/11/22 16:27:23 | 000,000,000 | ---D | M] -- C:\Windows\installer\{698BBAD8-B116-495D-B879-0F07A533E57F}
  3228. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}
  3229. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}
  3230. [2013/10/18 16:14:03 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}
  3231. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}
  3232. [2013/10/28 13:23:32 | 000,000,000 | ---D | M] -- C:\Windows\installer\{704C0303-D20C-45AF-BD2B-556EAF31BE09}
  3233. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{70C3CC75-9E14-D215-8FAD-5ABEAE3125D9}
  3234. [2013/07/12 22:56:29 | 000,000,000 | ---D | M] -- C:\Windows\installer\{758C8301-2696-4855-AF45-534B1200980A}
  3235. [2013/08/14 18:54:18 | 000,000,000 | ---D | M] -- C:\Windows\installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
  3236. [2013/10/17 00:14:14 | 000,000,000 | ---D | M] -- C:\Windows\installer\{7A3E6E1C-CF5A-4CE9-B8D6-A2F9B7BA18FC}
  3237. [2013/07/12 22:56:29 | 000,000,000 | ---D | M] -- C:\Windows\installer\{7AAA00C4-26E6-4EC0-8069-955B0A9D6009}
  3238. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
  3239. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{89BDAE1A-7B8E-4A0E-A169-02F7F366451D}
  3240. [2013/10/11 08:12:39 | 000,000,000 | ---D | M] -- C:\Windows\installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
  3241. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{90120000-002A-0000-1000-0000000FF1CE}
  3242. [2013/11/13 12:52:40 | 000,000,000 | ---D | M] -- C:\Windows\installer\{90120000-006E-0409-0000-0000000FF1CE}
  3243. [2013/10/11 17:47:31 | 000,000,000 | ---D | M] -- C:\Windows\installer\{91120000-002F-0000-0000-0000000FF1CE}
  3244. [2013/11/17 14:06:32 | 000,000,000 | ---D | M] -- C:\Windows\installer\{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}
  3245. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{96ED9087-7A6A-22A9-135F-901AF77474AC}
  3246. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
  3247. [2013/11/01 12:49:00 | 000,000,000 | ---D | M] -- C:\Windows\installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}
  3248. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
  3249. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}
  3250. [2013/06/03 22:35:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{B67BAFBA-4C9F-48FA-9496-933E3B255044}
  3251. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{C73F2967-062E-48F2-A462-D335B8950183}
  3252. [2013/05/06 10:00:04 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D0CB24F4-084F-40DE-B6B9-A03626E682F0}
  3253. [2013/11/29 11:54:52 | 000,000,000 | ---D | M] -- C:\Windows\installer\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}
  3254. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{DA97BDF9-BC72-46FD-8E76-427F2BB951EE}
  3255. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}
  3256. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E9A1960E-7756-2299-C700-DC7CA6EDD6E4}
  3257. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{E9D98510-A8B6-E39C-B8BA-BA9A511E040C}
  3258. [2013/10/28 13:23:16 | 000,000,000 | ---D | M] -- C:\Windows\installer\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}
  3259. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{EB4DF488-AAEF-406F-A341-CB2AAA315B90}
  3260. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}
  3261. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
  3262. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
  3263. [2013/10/17 00:14:14 | 000,000,000 | ---D | M] -- C:\Windows\installer\{F909BB1B-3FC1-4EDA-AF1F-8F1A89163591}
  3264. [2013/03/12 20:06:24 | 000,000,000 | ---D | M] -- C:\Windows\installer\{FA54C4B1-98E3-AEFA-7254-C4038DC739AF}
  3265.  
  3266. [color=#A23BEC]< %windir%\system32\*. >[/color]
  3267. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\0409
  3268. [2013/03/12 20:11:26 | 000,000,000 | ---D | M] -- C:\Windows\system32\AdvancedInstallers
  3269. [2013/01/18 11:42:33 | 000,000,000 | ---D | M] -- C:\Windows\system32\AI_RecycleBin
  3270. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\ar-SA
  3271. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\bg-BG
  3272. [2009/07/14 02:35:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\catroot
  3273. [2009/07/14 02:35:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\catroot2
  3274. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\system32\com
  3275. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\config
  3276. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\cs-CZ
  3277. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\da-DK
  3278. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\de-DE
  3279. [2011/12/11 15:16:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\Dell
  3280. [2012/03/16 11:22:48 | 000,000,000 | ---D | M] -- C:\Windows\system32\directx
  3281. [2013/03/12 20:11:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\Dism
  3282. [2013/11/12 00:03:40 | 000,000,000 | ---D | M] -- C:\Windows\system32\drivers
  3283. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\DriverStore
  3284. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\el-GR
  3285. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\en
  3286. [2013/11/13 19:56:53 | 000,000,000 | ---D | M] -- C:\Windows\system32\en-US
  3287. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\es-ES
  3288. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\et-EE
  3289. [2012/09/20 20:43:08 | 000,000,000 | ---D | M] -- C:\Windows\system32\Extensions
  3290. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\fi-FI
  3291. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\fr-FR
  3292. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\FxsTmp
  3293. [2009/07/14 02:34:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\GroupPolicy
  3294. [2009/07/14 02:34:27 | 000,000,000 | ---D | M] -- C:\Windows\system32\GroupPolicyUsers
  3295. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\he-IL
  3296. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\hr-HR
  3297. [2013/03/15 07:45:43 | 000,000,000 | ---D | M] -- C:\Windows\system32\hu-HU
  3298. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\icsxml
  3299. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\IME
  3300. [2009/07/14 02:36:55 | 000,000,000 | ---D | M] -- C:\Windows\system32\inetsrv
  3301. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\InstallShield
  3302. [2013/03/15 07:45:43 | 000,000,000 | ---D | M] -- C:\Windows\system32\it-IT
  3303. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\ja-JP
  3304. [2013/03/15 07:45:43 | 000,000,000 | ---D | M] -- C:\Windows\system32\ko-KR
  3305. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\LogFiles
  3306. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\lt-LT
  3307. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\lv-LV
  3308. [2013/03/12 20:07:36 | 000,000,000 | ---D | M] -- C:\Windows\system32\Macromed
  3309. [2013/03/12 20:11:29 | 000,000,000 | ---D | M] -- C:\Windows\system32\manifeststore
  3310. [2013/11/12 14:04:54 | 000,000,000 | ---D | M] -- C:\Windows\system32\migration
  3311. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\migwiz
  3312. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\Msdtc
  3313. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\MUI
  3314. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\nb-NO
  3315. [2009/07/14 02:34:31 | 000,000,000 | ---D | M] -- C:\Windows\system32\NDF
  3316. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\NetworkList
  3317. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\nl-NL
  3318. [2013/03/12 20:11:30 | 000,000,000 | ---D | M] -- C:\Windows\system32\oobe
  3319. [2013/03/15 07:45:43 | 000,000,000 | ---D | M] -- C:\Windows\system32\pl-PL
  3320. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\Printing_Admin_Scripts
  3321. [2013/03/15 07:45:43 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt-BR
  3322. [2013/03/15 07:45:43 | 000,000,000 | ---D | M] -- C:\Windows\system32\pt-PT
  3323. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\ras
  3324. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\Recovery
  3325. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\restore
  3326. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\ro-RO
  3327. [2013/10/18 19:15:51 | 000,000,000 | ---D | M] -- C:\Windows\system32\RTCOM
  3328. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\ru-RU
  3329. [2012/09/20 20:43:08 | 000,000,000 | ---D | M] -- C:\Windows\system32\searchplugins
  3330. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\Setup
  3331. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\sk-SK
  3332. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\sl-SI
  3333. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\slmgr
  3334. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\Speech
  3335. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\spp
  3336. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\sppui
  3337. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\sr-Latn-CS
  3338. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\sv-SE
  3339. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\sysprep
  3340. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\Tasks
  3341. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\th-TH
  3342. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\tr-TR
  3343. [2013/03/12 20:12:11 | 000,000,000 | ---D | M] -- C:\Windows\system32\uk-UA
  3344. [2013/03/12 20:07:40 | 000,000,000 | ---D | M] -- C:\Windows\system32\URTTEMP
  3345. [2013/07/12 22:57:04 | 000,000,000 | ---D | M] -- C:\Windows\system32\Wat
  3346. [2013/08/14 18:55:08 | 000,000,000 | ---D | M] -- C:\Windows\system32\wbem
  3347. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\WCN
  3348. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\system32\wdi
  3349. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\system32\WindowsPowerShell
  3350. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\system32\winrm
  3351. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-CN
  3352. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-HK
  3353. [2013/03/15 07:45:42 | 000,000,000 | ---D | M] -- C:\Windows\system32\zh-TW
  3354.  
  3355. [color=#A23BEC]< %windir%\sysnative\*. >[/color]
  3356. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\0409
  3357. [2013/03/12 20:12:04 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\AdvancedInstallers
  3358. [2013/03/12 20:12:04 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ar-SA
  3359. [2013/03/12 20:12:04 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\bg-BG
  3360. [2013/03/12 20:11:07 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Boot
  3361. [2010/04/15 12:39:06 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\CanonIJ Uninstaller Information
  3362. [2013/11/24 19:18:59 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\catroot
  3363. [2013/11/29 08:17:47 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\catroot2
  3364. [2013/07/12 22:56:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\CodeIntegrity
  3365. [2013/03/12 20:12:04 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\com
  3366. [2013/12/05 17:24:42 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\config
  3367. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\cs-CZ
  3368. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\da-DK
  3369. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\de-DE
  3370. [2013/04/05 08:27:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Dism
  3371. [2013/11/29 08:14:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\drivers
  3372. [2013/11/24 19:18:59 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\DriverStore
  3373. [2013/11/29 08:14:49 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\DRVSTORE
  3374. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\el-GR
  3375. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\en
  3376. [2013/11/13 19:56:53 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\en-US
  3377. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\es-ES
  3378. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\et-EE
  3379. [2013/03/12 20:07:21 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\EventProviders
  3380. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\fi-FI
  3381. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\fr-FR
  3382. [2010/04/15 08:03:17 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\FxsTmp
  3383. [2009/07/14 02:34:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\GroupPolicy
  3384. [2009/07/14 02:34:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\GroupPolicyUsers
  3385. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\he-IL
  3386. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\hr-HR
  3387. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\hu-HU
  3388. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ias
  3389. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\icsxml
  3390. [2009/07/14 03:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\IME
  3391. [2009/07/14 02:36:55 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\inetsrv
  3392. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\it-IT
  3393. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ja-JP
  3394. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ko-KR
  3395. [2011/02/10 23:42:02 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\LogFiles
  3396. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\lt-LT
  3397. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\lv-LV
  3398. [2013/06/23 19:48:07 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Macromed
  3399. [2013/03/12 20:11:22 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\manifeststore
  3400. [2009/07/14 04:45:42 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Microsoft
  3401. [2013/11/12 14:04:52 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\migration
  3402. [2013/07/12 22:57:35 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\migwiz
  3403. [2013/11/13 12:51:47 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\MRT
  3404. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Msdtc
  3405. [2009/07/14 05:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\MUI
  3406. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\nb-NO
  3407. [2013/11/28 05:02:09 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\NDF
  3408. [2009/07/14 03:20:11 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\NetworkList
  3409. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\nl-NL
  3410. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\oobe
  3411. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pl-PL
  3412. [2009/07/14 05:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Printing_Admin_Scripts
  3413. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pt-BR
  3414. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\pt-PT
  3415. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ras
  3416. [2010/04/12 07:40:09 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Recovery
  3417. [2013/08/14 18:54:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\restore
  3418. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ro-RO
  3419. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\ru-RU
  3420. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Setup
  3421. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sk-SK
  3422. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sl-SI
  3423. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\slmgr
  3424. [2009/07/14 03:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\SMI
  3425. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Speech
  3426. [2013/07/12 22:57:00 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\spool
  3427. [2009/07/14 03:20:13 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\spp
  3428. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sppui
  3429. [2013/03/12 20:07:27 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\SPReview
  3430. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sr-Latn-CS
  3431. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sv-SE
  3432. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\sysprep
  3433. [2013/11/29 08:14:05 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Tasks
  3434. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\th-TH
  3435. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\tr-TR
  3436. [2013/03/12 20:12:10 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\uk-UA
  3437. [2013/08/14 18:54:47 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\Wat
  3438. [2013/08/14 19:01:05 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wbem
  3439. [2009/07/14 05:37:45 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WCN
  3440. [2011/11/06 15:58:06 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wdi
  3441. [2013/08/14 19:01:05 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\wfp
  3442. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WinBioDatabase
  3443. [2013/03/12 20:11:26 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WinBioPlugIns
  3444. [2009/07/14 05:32:38 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\WindowsPowerShell
  3445. [2009/07/14 03:20:14 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\winevt
  3446. [2009/07/14 05:37:46 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\winrm
  3447. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-CN
  3448. [2013/03/15 07:45:41 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-HK
  3449. [2013/03/15 07:45:40 | 000,000,000 | ---D | M] -- C:\Windows\sysnative\zh-TW
  3450.  
  3451. [color=#A23BEC]< %Temp%\smtmp\1\*.* >[/color]
  3452.  
  3453. [color=#A23BEC]< %Temp%\smtmp\2\*.* >[/color]
  3454.  
  3455. [color=#A23BEC]< %Temp%\smtmp\3\*.* >[/color]
  3456.  
  3457. [color=#A23BEC]< %Temp%\smtmp\4\*.* >[/color]
  3458.  
  3459. [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
  3460.  
  3461. [color=#A23BEC]< %systemroot%\syswow64\*.dll /lockedfiles >[/color]
  3462.  
  3463. [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]
  3464.  
  3465. [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /90 >[/color]
  3466.  
  3467. [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
  3468.  
  3469. [color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /90 >[/color]
  3470.  
  3471. [color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /lockedfiles >[/color]
  3472.  
  3473. [color=#A23BEC]< %SYSTEMDRIVE%\*. /rp /s >[/color]
  3474.  
  3475. [color=#A23BEC]< %systemroot%\assembly\tmp\*.* /S /MD5 >[/color]
  3476.  
  3477. [color=#A23BEC]< %systemroot%\assembly\temp\*.* /S /MD5 >[/color]
  3478.  
  3479. [color=#A23BEC]< %systemroot%\assembly\GAC\*.ini >[/color]
  3480.  
  3481. [color=#A23BEC]< %systemroot%\assembly\GAC_32\*.ini >[/color]
  3482.  
  3483. [color=#A23BEC]< %systemroot%\assembly\GAC_64\*.ini >[/color]
  3484.  
  3485. [color=#A23BEC]< %SystemRoot%\assembly\GAC_MSIL\*.ini >[/color]
  3486.  
  3487. [color=#A23BEC]< wsSystemRoot|l,n,u,@;True;False;True;$,{ /fn >[/color]
  3488.  
  3489. [color=#A23BEC]< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >[/color]
  3490.  
  3491. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color]
  3492. "" = PSFactoryBuffer
  3493. [HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32]
  3494. "" = %systemroot%\system32\wbem\wbemsvc.dll -- [2009/07/14 01:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation)
  3495. "ThreadingModel" = Both
  3496.  
  3497. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color]
  3498.  
  3499. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color]
  3500.  
  3501. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >[/color]
  3502.  
  3503. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >[/color]
  3504. "" = MruPidlList
  3505. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  3506. "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 01:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
  3507. "ThreadingModel" = Apartment
  3508.  
  3509. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} /s >[/color]
  3510. "" = Start Menu Pin
  3511. "ImplementsVerbs" = startpin;startunpin
  3512. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}\InProcServer32]
  3513. "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 01:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
  3514. "ThreadingModel" = Apartment
  3515.  
  3516. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} /s >[/color]
  3517. "" = PSFactoryBuffer
  3518. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32]
  3519. "" = %systemroot%\system32\wbem\wbemsvc.dll -- [2009/07/14 01:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation)
  3520. "ThreadingModel" = Both
  3521.  
  3522. [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color]
  3523. "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper
  3524. [HKEY_CLASSES_ROOT\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32]
  3525. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 12:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
  3526. "ThreadingModel" = Free
  3527.  
  3528. [color=#A23BEC]< HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color]
  3529. "" = ShellFolder for CD Burning
  3530. [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  3531. "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 01:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
  3532. "ThreadingModel" = Apartment
  3533. [HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\MergedFolder]
  3534. "Attributes" = 0x0
  3535. "AttributeMask" = 0xffffffff
  3536. "Location" = @shell32.dll,-12591 -- [2013/07/26 01:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
  3537. "ConflictOverlayIcon" = %SystemRoot%\system32\imageres.dll,-169 -- [2009/07/14 01:06:03 | 020,268,032 | ---- | M] (Microsoft Corporation)
  3538.  
  3539. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9} /s >[/color]
  3540.  
  3541. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F} /s >[/color]
  3542. "" = Microsoft WBEM _WbemFetchRefresherMgr Proxy Helper
  3543. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32]
  3544. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 12:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
  3545. "ThreadingModel" = Free
  3546.  
  3547. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor /s >[/color]
  3548. "CompletionChar" = 64
  3549. "DefaultColor" = 0
  3550. "EnableExtensions" = 1
  3551. "PathCompletionChar" = 64
  3552.  
  3553. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{118BEDCC-A901-4203-B4F2-ADCB957D1887} /s >[/color]
  3554.  
  3555. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{312BED3C-A901-4203-B4F2-ADCB957D1887} /s >[/color]
  3556.  
  3557. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{F12BE2CC-A901-4203-B4F2-ADCB957D1887} /s >[/color]
  3558.  
  3559. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{312BFDCE-A901-4203-B4F2-ADCB957D1887} /s >[/color]
  3560.  
  3561. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{212B3DCC-A901-4203-B4F2-ADCB957D1887} /s >[/color]
  3562.  
  3563. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{A12BEDCC-A901-4203-B4F2-ADCB957D1887} /s >[/color]
  3564.  
  3565. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{118BEDCA-A901-4203-B4F2-ADCB957D188F} /s >[/color]
  3566.  
  3567. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{118BEDCA-A901-4203-B4F2-ADCB957D188B} /s >[/color]
  3568.  
  3569. [color=#A23BEC]< HKEY_CLASSES_ROOT\CLSID\{3543619C-D563-43f7-95EA-4DA7E1CC396A} /s >[/color]
  3570.  
  3571. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3543619C-D563-43f7-95EA-4DA7E1CC396A} /s >[/color]
  3572.  
  3573. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3543619C-D563-43f7-95EA-4DA7E1CC396A} /s >[/color]
  3574.  
  3575. [color=#A23BEC]< HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers /s >[/color]
  3576. [HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem]
  3577. "" = {217FC9C0-3AEA-1069-A2DB-08002B30309D}
  3578. [HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing]
  3579. "" = {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
  3580.  
  3581. [color=#A23BEC]< HKEY_CLASSES_ROOT\Directory\Shellex\CopyHookHandlers\MSCopy /s >[/color]
  3582.  
  3583. [color=#A23BEC]< HKEY_CURRENT_USER\Software\Classes\Directory\shellex\CopyHookHandlers /s >[/color]
  3584.  
  3585. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers /s >[/color]
  3586. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem]
  3587. "" = {217FC9C0-3AEA-1069-A2DB-08002B30309D}
  3588. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing]
  3589. "" = {40dd6e20-7c17-11ce-a804-00aa003ca9f6}
  3590.  
  3591. [color=#A23BEC]< HKEY_CURRENT_USER\Software\MSOLoad /s >[/color]
  3592.  
  3593. [color=#A23BEC]< type C:\WINDOWS\system.ini >> test.txt /c >[/color]
  3594. ; for 16-bit app support
  3595. [386Enh]
  3596. woafont=dosapp.fon
  3597. EGA80WOA.FON=EGA80WOA.FON
  3598. EGA40WOA.FON=EGA40WOA.FON
  3599. CGA80WOA.FON=CGA80WOA.FON
  3600. CGA40WOA.FON=CGA40WOA.FON
  3601. [drivers]
  3602. wave=mmdrv.dll
  3603. timer=timer.drv
  3604. [mci]
  3605.  
  3606. [color=#A23BEC]< bcdedit /enum all /v >C:\boot.txt /c >[/color]
  3607.  
  3608. [color=#A23BEC]< type c:\diskreport.txt /c >[/color]
  3609. Microsoft DiskPart version 6.1.7601
  3610. Copyright (C) 1999-2008 Microsoft Corporation.
  3611. On computer: MARION-PC
  3612. Volume ### Ltr Label Fs Type Size Status Info
  3613. ---------- --- ----------- ----- ---------- ------- --------- --------
  3614. Volume 0 D DVD-ROM 0 B No Media
  3615. Volume 1 System Rese NTFS Partition 100 MB Healthy System
  3616. Volume 2 C NTFS Partition 596 GB Healthy Boot
  3617. Volume 3 E Removable 0 B No Media
  3618. Volume 4 H Removable 0 B No Media
  3619. Volume 5 I Removable 0 B No Media
  3620. Volume 6 J Removable 0 B No Media
  3621. Volume 7 K Removable 0 B No Media
  3622. Volume 8 F Iomega HDD NTFS Partition 298 GB Healthy
  3623.  
  3624. [color=#A23BEC]< MD5 for: AFD.SYS >[/color]
  3625. [2013/09/14 01:11:05 | 000,496,128 | ---- | M] (Microsoft Corporation) MD5=26EF7E0DF4EDCD898EB7A671529410B8 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.22457_none_366f8b668e482477\afd.sys
  3626. [2013/09/14 01:10:19 | 000,497,152 | ---- | M] (Microsoft Corporation) MD5=314C17917AC8523EC77A710215012A65 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.18264_none_35d81beb75355772\afd.sys
  3627. [2013/09/28 01:14:56 | 000,496,128 | ---- | M] (Microsoft Corporation) MD5=50AB05903CBEF298D135A943D4432E3C -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.22467_none_3664bb7a8e504068\afd.sys
  3628. [2013/09/28 01:09:10 | 000,497,152 | ---- | M] (Microsoft Corporation) MD5=79059559E89D06E8B80CE2944BE20228 -- C:\Windows\SysNative\drivers\afd.sys
  3629. [2013/09/28 01:09:10 | 000,497,152 | ---- | M] (Microsoft Corporation) MD5=79059559E89D06E8B80CE2944BE20228 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.18272_none_35cb4b6b753f40b5\afd.sys
  3630. [2010/11/20 09:23:34 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=D31DC7A16DEA4A9BAF179F3D6FBDB38C -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_360e4801750ca991\afd.sys
  3631.  
  3632. [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
  3633. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Documents and Settings\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T163337119900\internal_ide_channel\atapi.sys
  3634. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Documents and Settings\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T190434247306\internal_ide_channel\atapi.sys
  3635. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Documents and Settings\Marion\AppData\Roaming\DriverFinder\Backup\Standard Dual Channel PCI IDE Controller - 6.1.7600.16385\atapi.sys
  3636. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T163337119900\internal_ide_channel\atapi.sys
  3637. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T190434247306\internal_ide_channel\atapi.sys
  3638. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Users\Marion\AppData\Roaming\DriverFinder\Backup\Standard Dual Channel PCI IDE Controller - 6.1.7600.16385\atapi.sys
  3639. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
  3640. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_552ea5111ec825a6\atapi.sys
  3641. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
  3642. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
  3643. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_3b457059383c66e6\atapi.sys
  3644. [2009/07/14 01:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_3be7afc0514717fa\atapi.sys
  3645.  
  3646. [color=#A23BEC]< MD5 for: CSC.SYS >[/color]
  3647. [2010/11/20 09:27:13 | 000,514,560 | ---- | M] (Microsoft Corporation) MD5=54DA3DFD29ED9F1619B6F53F3CE55E49 -- C:\Windows\winsxs\amd64_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7601.17514_none_fc6e4e567286d457\csc.sys
  3648.  
  3649. [color=#A23BEC]< MD5 for: DFSC.SYS >[/color]
  3650. [2010/11/20 09:26:32 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9BB2EF44EAA163B29C4A4587887A0FE4 -- C:\Windows\SysNative\drivers\dfsc.sys
  3651. [2010/11/20 09:26:32 | 000,102,400 | ---- | M] (Microsoft Corporation) MD5=9BB2EF44EAA163B29C4A4587887A0FE4 -- C:\Windows\winsxs\amd64_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7601.17514_none_e5c0334cfcbb6f1f\dfsc.sys
  3652.  
  3653. [color=#A23BEC]< MD5 for: DISK.SYS >[/color]
  3654. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Documents and Settings\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T163337119900\gendisk\disk.sys
  3655. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Documents and Settings\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T190434247306\gendisk\disk.sys
  3656. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T163337119900\gendisk\disk.sys
  3657. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T190434247306\gendisk\disk.sys
  3658. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\drivers\disk.sys
  3659. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\DriverStore\FileRepository\disk.inf_amd64_neutral_10ce25bbc5a9cc43\disk.sys
  3660. [2009/07/14 01:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_55bb738b8ddd8a01\disk.sys
  3661.  
  3662. [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
  3663. [2011/02/26 05:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
  3664. [2011/02/25 06:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
  3665. [2011/02/25 06:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
  3666. [2011/02/26 06:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
  3667. [2010/11/20 12:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
  3668. [2011/02/25 05:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
  3669. [2011/02/25 05:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
  3670. [2010/11/20 13:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
  3671.  
  3672. [color=#A23BEC]< MD5 for: FASTFAT.SYS >[/color]
  3673. [2009/07/13 23:23:29 | 000,204,800 | ---- | M] (Microsoft Corporation) MD5=0ADC83218B66A6DB380C330836F3E36D -- C:\Windows\SysNative\drivers\fastfat.sys
  3674. [2009/07/13 23:23:29 | 000,204,800 | ---- | M] (Microsoft Corporation) MD5=0ADC83218B66A6DB380C330836F3E36D -- C:\Windows\winsxs\amd64_microsoft-windows-fat_31bf3856ad364e35_6.1.7600.16385_none_0aa81d2771152f86\fastfat.sys
  3675.  
  3676. [color=#A23BEC]< MD5 for: I8042PRT.SYS >[/color]
  3677. [2009/07/13 23:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\drivers\i8042prt.sys
  3678. [2009/07/13 23:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\i8042prt.sys
  3679. [2009/07/13 23:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_neutral_7a5f47d3150cc0eb\i8042prt.sys
  3680. [2009/07/13 23:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_f5747347ef9876bf\i8042prt.sys
  3681. [2009/07/13 23:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=FA55C73D4AFFA7EE23AC4BE53B4592D3 -- C:\Windows\winsxs\amd64_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_aa28fd23ec0c39f9\i8042prt.sys
  3682.  
  3683. [color=#A23BEC]< MD5 for: KBDCLASS.SYS >[/color]
  3684. [2009/07/14 01:48:04 | 000,050,768 | ---- | M] (Microsoft Corporation) MD5=BC02336F1CBA7DCC7D1213BB588A68A5 -- C:\Windows\SysNative\drivers\kbdclass.sys
  3685. [2009/07/14 01:48:04 | 000,050,768 | ---- | M] (Microsoft Corporation) MD5=BC02336F1CBA7DCC7D1213BB588A68A5 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\kbdclass.sys
  3686. [2009/07/14 01:48:04 | 000,050,768 | ---- | M] (Microsoft Corporation) MD5=BC02336F1CBA7DCC7D1213BB588A68A5 -- C:\Windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_f5747347ef9876bf\kbdclass.sys
  3687.  
  3688. [color=#A23BEC]< MD5 for: KBDHID.SYS >[/color]
  3689. [2010/11/20 10:33:25 | 000,033,280 | ---- | M] (Microsoft Corporation) MD5=0705EFF5B42A9DB58548EEC3B26BB484 -- C:\Windows\SysNative\drivers\kbdhid.sys
  3690. [2010/11/20 10:33:25 | 000,033,280 | ---- | M] (Microsoft Corporation) MD5=0705EFF5B42A9DB58548EEC3B26BB484 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_neutral_0684fdc43059f486\kbdhid.sys
  3691. [2010/11/20 10:33:25 | 000,033,280 | ---- | M] (Microsoft Corporation) MD5=0705EFF5B42A9DB58548EEC3B26BB484 -- C:\Windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_f5747347ef9876bf\kbdhid.sys
  3692.  
  3693. [color=#A23BEC]< MD5 for: LSASS.EXE >[/color]
  3694. [2009/07/14 01:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
  3695. [2011/11/17 06:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
  3696. [2013/09/25 01:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=4D71227301DD8D09097B9E4CC6527E5A -- C:\Windows\SysNative\lsass.exe
  3697. [2013/09/25 01:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=4D71227301DD8D09097B9E4CC6527E5A -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18270_none_042b9307739f26ed\lsass.exe
  3698. [2012/08/24 17:43:36 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=77119F1F9B492B260030C34F9BE327FA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22099_none_04a88ce28cc4eb33\lsass.exe
  3699. [2011/11/17 06:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
  3700. [2011/11/17 06:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17940_none_044c26dd7386a58a\lsass.exe
  3701. [2013/09/25 01:08:17 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=F021DAFB1F87616FCEBA159C2ED7042F -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22465_none_04c503168cb026a0\lsass.exe
  3702.  
  3703. [color=#A23BEC]< MD5 for: MOUCLASS.SYS >[/color]
  3704. [2009/07/14 01:48:27 | 000,049,216 | ---- | M] (Microsoft Corporation) MD5=7D27EA49F3C1F687D357E77A470AEA99 -- C:\Windows\SysNative\drivers\mouclass.sys
  3705. [2009/07/14 01:48:27 | 000,049,216 | ---- | M] (Microsoft Corporation) MD5=7D27EA49F3C1F687D357E77A470AEA99 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_neutral_7a5f47d3150cc0eb\mouclass.sys
  3706. [2009/07/14 01:48:27 | 000,049,216 | ---- | M] (Microsoft Corporation) MD5=7D27EA49F3C1F687D357E77A470AEA99 -- C:\Windows\winsxs\amd64_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_aa28fd23ec0c39f9\mouclass.sys
  3707.  
  3708. [color=#A23BEC]< MD5 for: MOUHID.SYS >[/color]
  3709. [2009/07/14 00:00:20 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D3BF052C40B0C4166D9FD86A4288C1E6 -- C:\Windows\SysNative\drivers\mouhid.sys
  3710. [2009/07/14 00:00:20 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D3BF052C40B0C4166D9FD86A4288C1E6 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_neutral_7a5f47d3150cc0eb\mouhid.sys
  3711. [2009/07/14 00:00:20 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D3BF052C40B0C4166D9FD86A4288C1E6 -- C:\Windows\winsxs\amd64_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_aa28fd23ec0c39f9\mouhid.sys
  3712.  
  3713. [color=#A23BEC]< MD5 for: NETBT.SYS >[/color]
  3714. [2010/11/20 09:23:20 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=09594D1089C523423B32A4229263F068 -- C:\Windows\SysNative\drivers\netbt.sys
  3715. [2010/11/20 09:23:20 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=09594D1089C523423B32A4229263F068 -- C:\Windows\winsxs\amd64_microsoft-windows-netbt_31bf3856ad364e35_6.1.7601.17514_none_be8acdd10de3b1a6\netbt.sys
  3716.  
  3717. [color=#A23BEC]< MD5 for: SERIAL.SYS >[/color]
  3718. [2009/07/14 00:00:40 | 000,094,208 | ---- | M] (Brother Industries Ltd.) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\SysNative\drivers\serial.sys
  3719. [2009/07/14 00:00:40 | 000,094,208 | ---- | M] (Brother Industries Ltd.) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\SysNative\DriverStore\FileRepository\msports.inf_amd64_neutral_fdcfb86ce78678d1\serial.sys
  3720. [2009/07/14 00:00:40 | 000,094,208 | ---- | M] (Brother Industries Ltd.) MD5=C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 -- C:\Windows\winsxs\amd64_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_548ca258d20f4ada\serial.sys
  3721.  
  3722. [color=#A23BEC]< MD5 for: SERVICES.EXE >[/color]
  3723. [2009/07/14 01:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
  3724. [2009/07/14 01:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
  3725.  
  3726. [color=#A23BEC]< MD5 for: SMSS.EXE >[/color]
  3727. [2009/07/14 01:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
  3728. [2013/03/19 02:57:17 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=498E2A20E145199709CD100CDBA8603D -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22280_none_0a9a7b3b492b4d05\smss.exe
  3729. [2013/08/29 01:04:30 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=B2B31D4C79EFD883097FA24D02E79C12 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22436_none_0ad6905f48fd53a8\smss.exe
  3730. [2013/08/02 05:06:34 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=CB5DA3E44456D1084BCD87F5B1B3152B -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22411_none_0ae72ec548f19d13\smss.exe
  3731. [2013/03/19 03:06:33 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0371DE302FFFF8F086661611BE60848 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18113_none_0a5f8ec22fd235a9\smss.exe
  3732. [2013/08/02 00:59:09 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0970A4BC8395659C22BF53D0FADF16F -- C:\Windows\SysNative\smss.exe
  3733. [2013/08/02 00:59:09 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0970A4BC8395659C22BF53D0FADF16F -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18229_none_0a5ac2782fd4e6cb\smss.exe
  3734.  
  3735. [color=#A23BEC]< MD5 for: SPLDR.SYS >[/color]
  3736. [2009/07/14 01:45:55 | 000,019,008 | ---- | M] (Microsoft Corporation) MD5=B9E31E5CACDFE584F34F730A677803F9 -- C:\Windows\SysNative\drivers\spldr.sys
  3737. [2009/07/14 01:45:55 | 000,019,008 | ---- | M] (Microsoft Corporation) MD5=B9E31E5CACDFE584F34F730A677803F9 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59\spldr.sys
  3738.  
  3739. [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
  3740. [2009/07/14 01:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
  3741. [2009/07/14 01:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
  3742. [2009/07/14 01:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
  3743. [2009/07/14 01:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
  3744.  
  3745. [color=#A23BEC]< MD5 for: TCPIP.SYS >[/color]
  3746. [2012/10/03 17:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
  3747. [2013/05/08 06:14:42 | 001,900,392 | ---- | M] (Microsoft Corporation) MD5=3E94650745D4DAB67E161F5F32CEA597 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22319_none_11d29984961f0be0\tcpip.sys
  3748. [2013/09/08 02:30:37 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=40AF23633D197905F03AB5628C558C51 -- C:\Windows\SysNative\drivers\tcpip.sys
  3749. [2013/09/08 02:30:37 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=40AF23633D197905F03AB5628C558C51 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18254_none_1118bb977d265d27\tcpip.sys
  3750. [2010/11/20 13:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
  3751. [2013/09/07 02:27:48 | 001,896,896 | ---- | M] (Microsoft Corporation) MD5=75F9106B74585D38C8FF6BB5CAD262D7 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22444_none_11ad2a34963bde27\tcpip.sys
  3752. [2012/08/22 18:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
  3753. [2013/05/08 06:39:01 | 001,910,632 | ---- | M] (Microsoft Corporation) MD5=9849EA3843A2ADBDD1497E97A85D8CAE -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18148_none_11278ac57d1aa96b\tcpip.sys
  3754. [2013/07/06 05:20:38 | 001,900,992 | ---- | M] (Microsoft Corporation) MD5=B27F13153343BC37A27EAE01634D94E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_1190b9b296509a2f\tcpip.sys
  3755. [2013/01/03 06:00:54 | 001,913,192 | ---- | M] (Microsoft Corporation) MD5=B62A953F2BF3922C8764A29C34A22899 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_112187237d20143a\tcpip.sys
  3756. [2013/01/04 05:47:43 | 001,901,416 | ---- | M] (Microsoft Corporation) MD5=B8C1AAC0523E1C33AEB0EF7572144BA2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_11dd678a9616f2c8\tcpip.sys
  3757. [2012/10/03 17:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
  3758. [2013/07/06 06:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_114dcae97cfeb81b\tcpip.sys
  3759. [2012/08/22 18:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
  3760.  
  3761. [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
  3762. [2010/11/20 12:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
  3763. [2010/11/20 12:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
  3764. [2010/11/20 13:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
  3765. [2010/11/20 13:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
  3766.  
  3767. [color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color]
  3768. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Documents and Settings\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T163337119900\storage\volume\volsnap.sys
  3769. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Documents and Settings\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T190434247306\storage\volume\volsnap.sys
  3770. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T163337119900\storage\volume\volsnap.sys
  3771. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Users\Marion\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Backups\20130929T190434247306\storage\volume\volsnap.sys
  3772. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\SysNative\drivers\volsnap.sys
  3773. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_neutral_df8bea40ac96ca21\volsnap.sys
  3774. [2010/11/20 13:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) MD5=0D08D2F3B3FF84E433346669B5E0F639 -- C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7601.17514_none_73dcbcf012b4850e\volsnap.sys
  3775.  
  3776. [color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
  3777. [2009/07/14 01:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
  3778. [2009/07/14 01:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
  3779. [2009/07/14 01:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
  3780. [2009/07/14 01:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
  3781.  
  3782. [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
  3783. [2010/11/20 13:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
  3784. [2010/11/20 13:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
  3785.  
  3786. [color=#E56717]========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[/color]
  3787. [C:\Documents and Settings\All Users\Application Data] -> C:\ProgramData -> Junction
  3788. [C:\Documents and Settings\All Users\Desktop] -> C:\Users\Public\Desktop -> Junction
  3789. [C:\Documents and Settings\All Users\Documents] -> C:\Users\Public\Documents -> Junction
  3790. [C:\Documents and Settings\All Users\Favorites] -> C:\Users\Public\Favorites -> Junction
  3791. [C:\Documents and Settings\All Users\Start Menu] -> C:\ProgramData\Microsoft\Windows\Start Menu -> Junction
  3792. [C:\Documents and Settings\All Users\Templates] -> C:\ProgramData\Microsoft\Windows\Templates -> Junction
  3793. [C:\Documents and Settings\All Users] -> -> Unknown point type
  3794. [C:\Documents and Settings\Default User] -> C:\Users\Default -> Junction
  3795. [C:\Documents and Settings\Default\AppData\Local\Application Data] -> C:\Users\Default\AppData\Local -> Junction
  3796. [C:\Documents and Settings\Default\AppData\Local\History] -> C:\Users\Default\AppData\Local\Microsoft\Windows\History -> Junction
  3797. [C:\Documents and Settings\Default\AppData\Local\Temporary Internet Files] -> C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3798. [C:\Documents and Settings\Default\Application Data] -> C:\Users\Default\AppData\Roaming -> Junction
  3799. [C:\Documents and Settings\Default\Cookies] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3800. [C:\Documents and Settings\Default\Documents\My Music] -> C:\Users\Default\Music -> Junction
  3801. [C:\Documents and Settings\Default\Documents\My Pictures] -> C:\Users\Default\Pictures -> Junction
  3802. [C:\Documents and Settings\Default\Documents\My Videos] -> C:\Users\Default\Videos -> Junction
  3803. [C:\Documents and Settings\Default\Local Settings] -> C:\Users\Default\AppData\Local -> Junction
  3804. [C:\Documents and Settings\Default\My Documents] -> C:\Users\Default\Documents -> Junction
  3805. [C:\Documents and Settings\Default\NetHood] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3806. [C:\Documents and Settings\Default\PrintHood] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3807. [C:\Documents and Settings\Default\Recent] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3808. [C:\Documents and Settings\Default\SendTo] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3809. [C:\Documents and Settings\Default\Start Menu] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3810. [C:\Documents and Settings\Default\Templates] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3811. [C:\Documents and Settings\Marion\AppData\Local\Application Data] -> C:\Users\Marion\AppData\Local -> Junction
  3812. [C:\Documents and Settings\Marion\AppData\Local\History] -> C:\Users\Marion\AppData\Local\Microsoft\Windows\History -> Junction
  3813. [C:\Documents and Settings\Marion\AppData\Local\Temporary Internet Files] -> C:\Users\Marion\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3814. [C:\Documents and Settings\Marion\Application Data] -> C:\Users\Marion\AppData\Roaming -> Junction
  3815. [C:\Documents and Settings\Marion\Cookies] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3816. [C:\Documents and Settings\Marion\Documents\My Music] -> C:\Users\Marion\Music -> Junction
  3817. [C:\Documents and Settings\Marion\Documents\My Pictures] -> C:\Users\Marion\Pictures -> Junction
  3818. [C:\Documents and Settings\Marion\Documents\My Videos] -> C:\Users\Marion\Videos -> Junction
  3819. [C:\Documents and Settings\Marion\Local Settings] -> C:\Users\Marion\AppData\Local -> Junction
  3820. [C:\Documents and Settings\Marion\My Documents] -> C:\Users\Marion\Documents -> Junction
  3821. [C:\Documents and Settings\Marion\NetHood] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3822. [C:\Documents and Settings\Marion\PrintHood] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3823. [C:\Documents and Settings\Marion\Recent] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3824. [C:\Documents and Settings\Marion\SendTo] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3825. [C:\Documents and Settings\Marion\Start Menu] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3826. [C:\Documents and Settings\Marion\Templates] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3827. [C:\Documents and Settings\Public\Documents\My Music] -> C:\Users\Public\Music -> Junction
  3828. [C:\Documents and Settings\Public\Documents\My Pictures] -> C:\Users\Public\Pictures -> Junction
  3829. [C:\Documents and Settings\Public\Documents\My Videos] -> C:\Users\Public\Videos -> Junction
  3830. [C:\Documents and Settings\UpdatusUser\AppData\Local\Application Data] -> C:\Users\UpdatusUser\AppData\Local -> Junction
  3831. [C:\Documents and Settings\UpdatusUser\AppData\Local\History] -> C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History -> Junction
  3832. [C:\Documents and Settings\UpdatusUser\AppData\Local\Temporary Internet Files] -> C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3833. [C:\Documents and Settings\UpdatusUser\Application Data] -> C:\Users\UpdatusUser\AppData\Roaming -> Junction
  3834. [C:\Documents and Settings\UpdatusUser\Cookies] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3835. [C:\Documents and Settings\UpdatusUser\Documents\My Music] -> C:\Users\UpdatusUser\Music -> Junction
  3836. [C:\Documents and Settings\UpdatusUser\Documents\My Pictures] -> C:\Users\UpdatusUser\Pictures -> Junction
  3837. [C:\Documents and Settings\UpdatusUser\Documents\My Videos] -> C:\Users\UpdatusUser\Videos -> Junction
  3838. [C:\Documents and Settings\UpdatusUser\Local Settings] -> C:\Users\UpdatusUser\AppData\Local -> Junction
  3839. [C:\Documents and Settings\UpdatusUser\My Documents] -> C:\Users\UpdatusUser\Documents -> Junction
  3840. [C:\Documents and Settings\UpdatusUser\NetHood] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3841. [C:\Documents and Settings\UpdatusUser\PrintHood] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3842. [C:\Documents and Settings\UpdatusUser\Recent] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3843. [C:\Documents and Settings\UpdatusUser\SendTo] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3844. [C:\Documents and Settings\UpdatusUser\Start Menu] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3845. [C:\Documents and Settings\UpdatusUser\Templates] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3846. [C:\Documents and Settings] -> C:\Users -> Junction
  3847. [C:\ProgramData\Application Data] -> C:\ProgramData -> Junction
  3848. [C:\ProgramData\Desktop] -> C:\Users\Public\Desktop -> Junction
  3849. [C:\ProgramData\Documents] -> C:\Users\Public\Documents -> Junction
  3850. [C:\ProgramData\Favorites] -> C:\Users\Public\Favorites -> Junction
  3851. [C:\ProgramData\Start Menu] -> C:\ProgramData\Microsoft\Windows\Start Menu -> Junction
  3852. [C:\ProgramData\Templates] -> C:\ProgramData\Microsoft\Windows\Templates -> Junction
  3853. [C:\Users\All Users\Application Data] -> C:\ProgramData -> Junction
  3854. [C:\Users\All Users\Desktop] -> C:\Users\Public\Desktop -> Junction
  3855. [C:\Users\All Users\Documents] -> C:\Users\Public\Documents -> Junction
  3856. [C:\Users\All Users\Favorites] -> C:\Users\Public\Favorites -> Junction
  3857. [C:\Users\All Users\Start Menu] -> C:\ProgramData\Microsoft\Windows\Start Menu -> Junction
  3858. [C:\Users\All Users\Templates] -> C:\ProgramData\Microsoft\Windows\Templates -> Junction
  3859. [C:\Users\All Users] -> -> Unknown point type
  3860. [C:\Users\Default User] -> C:\Users\Default -> Junction
  3861. [C:\Users\Default\AppData\Local\Application Data] -> C:\Users\Default\AppData\Local -> Junction
  3862. [C:\Users\Default\AppData\Local\History] -> C:\Users\Default\AppData\Local\Microsoft\Windows\History -> Junction
  3863. [C:\Users\Default\AppData\Local\Temporary Internet Files] -> C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3864. [C:\Users\Default\Application Data] -> C:\Users\Default\AppData\Roaming -> Junction
  3865. [C:\Users\Default\Cookies] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3866. [C:\Users\Default\Documents\My Music] -> C:\Users\Default\Music -> Junction
  3867. [C:\Users\Default\Documents\My Pictures] -> C:\Users\Default\Pictures -> Junction
  3868. [C:\Users\Default\Documents\My Videos] -> C:\Users\Default\Videos -> Junction
  3869. [C:\Users\Default\Local Settings] -> C:\Users\Default\AppData\Local -> Junction
  3870. [C:\Users\Default\My Documents] -> C:\Users\Default\Documents -> Junction
  3871. [C:\Users\Default\NetHood] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3872. [C:\Users\Default\PrintHood] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3873. [C:\Users\Default\Recent] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3874. [C:\Users\Default\SendTo] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3875. [C:\Users\Default\Start Menu] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3876. [C:\Users\Default\Templates] -> C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3877. [C:\Users\Marion\AppData\Local\Application Data] -> C:\Users\Marion\AppData\Local -> Junction
  3878. [C:\Users\Marion\AppData\Local\History] -> C:\Users\Marion\AppData\Local\Microsoft\Windows\History -> Junction
  3879. [C:\Users\Marion\AppData\Local\Temporary Internet Files] -> C:\Users\Marion\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3880. [C:\Users\Marion\Application Data] -> C:\Users\Marion\AppData\Roaming -> Junction
  3881. [C:\Users\Marion\Cookies] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3882. [C:\Users\Marion\Documents\My Music] -> C:\Users\Marion\Music -> Junction
  3883. [C:\Users\Marion\Documents\My Pictures] -> C:\Users\Marion\Pictures -> Junction
  3884. [C:\Users\Marion\Documents\My Videos] -> C:\Users\Marion\Videos -> Junction
  3885. [C:\Users\Marion\Local Settings] -> C:\Users\Marion\AppData\Local -> Junction
  3886. [C:\Users\Marion\My Documents] -> C:\Users\Marion\Documents -> Junction
  3887. [C:\Users\Marion\NetHood] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3888. [C:\Users\Marion\PrintHood] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3889. [C:\Users\Marion\Recent] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3890. [C:\Users\Marion\SendTo] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3891. [C:\Users\Marion\Start Menu] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3892. [C:\Users\Marion\Templates] -> C:\Users\Marion\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3893. [C:\Users\Public\Documents\My Music] -> C:\Users\Public\Music -> Junction
  3894. [C:\Users\Public\Documents\My Pictures] -> C:\Users\Public\Pictures -> Junction
  3895. [C:\Users\Public\Documents\My Videos] -> C:\Users\Public\Videos -> Junction
  3896. [C:\Users\UpdatusUser\AppData\Local\Application Data] -> C:\Users\UpdatusUser\AppData\Local -> Junction
  3897. [C:\Users\UpdatusUser\AppData\Local\History] -> C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History -> Junction
  3898. [C:\Users\UpdatusUser\AppData\Local\Temporary Internet Files] -> C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3899. [C:\Users\UpdatusUser\Application Data] -> C:\Users\UpdatusUser\AppData\Roaming -> Junction
  3900. [C:\Users\UpdatusUser\Cookies] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3901. [C:\Users\UpdatusUser\Documents\My Music] -> C:\Users\UpdatusUser\Music -> Junction
  3902. [C:\Users\UpdatusUser\Documents\My Pictures] -> C:\Users\UpdatusUser\Pictures -> Junction
  3903. [C:\Users\UpdatusUser\Documents\My Videos] -> C:\Users\UpdatusUser\Videos -> Junction
  3904. [C:\Users\UpdatusUser\Local Settings] -> C:\Users\UpdatusUser\AppData\Local -> Junction
  3905. [C:\Users\UpdatusUser\My Documents] -> C:\Users\UpdatusUser\Documents -> Junction
  3906. [C:\Users\UpdatusUser\NetHood] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3907. [C:\Users\UpdatusUser\PrintHood] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3908. [C:\Users\UpdatusUser\Recent] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3909. [C:\Users\UpdatusUser\SendTo] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3910. [C:\Users\UpdatusUser\Start Menu] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3911. [C:\Users\UpdatusUser\Templates] -> C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3912. [C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3913. [C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
  3914. [C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3915. [C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
  3916. [C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3917. [C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
  3918. [C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
  3919. [C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
  3920. [C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3921. [C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
  3922. [C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3923. [C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3924. [C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3925. [C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3926. [C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3927. [C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3928. [C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3929. [C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
  3930. [C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
  3931. [C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
  3932. [C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
  3933. [C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
  3934. [C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
  3935. [C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
  3936. [C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
  3937. [C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
  3938. [C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
  3939. [C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
  3940. [C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
  3941. [C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
  3942. [C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
  3943. [C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
  3944.  
  3945. [color=#E56717]========== Alternate Data Streams ==========[/color]
  3946.  
  3947. @Alternate Data Stream - 249 bytes -> C:\Users\All Users\TEMP:F5E30F6A
  3948. @Alternate Data Stream - 249 bytes -> C:\ProgramData\TEMP:F5E30F6A
  3949. @Alternate Data Stream - 249 bytes -> C:\Documents and Settings\All Users\TEMP:F5E30F6A
  3950. @Alternate Data Stream - 238 bytes -> C:\Users\All Users\TEMP:CF75D88F
  3951. @Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:CF75D88F
  3952. @Alternate Data Stream - 238 bytes -> C:\Documents and Settings\All Users\TEMP:CF75D88F
  3953. @Alternate Data Stream - 236 bytes -> C:\Users\All Users\TEMP:FBA79096
  3954. @Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:FBA79096
  3955. @Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\TEMP:FBA79096
  3956. @Alternate Data Stream - 210 bytes -> C:\Users\All Users\TEMP:70B3C619
  3957. @Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:70B3C619
  3958. @Alternate Data Stream - 210 bytes -> C:\Documents and Settings\All Users\TEMP:70B3C619
  3959. @Alternate Data Stream - 197 bytes -> C:\Users\All Users\TEMP:114BD271
  3960. @Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:114BD271
  3961. @Alternate Data Stream - 197 bytes -> C:\Documents and Settings\All Users\TEMP:114BD271
  3962. @Alternate Data Stream - 195 bytes -> C:\Users\All Users\TEMP:7BA6D322
  3963. @Alternate Data Stream - 195 bytes -> C:\ProgramData\TEMP:7BA6D322
  3964. @Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\TEMP:7BA6D322
  3965. @Alternate Data Stream - 134 bytes -> C:\Users\All Users\TEMP:2CB9631F
  3966. @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:2CB9631F
  3967. @Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\TEMP:2CB9631F
  3968.  
  3969. < End of report >
  3970. )
Add Comment
Please, Sign In to add comment