TechSpot

[A] Same Sirefef virus

Inactive
By Seeker_lang
Jul 9, 2012
  1. Having the same Sirefef virus, might be linked to the fake adobe update..not sure.
    Having the same symptoms of everyone else, with the 1 minute restart after MSE finds it, so I have MSE disabled at the moment, and my firewall has been disabled by its own.

    Firefox also redirects me randomly sometimes.

    I have seen some posts with the start up process so I have downloaded FRST64 and will come back soon with the log.

    Thanks
     
  2. Broni

    Broni Malware Annihilator Posts: 48,032   +271

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ==========================================================

    What Windows version is it?
     
  3. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    Scan result of Farbar Recovery Scan Tool Version: 08-07-2012
    Ran by SYSTEM at 09-07-2012 00:47:42
    Running from F:\
    Windows 7 Home Premium (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ========================== Registry (Whitelisted) =============

    HKLM\...\Run: [set] c:\programdata\SetWallpaper.cmd [x]
    HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1216808 2007-12-06] (Synaptics, Inc.)
    HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7573024 2009-03-24] (Realtek Semiconductor)
    HKLM\...\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-03-24] (Realtek Semiconductor Corp.)
    HKLM\...\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE [x]
    HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [1126400 2008-09-30] (ATK)
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-11] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [37232 2008-06-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2008-08-14] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe [33136 2009-08-24] ()
    HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [159744 2008-08-19] (ASUS)
    HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [8392704 2009-03-04] (ASUS)
    HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [98304 2008-08-18] (ASUS)
    HKLM-x32\...\Run: [razer] "C:\Program Files (x86)\Razer Pro Solutions\ProClick v1.6\razerhid.exe" [126976 2007-03-02] ()
    HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [218408 2008-12-03] (CyberLink Corp.)
    HKLM-x32\...\Run: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe [108496 2011-01-07] (Threat Expert Ltd.)
    HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [397992 2011-07-26] (Ask)
    HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
    HKLM-x32\...\Run: [] [x]
    HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1996200 2012-06-27] (LogMeIn Inc.)
    HKLM-x32\...\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [1312080 2009-09-10] (Malwarebytes Corporation)
    HKU\Brian\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [163328 2009-07-13] (Microsoft Corporation)
    HKU\Brian\...\Run: [Google Update] "C:\Users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe" /c [135664 2010-01-05] (Google Inc.)
    HKU\Brian\...\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup [44544 2009-07-13] (Microsoft Corporation)
    HKU\Brian\...\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe" [495616 2007-09-02] ()
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\FancyStart daemon.lnk
    ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{DC905847-D537-427F-BF91-47CC7ACCDE58}\_DF3A81D17C478A2A6C60A5.exe ()
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

    ==================== Services (Whitelisted) ======

    3 Adobe Version Cue CS4; "C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" -win32service [284016 2008-08-15] (Adobe Systems Incorporated)
    2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [100920 2008-08-13] ()
    2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] ()
    2 Browser Defender Update Service; "C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe" [247760 2011-01-07] (Threat Expert Ltd.)
    2 Cepstral License Server; "C:\Program Files\Cepstral\bin\CepstralLicSrv.exe" [121856 2009-09-29] (Cepstral, LLC)
    2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [11776 2010-07-05] ()
    2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [2369960 2012-06-27] (LogMeIn Inc.)
    2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
    3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
    2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75064 2010-09-23] ()
    3 sdAuxService; C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [366840 2010-03-15] (PC Tools)
    3 sdCoreService; C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [1150936 2010-11-19] (PC Tools)
    3 TVersityMediaServer; "C:\Program Files (x86)\TVersity\Media Server\MediaServer.exe" [884736 2009-09-22] ()
    2 MSSQL$BWDATOOLSET; "C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sBWDATOOLSET [x]

    ========================== Drivers (Whitelisted) =============

    2 ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
    2 atksgt; C:\Windows\System32\Drivers\atksgt.sys [314016 2010-08-03] ()
    2 Dokan; C:\Windows\System32\Drivers\Dokan.sys [106888 2010-07-05] (Windows (R) Win 7 DDK provider)
    1 fanio; C:\Windows\SysWow64\Drivers\fanio.sys [14464 2007-02-16] (Christian Diefer)
    1 FileDisk; C:\Windows\SysWow64\Drivers\FileDisk.sys [9728 2004-05-29] (iolo technologies, LLC (based on original work by Bo Brantén))
    3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
    3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [17464 2008-06-02] ( )
    3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [17152 2011-02-04] ()
    0 Lbd; C:\Windows\System32\Drivers\Lbd.sys [69152 2010-12-03] (Lavasoft AB)
    2 lirsgt; C:\Windows\System32\Drivers\lirsgt.sys [43680 2010-08-03] ()
    3 MTsensor; C:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2006-10-28] ()
    0 PCTCore; C:\Windows\System32\drivers\PCTCore64.sys [257232 2010-12-10] (PC Tools)
    0 pctDS; C:\Windows\System32\drivers\pctDS64.sys [452872 2010-06-29] (PC Tools)
    0 pctEFA; C:\Windows\System32\drivers\pctEFA64.sys [816016 2010-07-16] (PC Tools)
    3 Razerlow; C:\Windows\System32\Drivers\Razerlow.sys [21120 2005-11-07] (Razer (Asia-Pacific) Pte Ltd)
    3 RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [19952 2010-01-07] ()
    3 SNP2UVC; C:\Windows\System32\Drivers\SNP2UVC.sys [1821952 2008-10-08] ()
    0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider)
    4 sptd; C:\Windows\System32\Drivers\sptd.sys [871408 2009-10-24] (Duplex Secure Ltd.)
    1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
    3 WinRing0_1_2_0; \??\C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
    1 dzwteeuj; \??\C:\Windows\system32\drivers\dzwteeuj.sys [x]
    1 MpKsl6c0ba002; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A8BE309E-F0EF-4B3F-9532-AC8BD1C21BF3}\MpKsl6c0ba002.sys [x]
    3 WINIO; \??\C:\Users\Brian\Desktop\winio.sys [x]

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============

    2012-07-08 20:38 - 2012-07-08 20:39 - 01433543 ____A (Farbar) C:\Users\Brian\Desktop\FRST64.exe
    2012-07-08 20:21 - 2012-07-08 20:21 - 00888748 ____A (Farbar) C:\Users\Brian\Desktop\FRST.exe
    2012-07-08 20:07 - 2012-07-08 20:07 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Brian\Downloads\tdsskiller(1).exe
    2012-07-08 19:56 - 2012-07-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6EB72CD01B12975D
    2012-07-08 19:53 - 2010-09-07 11:39 - 00150392 ____A (Sysinternals - www.sysinternals.com) C:\Users\Brian\Desktop\junction.exe
    2012-07-08 19:53 - 2006-07-28 05:32 - 00007005 ____N C:\Users\Brian\Desktop\Eula.txt
    2012-07-08 19:52 - 2012-07-08 19:53 - 00079623 ____A C:\Users\Brian\Downloads\Junction.zip
    2012-07-08 19:31 - 2012-07-08 19:34 - 00072811 ____A C:\Users\Brian\Downloads\yorkyt.exe.log
    2012-07-08 19:31 - 2012-07-08 19:31 - 01415784 ____A C:\Users\Brian\Downloads\yorkyt.exe
    2012-07-08 19:30 - 2012-07-08 19:30 - 00138120 ____A (ESET) C:\Users\Brian\Downloads\ESETSirefefRemover(1).exe
    2012-07-08 19:30 - 2012-07-08 19:30 - 00137096 ____A (ESET) C:\Users\Brian\Downloads\ESETSirefefRemover.exe
    2012-07-08 19:16 - 2012-07-08 19:16 - 00302592 ____A C:\Users\Brian\Downloads\7zjs7b55.exe
    2012-07-08 19:13 - 2012-07-08 19:13 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Brian\Downloads\tdsskiller.exe
    2012-07-08 18:58 - 2012-07-08 18:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2452A660AE3846DC
    2012-07-08 18:39 - 2012-07-08 18:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BE5EC8885EDDD163
    2012-07-08 18:39 - 2012-07-08 18:39 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\otlntjnh.sys
    2012-07-08 18:33 - 2012-07-08 18:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.226BA1B45B29EFB8
    2012-07-08 15:25 - 2012-07-08 15:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.330E192805BA92FD
    2012-07-08 15:21 - 2012-07-08 15:21 - 00229548 ____A C:\Users\Brian\Downloads\1055.BFE.reg
    2012-07-08 15:21 - 2012-07-08 15:21 - 00006396 ____A C:\Users\Brian\Downloads\0677.mpssvc.reg
    2012-07-08 15:10 - 2012-07-08 15:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E952AF82E1F48A2D
    2012-07-08 15:04 - 2012-07-08 15:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FDC7281CCF95F858
    2012-07-08 14:58 - 2012-07-08 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.988ACBBC3A10BE2D
    2012-07-08 14:43 - 2012-07-08 14:44 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-07-08 14:43 - 2012-07-08 14:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-07-08 14:41 - 2012-07-08 14:41 - 00001020 ____A C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    2012-07-08 14:41 - 2009-09-10 10:54 - 00038224 ____A (Malwarebytes Corporation) C:\Windows\SysWOW64\Drivers\mbamswissarmy.sys
    2012-07-08 14:41 - 2009-09-10 10:53 - 00022104 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-07-08 14:40 - 2012-07-08 14:40 - 00004057 ____A C:\Windows\wininit.ini
    2012-07-08 13:30 - 2012-07-08 13:30 - 00000000 ____D C:\Users\Brian\AppData\Local\Macromedia
    2012-07-08 11:58 - 2012-07-08 11:58 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2012-07-08 11:48 - 2012-07-08 14:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-07-08 11:48 - 2012-07-08 11:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-07-08 11:48 - 2012-07-08 11:48 - 00000000 ____D C:\Windows\System32\Macromed
    2012-07-07 23:43 - 2012-07-07 23:43 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
    2012-06-29 10:56 - 2012-06-29 10:56 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
    2012-06-26 18:34 - 2012-06-26 18:34 - 00001181 ____A C:\Users\UpdatusUser\Desktop\Perfect World International.lnk
    2012-06-26 18:34 - 2012-06-26 18:34 - 00001181 ____A C:\Users\Guest\Desktop\Perfect World International.lnk
    2012-06-26 18:34 - 2012-06-26 18:34 - 00001181 ____A C:\Users\Brian\Desktop\Perfect World International.lnk
    2012-06-26 18:22 - 2012-06-26 18:22 - 00000000 ____D C:\Perfect World Entertainment
    2012-06-26 18:11 - 2012-06-26 18:11 - 00000000 ____D C:\Users\Brian\Desktop\PWI
    2012-06-26 18:11 - 2012-06-26 18:09 - 00258352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\unicows.dll
    2012-06-26 17:10 - 2012-06-26 17:10 - 02167720 ____A C:\Users\Brian\Downloads\PWI_v639_Installer.exe
    2012-06-24 16:36 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-24 16:36 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-24 16:36 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-24 16:36 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-24 16:35 - 2012-06-02 11:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-24 16:35 - 2012-06-02 11:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-13 12:53 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-13 12:53 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-13 12:53 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-13 12:53 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-13 12:53 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-13 12:53 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-13 12:53 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-13 12:53 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-13 12:53 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-13 12:53 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-13 12:53 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-13 12:53 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-13 12:53 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-13 12:53 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-13 12:53 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-13 12:53 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-13 12:53 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-13 12:53 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-13 12:53 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-13 12:52 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-13 12:52 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-13 12:52 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-13 12:52 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-13 12:52 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-13 12:52 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-13 12:52 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-13 12:52 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-13 12:52 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-12 17:22 - 2012-07-05 22:36 - 00000000 ____D C:\Users\Brian\Documents\Diablo III
    2012-06-12 17:18 - 2012-06-12 17:19 - 00000000 ____D C:\Users\All Users\Battle.net
    2012-06-12 16:33 - 2012-06-26 16:10 - 00000000 ____D C:\Program Files (x86)\Diablo III
    2012-06-12 16:33 - 2012-06-12 17:07 - 00001200 ____A C:\Users\Public\Desktop\Diablo III.lnk
    2012-06-12 14:57 - 2012-05-14 17:32 - 03144192 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-12 14:57 - 2012-05-04 02:52 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-06-12 14:57 - 2012-05-04 02:08 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-06-12 14:57 - 2012-05-04 02:08 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-06-12 14:57 - 2012-05-01 21:32 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-06-12 14:57 - 2012-04-27 19:50 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-06-12 14:57 - 2012-04-25 21:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-06-12 14:57 - 2012-04-25 21:34 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-06-12 14:57 - 2012-04-25 21:28 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-06-12 14:57 - 2012-04-07 04:18 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-06-12 14:57 - 2012-04-07 03:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-06-12 14:56 - 2012-04-23 21:59 - 01460224 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-06-12 14:56 - 2012-04-23 21:59 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-06-12 14:56 - 2012-04-23 21:59 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-06-12 14:56 - 2012-04-23 20:47 - 01156608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-06-12 14:56 - 2012-04-23 20:47 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-06-12 14:56 - 2012-04-23 20:47 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll


    ============ 3 Months Modified Files ========================

    2012-07-08 20:45 - 2009-11-24 18:35 - 01708464 ____A C:\Windows\WindowsUpdate.log
    2012-07-08 20:43 - 2009-11-24 16:56 - 00011104 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-07-08 20:43 - 2009-11-24 16:56 - 00011104 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-07-08 20:39 - 2012-07-08 20:38 - 01433543 ____A (Farbar) C:\Users\Brian\Desktop\FRST64.exe
    2012-07-08 20:39 - 2010-01-06 22:50 - 00007595 ____A C:\Users\Brian\AppData\Local\resmon.resmoncfg
    2012-07-08 20:34 - 2010-12-06 16:28 - 00000402 ____A C:\Windows\Tasks\Free File Viewer Update Checker.job
    2012-07-08 20:34 - 2009-10-24 13:07 - 00045056 ____A C:\Windows\System32\acovcnt.exe
    2012-07-08 20:34 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-07-08 20:33 - 2010-09-19 04:26 - 02469426 ____A C:\Windows\setupact.log
    2012-07-08 20:21 - 2012-07-08 20:21 - 00888748 ____A (Farbar) C:\Users\Brian\Desktop\FRST.exe
    2012-07-08 20:07 - 2012-07-08 20:07 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Brian\Downloads\tdsskiller(1).exe
    2012-07-08 19:56 - 2012-07-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6EB72CD01B12975D
    2012-07-08 19:53 - 2012-07-08 19:52 - 00079623 ____A C:\Users\Brian\Downloads\Junction.zip
    2012-07-08 19:53 - 2010-01-05 19:47 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2418110221-3350712148-3301581529-1000UA.job
    2012-07-08 19:34 - 2012-07-08 19:31 - 00072811 ____A C:\Users\Brian\Downloads\yorkyt.exe.log
    2012-07-08 19:31 - 2012-07-08 19:31 - 01415784 ____A C:\Users\Brian\Downloads\yorkyt.exe
    2012-07-08 19:30 - 2012-07-08 19:30 - 00138120 ____A (ESET) C:\Users\Brian\Downloads\ESETSirefefRemover(1).exe
    2012-07-08 19:30 - 2012-07-08 19:30 - 00137096 ____A (ESET) C:\Users\Brian\Downloads\ESETSirefefRemover.exe
    2012-07-08 19:16 - 2012-07-08 19:16 - 00302592 ____A C:\Users\Brian\Downloads\7zjs7b55.exe
    2012-07-08 19:13 - 2012-07-08 19:13 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Brian\Downloads\tdsskiller.exe
    2012-07-08 18:58 - 2012-07-08 18:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2452A660AE3846DC
    2012-07-08 18:39 - 2012-07-08 18:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BE5EC8885EDDD163
    2012-07-08 18:39 - 2012-07-08 18:39 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\otlntjnh.sys
    2012-07-08 18:33 - 2012-07-08 18:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.226BA1B45B29EFB8
    2012-07-08 15:25 - 2012-07-08 15:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.330E192805BA92FD
    2012-07-08 15:21 - 2012-07-08 15:21 - 00229548 ____A C:\Users\Brian\Downloads\1055.BFE.reg
    2012-07-08 15:21 - 2012-07-08 15:21 - 00006396 ____A C:\Users\Brian\Downloads\0677.mpssvc.reg
    2012-07-08 15:10 - 2012-07-08 15:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E952AF82E1F48A2D
    2012-07-08 15:04 - 2012-07-08 15:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FDC7281CCF95F858
    2012-07-08 15:00 - 2009-11-24 18:20 - 00223380 ____A C:\Windows\PFRO.log
    2012-07-08 14:58 - 2012-07-08 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.988ACBBC3A10BE2D
    2012-07-08 14:58 - 2012-07-08 11:48 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-07-08 14:44 - 2011-02-01 19:46 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-07-08 14:44 - 2010-02-20 05:09 - 00866790 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-07-08 14:43 - 2009-07-13 21:13 - 00849204 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-07-08 14:41 - 2012-07-08 14:41 - 00001020 ____A C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    2012-07-08 14:40 - 2012-07-08 14:40 - 00004057 ____A C:\Windows\wininit.ini
    2012-07-08 11:58 - 2012-07-08 11:58 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2012-07-08 11:58 - 2012-07-08 11:48 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-07-08 11:58 - 2011-09-07 13:44 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-07-07 18:53 - 2010-01-05 19:47 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2418110221-3350712148-3301581529-1000Core.job
    2012-06-26 18:34 - 2012-06-26 18:34 - 00001181 ____A C:\Users\UpdatusUser\Desktop\Perfect World International.lnk
    2012-06-26 18:34 - 2012-06-26 18:34 - 00001181 ____A C:\Users\Guest\Desktop\Perfect World International.lnk
    2012-06-26 18:34 - 2012-06-26 18:34 - 00001181 ____A C:\Users\Brian\Desktop\Perfect World International.lnk
    2012-06-26 18:09 - 2012-06-26 18:11 - 00258352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\unicows.dll
    2012-06-26 17:10 - 2012-06-26 17:10 - 02167720 ____A C:\Users\Brian\Downloads\PWI_v639_Installer.exe
    2012-06-24 16:36 - 2011-02-11 13:21 - 02019572 ____A C:\Windows\System32\Drivers\Cat.DB
    2012-06-23 17:03 - 2011-11-26 12:52 - 00000336 ____A C:\Users\Brian\Desktop\New Text Document.txt
    2012-06-14 09:33 - 2010-01-06 20:04 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-06-14 09:26 - 2009-07-13 20:45 - 03029016 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-06-12 17:07 - 2012-06-12 16:33 - 00001200 ____A C:\Users\Public\Desktop\Diablo III.lnk
    2012-06-11 12:24 - 2010-01-22 14:48 - 00014336 ____A C:\Users\Brian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-06-07 17:19 - 2012-06-07 17:18 - 03857920 ____A C:\Users\Brian\Downloads\hamachi(2).msi
    2012-06-03 16:51 - 2012-06-03 16:51 - 03857920 ____A C:\Users\Brian\Downloads\hamachi(1).msi
    2012-06-02 14:19 - 2012-06-24 16:36 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-24 16:36 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-24 16:36 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:15 - 2012-06-24 16:36 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 11:19 - 2012-06-24 16:35 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 11:15 - 2012-06-24 16:35 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-05-27 13:48 - 2012-05-27 13:48 - 03857920 ____A C:\Users\Brian\Downloads\hamachi.msi
    2012-05-21 16:22 - 2012-05-21 16:22 - 00002364 ____A C:\Users\Public\Desktop\Gas Guzzlers Combat Carnage.lnk
    2012-05-19 08:36 - 2008-09-19 03:02 - 00604081 ____A C:\Windows\DirectX.log
    2012-05-17 18:47 - 2012-06-13 12:52 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-05-17 18:16 - 2012-06-13 12:52 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-05-17 18:06 - 2012-06-13 12:52 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-05-17 17:59 - 2012-06-13 12:53 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-05-17 17:59 - 2012-06-13 12:53 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-05-17 17:58 - 2012-06-13 12:53 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-05-17 17:58 - 2012-06-13 12:53 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-05-17 17:56 - 2012-06-13 12:53 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-05-17 17:55 - 2012-06-13 12:53 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-05-17 17:55 - 2012-06-13 12:52 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-05-17 17:54 - 2012-06-13 12:53 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-05-17 17:51 - 2012-06-13 12:53 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-05-17 17:51 - 2012-06-13 12:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-05-17 17:47 - 2012-06-13 12:53 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-05-17 15:11 - 2012-06-13 12:52 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-05-17 14:48 - 2012-06-13 12:52 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-05-17 14:45 - 2012-06-13 12:52 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-05-17 14:36 - 2012-06-13 12:53 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-05-17 14:35 - 2012-06-13 12:53 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-05-17 14:35 - 2012-06-13 12:53 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-05-17 14:33 - 2012-06-13 12:53 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-05-17 14:31 - 2012-06-13 12:52 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-05-17 14:29 - 2012-06-13 12:53 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-05-17 14:29 - 2012-06-13 12:52 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-05-17 14:27 - 2012-06-13 12:53 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-05-17 14:25 - 2012-06-13 12:53 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-05-17 14:24 - 2012-06-13 12:53 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-05-17 14:20 - 2012-06-13 12:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-05-14 17:32 - 2012-06-12 14:57 - 03144192 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-05-04 02:52 - 2012-06-12 14:57 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-05-04 02:08 - 2012-06-12 14:57 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-05-04 02:08 - 2012-06-12 14:57 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-05-01 21:32 - 2012-06-12 14:57 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-04-27 19:50 - 2012-06-12 14:57 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-04-25 21:34 - 2012-06-12 14:57 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-04-25 21:34 - 2012-06-12 14:57 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-04-25 21:28 - 2012-06-12 14:57 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-04-23 21:59 - 2012-06-12 14:56 - 01460224 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-04-23 21:59 - 2012-06-12 14:56 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-04-23 21:59 - 2012-06-12 14:56 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-04-23 20:47 - 2012-06-12 14:56 - 01156608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-04-23 20:47 - 2012-06-12 14:56 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-04-23 20:47 - 2012-06-12 14:56 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll


    ZeroAccess:
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\L
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\n
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\L\00000004.@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\L\1afb2d56
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\L\201d3dde
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U\00000004.@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U\00000008.@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U\000000cb.@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U\80000000.@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U\80000032.@
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U\80000064.@

    ZeroAccess:
    C:\Users\Brian\AppData\Local\{0f166282-95a0-4f2f-8f75-41a10802f62f}
    C:\Users\Brian\AppData\Local\{0f166282-95a0-4f2f-8f75-41a10802f62f}\@
    C:\Users\Brian\AppData\Local\{0f166282-95a0-4f2f-8f75-41a10802f62f}\L
    C:\Users\Brian\AppData\Local\{0f166282-95a0-4f2f-8f75-41a10802f62f}\U

    ZeroAccess:
    C:\Windows\assembly\GAC_32\Desktop.ini

    ZeroAccess:
    C:\Windows\assembly\GAC_64\Desktop.ini

    ========================= Known DLLs (Whitelisted) ============


    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ========================= Memory info ======================

    Percentage of memory in use: 15%
    Total physical RAM: 4095.11 MB
    Available physical RAM: 3454.14 MB
    Total Pagefile: 4093.26 MB
    Available Pagefile: 3456.04 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.88 MB

    ======================= Partitions =========================

    1 Drive c: (VistaOS) (Fixed) (Total:285.4 GB) (Free:6.8 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    2 Drive d: (RECOVERY) (Fixed) (Total:12.68 GB) (Free:3.8 GB) FAT32 ==>[System with boot components (obtained from reading drive)]
    3 Drive e: (D3C1.0.0) (CDROM) (Total:7.6 GB) (Free:0 GB) UDF
    4 Drive f: () (Fixed) (Total:298.09 GB) (Free:75.23 GB) NTFS
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 298 GB 0 B
    Disk 1 Online 298 GB 1024 KB

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 12 GB 31 KB
    Partition 2 Primary 285 GB 12 GB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 0C
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 D RECOVERY FAT32 Partition 12 GB Healthy

    ==================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C VistaOS NTFS Partition 285 GB Healthy

    ==================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 298 GB 31 KB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F NTFS Partition 298 GB Healthy

    ==================================================================================

    ==========================================================

    Last Boot: 2012-07-08 14:17

    ======================= End Of Log ==========================
     
  4. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    Windows 7 Home Premium 64-bit Operating System
     
  5. Broni

    Broni Malware Annihilator Posts: 48,032   +271

    In Vista or Windows 7: Boot to System Recovery Options and run FRST.
    In Windows XP: Please boot to UBCD and run FRST.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes to your reply.
     
  6. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    Farbar Recovery Scan Tool Version: 08-07-2012
    Ran by SYSTEM at 2012-07-09 01:22:46
    Running from F:\

    ================== Search: "services.exe" ===================

    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows\system64\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows\System32\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06

    ====== End Of Search ======
     
  7. Broni

    Broni Malware Annihilator Posts: 48,032   +271

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    Next...

    Restart normally.

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     

    Attached Files:

  8. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 08-07-2012
    Ran by SYSTEM at 2012-07-09 01:57:32 Run:1
    Running from F:\

    ==============================================

    HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
    C:\Windows\System32\consrv.dll not found.
    HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ Default Value restored successfully.
    dzwteeuj service deleted successfully.
    C:\Windows\System32\services.exe.6EB72CD01B12975D moved successfully.
    C:\Windows\System32\services.exe.2452A660AE3846DC moved successfully.
    C:\Windows\System32\services.exe.BE5EC8885EDDD163 moved successfully.
    C:\Windows\System32\Drivers\otlntjnh.sys moved successfully.
    C:\Windows\System32\services.exe.226BA1B45B29EFB8 moved successfully.
    C:\Windows\System32\services.exe.330E192805BA92FD moved successfully.
    C:\Windows\System32\services.exe.E952AF82E1F48A2D moved successfully.
    C:\Windows\System32\services.exe.FDC7281CCF95F858 moved successfully.
    C:\Windows\System32\services.exe.988ACBBC3A10BE2D moved successfully.
    C:\Windows\Installer\{0f166282-95a0-4f2f-8f75-41a10802f62f} moved successfully.
    C:\Users\Brian\AppData\Local\{0f166282-95a0-4f2f-8f75-41a10802f62f} moved successfully.
    C:\Windows\assembly\GAC_32\Desktop.ini moved successfully.
    C:\Windows\assembly\GAC_64\Desktop.ini moved successfully.
    C:\Windows\System32\services.exe moved successfully.
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe

    ==== End of Fixlog ====
     
  9. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    ComboFix 12-07-08.01 - Brian 07/09/2012 2:15.1.2 - x64
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4095.2673 [GMT -4:00]
    Running from: c:\users\Brian\Desktop\ComboFix.exe
    AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
    AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
    SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\data
    c:\data\IluPak_.exe
    C:\directwave_sampling.tmp
    c:\program files (x86)\LP
    c:\program files (x86)\LP\7EDD\54D3.tmp
    c:\program files (x86)\LP\7EDD\5A8.tmp
    c:\program files (x86)\LP\7EDD\5D3C.tmp
    c:\program files (x86)\sXe Injected
    c:\program files (x86)\sXe Injected\ddsxei.sys
    c:\program files (x86)\sXe Injected\default.reg
    c:\program files (x86)\sXe Injected\firechange.exe
    c:\program files (x86)\sXe Injected\localstrike.xml
    c:\program files (x86)\sXe Injected\Preferences
    c:\program files (x86)\sXe Injected\sXe-I EULA.txt
    c:\program files (x86)\sXe Injected\sXe Injected.exe
    c:\program files (x86)\sXe Injected\sXe Injected.txt
    c:\program files (x86)\sXe Injected\sXe.dll
    c:\program files (x86)\sXe Injected\uninstall.exe
    c:\program files (x86)\sXe Injected\uninstall.ini
    c:\programdata\C93666B22E.sys
    c:\programdata\LoJackNotifier.txt
    c:\users\Brian\AppData\Roaming\BDL+D
    c:\users\Brian\AppData\Roaming\BDL+D\MANGAGAMER.COM\B12AEB7E-B6E4-46CF-B5D6-B6B01AA4AC65\____.hld
    c:\users\Brian\AppData\Roaming\BDL+D\MANGAGAMER.COM\B12AEB7E-B6E4-46CF-B5D6-B6B01AA4AC65\____.sys
    c:\users\Brian\AppData\Roaming\Install.dat
    c:\users\Brian\AppData\Roaming\Microsoft\Windows Firewall
    c:\windows\apppatch\AppLoc.exe
    c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
    c:\windows\SysWow64\Config.ini
    c:\windows\SysWow64\drivers\npf.sys
    c:\windows\SysWow64\Packet.dll
    c:\windows\SysWow64\WanPacket.dll
    c:\windows\SysWow64\wpcap.dll
    H:\autorun.inf
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-06-09 to 2012-07-09 )))))))))))))))))))))))))))))))
    .
    .
    2012-07-09 08:47 . 2012-07-09 08:47 -------- d-----w- C:\FRST
    2012-07-09 06:34 . 2012-07-09 06:34 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
    2012-07-09 06:34 . 2012-07-09 06:34 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-07-09 06:34 . 2012-07-09 06:34 -------- d-----w- c:\users\Guest\AppData\Local\temp
    2012-07-08 22:41 . 2009-09-10 18:54 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
    2012-07-08 22:41 . 2009-09-10 18:53 22104 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-07-08 21:30 . 2012-07-08 21:30 -------- d-----w- c:\users\Brian\AppData\Local\Macromedia
    2012-07-08 19:58 . 2012-07-08 19:58 9815752 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
    2012-07-08 19:48 . 2012-07-08 19:58 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-07-08 19:48 . 2012-07-08 19:48 -------- d-----w- c:\windows\system32\Macromed
    2012-07-08 07:43 . 2012-07-08 07:43 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
    2012-06-29 18:56 . 2012-06-29 18:56 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
    2012-06-27 02:22 . 2012-06-27 02:22 -------- d-----w- C:\Perfect World Entertainment
    2012-06-27 02:11 . 2012-06-27 02:09 258352 ----a-w- c:\windows\SysWow64\unicows.dll
    2012-06-25 00:36 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
    2012-06-25 00:36 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
    2012-06-25 00:36 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
    2012-06-25 00:36 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
    2012-06-25 00:35 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
    2012-06-25 00:35 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe
    2012-06-13 20:52 . 2012-05-18 02:06 2311680 ----a-w- c:\windows\system32\jscript9.dll
    2012-06-13 20:52 . 2012-05-17 22:45 1800192 ----a-w- c:\windows\SysWow64\jscript9.dll
    2012-06-13 20:52 . 2012-05-18 02:01 499200 ----a-w- c:\program files\Internet Explorer\jsdbgui.dll
    2012-06-13 20:52 . 2012-05-17 22:38 678912 ----a-w- c:\program files (x86)\Internet Explorer\iedvtool.dll
    2012-06-13 20:52 . 2012-05-17 22:37 387584 ----a-w- c:\program files (x86)\Internet Explorer\jsdbgui.dll
    2012-06-13 20:52 . 2012-05-18 02:02 887296 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
    2012-06-13 01:18 . 2012-06-13 01:19 -------- d-----w- c:\programdata\Battle.net
    2012-06-13 00:33 . 2012-06-27 00:10 -------- d-----w- c:\program files (x86)\Diablo III
    2012-06-12 22:57 . 2012-04-26 05:34 76288 ----a-w- c:\windows\system32\rdpwsx.dll
    2012-06-12 22:57 . 2012-04-26 05:34 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
    2012-06-12 22:57 . 2012-04-26 05:28 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
    2012-06-12 22:57 . 2012-05-02 05:32 208896 ----a-w- c:\windows\system32\profsvc.dll
    2012-06-12 22:57 . 2012-05-04 10:52 5505392 ----a-w- c:\windows\system32\ntoskrnl.exe
    2012-06-12 22:57 . 2012-05-04 10:08 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
    2012-06-12 22:57 . 2012-05-04 10:08 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
    2012-06-12 22:57 . 2012-05-15 01:32 3144192 ----a-w- c:\windows\system32\win32k.sys
    2012-06-12 22:57 . 2012-04-28 03:50 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
    2012-06-12 22:57 . 2012-04-07 12:18 3213824 ----a-w- c:\windows\system32\msi.dll
    2012-06-12 22:57 . 2012-04-07 11:34 2342400 ----a-w- c:\windows\SysWow64\msi.dll
    2012-06-12 22:56 . 2012-04-24 05:59 1460224 ----a-w- c:\windows\system32\crypt32.dll
    2012-06-12 22:56 . 2012-04-24 04:47 1156608 ----a-w- c:\windows\SysWow64\crypt32.dll
    2012-06-12 22:56 . 2012-04-24 05:59 182272 ----a-w- c:\windows\system32\cryptsvc.dll
    2012-06-12 22:56 . 2012-04-24 05:59 140288 ----a-w- c:\windows\system32\cryptnet.dll
    2012-06-12 22:56 . 2012-04-24 04:47 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll
    2012-06-12 22:56 . 2012-04-24 04:47 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-07-09 06:37 . 2009-10-24 21:07 45056 ----a-w- c:\windows\system32\acovcnt.exe
    2012-07-08 19:58 . 2011-09-07 21:44 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-07-26 1493160]
    .
    [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
    .
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    2011-07-26 22:23 1493160 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-07-26 1493160]
    .
    [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 163328]
    "Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2009-07-14 44544]
    "RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "ACMON"="c:\program files (x86)\ASUS\Splendid\ACMON.exe" [2008-10-01 1126400]
    "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
    "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
    "AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
    "ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2009-08-24 33136]
    "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2008-08-19 159744]
    "ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-03-04 8392704]
    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
    "HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2008-08-18 98304]
    "razer"="c:\program files (x86)\Razer Pro Solutions\ProClick v1.6\razerhid.exe" [2007-03-02 126976]
    "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
    "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
    "PCTools FGuard"="c:\program files (x86)\PC Tools Security\BDT\FGuard.exe" [2011-01-07 108496]
    "ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-07-26 397992]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
    "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
    "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    FancyStart daemon.lnk - c:\windows\Installer\{DC905847-D537-427F-BF91-47CC7ACCDE58}\_DF3A81D17C478A2A6C60A5.exe [2009-8-24 12862]
    HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "EnableLinkedConnections"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "HideSCAHealth"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [x]
    R1 MpKsl6c0ba002;MpKsl6c0ba002;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A8BE309E-F0EF-4B3F-9532-AC8BD1C21BF3}\MpKsl6c0ba002.sys [x]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe [x]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
    R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-08 257224]
    R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2010-07-01 51600]
    R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-10-24 1038088]
    R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2011-02-04 17152]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
    R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
    R3 Razerlow;Razer Pro|Solutions;c:\windows\system32\drivers\Razerlow.sys [2005-11-07 21120]
    R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2010-01-07 19952]
    R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2010-03-15 366840]
    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-08-02 51712]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-01 1255736]
    R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\BatteryCare\WinRing0x64.sys [2008-07-26 14544]
    R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-10-24 871408]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-12-03 69152]
    S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2010-12-10 257232]
    S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2010-06-29 452872]
    S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2010-07-16 816016]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-02-06 54480]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
    S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
    S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
    S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
    S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-01-07 247760]
    S2 Cepstral License Server;Cepstral License Server;c:\program files\Cepstral\bin\CepstralLicSrv.exe [2009-09-29 121856]
    S2 Dokan;Dokan;c:\windows\system32\drivers\dokan.sys [2010-07-06 106888]
    S2 DokanMounter;DokanMounter;c:\program files (x86)\Dokan\DokanLibrary\mounter.exe [2010-07-05 11776]
    S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
    S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
    S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
    S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-19 59392]
    S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - AvgTdiA
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-07-09 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-08 19:48]
    .
    2012-07-09 c:\windows\Tasks\Free File Viewer Update Checker.job
    - c:\program files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2010-12-07 16:25]
    .
    2012-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2418110221-3350712148-3301581529-1000Core.job
    - c:\users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-06 03:47]
    .
    2012-07-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2418110221-3350712148-3301581529-1000UA.job
    - c:\users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-06 03:47]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
    @="{C5994560-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
    @="{C5994561-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
    @="{C5994562-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
    @="{C5994563-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
    @="{C5994564-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
    @="{C5994565-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
    @="{C5994566-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
    @="{C5994567-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
    @="{C5994568-53D9-4125-87C9-F193FC689CB2}"
    [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
    2010-03-21 12:55 99080 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1216808]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-24 7573024]
    "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-24 1833504]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x1
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://start.facemoods.com/?a=gear
    uDefault_Search_URL = hxxp://www.google.com/ie
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
    IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
    FF - ProfilePath - c:\users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\po79g1ib.default\

    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    Toolbar-Locked - (no file)
    Toolbar-Locked - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    HKLM-Run-set - c:\programdata\SetWallpaper.cmd
    AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
    AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe
    AddRemove-DFX for Windows Media Player - c:\program files\DFX\uninstall_WMP.exe
    AddRemove-Driving Speed 2_is1 - c:\program files (x86)\DrivingSpeed2\unins000.exe
    AddRemove-Drumaxx - c:\program files (x86)\Image-Line\Drumaxx\uninstall.exe
    AddRemove-FrostWire - c:\program files (x86)\FrostWir\Uninstall.exe
    AddRemove-OpenAL - c:\program files (x86)\OpenAL\oalinst.exe
    AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
    AddRemove-Sakura - c:\program files (x86)\Image-Line\Sakura\uninstall.exe
    AddRemove-Sauerbraten - c:\program files (x86)\Sauerbraten\uninstall.exe
    AddRemove-sXe Injected - c:\program files (x86)\sXe Injected\uninstall.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-2418110221-3350712148-3301581529-1000\Software\SecuROM\License information*]
    "datasecu"=hex:77,4f,fe,63,f6,e7,ce,34,16,dc,d8,2e,35,91,c5,c3,4b,2d,5c,1c,34,
    e3,98,a9,14,90,9f,ee,d1,58,4a,ef,85,be,7f,88,43,93,23,97,3c,07,27,b9,1f,ba,\
    "rkeysecu"=hex:cf,e5,6e,63,06,09,e6,91,00,ce,c1,c4,59,2f,9c,79
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
    c:\program files\ATKGFNEX\GFNEXSrv.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
    c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe
    c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
    c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
    c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe
    c:\windows\SysWOW64\PnkBstrA.exe
    c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files (x86)\Razer Pro Solutions\ProClick v1.6\razerofa.exe
    .
    **************************************************************************
    .
    Completion time: 2012-07-09 02:47:26 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-07-09 06:47
    .
    Pre-Run: 6,980,247,552 bytes free
    Post-Run: 12,827,488,256 bytes free
    .
    - - End Of File - - 53800336DE98B6F1C28540D12F0A38E8
     
  10. Broni

    Broni Malware Annihilator Posts: 48,032   +271

    Combofix log looks good :)

    Any current issues?

    =======================================

    You're running two AV programs, Lavasoft Ad-Watch Live! Anti-Virus and MSE.
    You must uninstall one of them.
    I suggest Lavasoft goes.

    ======================================

    Download Malwarebytes' Anti-Malware (MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop.
    NOTE. If you already have MBAM installed, update it before running the scan.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    ===========================================

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  11. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.07.09.11

    Windows 7 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Brian :: JACOB102010012 [administrator]

    7/9/2012 3:27:50 PM
    mbam-log-2012-07-09 (15-27-50).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 263942
    Time elapsed: 8 minute(s), 34 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
     
  12. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    OTL logfile created on: 7/9/2012 4:19:02 PM - Run 1
    OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brian\Downloads
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    4.00 Gb Total Physical Memory | 2.43 Gb Available Physical Memory | 60.68% Memory free
    8.00 Gb Paging File | 6.40 Gb Available in Paging File | 80.02% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 285.40 Gb Total Space | 11.84 Gb Free Space | 4.15% Space Free | Partition Type: NTFS
    Drive D: | 7.60 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

    Computer Name: JACOB102010012 | User Name: Brian | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/07/09 16:18:05 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Brian\Downloads\OTL.exe
    PRC - [2012/02/29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    PRC - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    PRC - [2011/08/30 12:18:30 | 002,358,656 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
    PRC - [2011/07/26 18:23:20 | 000,397,992 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
    PRC - [2011/01/07 15:54:12 | 000,108,496 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
    PRC - [2011/01/07 15:54:08 | 000,247,760 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe
    PRC - [2010/09/23 16:31:55 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
    PRC - [2010/07/05 08:37:08 | 000,011,776 | ---- | M] () -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
    PRC - [2010/03/25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
    PRC - [2009/08/24 16:19:41 | 000,033,136 | ---- | M] () -- C:\Windows\ASScrPro.exe
    PRC - [2009/03/04 13:26:24 | 008,392,704 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
    PRC - [2009/03/04 12:55:52 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
    PRC - [2008/12/22 20:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
    PRC - [2008/12/09 18:00:58 | 000,297,528 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
    PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2008/08/19 13:34:04 | 000,159,744 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
    PRC - [2008/08/14 00:00:08 | 000,113,208 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
    PRC - [2008/08/13 23:59:52 | 000,100,920 | ---- | M] () -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe
    PRC - [2008/08/13 19:21:56 | 002,482,176 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
    PRC - [2008/06/11 22:43:26 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    PRC - [2007/09/02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe
    PRC - [2007/08/08 03:08:40 | 000,094,208 | ---- | M] () -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe
    PRC - [2007/03/02 15:39:50 | 000,126,976 | ---- | M] () -- C:\Program Files (x86)\Razer Pro Solutions\ProClick v1.6\razerhid.exe
    PRC - [2007/02/27 14:44:00 | 000,106,496 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer Pro Solutions\ProClick v1.6\razerofa.exe


    ========== Modules (No Company Name) ==========

    MOD - [2009/08/24 16:19:41 | 000,033,136 | ---- | M] () -- C:\Windows\ASScrPro.exe
    MOD - [2007/09/02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe
    MOD - [2007/09/02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.dll
    MOD - [2007/03/02 15:39:50 | 000,126,976 | ---- | M] () -- C:\Program Files (x86)\Razer Pro Solutions\ProClick v1.6\razerhid.exe


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV:64bit: - [2009/10/24 19:52:27 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
    SRV:64bit: - [2009/09/29 09:27:24 | 000,121,856 | ---- | M] (Cepstral, LLC) [Auto | Running] -- C:\Program Files\Cepstral\bin\CepstralLicSrv.exe -- (Cepstral License Server)
    SRV:64bit: - [2009/07/20 13:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2007/08/08 03:08:40 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
    SRV - [2012/07/08 15:48:10 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/06/27 12:29:24 | 002,369,960 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
    SRV - [2012/06/16 01:22:38 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/02/29 20:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
    SRV - [2012/02/29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
    SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2011/10/21 16:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
    SRV - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
    SRV - [2011/08/30 12:18:30 | 002,358,656 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
    SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2011/01/07 15:54:08 | 000,247,760 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
    SRV - [2010/11/19 07:57:14 | 001,150,936 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools Security\pctsSvc.exe -- (sdCoreService)
    SRV - [2010/09/23 16:31:55 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
    SRV - [2010/07/05 08:37:08 | 000,011,776 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe -- (DokanMounter)
    SRV - [2010/03/25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @C:\Program Files (x86)
    SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/03/15 15:02:36 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
    SRV - [2009/10/24 19:49:04 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2009/09/22 14:40:36 | 000,884,736 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\TVersity\Media Server\MediaServer.exe -- (TVersityMediaServer)
    SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
    SRV - [2008/08/15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
    SRV - [2008/08/13 23:59:52 | 000,100,920 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV:64bit: - [2012/03/01 02:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2011/08/02 17:38:56 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/03/11 02:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 02:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/12/10 14:24:50 | 000,257,232 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore)
    DRV:64bit: - [2010/12/03 05:05:34 | 000,069,152 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
    DRV:64bit: - [2010/08/03 12:26:15 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
    DRV:64bit: - [2010/08/03 12:26:14 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
    DRV:64bit: - [2010/07/16 15:53:32 | 000,816,016 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\pctEFA64.sys -- (pctEFA)
    DRV:64bit: - [2010/07/05 21:29:12 | 000,106,888 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\dokan.sys -- (Dokan)
    DRV:64bit: - [2010/07/01 17:52:18 | 000,051,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
    DRV:64bit: - [2010/06/29 11:35:34 | 000,452,872 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pctDS64.sys -- (pctDS)
    DRV:64bit: - [2009/11/08 23:28:08 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
    DRV:64bit: - [2009/10/24 17:42:19 | 000,871,408 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
    DRV:64bit: - [2009/09/15 19:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Intel(R)
    DRV:64bit: - [2009/08/13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 20:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
    DRV:64bit: - [2009/07/13 19:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2009/06/19 22:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
    DRV:64bit: - [2009/06/17 12:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
    DRV:64bit: - [2009/06/17 12:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
    DRV:64bit: - [2009/06/17 12:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
    DRV:64bit: - [2009/06/10 16:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH)
    DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
    DRV:64bit: - [2009/02/11 05:26:17 | 000,407,576 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2008/12/08 20:35:52 | 000,061,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
    DRV:64bit: - [2008/10/08 23:39:01 | 001,821,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
    DRV:64bit: - [2008/08/06 20:26:07 | 000,174,592 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rtlh64.sys -- (RTL8169)
    DRV:64bit: - [2008/06/27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
    DRV:64bit: - [2008/06/24 16:50:00 | 000,065,024 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimmpx64.sys -- (rimmptsk)
    DRV:64bit: - [2008/06/03 02:41:49 | 000,017,464 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
    DRV:64bit: - [2008/02/06 03:00:00 | 000,054,480 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2007/12/18 20:57:12 | 000,059,392 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\itecir.sys -- (itecir)
    DRV:64bit: - [2007/12/06 06:12:55 | 000,320,048 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2007/07/27 22:45:52 | 000,057,856 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
    DRV:64bit: - [2007/07/26 23:33:54 | 000,055,296 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspx64.sys -- (rimsptsk)
    DRV:64bit: - [2007/07/24 14:11:32 | 000,014,904 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
    DRV:64bit: - [2006/10/28 10:01:07 | 000,013,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ATK64AMD.sys -- (MTsensor)
    DRV:64bit: - [2005/11/07 15:33:12 | 000,021,120 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Razerlow.sys -- (Razerlow)
    DRV - [2010/01/07 13:33:57 | 000,019,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys -- (RivaTuner64)
    DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2008/08/14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
    DRV - [2008/07/26 18:30:36 | 000,014,544 | ---- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\BatteryCare\WinRing0x64.sys -- (WinRing0_1_2_0)
    DRV - [2007/02/16 05:05:48 | 000,014,464 | ---- | M] (Christian Diefer) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\drivers\fanio.sys -- (fanio)
    DRV - [2006/07/24 17:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen)
    DRV - [2004/05/29 09:15:12 | 000,009,728 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Stopped] -- C:\Windows\SysWow64\drivers\filedisk.sys -- (FileDisk)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?source...nputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
    IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/...ahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=gear
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=gear&s={searchTerms}&f=4
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?c...pn_sauid=2B7143C7-6CF3-4F15-BC2F-9D9988795FDA
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?source...nputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/...ahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========



    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
    FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Brian\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Brian\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Brian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/02/10 21:32:20 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools Security\BDT\FireFox\ [2011/02/11 17:24:15 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/16 01:22:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/07 19:38:40 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/02/10 21:32:20 | 000,000,000 | ---D | M]

    [2009/11/24 22:06:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brian\AppData\Roaming\mozilla\Extensions
    [2009/10/26 18:34:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brian\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
    [2012/07/06 00:39:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brian\AppData\Roaming\mozilla\Firefox\Profiles\po79g1ib.default\extensions
    [2012/06/07 18:25:45 | 000,000,000 | ---D | M] (FT DeepDark) -- C:\Users\Brian\AppData\Roaming\mozilla\Firefox\Profiles\po79g1ib.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
    [2012/05/17 16:02:06 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Brian\AppData\Roaming\mozilla\Firefox\Profiles\po79g1ib.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    [2012/05/20 15:45:09 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Brian\AppData\Roaming\mozilla\Firefox\Profiles\po79g1ib.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
    [2011/08/18 22:51:39 | 000,002,395 | ---- | M] () -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\po79g1ib.default\searchplugins\askcom.xml
    [2009/11/05 14:08:53 | 000,001,190 | ---- | M] () -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\po79g1ib.default\searchplugins\urban-dictionary.xml
    [2012/04/25 17:38:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/06/30 10:05:27 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
    [2012/07/04 22:28:51 | 000,743,290 | ---- | M] () (No name found) -- C:\USERS\BRIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PO79G1IB.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
    [2011/10/28 22:26:47 | 000,434,392 | ---- | M] () (No name found) -- C:\USERS\BRIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PO79G1IB.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
    [2012/02/11 15:03:24 | 000,709,293 | ---- | M] () (No name found) -- C:\USERS\BRIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PO79G1IB.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
    [2011/05/07 18:03:12 | 000,330,316 | ---- | M] () (No name found) -- C:\USERS\BRIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PO79G1IB.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
    [2012/06/16 01:22:39 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2009/11/06 12:37:19 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
    [2012/04/03 16:17:18 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2009/11/06 12:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
    [2012/06/07 18:08:04 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011/05/10 20:55:29 | 000,002,047 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
    [2012/06/07 18:08:04 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: facemoods (Enabled)
    CHR - default_search_provider: search_url = http://start.facemoods.com/?a=gear&s={searchTerms}&f=4
    CHR - default_search_provider: suggest_url =
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Brian\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Brian\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Brian\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
    CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Brian\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
    CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
    CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    CHR - plugin: downloadUpdater (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
    CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
    CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
    CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
    CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
    CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
    CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
    CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: Unity Player (Enabled) = C:\Users\Brian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
    CHR - plugin: Google Update (Enabled) = C:\Users\Brian\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
    CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - Extension: YouTube = C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: Gmail = C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
     
  13. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    O1 HOSTS File: ([2012/07/09 02:38:14 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll File not found
    O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
    O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll File not found
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
    O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
    O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O3 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O3 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
    O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [set] c:\programdata\SetWallpaper.cmd File not found
    O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
    O4 - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ATK)
    O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
    O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
    O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe ()
    O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)
    O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
    O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
    O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
    O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
    O4 - HKLM..\Run: [razer] C:\Program Files (x86)\Razer Pro Solutions\ProClick v1.6\razerhid.exe ()
    O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
    O4 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\Windows\is-LG8SC.exe ()
    O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
    O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
    O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
    O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
    O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
    O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16:64bit: - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {700EF03F-A472-4D26-8ACB-300F4D04FD96} https://lojackforlaptops.absolute.com/ctmweb/testoc.cab (Recovery ActiveX Control Module)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8E32EF1D-40F7-4515-94CE-BA9C8956813E}: DhcpNameServer = 192.168.1.1
    O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O24 - Desktop WallPaper: C:\Users\Brian\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
    O24 - Desktop BackupWallPaper: C:\Users\Brian\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2012/02/02 17:42:35 | 000,000,058 | -H-- | M] () - D:\autorun.inf -- [ UDF ]
    O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/09 15:26:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/07/09 15:17:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
    [2012/07/09 15:17:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2012/07/09 04:47:21 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/07/09 02:47:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/07/09 02:38:32 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/07/09 02:12:32 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/07/09 02:12:32 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/07/09 02:12:32 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/07/09 02:12:26 | 000,000,000 | ---D | C] -- C:\ComboFix
    [2012/07/09 02:05:43 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/07/09 02:05:09 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/07/09 02:03:37 | 004,573,972 | R--- | C] (Swearware) -- C:\Users\Brian\Desktop\ComboFix.exe
    [2012/07/08 18:41:04 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/07/08 17:30:59 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Local\Macromedia
    [2012/07/08 15:48:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
    [2012/07/08 03:43:22 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/06/29 14:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
    [2012/06/29 14:56:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
    [2012/06/26 22:33:56 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
    [2012/06/26 22:33:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
    [2012/06/26 22:22:16 | 000,000,000 | ---D | C] -- C:\Perfect World Entertainment
    [2012/06/26 22:11:19 | 000,000,000 | ---D | C] -- C:\Users\Brian\Desktop\PWI
    [2012/06/12 21:22:35 | 000,000,000 | ---D | C] -- C:\Users\Brian\Documents\Diablo III
    [2012/06/12 21:18:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net
    [2012/06/12 20:33:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
    [2012/06/12 20:33:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diablo III
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
    ========== Files - Modified Within 30 Days ==========

    [2012/07/09 16:23:30 | 000,019,186 | ---- | M] () -- C:\Users\Brian\Desktop\Capture.PNG
    [2012/07/09 15:58:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/07/09 15:53:06 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2418110221-3350712148-3301581529-1000UA.job
    [2012/07/09 15:26:37 | 000,711,240 | ---- | M] () -- C:\Windows\is-LG8SC.exe
    [2012/07/09 15:26:37 | 000,010,498 | ---- | M] () -- C:\Windows\is-LG8SC.msg
    [2012/07/09 15:26:37 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/07/09 15:26:37 | 000,000,441 | ---- | M] () -- C:\Windows\is-LG8SC.lst
    [2012/07/09 15:23:16 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2012/07/09 15:17:46 | 000,866,790 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/07/09 15:17:46 | 000,712,270 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/07/09 15:17:46 | 000,141,000 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/07/09 15:17:16 | 000,011,104 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/07/09 15:17:16 | 000,011,104 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/07/09 15:01:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/07/09 02:38:14 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/07/09 02:37:42 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
    [2012/07/09 02:37:39 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\Free File Viewer Update Checker.job
    [2012/07/09 02:36:44 | 3220,525,056 | -HS- | M] () -- C:\hiberfil.sys
    [2012/07/09 02:07:47 | 000,007,595 | ---- | M] () -- C:\Users\Brian\AppData\Local\resmon.resmoncfg
    [2012/07/09 02:03:52 | 004,573,972 | R--- | M] (Swearware) -- C:\Users\Brian\Desktop\ComboFix.exe
    [2012/07/08 18:43:37 | 000,849,204 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/07/08 18:40:42 | 000,004,057 | ---- | M] () -- C:\Windows\wininit.ini
    [2012/07/07 22:53:01 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2418110221-3350712148-3301581529-1000Core.job
    [2012/07/07 18:49:36 | 000,000,040 | ---- | M] () -- C:\Users\Brian\jagex_cl_runescape_LIVE.dat
    [2012/06/26 22:34:06 | 000,001,181 | ---- | M] () -- C:\Users\Brian\Desktop\Perfect World International.lnk
    [2012/06/24 20:36:44 | 002,019,572 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
    [2012/06/14 13:26:46 | 003,029,016 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/06/12 21:07:34 | 000,001,200 | ---- | M] () -- C:\Users\Public\Desktop\Diablo III.lnk
    [2012/06/11 16:24:59 | 000,014,336 | ---- | M] () -- C:\Users\Brian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/07/09 15:26:37 | 000,711,240 | ---- | C] () -- C:\Windows\is-LG8SC.exe
    [2012/07/09 15:26:37 | 000,010,498 | ---- | C] () -- C:\Windows\is-LG8SC.msg
    [2012/07/09 15:26:37 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/07/09 15:26:37 | 000,000,441 | ---- | C] () -- C:\Windows\is-LG8SC.lst
    [2012/07/09 15:17:51 | 000,001,922 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2012/07/09 02:12:32 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/07/09 02:12:32 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/07/09 02:12:32 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/07/09 02:12:32 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/07/09 02:12:32 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/07/08 18:40:33 | 000,004,057 | ---- | C] () -- C:\Windows\wininit.ini
    [2012/07/08 15:48:10 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/06/26 22:34:06 | 000,001,181 | ---- | C] () -- C:\Users\Brian\Desktop\Perfect World International.lnk
    [2012/06/12 20:33:51 | 000,001,200 | ---- | C] () -- C:\Users\Public\Desktop\Diablo III.lnk
    [2012/02/29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
    [2011/12/31 23:19:56 | 000,000,600 | ---- | C] () -- C:\Users\Brian\AppData\Roaming\winscp.rnd
    [2011/12/03 20:38:21 | 000,009,784 | -HS- | C] () -- C:\Users\Brian\AppData\Local\u4ld08p3bp4lfq
    [2011/12/03 20:38:21 | 000,009,784 | -HS- | C] () -- C:\ProgramData\u4ld08p3bp4lfq
    [2011/10/27 22:54:41 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2011/10/13 20:32:11 | 000,000,000 | ---- | C] () -- C:\Windows\startup.INI
    [2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
    [2011/09/05 17:35:38 | 000,000,067 | ---- | C] () -- C:\Windows\swf2avi.INI
    [2011/07/14 16:27:58 | 000,000,023 | ---- | C] () -- C:\Windows\SWFDecompiler.INI
    [2011/06/17 17:23:10 | 000,168,307 | ---- | C] () -- C:\Windows\hphins33.dat.temp
    [2011/06/17 17:23:10 | 000,000,512 | ---- | C] () -- C:\Windows\hphmdl33.dat.temp
    [2011/05/01 18:54:17 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
    [2011/05/01 18:54:17 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
    [2011/02/11 17:24:08 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
    [2011/02/10 21:26:16 | 000,167,635 | ---- | C] () -- C:\Windows\hphins33.dat
    [2011/02/10 21:26:16 | 000,000,512 | ---- | C] () -- C:\Windows\hphmdl33.dat
    [2010/12/06 19:59:53 | 001,585,069 | ---- | C] () -- C:\Windows\DarkSteam Uninstaller.exe
    [2010/09/23 16:31:54 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
    [2010/09/19 13:03:03 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
    [2010/06/28 18:34:15 | 000,000,099 | ---- | C] () -- C:\ProgramData\nvUnsupRes.dat
    [2010/06/09 18:35:17 | 000,001,890 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
    [2010/01/27 15:09:09 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
    [2010/01/22 18:48:24 | 000,014,336 | ---- | C] () -- C:\Users\Brian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/01/07 02:50:05 | 000,007,595 | ---- | C] () -- C:\Users\Brian\AppData\Local\resmon.resmoncfg
    [2009/11/19 22:24:11 | 814,143,398 | ---- | C] () -- C:\Users\Brian\loleusetup.exe.partial
    [2009/10/24 17:20:36 | 000,000,000 | ---- | C] () -- C:\Users\Brian\AppData\Roaming\wklnhst.dat
     
  14. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    ========== LOP Check ==========

    [2012/06/07 21:41:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\.minecraft
    [2011/11/10 22:31:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\A3onF4amH
    [2011/11/10 22:30:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\a5sWJ7dELgZhXkV
    [2011/11/10 22:37:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\A77E9TjCwVlNx0i
    [2011/11/10 22:28:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AA1uSb3m5JdKR9X
    [2011/11/10 22:19:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ABOyA0Sbp5HW
    [2009/11/24 22:05:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Absolute
    [2010/09/19 12:22:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Absolute_Software
    [2009/11/24 22:05:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\acccore
    [2011/11/10 21:45:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AdEEEL8gRZqh
    [2011/11/10 22:27:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AeBrzONyx
    [2011/11/10 22:24:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AF4pmG5sQ6Ef9XU
    [2011/11/10 22:29:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\afRLTqYCrN
    [2011/11/10 22:35:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AgggTTZqjYCwIVl
    [2011/11/10 22:14:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aGQd8ZTjeIzy1Sb
    [2011/11/10 22:11:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AibF3pnG5Qd7LTq
    [2011/11/10 22:29:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ALRhwUltPci2FmJ
    [2011/11/10 22:03:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AOtxAci3GQ6KEgq
    [2011/11/10 22:25:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aPcivD3ona5JEgq
    [2011/11/10 22:03:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ApmGsQJ6d8ZTjeB
    [2011/11/10 21:45:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aqqqhYYXwk
    [2011/11/10 22:00:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AqYCkUVlOtPc
    [2011/11/10 22:16:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ARgqCIzt0
    [2011/11/10 22:13:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\arNPci3Gms7LT
    [2011/11/10 22:07:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\as7KRhwVIz
    [2011/11/10 22:41:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aSb3Ga6KLZYwrx1
    [2011/08/26 21:32:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Atari
    [2011/11/10 22:38:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aui3GaHsKf
    [2011/11/10 21:45:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\auuucSS1ibDon4a
    [2011/11/10 21:57:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AUVelt0yciDnp5Q
    [2011/11/10 22:29:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AUVrlOBtx
    [2011/11/10 22:27:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AYXwkUVOB
    [2011/11/10 22:18:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aZhCUlOBtP
    [2011/11/10 22:23:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AZhwVOzy1Dnp5JE
    [2012/07/08 18:54:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Azureus
    [2011/11/10 22:33:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\aZZqqYwUlBz0c1v
    [2011/11/10 22:34:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\B11uvoFpGadKfLT
    [2011/11/10 22:24:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\b4pmHsQJEg9
    [2011/11/10 22:13:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\b5aQJ6dWKfL
    [2011/11/10 22:02:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\b5sQJ7dEKgZhXj
    [2011/11/10 21:44:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\B888gTTZqhYwk
    [2011/11/10 22:30:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bA1uvD2b45JKR9T
    [2010/08/21 15:06:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BatteryCare
    [2011/11/10 21:45:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bCCwwkUVrlO
    [2011/11/10 22:10:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bCwkIVrlOtPuSi
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BD2ob4GsJEf9TwC
    [2011/11/10 22:15:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Bd8ZYjeBcu2Fms6
    [2011/11/10 22:05:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bFm5sQJ7dKgZhwU
    [2011/11/10 22:03:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BH5sQJ7dE8RhwVI
    [2011/11/10 22:20:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BItzPycA1Dbp5Q6
    [2011/11/10 21:56:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bKRhwVIzNAu2Fm
    [2011/11/10 22:39:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BlllOx0bnmWEZCU
    [2011/11/10 22:30:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BNA0c2ibDn
    [2011/11/10 22:38:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BNAS2bb3pGaJdWf
    [2011/11/10 22:06:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BNtxPu1Dna6JEgq
    [2011/11/10 22:08:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Bobms6KR9XUlrNA
    [2012/02/26 03:53:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BoneCraft
    [2011/11/10 21:44:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bqqjjYCCwkIrlN
    [2011/11/10 22:31:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BTjCkrNxuS3GaW7
    [2011/11/10 22:32:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BtnFW7dE8qXkV
    [2011/11/10 22:00:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bTqUeIzNAuSi3G
    [2011/11/10 22:30:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BtzPiDop5JKRhXj
    [2011/11/10 22:38:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BVrlBtx0S1v3FHW
    [2011/11/10 22:24:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bvS2bF3pGQdRgq
    [2011/11/10 22:13:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BWK8fR9hXUeBOy0
    [2011/11/10 22:26:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bwkUVOBzy1D4mJ
    [2011/11/10 21:42:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\BWWKffRL9gTXj
    [2011/11/10 22:04:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bXqjCIzt0Sbp4HW
    [2011/11/10 22:18:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\bYCwIlt0Sbo
    [2011/11/10 22:30:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\c0c2ibDnaHW7LgZ
    [2011/11/10 21:43:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\c1iibbD3onG4
    [2011/11/10 22:29:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\C3Ga6W7fLgZjwIr
    [2011/11/10 21:56:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\C3pmGa6WfLTjeB
    [2011/11/10 22:08:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\C7fLgTqCkzAc2bp
    [2011/11/10 22:19:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\C8ZYwkUVeOz0ci
    [2011/11/10 21:56:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\CaH6sWJf8ZYwVlt
    [2011/11/10 22:36:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cBy1v3n4m5W7E8R
    [2011/11/10 22:33:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\CJdf9XjeBzy1voF
    [2011/11/10 22:08:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cKg9YjVIt
    [2011/11/10 22:43:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cku5LIcaLwxDH8w
    [2011/11/10 22:43:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cKXrum6TkxFHfTe
    [2010/01/10 11:28:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2011/11/10 22:00:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cR9XYkrNAci3GQs
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\CRL9hTXqjCkBzNx
    [2011/11/10 22:30:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\CsQEK8fZ9TUzNxu
    [2011/11/10 22:05:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\csQJd8ZTwCIzy1S
    [2011/11/10 22:38:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\CVVrllOx0SiDn4
    [2011/11/10 22:33:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cwwkkVrOtPuSiDo
    [2011/11/10 21:57:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\cx3Fm5dZYkePcin
    [2011/11/10 22:21:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\czONtAu2D
    [2011/11/10 22:42:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\d11iivDD2on4
    [2011/11/10 22:18:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\D3nG5aQ6Kf9
    [2011/11/10 22:42:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\D444pmmGsQ6dE8
    [2011/11/10 22:32:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\D4sLhVz1n5E
    [2012/07/09 15:30:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\D67D0
    [2011/11/10 22:28:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\d7f9XjCIVOtui3Q
    [2011/11/10 22:06:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\d9hTXwjelBPxuSo
    [2009/11/24 22:06:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DAEMON Tools Lite
    [2011/11/10 22:00:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DasJEZYkrBPci3
    [2011/06/24 20:11:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Day 1 Studios
    [2011/11/10 22:21:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\db4pmG5sQ
    [2011/11/10 21:43:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DCeeIVVrzON
    [2011/11/10 22:31:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DCelIrzPNx12bpa
    [2011/11/10 22:37:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dD33onnF4amH
    [2011/11/10 22:43:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ddWK7fRL9TqYeIr
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dEKfZ9TXw
    [2011/11/10 22:32:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DEL8gTqCUrBPcvo
    [2011/11/10 22:32:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DEL8gTZwlPioa5J
    [2011/11/10 22:30:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\delIrPxu2
    [2011/12/31 23:37:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DiskAid
    [2011/11/10 22:29:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dJEgqYwUOz0ciDo
    [2011/11/10 21:56:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DL9gXYeVOt0Si3G
    [2011/11/10 22:04:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dlIBtzPNyAuDoFp
    [2011/10/13 20:32:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DLsite
    [2011/11/10 22:10:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dLTjwVOxu
    [2011/11/10 22:29:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DNAu2bpa6KRhqCI
    [2011/11/10 22:06:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dnFpQ8XlNv4Q8Te
    [2011/11/10 22:13:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DNtxP0ucSDo4H7
    [2011/11/10 22:19:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dNycA1uvD
    [2011/11/10 22:36:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Do4m6WfLTqYwUlB
    [2011/11/10 21:43:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DooonFF4pmH5J7E
    [2011/11/10 22:09:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DOxuSDoG4mWfZYk
    [2011/11/10 22:20:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DPNcD2bpQdKRjCl
    [2011/11/10 22:23:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DPyci2Fms7K
    [2010/06/16 19:33:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Dragon Age Toolset
    [2011/11/10 22:14:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DRL9XYkrNAc
    [2011/11/10 22:34:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\duccS1bbD
    [2011/11/10 22:31:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DUCelIrzPyAu2bp
    [2011/11/10 22:17:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DuSibD3pn4Q
    [2011/08/28 19:33:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DVDVideoSoft
    [2011/11/10 22:28:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dVrltucSb46fThw
    [2011/11/10 22:00:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dWfLTjeVzt0Si3G
    [2011/11/10 22:39:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DWJ7LgqYXkeltz0
    [2011/11/10 22:37:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\DwwwkIIVrlOtx0c
    [2011/11/10 22:10:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dx0Sbo4HWfLZhwU
    [2011/11/10 22:09:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\dZYjVIzyAvo4GQd
    [2011/11/10 22:42:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\e55ssWJJ7dL
    [2011/11/10 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\E5aQHdXqCIVOx0c
    [2011/11/10 22:33:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\e5s6dEK8ZTwClrP
    [2011/11/10 22:26:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\E8BFfr3LOo
    [2011/11/10 21:59:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\e8ZYklBA1vo4HQd
    [2011/11/10 22:24:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\e9ZjCkrNPci3Gms
    [2011/11/10 22:15:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eaJWKR9XjeB
    [2011/11/10 22:07:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eaQJ6dK8f9XeIz
    [2011/11/10 22:26:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ebo4HWf8TqCkrBP
    [2011/11/10 22:09:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ECkIVrlOtPc1b
    [2011/11/10 22:33:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ED2Fms6Ef9XUl
    [2011/11/10 22:19:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EdEL8RhwVO
    [2011/11/10 22:21:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EeIztAuc2bpGa6f
    [2011/11/10 22:40:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eFpaHdKfLTj
    [2011/11/10 22:35:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eG4aaHWWEThUrx0
    [2011/11/10 21:42:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EgTTZZqjYCwkV
    [2011/11/10 21:46:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EIBBrrzONyxAuv2
    [2011/11/10 22:37:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eIIVVrzNtxA
    [2011/11/10 22:03:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EJ6dEf9XUlrPxu2
    [2011/11/10 22:23:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EJ7L8TZqhCkVlBx
    [2011/11/10 22:43:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EKZYjeIzNAu2b
    [2011/11/10 22:13:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ELTqkIVrzNAci3G
    [2011/11/10 22:21:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eNAvo3GQ6KR
    [2011/11/10 22:10:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EoG4a6WJ7LThCkr
    [2011/11/10 22:36:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eOtxuSi3nHfLgY
    [2011/11/10 21:56:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ePNyxA1uv2b3m5Q
    [2011/11/10 21:44:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EPP00yccS1
    [2011/11/10 22:33:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eRL9gqYCerNxuSi
    [2011/11/10 22:11:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ErNAvo3GQd8LTje
    [2011/11/10 22:32:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\erOxuSip4QsKE9j
    [2011/11/10 22:22:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eS2bpaHW7EgZjwI
    [2011/11/10 22:16:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Es7KgZYjeBPcu
    [2011/11/10 22:29:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EtxPySiDna5JE
    [2011/11/10 21:46:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\etxxPP0ycS1iv3
    [2011/11/10 22:02:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EUCeBOx2Fna6KRg
    [2011/11/10 22:31:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EUINubmdRTCrA2p
    [2011/11/10 22:39:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\eUrOtPySvnaHsJ
    [2011/11/10 21:46:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\evvDD3oonFamHsW
    [2011/11/10 22:13:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EWK8fRL9hX
    [2011/11/10 22:31:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ex0Sbp4HWf9
    [2011/11/10 22:43:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\EXNbdwypfe0pW
    [2011/11/10 22:17:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\f0Sbp5HWfLTjeVO
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\f2ob4GsJEf9TwCl
    [2010/07/21 20:47:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\F3F7477A143605EAE703B9175D916372
    [2011/11/10 22:07:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\f4aHWd8ZYkeBPci
    [2011/11/10 22:19:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\f4GQd8ZTeP
    [2011/11/10 22:41:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\F999hTTXwjUlBzN
    [2011/11/10 22:09:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FamHs7LRhwVlt0A
    [2011/11/10 22:03:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fBPNyAuoFp
    [2011/11/10 22:00:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FBrPxuvS2bpGQdK
    [2011/11/10 22:26:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FD2obF4pm56Ef9X
    [2011/11/10 21:58:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FfRZTjCIz
    [2011/11/10 22:26:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FG5a6KRgq
    [2011/11/10 22:39:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FggRZ99hYXjU
    [2011/11/10 22:13:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FGQd7RgqCIzt0Sb
    [2011/11/10 22:21:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fgrNPci3Gms7L
    [2011/11/10 22:06:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FhwVIzy1Dbp5JEf
    [2011/11/10 21:58:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FIrzNt0ib3Gas7L
    [2011/11/10 22:20:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FJ7dLRhwV
    [2011/11/10 22:25:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fm5aQJ6dW8LTj
    [2011/11/10 22:21:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FnG5aQd7LTjeVOx
    [2011/11/10 22:09:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fpG5aQJ6dKfLqUe
    [2011/12/04 01:50:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FreeFileViewer
    [2011/07/23 00:47:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FrostWire
    [2011/11/10 21:59:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fRZ9TXjIzx
    [2011/11/10 22:06:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ftxPu1Dna6JEgqC
    [2011/11/10 22:37:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FUUCeBrzyAuSoFp
    [2011/11/10 21:44:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fUUVVellOBtP0cA
    [2011/11/10 22:00:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fuvD2Fms6Ef9Xjl
    [2011/11/10 22:30:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fwVltNcAuD
    [2011/11/10 21:45:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fwwkkUVVrlOtx0y
    [2011/11/10 22:40:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\fxxPP0y1vnaHs7L
    [2011/11/10 21:44:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FxxxP00ucS2bDpn
    [2011/11/10 22:22:22 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FYXwjUVelBzNc1v
    [2011/11/10 22:14:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\g2Fna6KRgqkO0ip
    [2011/11/10 22:02:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\G3onG4amHsJfLgZ
    [2011/11/10 22:10:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\G3pnG5H7f9jeVOx
    [2011/11/10 22:28:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\G4ps8YeNyAv2F
    [2011/11/10 22:17:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\G6dEK8fZTCByA2F
    [2011/11/10 22:27:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\G8RZhwVIBN1vFG6
    [2011/11/10 22:11:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\g9gGQs7LTjwIrOx
    [2011/11/10 22:41:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GAA11uvD2obFpm5
    [2011/11/10 22:05:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gcS1ibD3oGHWf8Z
    [2011/11/10 22:30:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gdK7fRL9gXjCVzN
    [2011/11/10 22:26:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gDna5Jd8ZYkeBP
    [2011/11/10 22:37:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\geIrNx1voFp5JdK
    [2010/11/28 23:00:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GetRightToGo
    [2011/11/10 22:07:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gF3nGa6KRgX
    [2011/11/10 22:29:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ggRZ9hYXweB
    [2011/11/10 22:17:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GHWdZkOzy1
    [2011/11/10 22:05:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GibD3onG4m
    [2011/11/10 22:02:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GibDo4amHsJf8Tq
    [2011/11/10 22:14:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gibF3n56KRgqCIz
    [2011/11/10 22:39:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GIOAv2b3GaHdK
    [2011/11/10 22:05:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GJ7dKRhXUltNAvo
    [2011/11/10 22:14:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GmH5sW7L8RhwVOz
    [2011/11/10 22:20:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GPci3Gms7LThwVO
    [2011/11/10 22:25:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Gs7LTYkrNPci3Gm
    [2011/11/10 22:40:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gSiDoFaHsJE
    [2011/11/10 21:57:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gTjYCwkIVlNx0c1
    [2011/11/10 22:09:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GucS2ibD3n4QWf9
    [2011/11/10 22:35:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\guSiFn5QdKfLgXY
    [2011/11/10 22:31:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\guvD2bF4pGsJdKf
    [2011/11/10 21:58:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GWf9TjeVOx0cbp4
    [2011/11/10 21:59:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\gxPcS1Do4Hs78R
    [2011/11/10 22:03:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GzONtxA0uSiDpGQ
    [2011/11/10 22:16:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\GZYkeBPci2FmsJE
    [2011/11/10 22:19:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\H0u2Dna6KEgqYkr
    [2011/11/10 21:58:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\h3pGaH6sW7E9Tqw
    [2011/11/10 22:28:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\h8gZqXwkU
    [2011/11/10 22:22:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ham67LThwVOx
    [2010/02/02 21:53:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Hardcore
    [2011/11/10 22:32:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Hb34HWf9TqCIlN
    [2011/11/10 22:38:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\HbpGaJdKfTjeBzy
    [2011/11/10 21:45:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hCCCwkkIVrlOtx0
    [2011/11/10 22:23:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hF4mH5sJEgZYwUe
    [2011/11/10 22:19:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hfRZ9hwUlrPy1vo
    [2011/11/10 22:02:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hG4amsWJfLgq
    [2011/11/10 22:38:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\HhhYkUeOtPy
    [2011/11/10 22:03:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hIBrzy0Sbp5W
    [2011/11/10 22:35:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\HjeVzNx0ciDpGa
    [2011/11/10 22:41:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hjjUUCeIzNx1v2b
    [2011/11/10 22:08:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hobF4pmG5Q6K
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\HONyxA0uv2b3n5Q
    [2011/11/10 22:40:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hrrlOBPy1DoFm5W
    [2011/11/10 22:32:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hSpHfZwrxS3aJLq
    [2011/11/10 22:31:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hTXjUCekBOyAuSb
    [2011/11/10 22:43:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hTXqjYCekVzNx0c
    [2011/11/10 22:38:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\huSoFm5Q6WfL
    [2011/11/10 22:06:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hVOxu2b3n4sfgqw
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hwUClBrNyASoFpG
    [2011/11/10 22:01:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\HxP0uci3Ga6JEg
    [2011/11/10 21:44:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\hZZZqhhYC
    [2011/11/10 22:21:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\I0ci3Gms7LgZYkr
    [2011/11/10 21:44:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\I111ivvD2onFpm5
    [2011/11/10 22:09:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\i4aQHWf9ZY
    [2011/11/10 22:21:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Ia6KRhqCIzNAviF
    [2011/11/10 21:45:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iBBBtxxP0yc1i
    [2011/11/10 22:13:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IbF4pmG5sJdKR9w
    [2011/11/10 21:45:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IcccSS1ivD3oF4m
    [2011/11/10 22:37:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iccSS1ibDonGHsJ
    [2011/11/10 22:14:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\icu2b4GQd8ZTj
    [2011/11/10 22:21:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iD3on4Hs7LRhUtA
    [2011/11/10 22:37:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IEEEgXjVlBzNAuD
    [2011/11/10 22:11:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IgR9hYXwjVIzyAu
    [2011/11/10 22:39:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\igTTXXqjCIzNt
    [2011/11/10 21:46:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IhhhTXXwjUClIBz
    [2011/11/10 22:40:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iIrOtAuSiDp4Q6W
    [2011/11/10 22:27:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IJ6dEK8fR
    [2011/11/10 22:42:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iJEhYwUVelItNAv
    [2011/11/10 22:20:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IK8RhqCIBNAvi3G
    [2010/07/20 15:04:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ImgBurn
    [2010/09/25 11:19:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iPhone.F4B6EDD4861104DF103CA831FC6755522BBBD9C1.1
    [2011/11/10 22:40:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\iqjYYCIrOt
    [2011/11/10 21:44:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IssWWJJ7dELg
    [2011/11/10 22:41:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IuubmsJdKfR9TUl
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IvD2ob4pmsJEf9T
    [2011/11/10 22:02:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IvD2onF4pHsJdKg
    [2011/11/10 22:39:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ixxuv2bpaJ
    [2011/11/10 22:22:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\IYXwUVelIzNAvo4
    [2011/11/10 22:33:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\J2D3G4QsKE9ZjIl
    [2011/11/10 22:14:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\J6dW8LTjeBOx
    [2011/11/10 22:08:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\J6WfLTjwVlNPu1b
    [2011/11/10 22:25:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\j8fLTjeBOxu2Fna
    [2011/11/10 22:20:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jamHsWJ7Eg
    [2011/11/10 22:23:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jF3pmGQd8LTjeBO
    [2011/11/10 22:10:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JfRZTjeBzy1F
    [2011/11/10 21:57:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JGms7LThCUlt0Sv
    [2011/11/10 22:02:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JH5s7KRhwVItNAv
    [2011/11/10 22:16:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jhYkrBPc1Dna5JE
    [2011/11/10 22:41:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JJ77dEgZhXUe
    [2011/11/10 22:19:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jJdERhwVOzy1DFm
    [2011/11/10 22:20:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jJdKf9XUlrNAvo3
    [2011/11/10 22:08:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JK8gRZ9hYwUeItP
    [2011/11/10 22:40:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jL8TqYwUrlOBP
    [2011/11/10 22:33:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JllIIBtzPNyc1uD
    [2011/11/10 22:37:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jltP1Fs9jlPADps
    [2011/11/10 22:25:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jmG5Qd8ZTjeBPy1
    [2011/11/10 22:34:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jn4Q6KfLgZCkV
    [2011/11/10 22:18:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jNAc2iDnKfLgqYw
    [2011/11/10 22:41:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JNtPc1ii3
    [2011/11/10 22:33:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jNxuSiDn4H
    [2011/11/10 22:05:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jonF4pmH5QEg9XU
    [2011/11/10 21:43:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JOOBBtxPP0cS1v3
    [2011/11/10 22:15:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Jp4aH7EgTjwrt0S
    [2011/11/10 22:34:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jpGaQsKfLgZjI
    [2011/11/10 22:20:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JpmGQd8ZTjeBPxu
    [2011/11/10 21:42:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JPPP0uucS
    [2011/11/10 22:10:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jQH6dWK7fL
    [2011/11/10 22:18:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JQJ7dEg9hXje
    [2011/11/10 22:09:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JR9hXwUlrNAvo3G
    [2011/11/10 22:34:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jRXetcvFHJ
    [2011/11/10 22:17:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jsQJdK8Rhw
    [2011/11/10 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jtSoHfTwtvmdq
    [2011/11/10 22:17:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jVrlOt0Sbo4HW
    [2011/11/10 22:39:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\JVrlOxPyD34sJ78
    [2011/11/10 22:24:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jXUCkBrzOyAvi3n
    [2011/11/10 22:11:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jy1vD3oamE
    [2011/11/10 21:45:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\jYYYCwwkUVrlBtP
    [2011/11/10 22:14:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\k2b3maJdKfLTqUk
    [2011/11/10 22:14:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\k2obF3pmGQd8LTj
    [2011/11/10 22:05:22 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\K5aQJ6dWKfLhXjk
    [2011/11/10 21:59:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\k8RhXwVlt0AvoFp
    [2011/11/10 21:41:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KA11uvSS2ob3pG5
    [2011/11/10 22:32:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KA1Db4GQdKR9X
    [2011/11/10 22:34:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kBBBx0cS13n
    [2011/11/10 22:30:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kc1D3onFaHsJE8h
    [2011/11/10 21:46:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kDD22obbF4p
    [2011/11/10 21:45:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KDDD3oonF4aH5
    [2011/11/10 22:15:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kE8ZwVOBPvFsEZk
    [2011/11/10 22:35:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KezAS5fqIxvbnHK
    [2011/11/10 21:43:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KffEEL9gTZqjCwI
    [2011/11/10 22:12:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kfRL9hTXqUe
    [2011/11/10 22:06:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kgTZhYwVOxy
    [2011/11/10 22:26:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KhXwkUVOBzy1D
    [2011/11/10 22:11:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KhYCkrBPci3Fa5J
    [2011/11/10 22:04:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KIBrzOxuSbp5HWf
    [2011/11/10 22:38:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kIrNx0uc2iDn4a
    [2011/11/10 22:06:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KIVlOxPu1D
    [2011/11/10 22:27:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kJ7dEL8gRqYwUeO
    [2011/11/10 22:04:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kjUVelIBtPyAuDo
    [2011/11/10 21:58:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kkrOx0c2D67LTje
    [2011/11/10 22:39:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kkUelOtz0ci
    [2011/11/10 22:20:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KlA3dTBunKXr0b4
    [2011/11/10 22:41:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KlOOBBtzP0c1v
    [2011/11/10 22:01:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\km5sd89XUeBPcDb
    [2011/11/10 22:40:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Kn4m5WJ7dEgYklt
    [2011/11/10 22:08:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KqhYXUlt0Avo4
    [2011/11/10 22:35:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KqYwUlBx0cioa
    [2011/11/10 22:00:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KrPx1SoFm5Jd8R9
    [2011/11/10 22:43:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\krt0Sb3Gms7
    [2011/11/10 22:36:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ks7LTqYwUByioas
    [2011/11/10 21:47:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KTTTXqqjYCekV
    [2011/11/10 21:46:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KUUUCeelIB
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kuvD2ob4GsJEf9
    [2011/11/10 22:38:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KW7E8TZqYwkVtyi
    [2011/11/10 22:37:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kWfLgXjCIrOtAu2
    [2011/11/10 22:30:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kwjUCelIrPxu2Fm
    [2011/11/10 22:37:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\kXVBPyADoFp5Q6E
    [2011/11/10 22:17:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ky0Sbp5HWf9XYkr
    [2011/11/10 22:14:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KYkrNAci3GQsKEg
    [2011/11/10 22:30:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KZjCwkIVrOxu1
    [2011/11/10 22:00:22 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\KzNyAviFna6KfLX
    [2011/11/10 21:59:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\L3pnG5HWf9XYkrN
    [2011/11/10 21:59:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\L3pnG5Qd7LTjeVO
    [2011/11/10 22:36:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\L55aaQJdKfLTqUe
    [2011/11/10 22:07:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\L5aQJ6dWKfLhXjC
    [2011/11/10 22:22:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\l7LTeOuDaW9q
    [2011/11/10 22:34:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Lb35Kf9XCBOx0vi
    [2011/11/10 22:33:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lCwkUVrlOtPy
    [2011/11/10 22:05:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lDobF4pmG
    [2009/11/24 22:06:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Leadertech
    [2011/11/10 21:42:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\LFFFppnG5aQ6dW7
    [2011/11/10 22:40:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lhXwkUUltPyAv2F
    [2011/11/10 22:40:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lhXwkUUOtPyAv2F
    [2010/11/02 10:46:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\LimeWire
    [2011/05/19 19:13:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Lionhead Studios
    [2011/11/10 22:26:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\LK7fEL9gTjwVlt0
    [2011/11/10 22:01:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lK8fRL9hTqCIzy0
    [2011/11/10 22:30:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lOBtzPyA1v2npQK
    [2009/12/22 03:18:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
     
  15. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    [2011/11/10 22:43:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lp6hlAFQfUO2
    [2011/11/10 22:30:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lR9TjeIzNAvi
    [2011/11/10 22:29:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Ls7LRhwUltPci2
    [2011/11/10 22:28:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ltxA0uc2i3na
    [2011/11/10 22:29:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\LTZqhYCwkVl
    [2011/11/10 22:07:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\LTZqYkrBPc1Dna
    [2011/11/10 22:30:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lx0ciDoGm
    [2011/11/10 22:31:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\lXwjrzNyAvp56KR
    [2011/11/10 22:35:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Lyx1v2b3GaJdKf
    [2011/11/10 22:14:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\m0Si3naHKR
    [2011/11/10 22:43:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\m1aECtimEqUtA
    [2011/11/10 22:34:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\m9TqUkzNxASbpGa
    [2011/11/10 22:29:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mam5Wd8ZYkeBP
    [2011/11/10 21:57:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mcuDb4GQd8
    [2011/11/10 22:00:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mEZYkrBPci3Fm57
    [2011/11/10 22:27:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mhTqeBrzOyAu2Fp
    [2011/11/10 22:39:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\miibF6TVNAciD4H
    [2011/11/10 22:25:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mIVrzt0SiD
    [2011/11/10 22:41:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mkkkIBzyAu2b3n5
    [2011/11/10 22:37:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mNtxP0uciDmEg
    [2011/11/10 22:02:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mtxP0ycSvo4HWd8
    [2011/11/10 21:46:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mwjjUUVelIBtPNc
    [2011/11/10 22:31:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mXjUVlIzNc1DbpG
    [2011/10/06 19:08:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\My Battle for Middle-earth Files
    [2011/11/10 22:12:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\mYwUeBzNc1voFm5
    [2011/11/10 21:42:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\N000uccS2ibDpn
    [2011/11/10 22:33:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\n0vi3GQWf9TjCIr
    [2011/11/10 22:32:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\N3o4aHsJEgqYUlB
    [2011/11/10 22:20:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\n4aH6sWJf
    [2011/11/10 22:19:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\n9hTXwjUClBPyAv
    [2011/11/10 22:37:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\N9YwUeItzPy1v2b
    [2011/11/10 22:35:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nA1i2FFm5
    [2011/11/10 21:57:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Nbp5QdKR9TjkVz
    [2011/11/10 22:26:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NCelIrxu2bpGQ6W
    [2010/06/09 19:34:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NCH Swift Sound
    [2011/11/10 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NdE8gZhXUVeItNu
    [2011/11/10 22:12:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NdEL8gRZYwVOzy
    [2011/11/10 21:57:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NHWd8RZhXkVlt0c
    [2011/11/10 22:20:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NhYXwjUVeBP
    [2011/11/10 22:16:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\niFnaHWf9
    [2011/11/10 22:17:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NIzySbp5JW9XUk
    [2011/11/10 22:35:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NjUelPyAuSbp5Qd
    [2011/11/10 22:07:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NmsJEg9XUltNAvo
    [2011/11/10 22:15:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nnG4msJE8ZhwUPc
    [2011/11/10 21:59:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nnG5Qd7LTjeVOxu
    [2011/11/10 22:31:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nnHgwlP14WgYkeO
    [2012/01/09 21:21:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Notepad++
    [2011/11/10 22:41:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nUCCkrOy0v2bpGQ
    [2011/11/10 22:38:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nWJJ7E8RqXlBPyA
    [2011/11/10 22:14:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NxA1v2oFm5JW8Lh
    [2011/11/10 22:04:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NYXwjUltNAvo4G
    [2011/11/10 21:44:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nYYCCwkkU
    [2011/11/10 21:47:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NyyxxA0uuv2
    [2011/11/10 22:37:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\nZZ99hYXwjUVeIt
    [2011/11/10 21:43:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\o111ivvD3on4aH
    [2011/11/10 21:58:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\O1Dnm78qwVlt0Si
    [2011/11/10 22:36:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\o33ppnG5aQH
    [2011/11/10 22:37:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\o555aHH6dWKfR9T
    [2011/11/10 22:12:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\O5aQd7LTjeVOxu2
    [2011/11/10 22:27:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\O5Q6dWL9gX
    [2011/11/10 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\o6E8R9TwUeI
    [2011/11/10 22:15:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oa5JEgqXUlt0Av2
    [2011/11/10 22:37:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oaHsJE8TqYwUrOt
    [2011/11/10 22:31:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OEL9gTZqjCkVl
    [2011/11/10 22:10:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OelItzPNcu2FmsE
    [2011/11/10 21:56:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\of8ThCUlBPc1DoF
    [2011/11/10 22:05:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ofR9gXYkrNA
    [2011/11/10 22:16:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OG4aQH6sW7E9TqY
    [2011/11/10 22:01:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oG5aQH6dW7R9Tq
    [2011/11/10 21:43:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oGGG4aamH6sJ7EL
    [2011/11/10 22:31:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OGJ6EKfRZhXUIrN
    [2011/11/10 22:08:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OgRZYkeBPci2F
    [2011/11/10 22:40:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ohhXUlBzNx1v2Fp
    [2011/11/10 22:43:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oIO0iGsfghwUBx
    [2011/11/10 22:21:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Oma6dWKRhqCIz
    [2011/11/10 22:07:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ooms7LqUBPc
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OPNyxA1uSoFpGaJ
    [2011/11/10 22:18:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oQJ7dEK8gZhXjVl
    [2011/11/10 22:40:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\oQQHH6ssWK7E9gZ
    [2011/11/10 22:38:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OQQQEKR9Xj
    [2011/11/10 22:28:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ou2Fms6EfZT
    [2011/11/10 22:12:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OuSbp5JWf9Xez0b
    [2011/11/10 21:58:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ovS2ob3GQd8
    [2011/11/10 22:09:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OWJ7LRhwVO
    [2011/11/10 22:31:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OwVOxc1Dna5JE
    [2011/11/10 21:46:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\OyyyccA1iv
    [2011/11/10 22:41:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\P0c11vvD2onFp5Q
    [2011/11/10 22:23:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\p0uSbp4HWf9ZYkr
    [2011/11/10 22:14:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\P5QJEgZYwVltPy1
    [2011/11/10 22:29:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\p7E8RYwUlBzy1vo
    [2011/11/10 22:27:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\P8RhVIzPNDbp5J8
    [2011/11/10 22:43:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\P9gTXqjYCkVzNx0
    [2011/11/10 22:02:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pD3ona5JE
    [2011/11/10 22:34:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PdEEK8ffZ9hTwU
    [2011/11/10 22:10:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PF3pnGaQ6KR9Tj
    [2011/11/10 22:39:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pfRRhTUeI
    [2011/11/10 22:24:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pIlt0Sbo4
    [2011/11/10 22:13:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pIVrlONtxu1Dn4m
    [2011/11/10 22:17:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PjUVelIBtPcu2F
    [2011/11/10 22:10:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PK7LTqCkrOx0c1
    [2011/11/10 22:40:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PLLL8TTZqYCwUrO
    [2011/11/10 22:39:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PlNNtPcS1iD
    [2011/11/10 22:17:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PnF4amHWd8ZhXkV
    [2011/11/10 21:43:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PoobbF3pmG5aQ6W
    [2011/11/10 22:21:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PP0ycS1iv3n4Hs7
    [2011/11/10 22:04:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PQHd7LTjeVOx0S
    [2011/11/10 22:30:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\prOt0Svo4HWd8ZY
    [2011/11/10 22:39:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pt0SSiDo4
    [2011/11/10 22:26:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\PUCelIrxu2bpGQ6
    [2011/11/10 22:32:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pXweBz0ci
    [2011/11/10 22:19:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\pZjP25fUN2aRIA3
    [2011/11/10 22:27:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Q1D3oGamHsJ
    [2011/11/10 22:29:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\q2F5aQJ6dKfLhXj
    [2011/11/10 22:29:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\q2obF5aQJdKfLhX
    [2011/11/10 22:36:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Q44aamH5sWJ7ELg
    [2011/11/10 21:59:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\q6RqCzAi5dLjVAb
    [2011/11/10 22:13:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Q7fEgqCIlNubnas
    [2011/11/10 22:07:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qBzNAu2b3maJdKR
    [2011/11/10 22:34:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qBzyAiDoFp5Q
    [2011/11/10 22:30:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QcF7hO1pEwtvGKw
    [2011/11/10 22:27:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QD3oGamH6WE
    [2011/11/10 22:09:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QF4amH5sW7EgqXU
    [2011/11/10 22:34:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Qf9TqYkIVzNxuS
    [2011/11/10 22:35:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QGG55QQ6E8fZhw
    [2011/11/10 22:05:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QgjwVOxu1Dn4HW
    [2011/11/10 22:38:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qHK9jkzNA
    [2011/11/10 22:12:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QiDoFm5WdLRhwV
    [2011/11/10 22:21:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qJ6dEK8f9XUlrNA
    [2011/11/10 22:22:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qjNoQLCybH7T
    [2011/11/10 22:37:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QLLL9TqYeIzNxuS
    [2011/11/10 22:39:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QmmG5sQJ6K8
    [2011/11/10 22:32:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qo4HW7EgZ
    [2011/11/10 22:30:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QonHQdKRUeIzyAv
    [2011/11/10 22:37:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Qp5QJ7dEERYwVl
    [2011/11/10 22:36:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qqqhhkeOB
    [2011/11/10 22:13:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qtxPu1Dn4
    [2011/11/10 22:04:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QUVrlOBtx0c
    [2011/11/10 22:09:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QVlt0Si3Gms7LgZ
    [2011/11/10 22:24:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qvopQdWKhXUI
    [2011/11/10 22:28:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\qvS2ibF3pGaHdKf
    [2011/11/10 22:40:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Qxx0c2b3n4Q6W7E
    [2011/11/10 22:37:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\QZZZ9hhYwVetA1v
    [2011/11/10 22:30:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\r0yAiDnp5JEgZYU
    [2011/11/10 22:12:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\r0ycA1ivDoFpHsJ
    [2011/11/10 22:24:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\r1bD3on4aHsfgqY
    [2011/11/10 22:39:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\R7ffE9ggZqYIrO
    [2011/11/10 21:58:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\R7RwINv4sERXez1
    [2011/11/10 22:37:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\r8gZhXklt0c1Do4
    [2011/08/11 17:11:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Rainmeter
    [2011/11/10 22:11:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RBtz0Avo4HQ
    [2011/11/10 22:15:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RCelBrPNy1voFm5
    [2010/04/29 13:56:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Red Kawa
    [2011/10/27 20:06:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\redsn0w
    [2009/11/24 22:06:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Regensoft
    [2011/11/10 22:23:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RF4pm5sJ6KRhUl
    [2011/11/10 22:23:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RIPxu2FmQd8
    [2011/11/10 22:36:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\rJJJ7ddEL8RZhXw
    [2011/11/10 22:39:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RjVezNADb4sJdKR
    [2011/11/10 22:12:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\rKf9XUkrNAvi3GQ
    [2011/11/10 22:31:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RoFms7Eg9YjetNA
    [2011/01/09 12:12:22 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Rovio
    [2011/11/10 22:35:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RrllOOBtxP0
    [2011/11/10 22:30:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\RrPy1Sbp5JWR9Tj
    [2011/11/10 22:03:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ruDb4msKRhwCIPy
    [2011/11/10 22:16:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\rxPucSibna6JEqC
    [2011/11/10 22:30:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\rycA1ivD2np5
    [2011/11/10 21:57:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\rYCwkIVrlt0ci3G
    [2011/11/10 22:38:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\s0c23GaHsKfLjCk
    [2011/11/10 21:45:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\s4aammH6sWJ7ELg
    [2011/11/10 22:06:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\S4Q6s7LTjw
    [2011/11/10 22:04:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\S5sQJ7dK8R9XjVl
    [2011/11/10 21:58:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\S9hTXwUelBzyA
    [2011/11/10 22:19:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\S9TXqjCkINx02Fn
    [2011/11/10 22:20:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\saHs7E8RhwV
    [2010/01/27 15:17:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Samsung
    [2011/11/10 22:07:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\saQJKfL9hXe
    [2011/11/10 22:26:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sBPcv3Fms7L
    [2011/11/10 21:46:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sBttzzPNycA1vDo
    [2011/11/10 21:59:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sBtzy1Dnp5JEg9Y
    [2011/11/10 22:40:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ScAA11uvD2obFpG
    [2011/11/10 22:16:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SCekIVrzOxuSb
    [2011/11/10 22:15:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sCIzy0SbpGQ
    [2010/02/28 10:20:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SecondLife
    [2011/11/10 22:38:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SeekkrOt0c
    [2011/11/10 22:12:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\selIBzy1Sbp56Kf
    [2011/11/10 21:59:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SFamH5J7dLgZhwU
    [2011/11/10 21:59:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sG5aQd8LhqCkrN
    [2011/11/10 22:33:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SG5s6dEK8ZTwClr
    [2011/11/10 22:11:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sgqCkrBxy1DnHWd
    [2011/11/10 22:41:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\shYXjeItPyAv2b4
    [2011/11/10 22:06:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sjeBOxAvi3GQd7L
    [2011/11/10 22:33:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SkkVrOtPuSiDoGm
    [2011/11/10 22:38:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SkVlBtP0ySi34ms
    [2011/11/10 22:36:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SL9gqYkrOt
    [2011/11/10 22:21:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sL9hXqjUCrO
    [2011/11/10 22:40:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sltPc1v3oFmHsJd
    [2011/11/10 22:05:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SnG4HWf8ZYkrBPc
    [2011/11/10 22:10:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sNycAvo4GJE8ZTj
    [2011/11/10 22:36:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SobbFF3pmG5Q6W8
    [2011/11/10 22:14:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sonG4amH6W7
    [2011/11/10 22:28:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sonGm6JfLgq
    [2011/11/10 22:36:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Soobb33pmG5QdKf
    [2011/11/10 21:59:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sOyAvi3a7LgqVOx
    [2011/11/10 22:15:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SP0cvo45Jd8ZYUt
    [2011/11/10 22:34:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\spm5JdK8RTj
    [2011/11/10 22:18:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SpmaJd8R9TqCkBN
    [2011/11/10 22:14:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sQJ6dW8LTje
    [2011/11/10 22:20:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SqjCekBrzyAu2b3
    [2011/11/10 22:40:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sqjjUUekIBOA0v2
    [2011/11/10 22:36:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SRRRUClBPx1ub3p
    [2011/11/10 21:43:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sS22iibF3pnGaQ
    [2011/11/10 21:56:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SSomWf8ThCUlBPc
    [2011/11/10 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\StzNNuv2bF4m5Q6
    [2010/10/30 19:30:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Subversion
    [2011/11/10 22:24:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sUVltPyAiDo4m5J
    [2011/11/10 22:06:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Sv2Fms7KRh
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SxA0uvS2iFpGaHd
    [2011/11/10 22:03:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\sXqeVONu2Dna6KE
    [2012/03/17 16:04:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\SystemRequirementsLab
    [2011/11/10 21:42:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\t33pnGG5aQH6WKf
    [2011/11/10 22:10:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\t5sQJ6dEKfZTjeB
    [2011/11/10 22:22:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\t6KRgTjCIzNx0cb
    [2011/11/10 22:23:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\T9hTXClIPxu2FmQ
    [2011/11/10 22:03:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tBzy1Sob3mQdK
    [2011/11/10 22:24:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tCVNP13a67
    [2011/11/10 22:33:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TD3nF4HWd
    [2011/11/10 22:06:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TDo4HW8Ye
    [2011/10/25 22:48:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TeamViewer
    [2011/11/10 22:22:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TFms7LRhw
    [2011/11/10 22:22:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tG4aQH6sW7Egq
    [2011/11/10 22:30:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ThkelOBtz
    [2011/11/10 22:27:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Tkltc3mWEgqXUBy
    [2011/11/10 22:24:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TkrONAu23na6
    [2011/11/10 22:24:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TlBtPcDpJfXlNv3
    [2011/11/10 22:07:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Tm6RqIyS3a6R
    [2011/11/10 22:16:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tonG4ams7LThCVO
    [2011/11/10 22:43:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TQgYUlBzD4dRUru
    [2011/11/10 22:16:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TS1ibD3on
    [2011/11/10 22:24:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Ts6Kf9XjeBzy
    [2011/11/10 22:38:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tTTXXqjUUekIrzN
    [2011/11/10 22:15:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Tv2o4GQd8ZTjeNA
    [2011/11/10 22:27:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tvSobF3ma6
    [2011/11/10 22:18:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TWJdEL8RhwVOzy1
    [2011/11/10 22:27:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\twkUVOPy1Dna5
    [2011/11/10 22:28:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TxA0uv2FpGQdKfL
    [2011/11/10 21:56:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TXwjUelIBPyAuSo
    [2011/11/10 22:41:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TXXXqjUCekIrzNx
    [2011/11/10 21:46:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\tzzPP0yccAivDoF
    [2011/11/10 22:32:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\u02FnaQdKf9T
    [2011/11/10 22:38:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\u22n4msJdKg9Xje
    [2011/11/10 22:38:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\U44ppmHJEghXUeI
    [2011/11/10 22:31:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\U4pm5Q6Kf9XjrNA
    [2011/11/10 22:02:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\U6sWJ7fELgZhCkr
    [2011/11/10 22:36:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\u7ddE8gR9
    [2011/11/10 22:36:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\u8fRRhTXwjClBPx
    [2011/11/10 22:20:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\u9XYkrNAu2Dna6K
    [2011/11/10 21:42:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UbbbD33pnGa
    [2011/11/10 21:46:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\uBBrrzPNyxA1uSo
    [2011/11/10 22:40:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UgjIOPSDG678qwr
    [2011/11/10 22:22:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\uIlt0Sbo4
    [2011/11/10 22:28:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\uIzy0Sbpna6WfLT
    [2011/11/10 22:30:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UjUCelIrPxu2Fma
    [2011/11/10 22:29:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UkBryAvi3GdLTYr
    [2011/11/10 22:35:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UkrOtD58UBv
    [2011/11/10 22:04:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\umH5sQJ7dKR9XjV
    [2011/11/10 21:43:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ummHH5sWJ
    [2011/11/10 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Un5aQHdXqCIOx0
    [2011/04/16 23:25:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Unity
    [2011/11/10 22:00:31 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UQ6K7fL9TqCkzt0
    [2011/11/10 22:09:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UsWKE9ZjCkrOxuS
    [2011/11/10 22:15:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UUlt0Svo4HWd8ZY
    [2011/11/10 22:00:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\UW7LTZqjCIl
    [2011/11/10 22:43:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\uxF5RTBybnfgINi
    [2011/11/10 21:45:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\v11iibDD3on4aH6
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\v1uvD2ob4GsJE
    [2011/11/10 22:41:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\v3n4msJdRh
    [2011/11/10 22:23:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\V3onF4amHs7L
    [2011/11/10 21:44:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\V44aammH5sW7
    [2011/11/10 22:28:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\V4qhYCwkUrx0SiD
    [2011/11/10 22:36:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\V6W7EgZjk
    [2011/11/10 22:32:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\V8fZ9TXwjCIrPSF
    [2011/11/10 22:29:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\v9gTqCIrNPu1D4H
    [2011/11/10 22:26:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\v9hTXwjUCl
    [2011/11/10 21:42:28 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VbFF4ppmG
    [2011/11/10 22:41:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vcciivDom5
    [2011/11/10 22:16:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vd8LTjeBOx
    [2011/11/10 22:41:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vEELL9gTZjYwOxu
    [2011/11/10 22:42:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vF44amW7dEgqYXk
    [2011/11/10 22:22:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VFms78ZXU
    [2011/11/10 22:25:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VfRL9hTXqUeI
    [2011/11/10 22:36:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vjUUCCekIBrzN
    [2011/11/10 22:01:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VKf9hTXjUerOxu2
    [2011/11/10 22:31:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VkVelOBPc12FHQd
    [2011/11/10 22:23:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VNyx1uvS2
    [2011/11/10 22:14:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vOPciDonaHsJf
    [2011/11/10 22:14:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vRZ9hTXwjClBzNx
    [2011/11/10 22:20:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Vs7LgqCIlt01DoG
    [2011/11/10 21:41:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VsKEgqYkVOxu1bo
    [2011/11/10 22:11:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VsWKf9ZYwVOxu1D
    [2011/11/10 21:57:27 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VTXjekIBrOy0vip
    [2011/11/10 22:08:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VtxP0ucS1b3n4m6
    [2011/11/10 22:39:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VVltPNy1u
    [2011/11/10 22:22:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vWK7fRL9gX
    [2011/11/10 22:16:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vXUeBOxu2Fna6
    [2011/11/10 21:56:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VXUkBNxu2Fna6Kf
    [2011/11/10 22:22:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VXwUeIzNAvo4GQd
    [2011/11/10 22:22:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\vycv4Q8TeP1b5
    [2011/11/10 22:06:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VzPy1vbF4msJdfT
    [2011/11/10 22:06:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\W1uvD2obFpGsJdK
    [2011/11/10 22:26:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\w3Gms7LThw
    [2011/11/10 22:18:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\W4aQH6sWKfLZjwI
    [2011/11/10 22:38:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\W6R9TqUeBzNx0v2
    [2011/11/10 22:19:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\w6sWJ7fELgZhCkV
    [2011/11/10 22:10:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\W9TXjCkBOy0v2Fp
    [2011/11/10 22:27:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Wb5dLqrcG7jr03m
    [2011/11/10 22:41:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WEEEL9gTZjYkVOt
    [2011/11/10 22:16:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\welrNAvo3G
    [2011/11/10 22:06:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wG4asWfEgqwIt
    [2011/11/10 22:03:15 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wgRhwVIzy1Dbp
    [2011/11/10 22:18:39 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WgZYUlByD4Q8Yez
    [2011/11/10 22:17:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wH6sEgqCIlt0ci3
    [2011/11/10 22:40:35 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WHHH6s7E8ZCkVlB
    [2010/05/31 13:23:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WildTangent
    [2011/10/27 23:19:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WindSolutions
    [2011/11/10 22:43:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wKLkOS3dLerSD6K
    [2011/11/10 22:26:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wLgRZqhXwU
    [2011/11/10 22:18:49 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wlIBrzNxu2Fma6K
    [2011/11/10 22:20:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wlOBtxPy1Dna5
    [2011/11/10 22:25:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WLTqYwIrN
    [2011/11/10 22:15:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WNtx0ucSi3Ga
    [2011/11/10 22:05:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WoF3pmG5aJdKfLh
    [2011/11/10 22:30:44 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WONyx0S2i
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wQJEKfZ9TwUlBNx
    [2011/11/10 22:00:12 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wSpHfXkNuDaKgCl
    [2011/11/10 22:24:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wVrlNx0uc1Dna6J
    [2011/11/10 22:07:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wwVIzy1Do4GQd8Z
    [2011/11/10 22:16:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\wx0ucS1ibnmsJE8
    [2011/11/10 22:35:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WXYeIzNx0c2DpGa
    [2011/11/10 22:18:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WZqjYCwVO
    [2011/11/10 22:36:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WZZZqhhYCwkV
    [2011/11/10 22:16:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\x12FmsdZTjeBPy1
    [2011/11/10 22:04:18 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\x5sJd8ZhwUlBzcu
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XBrzONyxAuSiFpG
    [2011/11/10 22:26:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xCNiQLexD69
    [2011/11/10 22:10:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xg9XUelItPc
    [2011/11/10 22:36:00 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xIIBBrzOOyx
    [2011/11/10 22:31:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XjVlzcA1uhUeBPy
    [2011/11/10 22:42:17 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XlllOBBtxP0yS1v
    [2011/11/10 22:26:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xNoQLCNiQLexD69
    [2011/11/10 22:30:22 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XONxu1Dn4msJEgq
    [2011/11/10 22:23:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XQJ7Eg9XUltNcu2
    [2011/11/10 22:01:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xrBPci3n4ms7E8
    [2011/11/10 22:09:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XrzPy1Sbp5JWf9X
    [2011/11/10 22:02:41 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xtzPNycA1v2b4m5
    [2011/11/10 22:26:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xUt0Svo4HW7LgZh
    [2011/11/10 22:25:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xv2ob4GsJdKR9X
    [2011/11/10 22:31:02 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xvD3onF4aHsJdLg
    [2011/11/10 22:42:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XvDD3oFF4mW7dgq
    [2011/11/10 22:36:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XvoFpGaJW8
    [2011/11/10 22:11:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xvS2obF3pGaJdK
    [2011/11/10 21:58:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\xwVIzyAvo4GQdRw
    [2011/11/10 22:31:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XwVlzcA1uhUeBPy
    [2011/11/10 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\XzPNyc1uv2
    [2011/11/10 22:41:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Y00ycSivDn4a5JE
    [2011/11/10 22:07:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Y7L9TjwVOxu1Dna
    [2011/11/10 22:00:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\y89XUlrNAvo
    [2011/11/10 22:32:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yA0ucib3pGaHKf
    [2011/11/10 22:20:04 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yb4W9Cl0b4W
    [2011/11/10 22:17:53 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YBtxP0ycSi
    [2011/11/10 21:56:22 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yc1Do4mG5QdRXlP
    [2011/11/10 22:03:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yD2nm5Jd8R9XjVl
    [2011/11/10 22:31:55 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yD3n4mHWJdLRqYw
    [2011/11/10 22:23:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yd8ZXUlBzciHJE
    [2011/11/10 22:08:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YelOBtzP0c
    [2011/11/10 22:29:33 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YEZjwVlNx0cbo
    [2011/11/10 22:27:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yFp5Qd7RgqYkrNx
    [2011/11/10 22:32:54 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yFs7EgZYwUeIzy1
    [2011/11/10 22:11:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yhTXqjUCeIrOyA
    [2011/11/10 22:15:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YJ6dW8LTje
    [2011/11/10 22:15:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ylIrPNyx1Sb
    [2011/11/10 22:40:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YLL88gTZZqYCwUr
    [2011/11/10 22:30:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yltNcAuDb4m5Jd
    [2011/11/10 21:44:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yONNttxP0uc
    [2011/11/10 22:16:20 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yONx0ucS1bnmsJ
    [2011/11/10 22:38:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yPcDn4m6JfL
    [2011/11/10 22:29:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ypnGaQ6dW79
    [2011/11/10 22:00:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YqYkrNPci3nms7L
    [2011/11/10 22:43:47 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\yS2obF3pm5Q
    [2011/11/10 22:04:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YtPuSb3onm6W7
    [2011/11/10 21:44:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YtttxPP0ucS1bDo
    [2011/11/10 22:21:57 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\YTZYkrBPci3Fms7
    [2011/11/10 22:07:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Z3on4aHsW7EThwV
    [2011/11/10 22:36:19 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\z6E88hXjeIrNx
    [2011/11/10 22:24:10 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Z6KRhwCIzySbGQd
    [2011/11/10 21:59:24 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Z6sWf9ZjwVOx
    [2011/11/10 22:26:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Z8UNoQLCN
    [2011/11/10 21:46:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZBBttzPP0
    [2011/11/10 22:29:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZCelIBrzPyAv23m
    [2011/11/10 22:39:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zD33pnG4aHsW79T
    [2011/11/10 22:08:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZD3nG4a6JEgqYkV
    [2011/11/10 22:06:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Zd8LTjeBOxu2Fna
    [2011/11/10 22:10:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zd8ZTjeBPxu2F
    [2011/11/10 22:20:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zEgqCIrNPciDna6
    [2011/11/10 22:03:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZekIVrzOtAci
    [2011/11/10 22:22:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zEL8gqXUlt0A2mJ
    [2011/11/10 22:40:52 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZFpGaJdKfLTCkIr
    [2011/11/10 22:17:42 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zH6dK7RLgXjCI
    [2011/11/10 22:39:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZHd7TqCIrNxcD3G
    [2011/11/10 22:19:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zIlt0ci3Ga6W7E8
    [2011/11/10 22:11:38 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZjYCIlt0Si3Gms7
    [2011/11/10 22:38:56 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zkkIVzNx0c2b3n4
    [2011/11/10 22:11:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZL9gTXqjYeVOxuS
    [2011/11/10 22:08:32 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Zna6KRgqCIzt
    [2011/11/10 22:25:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZnG4a6KEgqCI
    [2011/11/10 22:07:01 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zNubp4HWfgqCI
    [2011/11/10 22:02:08 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zo3GQd8LTjeIzNx
    [2011/11/10 22:07:30 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zONtPc1Do4
    [2011/11/10 22:14:25 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZOtzP0ycAi2FmsJ
    [2011/11/10 22:19:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZrlOtxP0yi3FaHW
    [2011/11/10 22:13:21 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZS1Do4H7gCrBPci
    [2011/11/10 22:18:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zS1ivDoF45W7E
    [2011/11/10 22:29:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zTjIzy1Sbp5JWf9
    [2011/11/10 22:36:11 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zTTjYCktuS2DpGa
    [2011/11/10 22:24:37 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ztxy1Dna5JEgq
    [2011/11/10 22:20:51 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zuFsKhCz1b5W9
    [2011/11/10 22:38:48 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zv3naHsJE8
    [2011/11/10 22:38:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZvDD2oobF
    [2011/11/10 22:23:14 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zVrlONtxPuSiDoG
    [2011/11/10 22:38:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZwjUClBzNx1SoFm
    [2011/11/10 22:32:07 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZWK8fRL9TqUeIry
    [2011/11/10 22:00:23 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zxPcD4HW7L
    [2011/11/10 22:35:40 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\zXXwjUePyAuSbp5
    [2011/11/10 22:23:29 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZYCwkUVrlBx0c1v
    [2011/11/10 22:09:34 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\ZzPNyxA1u
    [2012/07/09 02:37:39 | 000,000,402 | ---- | M] () -- C:\Windows\Tasks\Free File Viewer Update Checker.job
    [2011/12/30 18:30:25 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
    [C:\Windows\system64] -> \systemroot\system32 -> Mount Point

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 198 bytes -> C:\ProgramData\Temp:0C1EFF69
    @Alternate Data Stream - 170 bytes -> C:\ProgramData\Temp:DFC5A2B2
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:302A9871
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84

    < End of report >
     
  16. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    OTL Extras logfile created on: 7/9/2012 4:19:02 PM - Run 1
    OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brian\Downloads
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    4.00 Gb Total Physical Memory | 2.43 Gb Available Physical Memory | 60.68% Memory free
    8.00 Gb Paging File | 6.40 Gb Available in Paging File | 80.02% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 285.40 Gb Total Space | 11.84 Gb Free Space | 4.15% Space Free | Partition Type: NTFS
    Drive D: | 7.60 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

    Computer Name: JACOB102010012 | User Name: Brian | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [TVersity] -- "C:\Program Files (x86)\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [TVersity] -- "C:\Program Files (x86)\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
    "{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
    "{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
    "{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
    "{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
    "{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
    "{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
    "{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
    "{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{26261401-1676-4C50-8836-0BECCEE7FA10}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
    "{28AB0279-85AE-4821-9E6F-C336218E608C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
    "{44B6F716-FA45-498A-8723-973789F4AF43}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
    "{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{7EE43F2E-D5D2-4E1E-AB5A-13A6B6C578E3}" = protocol=58 | dir=in | app=system |
    "{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
    "{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "TCP Query User{FCD08F65-9762-4300-AE72-43E985516A00}C:\program files (x86)\diablo iii\diablo iii.exe" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
    "UDP Query User{6713CBF7-9AC4-43BC-9AF1-ABF2E4A999DD}C:\program files (x86)\diablo iii\diablo iii.exe" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
    "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
    "{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}" = ASUS Power4Gear Hybrid
    "{1A570BFA-D775-47EE-8071-06E9559C14F5}" = HP Deskjet 1000 J110 series Product Improvement Study
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    "{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
    "{26A24AE4-039D-4CA4-87B4-2F86416022FF}" = Java(TM) 6 Update 22 (64-bit)
    "{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
    "{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
    "{39107B20-EA1C-4974-881C-607300BB3C99}" = MobileMe Control Panel
    "{48B0F24F-B828-4B1A-A22E-C65454B32A7A}" = Windows Live Family Safety
    "{491DF203-7B61-4F0E-BDCB-A1218C4DAFE9}" = Native Instruments Massive
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{64A3A4F4-B792-11D6-A78A-00B0D0160220}" = Java(TM) SE Development Kit 6 Update 22 (64-bit)
    "{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
    "{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}" = HP Deskjet 1000 J110 series Basic Device Software
    "{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
    "{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
    "{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{8E4B6E39-A0A8-4AFD-91C7-56421C194C29}" = TortoiseSVN 1.6.11.20210 (64 bit)
    "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
    "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
    "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
    "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
    "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
    "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    "{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{96178C0A-BAF9-4E49-A2A5-CDE76722105B}" = HP Deskjet D1600 Printer Driver Software 14.0 Rel. 6
    "{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client
    "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
    "{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
    "{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
    "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
    "{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
    "{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 296.10
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 296.10
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 296.10
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
    "{B45B875E-5CE7-4BAE-AAD3-686F3A818E40}" = Cepstral Damien 5.2.0
    "{B636C9B9-A3F2-4DCE-ADCC-72E095018385}" = Microsoft SQL Server VSS Writer
    "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    "{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
    "{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
    "{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
    "{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
    "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
    "{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
    "{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "EPSON Printer and Utilities" = EPSON Printer Software
    "HP Imaging Device Functions" = HP Imaging Device Functions 14.0
    "HP Smart Web Printing" = HP Smart Web Printing 4.60
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
    "HPExtendedCapabilities" = HP Customer Participation Program 14.0
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Microsoft Security Client" = Microsoft Security Essentials
    "NVIDIA Display Control Panel" = NVIDIA Display Control Panel
    "NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
    "SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
    "SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
    "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software
    "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
    "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
    "Shop for HP Supplies" = Shop for HP Supplies
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "USB 2.0 UVC 1.3M WebCam" = USB 2.0 UVC 1.3M WebCam
    "WinRAR archiver" = WinRAR archiver

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
    "{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
    "{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
    "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
    "{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
    "{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
    "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
    "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
    "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
     
  17. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    "{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1" = Geeks3D PhysX FluidMark v1.2.0
    "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
    "{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
    "{0E2B767B-EA6A-489B-BF83-8083FE1DB661}" = Pcsx2 0.9.6
    "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
    "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
    "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
    "{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
    "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
    "{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
    "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
    "{166FCF01-AC98-4288-A01C-90BEB808C059}" = Sony RAW Driver
    "{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
    "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
    "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
    "{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
    "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
    "{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
    "{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
    "{2208D65A-1BF9-485E-A308-1BA6CADCDC1D}" = Windows Live Movie Maker Beta
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{23170F69-40C1-2701-0464-000001000000}" = 7-Zip 4.64
    "{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
    "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
    "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
    "{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
    "{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
    "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
    "{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
    "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (BWDATOOLSET)
    "{2B885437-7098-4409-8A94-F06990D32D76}" = NVIDIA PhysX Particle Fluid Demo
    "{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
    "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
    "{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
    "{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
    "{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
    "{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
    "{343A1706-26A4-45EA-88CF-37CA172B0F27}" = D1600
    "{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
    "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
    "{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
    "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
    "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
    "{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
    "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
    "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
    "{40580068-9B10-40B5-9548-536CE88AB23C}" = ITECIR
    "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
    "{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
    "{4343080E-91B7-4388-AB4D-FB1000008200}" = Dead Rising 2
    "{43430FA5-AF68-4A2D-A7D4-891000008200}" = Street Fighter X Tekken
    "{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
    "{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
    "{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
    "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
    "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
    "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
    "{4D53090A-9B45-437B-A66A-831000008300}" = Fable III
    "{5164E4B0-9CD0-454A-BAC0-6771A15EEB64}" = Air Mouse Server
    "{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
    "{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
    "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
    "{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
    "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
    "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
    "{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
    "{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2
    "{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
    "{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
    "{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
    "{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
    "{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
    "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
    "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
    "{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
    "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
    "{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
    "{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
    "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
    "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
    "{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
    "{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
    "{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
    "{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
    "{71C27D05-DFB4-4585-919E-631379695D72}" = Samsung PC Studio 3
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
    "{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
    "{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
    "{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
    "{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
    "{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
    "{7FB413C8-3CAD-49F7-A67C-6EFEB4B04050}" = LogMeIn Hamachi
    "{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1" = iExplorer 2.2.1.3
    "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
    "{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
    "{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
    "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
    "{865CD808-6D31-4269-9D36-693CFE75D26A}" = Express Gate
    "{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
    "{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
    "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{8EB8E60B-315D-44EB-A896-10D88602EE46}" = Adobe Setup
    "{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
    "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
    "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
    "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90140000-001B-0000-0000-0000000FF1CE}" = Microsoft Office Word 2010
    "{90140000-001B-0000-0000-0000000FF1CE}_Office14.WORD_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001B-0409-0000-0000000FF1CE}_Office14.WORD_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-0409-0000-0000000FF1CE}_Office14.WORD_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-040C-0000-0000000FF1CE}_Office14.WORD_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.WORD_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002A-0000-1000-0000000FF1CE}_Office14.WORD_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002A-0409-1000-0000000FF1CE}_Office14.WORD_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-002C-0409-0000-0000000FF1CE}_Office14.WORD_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-006E-0409-0000-0000000FF1CE}_Office14.WORD_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0115-0409-0000-0000000FF1CE}_Office14.WORD_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0116-0409-1000-0000000FF1CE}_Office14.WORD_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
    "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
    "{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
    "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
    "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
    "{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
    "{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
    "{A4B308CA-8235-404D-8876-8A73BA4497B1}" = BatteryCare
    "{A589DA26-51BD-475D-8C32-E19E34145842}" = Camtasia Studio 6
    "{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
    "{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5
    "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
    "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
    "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
    "{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
    "{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
    "{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
    "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
    "{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
    "{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
    "{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
    "{BABBE752-6969-42EC-8EAC-5D07604BCD08}_is1" = Find Password Protected Documents version 7.0
    "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
    "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
    "{BC99E569-2C69-42EC-8422-77BAAF46F1B7}_is1" = Tag - v1.1
    "{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1" = Sothink SWF Decompiler
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
    "{C0A7E4F3-82CC-416B-82C6-BA06AACFD635}_is1" = Auto Clicker v1.1
    "{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
    "{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
    "{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
    "{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
    "{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
    "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
    "{C9B2F671-870B-43A0-8B9D-7DB30CEBD87E}" = DJ_SF_06_D1600_SW_Min
    "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
    "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
    "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
    "{D04D8636-FB60-47FD-8F8C-18D475C52456}_is1" = Auto Typer by MurGee v1.1
    "{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
    "{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
    "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
    "{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
    "{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
    "{D47087E7-AA15-4D1D-8C0A-60F7E446D597}" = PSP ISO Compressor
    "{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
    "{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
    "{D6D5CFB3-7095-4073-B6B7-B7E909838C57}" = Razer ProlClick v1.6
    "{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
    "{D8B5C1BB-5951-422D-A4D5-451675614956}_is1" = Men of War: Assault Squad (Remove Only)
    "{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
    "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
    "{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
    "{DC905847-D537-427F-BF91-47CC7ACCDE58}" = ASUS FancyStart
    "{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}" = HP Deskjet 1000 J110 series Help
    "{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
    "{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
    "{E0217B26-F1EF-4D07-8448-DDBF8C2843E1}_is1" = Auto Mouse Click version 1.1
    "{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
    "{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
    "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
    "{E426CEC1-35C5-42BF-913E-6EF8F1211D01}" = Overlord II
    "{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
    "{E8C37E27-5205-4C8A-BECB-B00533045AAE}" = SHIFT 2 UNLEASHED™
    "{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
    "{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
    "{EDBE26EE-6FD1-6E94-D066-9460B9C17194}" = Desktop iPhone
    "{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
    "{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
    "{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
    "{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
    "{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
    "{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
    "{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
    "{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
    "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
    "{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
    "{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
    "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
    "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
    "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
    "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
    "{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
    "{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}" = Barbarian Invasion
    "{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "3D Driving-School" = 3D Driving-School
    "4U MP4 Video Converter_is1" = 4U MP4 Video Converter (version 3.8.6)
    "4Videosoft MKV Video Converter_is1" = 4Videosoft MKV Video Converter
    "8461-7759-5462-8226" = Vuze
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "Adobe_5aab5a491a3a52ae624fd639f6aaa95" = Adobe After Effects CS4 Third Party Content
    "Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
    "Age of Mythology 1.0" = Age of Mythology
    "Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
    "Air Video Server" = Air Video Server 2.1.7
    "AirStrike3D - Operation W.A.T._is1" = AirStrike3D - Operation W.A.T. v1.31
    "Alien vs. Triangles" = NVIDIA Alien vs. Triangles demo
    "AnalogX AutoTune" = AnalogX AutoTune
    "ASIO4ALL" = ASIO4ALL
    "AssaultCube_v1.0" = AssaultCube v1.0
    "Audacity_is1" = Audacity 1.2.6
    "AVCWare iPod to iPod/Computer/iTunes Transfer" = AVCWare iPod to iPod/Computer/iTunes Transfer
    "AviSynth" = AviSynth 2.5
    "AVS Update Manager_is1" = AVS Update Manager 1.0
    "AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
    "AVS4YOU Video Converter 7_is1" = AVS Video Converter 7
    "Browser Defender_is1" = Browser Defender 3.0
    "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "Counter Strike 1.6 V34" = Counter Strike 1.6 V34
    "Counter-Strike 1.6" = Counter-Strike 1.6
    "Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
    "DAEMON Tools Toolbar" = DAEMON Tools Toolbar
    "DarkSteam" = DarkSteam
    "Debut" = Debut Video Capture Software
    "DemonStar Full v3.25" = DemonStar Full v3.25
    "DemonStar Secret Missions 1_is1" = DemonStar Secret Missions 1
    "DemonStar Secret Missions 2_is1" = DemonStar Secret Missions 2
    "DFX for Windows Media Player" = DFX for Windows Media Player
    "Diablo III" = Diablo III
    "Disk Checker" = Disk Checker
    "DiskAid_is1" = DiskAid 5.08
    "DokanLibrary" = Dokan Library 0.5.3
    "Driver San Francisco" = Driver San Francisco
    "Driving Speed 2_is1" = Driving Speed 2.0
    "Drumaxx" = Drumaxx
    "E3F5A4BD-ED28-4339-889D-73DC3683540B" = Blackhawk Striker 2 from WildTangent (remove only)
    "EADM" = EA Download Manager
    "Easy WiFi Radar" = Easy WiFi Radar 1.0.5
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "EPSON Scanner" = EPSON Scan
    "EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.30
    "F.E.A.R. 3_is1" = F.E.A.R. 3
    "ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
    "FL Studio 9" = FL Studio 9
    "FLV Player" = FLV Player 2.0 (build 25)
    "FMS" = FMS
    "Fraps" = Fraps (remove only)
    "Free Audio CD Burner_is1" = Free Audio CD Burner version 1.5.815
    "FreeFileViewer_is1" = Free File Viewer 2010
    "FrostWire" = FrostWire 4.21.7
    "GameSpy Arcade" = GameSpy Arcade
    "Gas Guzzlers Combat Carnage_is1" = Gas Guzzlers Combat Carnage
    "GFWL_{4343080E-91B7-4388-AB4D-FB1000008200}" = Dead Rising 2
    "GFWL_{4D53090A-9B45-437B-A66A-831000008300}" = Fable III
    "Halo Trial" = Microsoft Halo Trial
    "Higher Score on the SAT/PSAT_is1" = Higher Score on the SAT/PSAT
    "HP Photo Creations" = HP Photo Creations
    "HyperSnap 6" = HyperSnap 6
    "IGI 2" = IGI 2
    "IL Download Manager" = IL Download Manager
    "ImgBurn" = ImgBurn
    "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
    "InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
    "InstallShield_{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
    "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
    "InstallShield_{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
    "iPhone.F4B6EDD4861104DF103CA831FC6755522BBBD9C1.1" = Desktop iPhone
    "iWisoft Flash SWF to Video Converter_is1" = iWisoft Flash SWF to Video Converter 3.4
    "JDownloader" = JDownloader
    "LimeWire" = LimeWire 5.5.8
    "LogMeIn Hamachi" = LogMeIn Hamachi
    "Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
    "Microsoft SQL Server 2005" = Microsoft SQL Server 2005
    "MIDI to WAV Converter_is1" = MIDI to WAV Converter 6.1
    "MKV Minimum Set (LD-Anime) - MatroskaSplitter & VSFilter_is1" = Matroska Pack - Lazy Man's MKV 0.9.9
    "Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "Native Instruments Massive" = Native Instruments Massive
    "Native Instruments Massive v1.0.1.008 VSTi DXi RTAS" = Native Instruments Massive v1.0.1.008 VSTi DXi RTAS
    "Native Instruments Service Center" = Native Instruments Service Center
    "Notebook Hardware Control" = Notebook Hardware Control 2.0 Pre-Release-06 Bugfix
    "Notepad++" = Notepad++
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "Office14.WORD" = Microsoft Word 2010
    "OpenAL" = OpenAL
    "Orcs Must Die!_is1" = Orcs Must Die!
    "Picasa 3" = Picasa 3
    "PoiZone" = PoiZone
    "PowerISO" = PowerISO
    "Prism" = Prism Video File Converter
    "PunkBusterSvc" = PunkBuster Services
    "Quick Memory Editor_is1" = Quick Memory Editor 5.5
    "Rainmeter" = Rainmeter
    "reFX Nexus_is1" = reFX Nexus VSTi RTAS v2.2.0
    "RivaTuner" = RivaTuner v2.03
    "RocketDock_is1" = RocketDock 1.3.5
    "Roller Coaster Tycoon 3 Platinum - CarlesNeo !" = Roller Coaster Tycoon 3 Platinum - CarlesNeo !
    "RPG Maker VX RTP_is1" = RPG Maker VX RTP
    "RPGToolkit3" = RPGToolkit, Version 3.1.0
    "RW-Everything_is1" = RW-Everything v1.5.2
    "Saints Row The Third_is1" = Saints Row The Third
    "Sakura" = Sakura
    "Sauerbraten" = Sauerbraten
    "Sawer" = Sawer
    "Search and Recover 3_is1" = iolo technologies' Search and Recover 3
    "Seven Kingdoms II" = Seven Kingdoms II
    "Sniper Elite V2_is1" = Sniper Elite V2
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "SpeedFan" = SpeedFan (remove only)
    "Spyware Doctor" = Spyware Doctor 8.0
    "sXe Injected" = sXe Injected
    "SystemRequirementsLab" = System Requirements Lab
    "TeamViewer 6" = TeamViewer 6
    "Toxic Biohazard" = Toxic Biohazard
    "TVersity Codec Pack" = TVersity Codec Pack 1.2
    "TVersity Media Server Pro" = TVersity Media Server Pro 1.7.2.1 Beta
    "Two Worlds II" = Two Worlds II
    "Videora iPod Converter" = Videora iPod Converter 5.03
    "Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
    "Virtual DJ Pro Full - Atomix Productions" = Virtual DJ Pro Full - Atomix Productions
    "Virus Demo_is1" = Virus 1.22.4 Demo
    "VLC media player" = VLC media player 1.0.2
    "WavePad" = WavePad Sound Editor
    "WildTangent wildgames Master Uninstall" = WildGames
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "winscp3_is1" = WinSCP 4.3.6
    "Xvid_is1" = Xvid 1.2.2 final uninstall
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! Messenger" = Yahoo! Messenger
    "Yahoo! Software Update" = Yahoo! Software Update
    "YouTube Downloader App" = YouTube Downloader App 2.03
    "YS FLIGHT SIMULATOR" = YS FLIGHT SIMULATOR

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-2418110221-3350712148-3301581529-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "7425f1d58341147e" = ES40 iPhone Emulator
    "CopyTrans Suite" = CopyTrans Suite Remove Only
    "Google Chrome" = Google Chrome
    "Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
    "SwiftKit" = SwiftKit
    "UnityWebPlayer" = Unity Web Player

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 11/26/2011 1:30:48 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 4010

    Error - 11/26/2011 1:30:49 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 11/26/2011 1:30:49 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 5008

    Error - 11/26/2011 1:30:49 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 5008

    Error - 11/30/2011 1:30:55 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 11/30/2011 1:30:55 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 999

    Error - 11/30/2011 1:30:55 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 999

    Error - 11/30/2011 1:30:56 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 11/30/2011 1:30:56 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 2200

    Error - 11/30/2011 1:30:56 AM | Computer Name = jacob102010012 | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 2200

    [ Media Center Events ]
    Error - 10/2/2010 7:05:26 AM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 7:05:16 AM - Error connecting to the internet. 7:05:17 AM - Unable
    to contact server..

    Error - 10/4/2010 5:30:02 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 5:30:01 PM - Error connecting to the internet. 5:30:01 PM - Unable
    to contact server..

    Error - 10/4/2010 5:30:14 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 5:30:07 PM - Error connecting to the internet. 5:30:07 PM - Unable
    to contact server..

    Error - 10/5/2010 4:14:09 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 4:14:09 PM - Error connecting to the internet. 4:14:09 PM - Unable
    to contact server..

    Error - 10/5/2010 4:14:22 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 4:14:15 PM - Error connecting to the internet. 4:14:15 PM - Unable
    to contact server..

    Error - 10/9/2010 7:32:29 AM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 7:32:21 AM - Error connecting to the internet. 7:32:21 AM - Unable
    to contact server..

    Error - 10/9/2010 12:10:38 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 12:10:37 PM - Error connecting to the internet. 12:10:37 PM - Unable
    to contact server..

    Error - 10/9/2010 12:10:51 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 12:10:43 PM - Error connecting to the internet. 12:10:43 PM - Unable
    to contact server..

    Error - 10/10/2010 9:01:41 AM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 9:01:33 AM - Error connecting to the internet. 9:01:33 AM - Unable
    to contact server..

    Error - 10/14/2010 4:09:07 PM | Computer Name = jacob102010012 | Source = MCUpdate | ID = 0
    Description = 4:09:00 PM - Error connecting to the internet. 4:09:00 PM - Unable
    to contact server..

    [ OSession Events ]
    Error - 2/9/2012 9:06:31 PM | Computer Name = jacob102010012 | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1374
    seconds with 300 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 7/9/2012 4:00:22 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume C:.

    Error - 7/9/2012 4:00:24 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.

    Error - 7/9/2012 4:00:24 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.

    Error - 7/9/2012 4:00:24 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.

    Error - 7/9/2012 4:00:38 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.

    Error - 7/9/2012 4:00:38 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume C:.

    Error - 7/9/2012 4:00:38 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.

    Error - 7/9/2012 4:22:22 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume C:.

    Error - 7/9/2012 4:24:37 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.

    Error - 7/9/2012 4:24:46 PM | Computer Name = jacob102010012 | Source = Ntfs | ID = 262199
    Description = The file system structure on the disk is corrupt and unusable. Please
    run the chkdsk utility on the volume VistaOS.


    < End of report >
     
  18. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    As you can see in the logs though, I keep getting the "run the chkdsk utility" cause C:/windows/help is corrupt or something like that....should I run chkdsk?
     
  19. Broni

    Broni Malware Annihilator Posts: 48,032   +271

    Usually you do if computer asks you.
    Hold on...
     
  20. Broni

    Broni Malware Annihilator Posts: 48,032   +271

  21. Seeker_lang

    Seeker_lang TS Rookie Topic Starter Posts: 16

    Okay so what does this mean whats the next step...I should chkdsk correct? What else
     
  22. Broni

    Broni Malware Annihilator Posts: 48,032   +271

    Did you read my reply #20?

    BEFORE you do that....

    Click Start button and in "Start search" type:
    cmd
    Hold CTRL and SHIFT buttons and press Enter.
    Command prompt window will open.
    Paste this in:
    chkdsk /f /r (<------watch for "spaces")
    Press Enter.
    Restart the computer.
    Chkdsk will run.
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.