Sirefef virus

Solved
By Rick van Ginkel
Jun 22, 2012
  1. Good day,

    I have a problem with my computer.
    I figured that I have 2 firefef virusses, I was too dumb to seek help from people who know stuff about this. It got to the point where my computer was unbootable. Windows was able to load from a restart point, but that's still at the point where I have the virusses (but I am able to start windows just fine without the 1 minute countdown). I tried running malwarebytes on quick scan but it found a virus and it deleted it, but none of the Sirefef ones. I am unable to turn on my windows firewall or use Microsoft Security Essentials (my current antivirus). I am running windows 7 ultimate 64 bit.
    Could someone help me with this problem and make my computer virus-free?
    I would be in your dept, I hope I gave you enough information to help me.

    Rick van Ginkel
  2. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===============================================================

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
  3. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    I tried pressing F8 but that didnt work, I realized I could start the pc without troubles so I just opened it in windows.


    Scan result of Farbar Recovery Scan Tool Version: 22-06-2012
    Ran by Wolf at 23-06-2012 05:56:20
    Running from E:\
    Service Pack 1 (X64) OS Language: English(US)
    Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.

    ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.


    ============ One Month Created Files and Folders ==============

    2012-06-23 05:55 - 2012-06-23 05:56 - 00000000 ____D C:\FRST
    2012-06-23 05:19 - 2012-06-23 05:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-23 05:19 - 2012-04-04 15:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-23 05:17 - 2012-06-23 05:17 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Wolf\Downloads\mbam-setup-1.61.0.1400.exe
    2012-06-23 05:15 - 2012-06-23 05:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BA2FCC45-41CF-4CE1-9A35-DF6C90610EC6}
    2012-06-23 05:15 - 2012-06-23 05:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A80C7E37-2C66-42EF-B700-CAD836E02A79}
    2012-06-23 04:46 - 2012-06-23 04:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CDDBEACB-4201-4A8D-AF2E-0DFB32D4E345}
    2012-06-23 04:46 - 2012-06-23 04:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C1819089-6D43-46EC-9F62-DF51C748EFE8}
    2012-06-23 04:37 - 2012-06-23 05:19 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-23 04:37 - 2012-06-23 04:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Malwarebytes
    2012-06-23 04:37 - 2012-06-23 04:37 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-06-22 16:43 - 2012-06-22 16:43 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77DABEC5-5C82-451E-9F08-AC88BC745E43}
    2012-06-22 16:42 - 2012-06-22 16:43 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3ED33445-25D4-4BB7-AA43-18DE6DA892B7}
    2012-06-22 14:38 - 2012-06-22 15:04 - 00003003 ____A C:\formatter.log
    2012-06-22 14:37 - 2012-06-22 14:37 - 00000000 ____D C:\Program Files (x86)\SDA
    2012-06-22 14:36 - 2012-06-22 15:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\Downloaded Installations
    2012-06-22 08:49 - 2012-06-03 00:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-22 08:49 - 2012-06-03 00:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-22 08:49 - 2012-06-03 00:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-22 08:48 - 2012-06-03 00:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-22 08:48 - 2012-06-03 00:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-22 08:48 - 2012-06-03 00:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-22 08:48 - 2012-06-03 00:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-22 08:48 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-22 08:48 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-22 04:42 - 2012-06-22 04:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{904B9BEC-36D2-42B7-ABD5-6D0BD92B144E}
    2012-06-22 03:42 - 2012-06-22 03:48 - 56679244 ____A C:\Users\Wolf\Downloads\XXXX-PCPv2-U.rar
    2012-06-22 03:42 - 2012-06-22 03:42 - 00000617 ____A C:\Users\Public\Desktop\TERA-Launcher.lnk
    2012-06-22 03:42 - 2012-06-22 03:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\TERA
    2012-06-22 03:39 - 2012-06-22 03:41 - 90847904 ____A (En Masse Entertainment) C:\Users\Wolf\Downloads\TERA-Setup.exe
    2012-06-22 02:58 - 2012-06-22 05:58 - 00000000 ____D C:\Users\Wolf\Desktop\New folder (2)
    2012-06-22 02:57 - 2012-06-22 03:09 - 56701864 ____A C:\Users\Wolf\Downloads\6039 - Pokemon Conquest (U).rar
    2012-06-22 02:57 - 2012-06-22 02:57 - 00060136 ____A C:\Users\Wolf\Downloads\PMQ_USA_AP-Patch2.rar
    2012-06-22 02:46 - 2012-06-22 02:46 - 03095908 ____A C:\Users\Wolf\Downloads\AKAIO 1.8.9z.rar
    2012-06-22 02:46 - 2012-06-22 02:46 - 00984640 ____A C:\Users\Wolf\Downloads\USRCheat_4-11-12.7z
    2012-06-22 02:32 - 2012-06-22 02:34 - 57350521 ____A C:\Users\Wolf\Downloads\XXXX - Pok駑on Conquest (USA) (PATCHEDv2).rar
    2012-06-21 16:42 - 2012-06-21 16:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{8C33D810-B9B6-483E-B34E-118A76D469D3}
    2012-06-21 16:41 - 2012-06-22 04:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{18F95A37-F8CE-4FEE-A2FC-B0335E1C4D06}
    2012-06-21 15:44 - 2012-06-21 19:23 - 00000000 ____D C:\Users\Wolf\Downloads\The.Last.Remnant-RELOADED
    2012-06-21 15:42 - 2012-06-21 15:44 - 73520661 ____A C:\Users\Wolf\Downloads\minecraft.rar
    2012-06-21 15:20 - 2012-06-21 15:20 - 00955840 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-06-21 15:20 - 2012-06-21 15:20 - 00839096 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-06-21 15:20 - 2012-06-21 15:20 - 00268720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-06-21 15:20 - 2012-06-21 15:20 - 00189360 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-06-21 15:20 - 2012-06-21 15:20 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-06-21 15:20 - 2012-06-21 15:20 - 00000000 ____D C:\Program Files\Java
    2012-06-21 15:19 - 2012-06-21 15:19 - 21869488 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jre-7u5-windows-x64.exe
    2012-06-21 15:18 - 2012-06-21 17:02 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\.minecraft
    2012-06-21 15:17 - 2012-06-21 15:17 - 00278561 ____A C:\Users\Wolf\Downloads\Minecraft.exe
    2012-06-21 15:17 - 2012-06-21 15:17 - 00001063 ____A C:\Users\Wolf\Desktop\Minecraft - Shortcut.lnk
    2012-06-21 13:09 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-06-21 13:09 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-06-21 04:41 - 2012-06-21 04:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B258CAE5-67E1-4958-BE42-32FEE0B205DD}
    2012-06-21 03:56 - 2012-06-21 04:57 - 00004725 ____A C:\Users\Wolf\Desktop\New Text Document (3).txt
    2012-06-20 23:24 - 2012-06-20 23:24 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-06-20 16:41 - 2012-06-20 16:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9259AB6-1DC3-4E8B-8AC8-9ACCA67DB57F}
    2012-06-20 16:40 - 2012-06-21 04:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB8A37B4-6AE8-4614-9533-7AFD0F18838C}
    2012-06-20 02:12 - 2012-06-20 02:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{967CB5D5-3013-4872-9DFA-B2CBDE65073B}
    2012-06-19 17:16 - 2012-06-19 17:16 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Folding@home-x86
    2012-06-19 17:16 - 2012-06-19 17:16 - 00000000 ____D C:\Program Files (x86)\Folding@home
    2012-06-19 17:15 - 2012-06-19 17:15 - 02878976 ____A C:\Users\Wolf\Downloads\Folding@home-Win32-x86-systray-623.msi
    2012-06-19 16:55 - 2012-06-19 16:55 - 03793814 ____A C:\Users\Wolf\Downloads\KatawaShoujo_MomentOfDecision.mp3
    2012-06-19 14:11 - 2012-06-20 02:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E7495E72-311F-4F4E-9F23-312AE87026EA}
    2012-06-19 14:11 - 2012-06-19 14:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{34B56388-6578-42AB-9D56-59148B615D56}
    2012-06-18 16:54 - 2012-06-18 17:13 - 00006527 ____A C:\Users\Wolf\Desktop\New Text Document (2).txt
    2012-06-18 16:49 - 2012-06-18 16:49 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F7C8FF26-2A7C-44BA-A1BE-6E12077664B8}
    2012-06-17 23:33 - 2012-06-17 23:34 - 00000000 ____D C:\Users\Wolf\Desktop\New folder
    2012-06-17 16:09 - 2012-06-18 04:10 - 00000000 ____D C:\Users\Wolf\AppData\Local\{864C3DB0-747B-4FAB-9441-5A31AA087E0C}
    2012-06-16 17:18 - 2012-06-16 17:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{81C49DF4-92B8-4818-8C70-98075EAA9A99}
    2012-06-16 16:06 - 2012-06-16 16:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\Macromedia
    2012-06-16 04:42 - 2012-06-16 04:42 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
    2012-06-16 04:16 - 2012-06-16 04:16 - 00000000 ____D C:\Users\All Users\Rockstar Games
    2012-06-16 02:59 - 2012-06-16 03:04 - 161912074 ____A C:\Users\Wolf\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68].zip
    2012-06-16 01:07 - 2012-06-16 16:58 - 00000000 ____D C:\Users\Wolf\Documents\LOLReplay
    2012-06-16 01:07 - 2012-06-16 01:07 - 00001905 ____A C:\Users\Public\Desktop\LOL Recorder.lnk
    2012-06-16 01:07 - 2012-06-16 01:07 - 00000000 ____D C:\Program Files (x86)\LOLReplay
    2012-06-16 01:06 - 2012-06-16 01:06 - 01501409 ____A C:\Users\Wolf\Downloads\LOLReplay-0.7.9.1.exe
    2012-06-15 18:58 - 2012-06-15 18:58 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\RenPy
    2012-06-15 18:51 - 2012-06-15 18:51 - 00000797 ____A C:\Users\Wolf\Desktop\Katawa Shoujo.lnk
    2012-06-15 17:17 - 2012-06-16 05:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{56F6CB7D-2198-4E18-A4CB-DF4C266BC3FB}
    2012-06-15 03:00 - 2012-05-18 04:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-15 03:00 - 2012-05-18 04:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-15 03:00 - 2012-05-18 04:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-15 03:00 - 2012-05-18 03:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-15 03:00 - 2012-05-18 03:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-15 03:00 - 2012-05-18 03:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-15 03:00 - 2012-05-18 03:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-15 03:00 - 2012-05-18 03:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-15 03:00 - 2012-05-18 03:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-15 03:00 - 2012-05-18 03:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-15 03:00 - 2012-05-18 03:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-15 03:00 - 2012-05-18 03:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-15 03:00 - 2012-05-18 03:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-15 03:00 - 2012-05-18 03:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-15 03:00 - 2012-05-18 01:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-15 03:00 - 2012-05-18 00:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-15 03:00 - 2012-05-18 00:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-15 03:00 - 2012-05-18 00:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-15 03:00 - 2012-05-18 00:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-15 03:00 - 2012-05-18 00:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-15 03:00 - 2012-05-18 00:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-15 03:00 - 2012-05-18 00:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-15 03:00 - 2012-05-18 00:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-15 03:00 - 2012-05-18 00:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-15 03:00 - 2012-05-18 00:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-15 03:00 - 2012-05-18 00:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-15 03:00 - 2012-05-18 00:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-15 03:00 - 2012-05-18 00:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-15 00:28 - 2012-06-15 00:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{6221A1EF-FAC8-4A7D-AA70-6B5507BC541C}
    2012-06-14 23:43 - 2012-06-14 23:43 - 00000000 ____D C:\Users\Wolf\Documents\Hitman Blood Money
    2012-06-14 23:42 - 2012-06-14 23:42 - 00098304 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll
    2012-06-14 16:01 - 2012-06-14 20:23 - 00000000 ____D C:\Users\All Users\Firefly Studios
    2012-06-14 12:34 - 2012-05-15 03:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-14 12:34 - 2012-05-04 13:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-06-14 12:34 - 2012-05-04 12:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-06-14 12:34 - 2012-05-04 12:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-06-14 12:34 - 2012-05-01 07:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-06-14 12:34 - 2012-04-28 07:32 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
    2012-06-14 12:34 - 2012-04-28 05:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-06-14 12:34 - 2012-04-26 07:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-06-14 12:34 - 2012-04-26 07:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-06-14 12:34 - 2012-04-26 07:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-06-14 12:34 - 2012-04-07 14:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-06-14 12:34 - 2012-04-07 13:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-06-14 12:33 - 2012-04-24 07:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-06-14 12:33 - 2012-04-24 07:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-06-14 12:33 - 2012-04-24 07:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-06-14 12:33 - 2012-04-24 06:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-06-14 12:33 - 2012-04-24 06:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-06-14 12:33 - 2012-04-24 06:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2012-06-14 12:28 - 2012-06-14 12:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E3238C17-E207-438F-82A3-EB89356E3DA8}
    2012-06-14 12:26 - 2012-06-15 00:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{31F9B074-5896-404F-9BF6-E4385BDDF5B3}
    2012-06-14 12:20 - 2012-06-14 12:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A6D7F2EE-D2D4-41F2-B3FC-8BD145B0A190}
    2012-06-14 12:19 - 2012-06-14 12:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BC331A7B-64D7-432F-82FD-9784E929841B}
    2012-06-14 05:13 - 2012-06-14 05:13 - 00001178 ____A C:\Users\Wolf\Desktop\Warriors Orochi (ToeD).lnk
    2012-06-14 05:13 - 2012-06-14 05:13 - 00000000 ____D C:\Users\Wolf\Documents\KOEI
    2012-06-14 04:55 - 2012-06-14 05:00 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold Crusader
    2012-06-14 00:19 - 2012-06-14 00:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{41DA6438-34AD-493B-B393-AAF7819B10BA}
    2012-06-14 00:18 - 2012-06-14 00:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5ED84925-45EB-494B-96A5-F5B3967C1BF8}
    2012-06-13 12:18 - 2012-06-13 12:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB1209B6-035D-4466-8757-B893040597D9}
    2012-06-13 12:18 - 2012-06-13 12:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69E680C4-A7DF-4C1A-9D8A-0BC66D71EB32}
    2012-06-13 04:11 - 2012-06-14 04:53 - 00005761 ____A C:\Users\Wolf\Desktop\New Text Document.txt
    2012-06-13 03:36 - 2012-06-13 03:36 - 00000019 ____A C:\Windows\D.ini
    2012-06-13 00:04 - 2012-06-13 00:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{78F62976-66E7-43ED-BB9F-D5DF3AC5F3AC}
    2012-06-13 00:04 - 2012-06-13 00:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1EBA75EF-77A7-44FE-8A9C-BB81E330A07D}
    2012-06-12 19:21 - 2012-06-12 19:21 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\ScummVM
    2012-06-12 19:12 - 2012-06-13 05:37 - 00000000 ____D C:\Sword
    2012-06-12 12:04 - 2012-06-12 12:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B33236EC-D70C-4821-8D05-10DB19CDFE07}
    2012-06-12 12:04 - 2012-06-12 12:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{29AB2770-F23A-4F39-B983-E42EF3988371}
    2012-06-12 04:17 - 2012-06-12 04:18 - 00000049 ____A C:\Users\Wolf\Desktop\Pinger.txt
    2012-06-11 20:27 - 2012-06-11 20:27 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold 3
    2012-06-11 17:08 - 2012-06-11 17:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A0EAE8F3-D293-482A-914A-4F450BE3CB89}
    2012-06-11 17:08 - 2012-06-11 17:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9C28CCC3-A5D0-480B-8B88-C5A40CA00C3B}
    2012-06-11 05:07 - 2012-06-11 05:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E3AD0B0-35C8-4E43-8572-BD0F9840F37A}
    2012-06-10 22:19 - 2012-06-10 22:19 - 01735565 ____A (Alexander Vigovsky ) C:\Users\Wolf\Downloads\ac3filter_2_4a_lite.exe
    2012-06-10 22:19 - 2012-06-10 22:19 - 00000000 ____D C:\Program Files (x86)\AC3Filter
    2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Wolf\AppData\Local\DDMSettings
    2012-06-10 21:26 - 2012-06-10 22:18 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DivX
    2012-06-10 21:26 - 2012-06-10 21:26 - 00000000 ____D C:\Program Files\DivX
    2012-06-10 21:25 - 2012-06-10 21:26 - 00000000 ____D C:\Program Files (x86)\DivX
    2012-06-10 21:20 - 2012-06-10 21:26 - 00000000 ____D C:\Users\All Users\DivX
    2012-06-10 21:20 - 2012-06-10 21:20 - 00933256 ____A (DivX, LLC) C:\Users\Wolf\Downloads\DivXInstaller.exe
    2012-06-10 17:27 - 2012-06-10 17:49 - 00000000 ____D C:\Users\Wolf\Desktop\Snes
    2012-06-10 17:07 - 2012-06-10 17:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7958BFCE-14B8-4F0B-95C9-96460C9F6439}
    2012-06-10 17:06 - 2012-06-11 05:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B7E5E7DB-1CB1-4FDB-B085-C2C0D59F575D}
    2012-06-10 05:05 - 2012-06-10 05:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E7DF313-0B3B-4FD1-9C44-C7DF656F2830}
    2012-06-09 17:05 - 2012-06-09 17:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DA3EFC53-A72C-4455-BCD6-719EEBAC89AD}
    2012-06-09 17:04 - 2012-06-10 05:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5EF250FE-5D75-4BB1-AB3C-B195035F51DF}
    2012-06-09 04:00 - 2012-06-09 04:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\{74197D9F-12B8-4F93-A066-2A5D76826950}
    2012-06-09 01:46 - 2012-06-09 01:48 - 00000000 ____D C:\Users\Wolf\Documents\ArmA 2
    2012-06-09 01:46 - 2012-06-09 01:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\ArmA 2 Free
    2012-06-08 16:23 - 2012-06-08 16:23 - 00000885 ____A C:\Users\UpdatusUser\Desktop\Play Star Wars Republic Commando.lnk
    2012-06-08 15:59 - 2012-06-09 04:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEA05E89-8748-47D1-B07B-E8D794B8F9B1}
    2012-06-08 15:59 - 2012-06-08 15:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9D3BF70-4F64-48BB-A8F4-E611A769B662}
    2012-06-08 03:59 - 2012-06-08 03:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEFB5670-0786-498C-A1E1-F7243588A15A}
    2012-06-07 18:26 - 2012-06-07 18:26 - 00000000 ____D C:\Users\Wolf\Desktop\dolphin
    2012-06-07 15:58 - 2012-06-08 03:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AA46DBB4-DB4A-472F-82EB-FBDFC6556532}
    2012-06-07 15:58 - 2012-06-07 15:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FC53B60C-6F6E-4ED4-B40C-009BD43E92B4}
    2012-06-07 03:20 - 2012-06-07 03:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AC65E5A8-92D1-4634-946A-2E9F7E9A46FB}
    2012-06-07 02:06 - 2012-06-07 02:06 - 00000000 ____D C:\Nocturnal
    2012-06-07 02:05 - 2012-06-07 02:05 - 00000223 ____A C:\Windows\MugE.ini
    2012-06-07 01:07 - 2012-06-07 01:07 - 00188960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingde.dll
    2012-06-07 01:02 - 2012-06-07 01:02 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing32.dll
    2012-06-07 01:02 - 2012-06-07 01:02 - 00006736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingdib.drv
    2012-06-07 01:02 - 2012-06-07 01:02 - 00005024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingpal.wnd
    2012-06-07 01:01 - 2012-06-07 01:01 - 00092208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing.dll
    2012-06-06 15:19 - 2012-06-07 03:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{018EFAE0-DA5F-42D6-9FB4-F021E1130510}
    2012-06-06 15:19 - 2012-06-06 15:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7223F4E9-A6ED-4984-9F12-0553BE51A9FA}
    2012-06-06 03:19 - 2012-06-06 03:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AEBC6B16-FA61-472F-B178-7947B70D4644}
    2012-06-06 03:19 - 2012-06-06 03:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77EDE412-92A0-4FE2-B150-A38B2E91C713}
    2012-06-05 22:08 - 2012-06-05 22:08 - 00000000 ____D C:\Program Files (x86)\SplitMediaLabs
    2012-06-05 15:18 - 2012-06-05 15:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{396C4775-9424-4BB2-A423-6B2436410DE2}
    2012-06-05 15:18 - 2012-06-05 15:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2EE4F770-25FF-4D67-AE38-FF1ECCA34319}
    2012-06-05 03:18 - 2012-06-05 03:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{669C431C-59C4-4CFA-9965-6CCB0F8DD7E6}
    2012-06-04 15:17 - 2012-06-05 03:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9E2CB37D-DD5F-4DEC-9A37-4E8E73599B3F}
    2012-06-04 15:17 - 2012-06-04 15:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{4A04846C-C294-40F1-B047-C441C907CCF9}
    2012-06-04 02:34 - 2012-06-04 02:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D94B41B9-EF3A-4674-AE3A-1DADE4352553}
    2012-06-03 14:34 - 2012-06-04 02:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C91224FA-142A-404C-9C41-94A14AAB6355}
    2012-06-03 14:34 - 2012-06-03 14:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E64A22F0-D582-4DBC-BE24-0B861F843E90}
    2012-06-03 02:30 - 2012-06-03 02:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E9B1A525-2BB8-4999-A4FA-B4C972C0A7CF}
    2012-06-03 01:11 - 2012-06-03 01:11 - 00001234 ____A C:\Users\Wolf\Desktop\Vindictus - Shortcut.lnk
    2012-06-03 01:10 - 2012-06-06 22:35 - 00000000 ____D C:\Users\Wolf\Documents\Vindictus EU
    2012-06-03 01:08 - 2012-06-03 01:08 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
    2012-06-03 00:49 - 2012-06-03 00:52 - 130416408 ____A C:\Users\Wolf\Downloads\bmw_perfect_v97.rar
    2012-06-03 00:48 - 2012-06-03 00:48 - 00000000 ____D C:\Users\Wolf\Documents\bmw_english4V_95
    2012-06-03 00:41 - 2008-03-31 21:04 - 00249856 ____N (nobukichi) C:\Windows\eiunin21.exe
    2012-06-02 23:46 - 2012-06-03 01:08 - 00000000 ____D C:\Download
    2012-06-02 23:46 - 2012-06-02 23:46 - 00536576 ____A (Nexon) C:\Users\Wolf\Downloads\Vindictus_Downloader.exe
    2012-06-02 23:46 - 2012-06-02 23:46 - 00446464 ____A (NEXON Inc.) C:\Windows\NEXON_EU_DownloaderUpdater.exe
    2012-06-02 23:46 - 2012-06-02 23:46 - 00000235 ____A C:\Windows\SysWOW64\nxEuUninstall.bat
    2012-06-02 23:36 - 2012-06-03 01:11 - 00000000 ____D C:\Users\All Users\NexonEU
    2012-06-02 23:35 - 2012-06-02 23:35 - 03655576 ____A (Nexon) C:\Users\Wolf\Downloads\Setup.exe
    2012-06-02 21:06 - 2012-06-13 19:23 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\TeamViewer
    2012-06-02 18:21 - 2012-06-02 18:21 - 00621160 ____A (Copyright ゥ 2010 eSupport.com. All Rights Reserved.) C:\Users\Wolf\Downloads\driveragent_987.exe
    2012-06-02 18:21 - 2012-06-02 18:21 - 00021712 ____A (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
    2012-06-02 18:21 - 2012-06-02 18:21 - 00000000 ____D C:\Users\Wolf\AppData\Local\eSupport.com
    2012-06-02 18:20 - 2012-06-02 18:20 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SystemRequirementsLab
    2012-06-02 18:03 - 2012-06-03 01:07 - 00000000 ____D C:\Nexon
    2012-06-02 18:03 - 2012-06-02 18:03 - 00000000 ____D C:\Users\All Users\NexonUS
    2012-06-02 17:13 - 2012-06-02 17:13 - 00000000 ____D C:\Users\All Users\Nexon
    2012-06-02 17:08 - 2012-06-02 17:08 - 02013336 ____A C:\Users\Wolf\Downloads\MapleStoryDownloader.exe
    2012-06-02 16:11 - 2012-06-02 16:11 - 00000000 ____D C:\Users\Wolf\Documents\DragonSaga
    2012-06-02 16:10 - 2012-06-02 16:10 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DragonSaga
    2012-06-02 16:08 - 2012-06-02 16:27 - 113899850 ____A C:\Users\Wolf\Downloads\Bf3-mpcr.rar
    2012-06-02 14:29 - 2012-06-03 02:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2A798180-069D-448F-9C03-618665668D41}
    2012-06-02 14:29 - 2012-06-02 14:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F03D9EB4-CF0B-4A74-A47B-E056FEB39EDD}
    2012-06-02 02:29 - 2012-06-02 02:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{72BAC764-B627-4F15-A603-D553B12B02B6}
    2012-06-01 18:24 - 2012-06-01 18:24 - 04171406 ____A C:\Users\Wolf\Downloads\XMouseButtonControlSetup.2.4.exe
    2012-06-01 18:24 - 2012-06-01 18:24 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Highresolution Enterprises
    2012-06-01 18:24 - 2012-06-01 18:24 - 00000000 ____D C:\Program Files\Highresolution Enterprises
    2012-06-01 18:03 - 2012-06-01 18:03 - 00000000 ____D C:\Users\All Users\BioWare
    2012-06-01 18:01 - 2012-06-01 18:01 - 00000000 ____D C:\Users\Wolf\Documents\BioWare
    2012-06-01 17:49 - 2012-06-07 04:23 - 00000000 ____D C:\Users\Wolf\Documents\DepthHunter
    2012-06-01 14:28 - 2012-06-02 02:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{45C6FCE0-68C7-48EE-9121-BAEDFCA89588}
    2012-06-01 14:28 - 2012-06-01 14:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BDF956F0-D59B-4350-AFFF-357CAE62018C}
    2012-06-01 01:31 - 2012-06-01 01:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69CA7DA5-AAE2-4F3D-B062-F5ADF10EB800}
    2012-06-01 01:31 - 2012-06-01 01:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{30921632-D6C6-470F-8A0C-F20D93AE4ED0}
    2012-06-01 01:24 - 2012-06-01 01:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DFCEAD23-D76A-4193-B976-F76F825D9117}
    2012-06-01 01:24 - 2012-06-01 01:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{24380E14-2AF3-4C52-A2FC-7DAD465977B8}
    2012-06-01 01:20 - 2012-06-01 01:20 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{d49c2933-ab76-11e1-bc6a-bc5ff438e47c}.TxR.blf
    2012-06-01 01:14 - 2012-06-01 01:14 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{1aa4bd2d-ab76-11e1-8460-bc5ff438e47c}.TxR.blf
    2012-06-01 01:14 - 2012-06-01 01:14 - 00000092 ____A C:\Users\Wolf\AppData\Local\fusioncache.dat
    2012-06-01 01:14 - 2012-06-01 01:14 - 00000000 ____D C:\Users\Wolf\AppData\Local\GameSpy
    2012-06-01 00:40 - 2010-08-03 08:41 - 00819200 ____A C:\Windows\SysWOW64\xvidcore.dll
    2012-06-01 00:40 - 2010-08-03 08:41 - 00180224 ____A C:\Windows\SysWOW64\xvidvfw.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-06-01 00:23 - 2012-05-15 12:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-06-01 00:23 - 2012-05-15 12:48 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-06-01 00:23 - 2012-04-18 19:08 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
    2012-06-01 00:23 - 2012-04-18 19:08 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-06-01 00:23 - 2012-04-18 19:08 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-06-01 00:19 - 2012-06-01 00:22 - 168454136 ____A (NVIDIA Corporation) C:\Users\Wolf\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
    2012-06-01 00:19 - 2012-06-01 00:19 - 00000000 ____D C:\Users\All Users\Sun
    2012-06-01 00:18 - 2012-06-01 00:18 - 00772552 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-06-01 00:18 - 2012-06-01 00:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-06-01 00:18 - 2012-06-01 00:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-06-01 00:18 - 2012-06-01 00:18 - 00000000 ____D C:\Program Files (x86)\Oracle
    2012-06-01 00:18 - 2012-06-01 00:18 - 00000000 ____D C:\Program Files (x86)\Java
    2012-06-01 00:18 - 2012-04-04 18:47 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-06-01 00:18 - 2012-04-04 18:47 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-06-01 00:17 - 2012-06-01 00:17 - 00892360 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jxpiinstall.exe
    2012-05-31 19:22 - 2012-05-31 19:22 - 00000000 ____D C:\Program Files (x86)\GameSpy
    2012-05-31 19:18 - 2012-05-31 19:18 - 00001298 ____A C:\Users\Public\Desktop\Crysis.lnk
    2012-05-31 15:37 - 2012-05-31 15:37 - 21503784 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HWSE_SE_v3.2.2.1.exe
    2012-05-31 15:37 - 2012-05-31 15:37 - 00000000 ____D C:\Program Files (x86)\Hercules
    2012-05-31 15:37 - 2006-08-01 12:31 - 03600384 ____A C:\Windows\ffmpeg.exe
    2012-05-31 15:36 - 2012-05-31 15:36 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(2).exe
    2012-05-31 15:29 - 2012-05-31 15:29 - 62444312 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v2.9.0.0.exe
    2012-05-31 15:28 - 2012-05-31 15:28 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(1).exe
    2012-05-31 15:06 - 2012-05-31 15:06 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\InstallShield
    2012-05-31 15:06 - 2009-10-19 17:39 - 00718632 ____A (Guillemot) C:\Windows\SysWOW64\WebCamPropertyWindow.dll
    2012-05-31 15:06 - 2009-10-19 17:39 - 00037672 ____A C:\Windows\SysWOW64\WebCamKSProxyPlugin.ax
    2012-05-31 15:06 - 2009-10-19 17:39 - 00029480 ____A (Guillemot Corporation S.A.) C:\Windows\SysWOW64\libcmmn.dll
    2012-05-31 15:05 - 2012-05-31 15:06 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1.exe
    2012-05-31 13:23 - 2012-05-31 13:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C33CF4EE-A3BE-4355-A681-463A8BE50A8B}
    2012-05-31 13:23 - 2012-05-31 13:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{47DD7949-55AC-4910-B63E-0625A8C88C07}
    2012-05-30 21:34 - 2012-05-30 21:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{308AC941-8DFC-4CE8-94F0-EB570AE23E93}
    2012-05-30 16:02 - 2012-05-30 16:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Chart Controls
    2012-05-30 14:28 - 2012-05-30 14:28 - 00001802 ____A C:\Users\Public\Desktop\Dragon Saga.lnk
    2012-05-30 13:48 - 2012-05-30 13:48 - 00330120 ____A (Gravity Interactive, Inc.) C:\Users\Wolf\Downloads\DragonSaga-Installer-0.2.5-20120330.exe
    2012-05-30 09:34 - 2012-05-30 09:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D9ED8115-E416-4B42-93EA-D62BFF6A48D3}
    2012-05-30 09:33 - 2012-05-30 21:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3BCE797B-4A95-4C3C-841B-891768931583}
    2012-05-29 16:49 - 2012-05-29 16:49 - 00001989 ____A C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
    2012-05-29 16:49 - 2012-05-29 16:49 - 00000000 ____D C:\Program Files (x86)\PCSX2 0.9.8
    2012-05-29 16:48 - 2012-05-29 16:48 - 12780479 ____A C:\Users\Wolf\Downloads\pcsx2-0.9.8-r4600-setup.exe
    2012-05-29 16:48 - 2012-05-29 16:48 - 04353259 ____A (Igor Pavlov) C:\Users\Wolf\Downloads\dolphin-3.0-win64.exe
    2012-05-29 15:41 - 2012-05-29 15:41 - 00002105 ____A C:\Users\Public\Desktop\A.V.A.lnk
    2012-05-29 15:41 - 2012-05-29 15:41 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
    2012-05-29 15:41 - 2012-03-06 17:19 - 03953632 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
    2012-05-29 15:41 - 2012-02-03 00:50 - 00005265 ____A C:\Windows\SysWOW64\nppt9x.vxd
    2012-05-29 15:41 - 2012-02-03 00:50 - 00004774 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
    2012-05-29 12:32 - 2012-05-29 12:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{65655CD4-236C-47ED-BF7C-D5B292418970}
    2012-05-29 12:32 - 2012-05-29 12:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1DA6169D-DEBF-47A1-B3DF-FC4F0D7EA61D}
    2012-05-29 00:48 - 2012-05-29 00:48 - 00002560 ____A C:\Users\Wolf\Documents\Register Vegas Pro.htm
    2012-05-29 00:48 - 2012-05-29 00:48 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Publish Providers
    2012-05-29 00:46 - 2012-05-29 00:48 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Sony
    2012-05-29 00:46 - 2012-05-29 00:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\Sony
    2012-05-29 00:44 - 2012-05-29 00:44 - 00001908 ____A C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
    2012-05-29 00:44 - 2012-05-29 00:44 - 00000000 ____D C:\Users\All Users\Sony
    2012-05-29 00:43 - 2012-05-29 00:43 - 00000000 ____D C:\Program Files (x86)\Sony
    2012-05-29 00:38 - 2012-05-31 03:50 - 00000000 ____D C:\Fraps
    2012-05-29 00:38 - 2012-05-29 00:38 - 00000562 ____A C:\Users\Wolf\Desktop\Fraps.lnk
    2012-05-29 00:31 - 2012-05-29 00:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FB225DD7-B02B-4BE6-8F32-D5F446DE2EAB}
    2012-05-29 00:31 - 2012-05-29 00:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{160F752A-7CFD-4058-914C-AEA7BDA6BF80}
    2012-05-28 22:56 - 2012-05-28 22:56 - 00298016 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
    2012-05-28 22:55 - 2012-05-28 22:55 - 00000000 ____D C:\Users\Wolf\AppData\Local\PunkBuster
    2012-05-28 22:53 - 2012-05-28 22:53 - 00001907 ____A C:\Users\Public\Desktop\ijji REACTOR.lnk
    2012-05-28 22:53 - 2010-03-24 16:57 - 00713312 ____A (NHN USA) C:\Windows\SysWOW64\ijjiSetup.exe
    2012-05-28 22:53 - 2010-03-24 16:56 - 00062048 ____A (NHN USA Inc.) C:\Windows\SysWOW64\ijjiProcessRestarter.exe
    2012-05-28 22:52 - 2012-05-29 15:41 - 00000000 ____D C:\Program Files (x86)\REACTOR
    2012-05-28 22:52 - 2012-05-28 22:52 - 07822632 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\IJJI_REACTOR_INST_EN.exe
    2012-05-28 22:44 - 2012-01-09 08:45 - 207767247 ____A C:\Users\Wolf\Downloads\data4.cab
    2012-05-28 22:44 - 2012-01-09 08:45 - 00239126 ____A C:\Users\Wolf\Downloads\setup.inx
    2012-05-28 22:44 - 2012-01-09 08:45 - 00002380 ____A C:\Users\Wolf\Downloads\setup.ini
    2012-05-28 22:44 - 2012-01-09 08:45 - 00000658 ____A C:\Users\Wolf\Downloads\layout.bin
    2012-05-28 22:43 - 2012-01-09 08:44 - 2147483648 ____A C:\Users\Wolf\Downloads\data3.cab
    2012-05-28 22:42 - 2012-01-09 14:01 - 00811520 ____A (ijji.com) C:\Users\Wolf\Downloads\U_AVA_SETUP.exe
    2012-05-28 22:42 - 2012-01-09 08:45 - 00579584 ____A (Flexera Software, Inc.) C:\Users\Wolf\Downloads\ISSetup.dll
    2012-05-28 22:42 - 2012-01-09 08:29 - 2145083392 ____A C:\Users\Wolf\Downloads\data2.cab
    2012-05-28 22:42 - 2012-01-09 08:14 - 00624307 ____A C:\Users\Wolf\Downloads\data1.cab
    2012-05-28 22:42 - 2012-01-09 08:14 - 00108193 ____A C:\Users\Wolf\Downloads\data1.hdr
    2012-05-28 22:42 - 2012-01-09 08:14 - 00022492 ____A C:\Users\Wolf\Downloads\0x0409.ini
    2012-05-28 20:12 - 2012-05-28 20:12 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
    2012-05-28 20:11 - 2012-05-28 19:58 - 03130440 ____A C:\Windows\SysWOW64\pbsvc_blr.exe
    2012-05-28 19:43 - 2012-05-29 03:52 - 00000000 ____D C:\Users\Wolf\Documents\DragonNest
    2012-05-28 19:12 - 2012-05-28 19:12 - 00000796 ____A C:\Users\Public\Desktop\Dragon Nest.lnk
    2012-05-28 18:05 - 2012-05-28 18:08 - 00000000 ____D C:\Users\Wolf\Documents\Battlefield 3
    2012-05-28 18:03 - 2012-06-09 04:02 - 00107832 ____A C:\Windows\SysWOW64\PnkBstrB.exe
    2012-05-28 18:03 - 2012-06-09 04:02 - 00066872 ____A C:\Windows\SysWOW64\PnkBstrA.exe
    2012-05-28 18:03 - 2012-05-28 20:11 - 00189248 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
    2012-05-28 17:34 - 2012-05-28 21:12 - 198654664 ____A C:\Users\Wolf\Downloads\U_AVA_SETUP_Jan2012.zip
    2012-05-28 17:34 - 2012-05-28 18:05 - 00000000 ____D C:\Games
    2012-05-28 17:34 - 2011-10-10 16:42 - 02580552 ___RA C:\Windows\SysWOW64\pbsvc.exe
    2012-05-28 17:28 - 2012-05-28 18:40 - 2536606647 ____A (Shanda Games International) C:\Users\Wolf\Downloads\DNClientVer60_20120423.exe
    2012-05-28 17:18 - 2012-05-28 17:19 - 02072456 ____A C:\Users\Wolf\Downloads\BlacklightRetribution_Downloader_EN.exe
    2012-05-28 13:14 - 2012-05-28 13:14 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00000725 ____A C:\Users\Wolf\Desktop\Dustforce.lnk
    2012-05-28 13:14 - 2012-05-28 13:14 - 00000000 ____D C:\Program Files (x86)\OpenAL
    2012-05-28 12:31 - 2012-05-28 12:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CD0B5883-D705-4B3F-878D-1CEB81D6E307}
    2012-05-28 12:31 - 2012-05-28 12:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{466B1E6A-4A0C-4E36-8C2B-545561C19512}
    2012-05-28 03:12 - 2012-05-28 13:14 - 00000000 ____D C:\Users\Wolf\Downloads\Crysis_2-FLT
    2012-05-28 00:30 - 2012-05-28 00:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3B0B234A-AD01-4412-A755-6F9EC247B549}
    2012-05-28 00:30 - 2012-05-28 00:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{38946F5D-E76A-4FAC-9F90-365593EAA120}
    2012-05-27 23:05 - 2012-05-27 23:05 - 00000754 ____A C:\Users\Public\Desktop\Dragon Age Origins.lnk
    2012-05-27 23:05 - 2012-05-27 23:05 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP
    2012-05-27 22:51 - 2012-05-27 23:17 - 00021225 ____A C:\Users\Wolf\Documents\Install Dragon Age Origins.log
    2012-05-27 19:36 - 2012-05-27 19:36 - 00001147 ____A C:\Users\Public\Desktop\Bamboo Dock.lnk
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Wacom
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Users\All Users\Wacom
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Program Files (x86)\Bamboo Dock
    2012-05-27 19:34 - 2012-05-27 19:34 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WTablet
    2012-05-27 19:34 - 2012-05-27 19:34 - 00000000 ____D C:\Program Files\Tablet
    2012-05-27 19:34 - 2012-05-27 19:34 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
    2012-05-27 19:34 - 2011-09-08 17:49 - 00016168 ____A (Wacom Technology) C:\Windows\System32\Drivers\wacomvhid.sys
    2012-05-27 19:34 - 2011-09-08 17:49 - 00012848 ____A (Wacom Technology) C:\Windows\System32\Drivers\wacommousefilter.sys
    2012-05-27 19:34 - 2011-09-08 17:48 - 01665400 ____A (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.dll
    2012-05-27 19:34 - 2011-09-08 17:48 - 01401208 ____A (Wacom Technology, Corp.) C:\Windows\System32\Wintab32.dll
    2012-05-27 19:34 - 2011-09-08 17:48 - 01392504 ____A (Wacom Technology, Corp.) C:\Windows\System32\WacomMT.dll
    2012-05-27 19:34 - 2011-09-08 17:48 - 01326456 ____A (Wacom Technology, Corp.) C:\Windows\System32\Pen_Touch_Tablet.dll
    2012-05-27 19:34 - 2011-09-08 17:48 - 01156472 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
    2012-05-27 19:34 - 2011-09-08 17:48 - 01152888 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
    2012-05-27 19:34 - 2011-09-08 17:48 - 01107832 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Touch_Tablet.dll
    2012-05-27 19:34 - 2011-06-16 00:00 - 00000488 ____A C:\Windows\System32\PenTabletUserDefaults.xml
    2012-05-27 19:33 - 2012-05-27 19:33 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(2).exe
    2012-05-27 19:17 - 2011-09-08 17:48 - 01369464 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Tablet.dll
    2012-05-27 19:15 - 2012-05-27 19:15 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(1).exe
    2012-05-27 19:05 - 2012-05-27 19:05 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
    2012-05-27 13:22 - 2012-05-27 13:22 - 00001003 ____A C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
    2012-05-27 13:21 - 2012-05-27 13:21 - 00000000 ____D C:\Windows\SysWOW64\xlive
    2012-05-27 13:21 - 2012-05-27 13:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
    2012-05-27 12:59 - 2012-05-27 13:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\SniperV2
    2012-05-27 12:57 - 2012-05-27 12:57 - 00001095 ____A C:\Users\Public\Desktop\Sniper Elite V2.lnk
    2012-05-27 12:44 - 2012-05-27 12:49 - 00000000 ____D C:\Users\Wolf\AppData\Local\XBlades
    2012-05-27 12:44 - 2012-05-27 12:48 - 00000000 ____D C:\Users\All Users\XBlades
    2012-05-27 12:44 - 2012-05-27 12:46 - 00000422 ____A C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
    2012-05-27 12:33 - 2012-05-28 23:25 - 00000000 ____D C:\Users\Wolf\AppData\Local\BladesOfTime
    2012-05-27 12:32 - 2012-05-27 12:32 - 00000984 ____A C:\Users\Public\Desktop\Blades of Time.lnk
    2012-05-27 12:29 - 2012-05-27 12:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{452C3747-247D-49E6-92F9-FF22C9404000}
    2012-05-27 12:29 - 2012-05-27 12:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B2C1155D-6711-4A9A-BE54-8C430A6B998F}
    2012-05-27 04:22 - 2012-05-27 04:22 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
    2012-05-27 04:17 - 2012-05-27 04:17 - 00000999 ____A C:\Users\Public\Desktop\Magicka.lnk
    2012-05-26 23:40 - 2012-05-26 23:40 - 00000000 ____D C:\Windows\System32\Macromed
    2012-05-26 23:40 - 2012-05-26 23:40 - 00000000 ____D C:\Users\Wolf\AppData\Local\SplitMediaLabs
    2012-05-26 23:38 - 2012-05-26 23:38 - 00000000 ____D C:\Users\All Users\SplitMediaLabs
    2012-05-26 23:37 - 2012-05-26 23:37 - 24220864 ____A (SplitMediaLabs) C:\Users\Wolf\Downloads\xsplit_installer_v1.0.1204.1301.exe
    2012-05-26 23:37 - 2012-05-26 23:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SplitMediaLabs
    2012-05-26 23:07 - 2012-05-26 23:07 - 00000857 ____A C:\Users\Wolf\Desktop\League of Legends.lnk
    2012-05-26 21:46 - 2012-05-26 21:47 - 00000000 ____D C:\Users\Wolf\AppData\Local\{525FBECE-BEC1-4B0B-BCDD-A5CB91553E59}
    2012-05-26 21:46 - 2012-05-26 21:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CB91DDC8-FE7D-4956-A352-3D8415C5CF6F}
    2012-05-26 21:20 - 2012-05-26 21:20 - 00001727 ____A C:\Users\Wolf\Desktop\Photoshop - Shortcut.lnk
    2012-05-26 21:18 - 2012-05-26 21:18 - 00000000 ____D C:\Users\Wolf\AdobeLicensingFilesBackup
    2012-05-26 21:11 - 2012-05-26 21:19 - 00000000 ____D C:\Users\All Users\FLEXnet
    2012-05-26 21:04 - 2012-05-26 21:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\Microsoft Games
    2012-05-26 21:02 - 2012-05-26 21:02 - 00000000 ____D C:\Windows\SysWOW64\spool
    2012-05-26 20:59 - 2012-05-26 20:59 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
    2012-05-26 20:34 - 2012-05-26 21:04 - 00000000 ____D C:\Program Files\Adobe
    2012-05-26 20:29 - 2012-05-26 21:05 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2012-05-26 20:20 - 2012-05-26 20:20 - 00000000 ____D C:\Windows\SysWOW64\syncdb
    2012-05-26 18:28 - 2012-05-26 20:45 - 00000000 ____D C:\Users\All Users\regid.1986-12.com.adobe
    2012-05-26 17:59 - 2012-05-26 17:59 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Ambient Design
    2012-05-26 17:47 - 2012-05-26 18:17 - 2119376047 ____A C:\Users\Wolf\Downloads\PSE9.zip
    2012-05-26 17:34 - 2012-05-26 17:43 - 544160151 ____A C:\Users\Wolf\Downloads\PSE9.zip.part
    2012-05-26 17:34 - 2012-05-26 17:36 - 72725528 ____A (Ambient Design) C:\Users\Wolf\Downloads\install_artrage_studiopro.exe
    2012-05-26 17:34 - 2012-05-26 17:35 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final.exe
    2012-05-26 17:17 - 2012-05-26 17:17 - 00001181 ____A C:\Users\Public\Desktop\openCanvas5e.lnk
    2012-05-26 17:17 - 2012-05-26 17:17 - 00000000 ____D C:\Program Files (x86)\portalgraphics
    2012-05-26 17:13 - 2012-05-26 17:13 - 02330770 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04e.exe
    2012-05-26 17:11 - 2012-05-26 17:11 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\portalgraphics
    2012-05-26 17:10 - 2012-05-26 17:10 - 02271209 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04.exe
    2012-05-26 16:25 - 2012-05-26 16:49 - 00000000 ____D C:\Users\All Users\Alias
    2012-05-26 16:25 - 2012-05-26 16:25 - 00002156 ____A C:\Users\Public\Desktop\Autodesk SketchBookPro 2011.lnk
    2012-05-26 16:25 - 2012-05-26 16:25 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Autodesk
    2012-05-26 16:24 - 2012-05-26 16:24 - 00001152 ____A C:\Users\Wolf\Desktop\Play IW4M (Modern Warfare 2).lnk
    2012-05-26 16:24 - 2012-05-26 16:24 - 00000000 ____D C:\Program Files (x86)\Autodesk
    2012-05-26 16:23 - 2012-05-26 16:23 - 00001013 ____A C:\Users\Public\Desktop\Worms Ultimate Mayhem.lnk
    2012-05-26 16:12 - 2012-05-27 19:36 - 00000002 ____A C:\Users\Wolf\.bdockinstall.log
    2012-05-26 16:12 - 2012-05-26 16:12 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2012-05-26 16:12 - 2012-05-26 16:12 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2012-05-26 16:10 - 2011-06-16 00:00 - 00000488 ____A C:\Windows\System32\PenTouchTabletUserDefaults.xml
    2012-05-26 15:47 - 2012-05-28 13:16 - 00000000 ____D C:\Users\Wolf\AppData\Local\Adobe
    2012-05-26 12:00 - 2012-06-15 01:02 - 00000000 ____D C:\Users\Wolf\AppData\Local\SKIDROW
    2012-05-26 12:00 - 2012-05-26 12:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\BigHugeEngine
    2012-05-26 11:58 - 2012-05-26 11:58 - 00001185 ____A C:\Users\Wolf\Desktop\Dead Island.lnk
    2012-05-26 10:15 - 2012-05-26 10:15 - 00001083 ____A C:\Users\Public\Desktop\Kingdoms of Amalur Reckoning.lnk
    2012-05-26 09:46 - 2012-05-26 09:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A5BF4313-036F-4A54-A8FA-9DA6C12A656C}
    2012-05-26 09:46 - 2012-05-26 09:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5634B62E-A929-4F3F-97F4-35CD08166140}
    2012-05-26 00:32 - 2012-05-26 00:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\.inapptracking
    2012-05-26 00:31 - 2012-05-26 00:31 - 00000786 ____A C:\Users\Public\Desktop\Sonic Generations.lnk
    2012-05-25 21:44 - 2012-05-25 22:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\IW4M
    2012-05-25 21:44 - 2012-05-25 21:44 - 00156672 ____A (Microsoft) C:\Users\Wolf\Downloads\InstallIW4M.exe
    2012-05-25 21:29 - 2012-05-25 21:29 - 15556319 ____A C:\Users\Wolf\Downloads\4D1 Patcher(r88).zip
    2012-05-25 21:26 - 2012-05-25 21:26 - 07731209 ____A C:\Users\Wolf\Downloads\alterRevolution Client.rar
    2012-05-25 21:26 - 2012-05-25 21:26 - 02246711 ____A C:\Users\Wolf\Downloads\alterRevolution Dedicated 0.3c.rar
    2012-05-25 20:12 - 2012-05-25 20:12 - 00001309 ____A C:\Users\Wolf\Desktop\Devil May Cry 4.lnk
    2012-05-25 17:57 - 2012-05-31 19:21 - 03475636 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-05-25 17:57 - 2012-05-25 17:57 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-05-25 17:56 - 2012-06-23 15:12 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-05-25 17:56 - 2012-06-23 15:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-05-25 17:48 - 2012-05-25 17:49 - 12621696 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe
    2012-05-25 17:48 - 2012-05-25 17:48 - 00523840 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe.part
    2012-05-25 17:03 - 2012-05-27 13:40 - 00000000 ____D C:\Users\Wolf\Documents\CAPCOM
    2012-05-25 17:03 - 2012-05-25 17:03 - 00000000 ____D C:\Users\Wolf\AppData\Local\CAPCOM
    2012-05-25 15:50 - 2012-05-25 15:53 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3157081A-C7D3-4452-9C7E-F0E660292DB2}
    2012-05-25 15:50 - 2012-05-25 15:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{93B44AF1-3B18-4C2A-B279-24923486D8F6}
    2012-05-25 13:59 - 2012-05-25 13:59 - 00002213 ____A C:\Users\Public\Desktop\AION Free-To-Play.lnk
    2012-05-25 13:59 - 2012-05-25 13:59 - 00000000 ____D C:\Program Files (x86)\Gameforge
    2012-05-25 13:39 - 2012-05-25 13:44 - 145138568 ____A (Gameforge) C:\Users\Wolf\Downloads\setup_20120224.exe
    2012-05-25 13:30 - 2012-05-25 13:30 - 01639789 ____A C:\Users\Wolf\Downloads\winrar-x64-411.exe
    2012-05-25 13:30 - 2012-05-25 13:30 - 00000000 ____D C:\Program Files\WinRAR
    2012-05-25 13:29 - 2012-05-25 13:31 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WinRAR
    2012-05-25 13:29 - 2012-05-25 13:29 - 01506653 ____A C:\Users\Wolf\Downloads\wrar411.exe
    2012-05-25 13:29 - 2012-05-25 13:29 - 00000000 ____D C:\Program Files (x86)\WinRAR
    2012-05-25 12:44 - 2012-05-25 12:44 - 00000000 ____D C:\Program Files\7-Zip
    2012-05-25 12:43 - 2012-05-25 12:43 - 01376768 ____A C:\Users\Wolf\Downloads\7z920-x64.msi
  4. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    ============ 3 Months Modified Files and Folders =============

    2012-06-23 15:12 - 2012-05-25 17:56 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-06-23 15:12 - 2012-05-25 17:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-06-23 15:12 - 2012-02-01 16:11 - 00000000 ___RD C:\Program Files (x86)\Skype
    2012-06-23 15:12 - 2012-02-01 16:11 - 00000000 ____D C:\Users\All Users\Skype
    2012-06-23 15:12 - 2012-02-01 15:58 - 00000000 ____D C:\Users\All Users\PMB Files
    2012-06-23 15:12 - 2012-02-01 15:52 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\uTorrent
    2012-06-23 15:12 - 2012-02-01 15:20 - 00000000 ____D C:\Users\All Users\FNET
    2012-06-23 15:12 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV
    2012-06-23 15:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
    2012-06-23 05:56 - 2012-06-23 05:55 - 00000000 ____D C:\FRST
    2012-06-23 05:56 - 2012-02-01 16:11 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Skype
    2012-06-23 05:55 - 2012-02-01 16:07 - 00000000 ____D C:\Program Files (x86)\Steam
    2012-06-23 05:55 - 2012-02-01 15:33 - 00000000 ____D C:\Users\All Users\NVIDIA
    2012-06-23 05:55 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-06-23 05:55 - 2009-07-14 06:51 - 00030874 ____A C:\Windows\setupact.log
    2012-06-23 05:49 - 2012-02-02 00:03 - 01670487 ____A C:\Windows\WindowsUpdate.log
    2012-06-23 05:32 - 2009-07-14 06:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-06-23 05:32 - 2009-07-14 06:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-06-23 05:24 - 2010-11-21 05:47 - 00320732 ____A C:\Windows\PFRO.log
    2012-06-23 05:19 - 2012-06-23 05:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-23 05:19 - 2012-06-23 04:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-23 05:17 - 2012-06-23 05:17 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Wolf\Downloads\mbam-setup-1.61.0.1400.exe
    2012-06-23 05:15 - 2012-06-23 05:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BA2FCC45-41CF-4CE1-9A35-DF6C90610EC6}
    2012-06-23 05:15 - 2012-06-23 05:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A80C7E37-2C66-42EF-B700-CAD836E02A79}
    2012-06-23 05:15 - 2012-02-01 16:35 - 00000000 ____D C:\Users\Wolf\AppData\Local\Windows Live
    2012-06-23 05:13 - 2012-02-01 15:14 - 00000000 ____D C:\users\Wolf
    2012-06-23 04:46 - 2012-06-23 04:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CDDBEACB-4201-4A8D-AF2E-0DFB32D4E345}
    2012-06-23 04:46 - 2012-06-23 04:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C1819089-6D43-46EC-9F62-DF51C748EFE8}
    2012-06-23 04:41 - 2012-02-01 15:49 - 00000000 __SHD C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}
    2012-06-23 04:37 - 2012-06-23 04:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Malwarebytes
    2012-06-23 04:37 - 2012-06-23 04:37 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-06-23 00:47 - 2012-02-01 16:02 - 00000000 ____D C:\Users\Wolf\AppData\Local\PMB Files
    2012-06-22 23:29 - 2012-02-01 18:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\CrashDumps
    2012-06-22 16:43 - 2012-06-22 16:43 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77DABEC5-5C82-451E-9F08-AC88BC745E43}
    2012-06-22 16:43 - 2012-06-22 16:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3ED33445-25D4-4BB7-AA43-18DE6DA892B7}
    2012-06-22 15:06 - 2012-06-22 14:36 - 00000000 ____D C:\Users\Wolf\AppData\Local\Downloaded Installations
    2012-06-22 15:04 - 2012-06-22 14:38 - 00003003 ____A C:\formatter.log
    2012-06-22 14:59 - 2012-02-01 16:01 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-06-22 14:37 - 2012-06-22 14:37 - 00000000 ____D C:\Program Files (x86)\SDA
    2012-06-22 08:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\sk-SK
    2012-06-22 05:58 - 2012-06-22 02:58 - 00000000 ____D C:\Users\Wolf\Desktop\New folder (2)
    2012-06-22 04:42 - 2012-06-22 04:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{904B9BEC-36D2-42B7-ABD5-6D0BD92B144E}
    2012-06-22 04:42 - 2012-06-21 16:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{18F95A37-F8CE-4FEE-A2FC-B0335E1C4D06}
    2012-06-22 03:48 - 2012-06-22 03:42 - 56679244 ____A C:\Users\Wolf\Downloads\XXXX-PCPv2-U.rar
    2012-06-22 03:42 - 2012-06-22 03:42 - 00000617 ____A C:\Users\Public\Desktop\TERA-Launcher.lnk
    2012-06-22 03:42 - 2012-06-22 03:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\TERA
    2012-06-22 03:42 - 2012-02-01 15:30 - 00259771 ____A C:\Windows\DirectX.log
    2012-06-22 03:41 - 2012-06-22 03:39 - 90847904 ____A (En Masse Entertainment) C:\Users\Wolf\Downloads\TERA-Setup.exe
    2012-06-22 03:09 - 2012-06-22 02:57 - 56701864 ____A C:\Users\Wolf\Downloads\6039 - Pokemon Conquest (U).rar
    2012-06-22 02:57 - 2012-06-22 02:57 - 00060136 ____A C:\Users\Wolf\Downloads\PMQ_USA_AP-Patch2.rar
    2012-06-22 02:46 - 2012-06-22 02:46 - 03095908 ____A C:\Users\Wolf\Downloads\AKAIO 1.8.9z.rar
    2012-06-22 02:46 - 2012-06-22 02:46 - 00984640 ____A C:\Users\Wolf\Downloads\USRCheat_4-11-12.7z
    2012-06-22 02:37 - 2012-02-01 19:40 - 00403016 ____A C:\Windows\System32\perfh011.dat
    2012-06-22 02:37 - 2012-02-01 19:40 - 00111342 ____A C:\Windows\System32\perfc011.dat
    2012-06-22 02:37 - 2012-02-01 19:19 - 00414324 ____A C:\Windows\System32\perfh012.dat
    2012-06-22 02:37 - 2012-02-01 19:19 - 00109630 ____A C:\Windows\System32\perfc012.dat
    2012-06-22 02:37 - 2012-02-01 19:12 - 00711326 ____A C:\Windows\System32\perfh013.dat
    2012-06-22 02:37 - 2012-02-01 19:12 - 00138788 ____A C:\Windows\System32\perfc013.dat
    2012-06-22 02:37 - 2012-02-01 18:44 - 00664336 ____A C:\Windows\System32\perfh007.dat
    2012-06-22 02:37 - 2012-02-01 18:44 - 00135232 ____A C:\Windows\System32\perfc007.dat
    2012-06-22 02:37 - 2009-07-14 07:13 - 03396364 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-06-22 02:36 - 2012-02-01 15:40 - 00032320 ____A (FNet Co., Ltd.) C:\Windows\System32\Drivers\FNETTBOH_305.SYS
    2012-06-22 02:34 - 2012-06-22 02:32 - 57350521 ____A C:\Users\Wolf\Downloads\XXXX - Pok駑on Conquest (USA) (PATCHEDv2).rar
    2012-06-21 19:23 - 2012-06-21 15:44 - 00000000 ____D C:\Users\Wolf\Downloads\The.Last.Remnant-RELOADED
    2012-06-21 17:02 - 2012-06-21 15:18 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\.minecraft
    2012-06-21 16:42 - 2012-06-21 16:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{8C33D810-B9B6-483E-B34E-118A76D469D3}
    2012-06-21 15:44 - 2012-06-21 15:42 - 73520661 ____A C:\Users\Wolf\Downloads\minecraft.rar
    2012-06-21 15:20 - 2012-06-21 15:20 - 00955840 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-06-21 15:20 - 2012-06-21 15:20 - 00839096 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-06-21 15:20 - 2012-06-21 15:20 - 00268720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-06-21 15:20 - 2012-06-21 15:20 - 00189360 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-06-21 15:20 - 2012-06-21 15:20 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-06-21 15:20 - 2012-06-21 15:20 - 00000000 ____D C:\Program Files\Java
    2012-06-21 15:19 - 2012-06-21 15:19 - 21869488 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jre-7u5-windows-x64.exe
    2012-06-21 15:17 - 2012-06-21 15:17 - 00278561 ____A C:\Users\Wolf\Downloads\Minecraft.exe
    2012-06-21 15:17 - 2012-06-21 15:17 - 00001063 ____A C:\Users\Wolf\Desktop\Minecraft - Shortcut.lnk
    2012-06-21 04:57 - 2012-06-21 03:56 - 00004725 ____A C:\Users\Wolf\Desktop\New Text Document (3).txt
    2012-06-21 04:41 - 2012-06-21 04:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B258CAE5-67E1-4958-BE42-32FEE0B205DD}
    2012-06-21 04:41 - 2012-06-20 16:40 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB8A37B4-6AE8-4614-9533-7AFD0F18838C}
    2012-06-20 23:24 - 2012-06-20 23:24 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-06-20 23:21 - 2012-02-01 16:01 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-06-20 23:21 - 2012-02-01 16:01 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-06-20 16:41 - 2012-06-20 16:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9259AB6-1DC3-4E8B-8AC8-9ACCA67DB57F}
    2012-06-20 02:12 - 2012-06-20 02:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{967CB5D5-3013-4872-9DFA-B2CBDE65073B}
    2012-06-20 02:12 - 2012-06-19 14:11 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E7495E72-311F-4F4E-9F23-312AE87026EA}
    2012-06-19 17:16 - 2012-06-19 17:16 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Folding@home-x86
    2012-06-19 17:16 - 2012-06-19 17:16 - 00000000 ____D C:\Program Files (x86)\Folding@home
    2012-06-19 17:15 - 2012-06-19 17:15 - 02878976 ____A C:\Users\Wolf\Downloads\Folding@home-Win32-x86-systray-623.msi
    2012-06-19 16:55 - 2012-06-19 16:55 - 03793814 ____A C:\Users\Wolf\Downloads\KatawaShoujo_MomentOfDecision.mp3
    2012-06-19 14:12 - 2012-06-19 14:11 - 00000000 ____D C:\Users\Wolf\AppData\Local\{34B56388-6578-42AB-9D56-59148B615D56}
    2012-06-18 17:13 - 2012-06-18 16:54 - 00006527 ____A C:\Users\Wolf\Desktop\New Text Document (2).txt
    2012-06-18 16:49 - 2012-06-18 16:49 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F7C8FF26-2A7C-44BA-A1BE-6E12077664B8}
    2012-06-18 15:22 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
  5. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    2012-06-18 04:10 - 2012-06-17 16:09 - 00000000 ____D C:\Users\Wolf\AppData\Local\{864C3DB0-747B-4FAB-9441-5A31AA087E0C}
    2012-06-17 23:34 - 2012-06-17 23:33 - 00000000 ____D C:\Users\Wolf\Desktop\New folder
    2012-06-17 16:08 - 2012-02-01 15:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2012-06-16 17:18 - 2012-06-16 17:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{81C49DF4-92B8-4818-8C70-98075EAA9A99}
    2012-06-16 16:58 - 2012-06-16 01:07 - 00000000 ____D C:\Users\Wolf\Documents\LOLReplay
    2012-06-16 16:06 - 2012-06-16 16:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\Macromedia
    2012-06-16 15:44 - 2012-02-01 15:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2012-06-16 05:17 - 2012-06-15 17:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{56F6CB7D-2198-4E18-A4CB-DF4C266BC3FB}
    2012-06-16 04:42 - 2012-06-16 04:42 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
    2012-06-16 04:16 - 2012-06-16 04:16 - 00000000 ____D C:\Users\All Users\Rockstar Games
    2012-06-16 04:16 - 2012-02-01 15:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2012-06-16 03:04 - 2012-06-16 02:59 - 161912074 ____A C:\Users\Wolf\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68].zip
    2012-06-16 01:07 - 2012-06-16 01:07 - 00001905 ____A C:\Users\Public\Desktop\LOL Recorder.lnk
    2012-06-16 01:07 - 2012-06-16 01:07 - 00000000 ____D C:\Program Files (x86)\LOLReplay
    2012-06-16 01:06 - 2012-06-16 01:06 - 01501409 ____A C:\Users\Wolf\Downloads\LOLReplay-0.7.9.1.exe
    2012-06-15 18:58 - 2012-06-15 18:58 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\RenPy
    2012-06-15 18:51 - 2012-06-15 18:51 - 00000797 ____A C:\Users\Wolf\Desktop\Katawa Shoujo.lnk
    2012-06-15 17:15 - 2009-07-14 06:45 - 04903968 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-06-15 03:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
    2012-06-15 03:07 - 2012-02-01 16:15 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-06-15 01:02 - 2012-05-26 12:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\SKIDROW
    2012-06-15 00:28 - 2012-06-15 00:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{6221A1EF-FAC8-4A7D-AA70-6B5507BC541C}
    2012-06-15 00:28 - 2012-06-14 12:26 - 00000000 ____D C:\Users\Wolf\AppData\Local\{31F9B074-5896-404F-9BF6-E4385BDDF5B3}
    2012-06-14 23:43 - 2012-06-14 23:43 - 00000000 ____D C:\Users\Wolf\Documents\Hitman Blood Money
    2012-06-14 23:42 - 2012-06-14 23:42 - 00098304 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll
    2012-06-14 23:01 - 2012-02-01 15:33 - 00060984 ____A C:\Users\Wolf\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-06-14 20:23 - 2012-06-14 16:01 - 00000000 ____D C:\Users\All Users\Firefly Studios
    2012-06-14 12:28 - 2012-06-14 12:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E3238C17-E207-438F-82A3-EB89356E3DA8}
    2012-06-14 12:20 - 2012-06-14 12:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A6D7F2EE-D2D4-41F2-B3FC-8BD145B0A190}
    2012-06-14 12:20 - 2012-06-14 12:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BC331A7B-64D7-432F-82FD-9784E929841B}
    2012-06-14 05:13 - 2012-06-14 05:13 - 00001178 ____A C:\Users\Wolf\Desktop\Warriors Orochi (ToeD).lnk
    2012-06-14 05:13 - 2012-06-14 05:13 - 00000000 ____D C:\Users\Wolf\Documents\KOEI
    2012-06-14 05:00 - 2012-06-14 04:55 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold Crusader
    2012-06-14 04:53 - 2012-06-13 04:11 - 00005761 ____A C:\Users\Wolf\Desktop\New Text Document.txt
    2012-06-14 00:19 - 2012-06-14 00:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{41DA6438-34AD-493B-B393-AAF7819B10BA}
    2012-06-14 00:19 - 2012-06-14 00:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5ED84925-45EB-494B-96A5-F5B3967C1BF8}
    2012-06-13 19:23 - 2012-06-02 21:06 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\TeamViewer
    2012-06-13 12:18 - 2012-06-13 12:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB1209B6-035D-4466-8757-B893040597D9}
    2012-06-13 12:18 - 2012-06-13 12:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69E680C4-A7DF-4C1A-9D8A-0BC66D71EB32}
    2012-06-13 05:37 - 2012-06-12 19:12 - 00000000 ____D C:\Sword
    2012-06-13 03:36 - 2012-06-13 03:36 - 00000019 ____A C:\Windows\D.ini
    2012-06-13 00:05 - 2012-06-13 00:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{78F62976-66E7-43ED-BB9F-D5DF3AC5F3AC}
    2012-06-13 00:04 - 2012-06-13 00:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1EBA75EF-77A7-44FE-8A9C-BB81E330A07D}
    2012-06-12 19:21 - 2012-06-12 19:21 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\ScummVM
    2012-06-12 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
    2012-06-12 12:04 - 2012-06-12 12:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B33236EC-D70C-4821-8D05-10DB19CDFE07}
    2012-06-12 12:04 - 2012-06-12 12:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{29AB2770-F23A-4F39-B983-E42EF3988371}
    2012-06-12 04:18 - 2012-06-12 04:17 - 00000049 ____A C:\Users\Wolf\Desktop\Pinger.txt
    2012-06-11 20:27 - 2012-06-11 20:27 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold 3
    2012-06-11 17:08 - 2012-06-11 17:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A0EAE8F3-D293-482A-914A-4F450BE3CB89}
    2012-06-11 17:08 - 2012-06-11 17:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9C28CCC3-A5D0-480B-8B88-C5A40CA00C3B}
    2012-06-11 05:07 - 2012-06-11 05:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E3AD0B0-35C8-4E43-8572-BD0F9840F37A}
    2012-06-11 05:07 - 2012-06-10 17:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B7E5E7DB-1CB1-4FDB-B085-C2C0D59F575D}
    2012-06-10 22:19 - 2012-06-10 22:19 - 01735565 ____A (Alexander Vigovsky ) C:\Users\Wolf\Downloads\ac3filter_2_4a_lite.exe
    2012-06-10 22:19 - 2012-06-10 22:19 - 00000000 ____D C:\Program Files (x86)\AC3Filter
    2012-06-10 22:18 - 2012-06-10 21:26 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DivX
    2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Wolf\AppData\Local\DDMSettings
    2012-06-10 21:26 - 2012-06-10 21:26 - 00000000 ____D C:\Program Files\DivX
    2012-06-10 21:26 - 2012-06-10 21:25 - 00000000 ____D C:\Program Files (x86)\DivX
    2012-06-10 21:26 - 2012-06-10 21:20 - 00000000 ____D C:\Users\All Users\DivX
    2012-06-10 21:20 - 2012-06-10 21:20 - 00933256 ____A (DivX, LLC) C:\Users\Wolf\Downloads\DivXInstaller.exe
    2012-06-10 17:49 - 2012-06-10 17:27 - 00000000 ____D C:\Users\Wolf\Desktop\Snes
    2012-06-10 17:07 - 2012-06-10 17:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7958BFCE-14B8-4F0B-95C9-96460C9F6439}
    2012-06-10 05:05 - 2012-06-10 05:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E7DF313-0B3B-4FD1-9C44-C7DF656F2830}
    2012-06-10 05:05 - 2012-06-09 17:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5EF250FE-5D75-4BB1-AB3C-B195035F51DF}
    2012-06-09 17:05 - 2012-06-09 17:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DA3EFC53-A72C-4455-BCD6-719EEBAC89AD}
    2012-06-09 04:23 - 2012-02-01 22:07 - 00000000 ____D C:\Users\Wolf\Documents\My Games
    2012-06-09 04:02 - 2012-05-28 18:03 - 00107832 ____A C:\Windows\SysWOW64\PnkBstrB.exe
    2012-06-09 04:02 - 2012-05-28 18:03 - 00066872 ____A C:\Windows\SysWOW64\PnkBstrA.exe
    2012-06-09 04:02 - 2012-02-02 08:28 - 00000000 ____D C:\Users\All Users\Ubisoft
    2012-06-09 04:00 - 2012-06-09 04:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\{74197D9F-12B8-4F93-A066-2A5D76826950}
    2012-06-09 04:00 - 2012-06-08 15:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEA05E89-8748-47D1-B07B-E8D794B8F9B1}
    2012-06-09 01:48 - 2012-06-09 01:46 - 00000000 ____D C:\Users\Wolf\Documents\ArmA 2
    2012-06-09 01:46 - 2012-06-09 01:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\ArmA 2 Free
    2012-06-08 16:23 - 2012-06-08 16:23 - 00000885 ____A C:\Users\UpdatusUser\Desktop\Play Star Wars Republic Commando.lnk
    2012-06-08 15:59 - 2012-06-08 15:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9D3BF70-4F64-48BB-A8F4-E611A769B662}
    2012-06-08 03:59 - 2012-06-08 03:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEFB5670-0786-498C-A1E1-F7243588A15A}
    2012-06-08 03:59 - 2012-06-07 15:58 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AA46DBB4-DB4A-472F-82EB-FBDFC6556532}
    2012-06-07 18:26 - 2012-06-07 18:26 - 00000000 ____D C:\Users\Wolf\Desktop\dolphin
    2012-06-07 15:59 - 2012-06-07 15:58 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FC53B60C-6F6E-4ED4-B40C-009BD43E92B4}
    2012-06-07 04:23 - 2012-06-01 17:49 - 00000000 ____D C:\Users\Wolf\Documents\DepthHunter
    2012-06-07 03:20 - 2012-06-07 03:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AC65E5A8-92D1-4634-946A-2E9F7E9A46FB}
    2012-06-07 03:20 - 2012-06-06 15:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{018EFAE0-DA5F-42D6-9FB4-F021E1130510}
    2012-06-07 02:06 - 2012-06-07 02:06 - 00000000 ____D C:\Nocturnal
    2012-06-07 02:05 - 2012-06-07 02:05 - 00000223 ____A C:\Windows\MugE.ini
    2012-06-07 01:07 - 2012-06-07 01:07 - 00188960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingde.dll
    2012-06-07 01:02 - 2012-06-07 01:02 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing32.dll
    2012-06-07 01:02 - 2012-06-07 01:02 - 00006736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingdib.drv
    2012-06-07 01:02 - 2012-06-07 01:02 - 00005024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingpal.wnd
    2012-06-07 01:01 - 2012-06-07 01:01 - 00092208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing.dll
    2012-06-06 22:35 - 2012-06-03 01:10 - 00000000 ____D C:\Users\Wolf\Documents\Vindictus EU
    2012-06-06 21:32 - 2012-02-01 15:22 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Adobe
    2012-06-06 15:19 - 2012-06-06 15:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7223F4E9-A6ED-4984-9F12-0553BE51A9FA}
    2012-06-06 03:19 - 2012-06-06 03:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AEBC6B16-FA61-472F-B178-7947B70D4644}
    2012-06-06 03:19 - 2012-06-06 03:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77EDE412-92A0-4FE2-B150-A38B2E91C713}
    2012-06-05 22:08 - 2012-06-05 22:08 - 00000000 ____D C:\Program Files (x86)\SplitMediaLabs
    2012-06-05 15:18 - 2012-06-05 15:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{396C4775-9424-4BB2-A423-6B2436410DE2}
    2012-06-05 15:18 - 2012-06-05 15:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2EE4F770-25FF-4D67-AE38-FF1ECCA34319}
    2012-06-05 03:18 - 2012-06-05 03:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{669C431C-59C4-4CFA-9965-6CCB0F8DD7E6}
    2012-06-05 03:18 - 2012-06-04 15:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9E2CB37D-DD5F-4DEC-9A37-4E8E73599B3F}
    2012-06-04 15:17 - 2012-06-04 15:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{4A04846C-C294-40F1-B047-C441C907CCF9}
    2012-06-04 02:34 - 2012-06-04 02:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D94B41B9-EF3A-4674-AE3A-1DADE4352553}
    2012-06-04 02:34 - 2012-06-03 14:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C91224FA-142A-404C-9C41-94A14AAB6355}
    2012-06-03 14:34 - 2012-06-03 14:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E64A22F0-D582-4DBC-BE24-0B861F843E90}
    2012-06-03 02:30 - 2012-06-03 02:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E9B1A525-2BB8-4999-A4FA-B4C972C0A7CF}
    2012-06-03 02:30 - 2012-06-02 14:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2A798180-069D-448F-9C03-618665668D41}
    2012-06-03 01:11 - 2012-06-03 01:11 - 00001234 ____A C:\Users\Wolf\Desktop\Vindictus - Shortcut.lnk
    2012-06-03 01:11 - 2012-06-02 23:36 - 00000000 ____D C:\Users\All Users\NexonEU
    2012-06-03 01:08 - 2012-06-03 01:08 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
    2012-06-03 01:08 - 2012-06-02 23:46 - 00000000 ____D C:\Download
    2012-06-03 01:07 - 2012-06-02 18:03 - 00000000 ____D C:\Nexon
    2012-06-03 00:52 - 2012-06-03 00:49 - 130416408 ____A C:\Users\Wolf\Downloads\bmw_perfect_v97.rar
    2012-06-03 00:48 - 2012-06-03 00:48 - 00000000 ____D C:\Users\Wolf\Documents\bmw_english4V_95
    2012-06-03 00:19 - 2012-06-22 08:49 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-03 00:19 - 2012-06-22 08:49 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-03 00:19 - 2012-06-22 08:48 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-03 00:19 - 2012-06-22 08:48 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-03 00:19 - 2012-06-22 08:48 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-03 00:15 - 2012-06-22 08:49 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-03 00:15 - 2012-06-22 08:48 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 23:46 - 2012-06-02 23:46 - 00536576 ____A (Nexon) C:\Users\Wolf\Downloads\Vindictus_Downloader.exe
    2012-06-02 23:46 - 2012-06-02 23:46 - 00446464 ____A (NEXON Inc.) C:\Windows\NEXON_EU_DownloaderUpdater.exe
    2012-06-02 23:46 - 2012-06-02 23:46 - 00000235 ____A C:\Windows\SysWOW64\nxEuUninstall.bat
    2012-06-02 23:35 - 2012-06-02 23:35 - 03655576 ____A (Nexon) C:\Users\Wolf\Downloads\Setup.exe
    2012-06-02 18:21 - 2012-06-02 18:21 - 00621160 ____A (Copyright ゥ 2010 eSupport.com. All Rights Reserved.) C:\Users\Wolf\Downloads\driveragent_987.exe
    2012-06-02 18:21 - 2012-06-02 18:21 - 00021712 ____A (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
    2012-06-02 18:21 - 2012-06-02 18:21 - 00000000 ____D C:\Users\Wolf\AppData\Local\eSupport.com
    2012-06-02 18:20 - 2012-06-02 18:20 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SystemRequirementsLab
    2012-06-02 18:03 - 2012-06-02 18:03 - 00000000 ____D C:\Users\All Users\NexonUS
    2012-06-02 17:13 - 2012-06-02 17:13 - 00000000 ____D C:\Users\All Users\Nexon
    2012-06-02 17:08 - 2012-06-02 17:08 - 02013336 ____A C:\Users\Wolf\Downloads\MapleStoryDownloader.exe
    2012-06-02 16:27 - 2012-06-02 16:08 - 113899850 ____A C:\Users\Wolf\Downloads\Bf3-mpcr.rar
    2012-06-02 16:11 - 2012-06-02 16:11 - 00000000 ____D C:\Users\Wolf\Documents\DragonSaga
    2012-06-02 16:10 - 2012-06-02 16:10 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DragonSaga
    2012-06-02 15:19 - 2012-06-22 08:48 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 15:15 - 2012-06-22 08:48 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-02 14:29 - 2012-06-02 14:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F03D9EB4-CF0B-4A74-A47B-E056FEB39EDD}
    2012-06-02 02:29 - 2012-06-02 02:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{72BAC764-B627-4F15-A603-D553B12B02B6}
    2012-06-02 02:29 - 2012-06-01 14:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{45C6FCE0-68C7-48EE-9121-BAEDFCA89588}
    2012-06-01 18:24 - 2012-06-01 18:24 - 04171406 ____A C:\Users\Wolf\Downloads\XMouseButtonControlSetup.2.4.exe
    2012-06-01 18:24 - 2012-06-01 18:24 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Highresolution Enterprises
    2012-06-01 18:24 - 2012-06-01 18:24 - 00000000 ____D C:\Program Files\Highresolution Enterprises
    2012-06-01 18:03 - 2012-06-01 18:03 - 00000000 ____D C:\Users\All Users\BioWare
    2012-06-01 18:03 - 2012-02-02 08:27 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\NVIDIA
    2012-06-01 18:01 - 2012-06-01 18:01 - 00000000 ____D C:\Users\Wolf\Documents\BioWare
    2012-06-01 14:28 - 2012-06-01 14:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BDF956F0-D59B-4350-AFFF-357CAE62018C}
    2012-06-01 01:31 - 2012-06-01 01:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69CA7DA5-AAE2-4F3D-B062-F5ADF10EB800}
    2012-06-01 01:31 - 2012-06-01 01:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{30921632-D6C6-470F-8A0C-F20D93AE4ED0}
    2012-06-01 01:24 - 2012-06-01 01:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DFCEAD23-D76A-4193-B976-F76F825D9117}
    2012-06-01 01:24 - 2012-06-01 01:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{24380E14-2AF3-4C52-A2FC-7DAD465977B8}
    2012-06-01 01:20 - 2012-06-01 01:20 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{d49c2933-ab76-11e1-bc6a-bc5ff438e47c}.TxR.blf
    2012-06-01 01:14 - 2012-06-01 01:14 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{1aa4bd2d-ab76-11e1-8460-bc5ff438e47c}.TxR.blf
    2012-06-01 01:14 - 2012-06-01 01:14 - 00000092 ____A C:\Users\Wolf\AppData\Local\fusioncache.dat
    2012-06-01 01:14 - 2012-06-01 01:14 - 00000000 ____D C:\Users\Wolf\AppData\Local\GameSpy
    2012-06-01 01:14 - 2012-02-01 15:14 - 00000000 ____D C:\Users\Wolf\AppData\Local\VirtualStore
    2012-06-01 00:25 - 2012-02-01 15:32 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2012-06-01 00:25 - 2012-02-01 15:31 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2012-06-01 00:22 - 2012-06-01 00:19 - 168454136 ____A (NVIDIA Corporation) C:\Users\Wolf\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
    2012-06-01 00:19 - 2012-06-01 00:19 - 00000000 ____D C:\Users\All Users\Sun
    2012-06-01 00:18 - 2012-06-01 00:18 - 00772552 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-06-01 00:18 - 2012-06-01 00:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-06-01 00:18 - 2012-06-01 00:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-06-01 00:18 - 2012-06-01 00:18 - 00000000 ____D C:\Program Files (x86)\Oracle
    2012-06-01 00:18 - 2012-06-01 00:18 - 00000000 ____D C:\Program Files (x86)\Java
    2012-06-01 00:17 - 2012-06-01 00:17 - 00892360 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jxpiinstall.exe
    2012-05-31 19:22 - 2012-05-31 19:22 - 00000000 ____D C:\Program Files (x86)\GameSpy
    2012-05-31 19:21 - 2012-05-25 17:57 - 03475636 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-05-31 19:18 - 2012-05-31 19:18 - 00001298 ____A C:\Users\Public\Desktop\Crysis.lnk
    2012-05-31 15:37 - 2012-05-31 15:37 - 21503784 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HWSE_SE_v3.2.2.1.exe
    2012-05-31 15:37 - 2012-05-31 15:37 - 00000000 ____D C:\Program Files (x86)\Hercules
    2012-05-31 15:36 - 2012-05-31 15:36 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(2).exe
    2012-05-31 15:29 - 2012-05-31 15:29 - 62444312 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v2.9.0.0.exe
    2012-05-31 15:28 - 2012-05-31 15:28 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(1).exe
    2012-05-31 15:06 - 2012-05-31 15:06 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\InstallShield
    2012-05-31 15:06 - 2012-05-31 15:05 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1.exe
    2012-05-31 13:23 - 2012-05-31 13:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C33CF4EE-A3BE-4355-A681-463A8BE50A8B}
    2012-05-31 13:23 - 2012-05-31 13:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{47DD7949-55AC-4910-B63E-0625A8C88C07}
    2012-05-31 03:50 - 2012-05-29 00:38 - 00000000 ____D C:\Fraps
    2012-05-30 21:34 - 2012-05-30 21:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{308AC941-8DFC-4CE8-94F0-EB570AE23E93}
    2012-05-30 21:34 - 2012-05-30 09:33 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3BCE797B-4A95-4C3C-841B-891768931583}
    2012-05-30 16:02 - 2012-05-30 16:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Chart Controls
    2012-05-30 14:28 - 2012-05-30 14:28 - 00001802 ____A C:\Users\Public\Desktop\Dragon Saga.lnk
    2012-05-30 13:48 - 2012-05-30 13:48 - 00330120 ____A (Gravity Interactive, Inc.) C:\Users\Wolf\Downloads\DragonSaga-Installer-0.2.5-20120330.exe
    2012-05-30 09:34 - 2012-05-30 09:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D9ED8115-E416-4B42-93EA-D62BFF6A48D3}
    2012-05-29 16:49 - 2012-05-29 16:49 - 00001989 ____A C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
    2012-05-29 16:49 - 2012-05-29 16:49 - 00000000 ____D C:\Program Files (x86)\PCSX2 0.9.8
    2012-05-29 16:48 - 2012-05-29 16:48 - 12780479 ____A C:\Users\Wolf\Downloads\pcsx2-0.9.8-r4600-setup.exe
    2012-05-29 16:48 - 2012-05-29 16:48 - 04353259 ____A (Igor Pavlov) C:\Users\Wolf\Downloads\dolphin-3.0-win64.exe
    2012-05-29 15:41 - 2012-05-29 15:41 - 00002105 ____A C:\Users\Public\Desktop\A.V.A.lnk
    2012-05-29 15:41 - 2012-05-29 15:41 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
    2012-05-29 15:41 - 2012-05-28 22:52 - 00000000 ____D C:\Program Files (x86)\REACTOR
    2012-05-29 12:32 - 2012-05-29 12:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{65655CD4-236C-47ED-BF7C-D5B292418970}
    2012-05-29 12:32 - 2012-05-29 12:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1DA6169D-DEBF-47A1-B3DF-FC4F0D7EA61D}
    2012-05-29 03:52 - 2012-05-28 19:43 - 00000000 ____D C:\Users\Wolf\Documents\DragonNest
    2012-05-29 00:48 - 2012-05-29 00:48 - 00002560 ____A C:\Users\Wolf\Documents\Register Vegas Pro.htm
    2012-05-29 00:48 - 2012-05-29 00:48 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Publish Providers
    2012-05-29 00:48 - 2012-05-29 00:46 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Sony
    2012-05-29 00:46 - 2012-05-29 00:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\Sony
    2012-05-29 00:44 - 2012-05-29 00:44 - 00001908 ____A C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
    2012-05-29 00:44 - 2012-05-29 00:44 - 00000000 ____D C:\Users\All Users\Sony
    2012-05-29 00:43 - 2012-05-29 00:43 - 00000000 ____D C:\Program Files (x86)\Sony
    2012-05-29 00:38 - 2012-05-29 00:38 - 00000562 ____A C:\Users\Wolf\Desktop\Fraps.lnk
    2012-05-29 00:32 - 2012-05-29 00:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FB225DD7-B02B-4BE6-8F32-D5F446DE2EAB}
    2012-05-29 00:31 - 2012-05-29 00:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{160F752A-7CFD-4058-914C-AEA7BDA6BF80}
    2012-05-28 23:25 - 2012-05-27 12:33 - 00000000 ____D C:\Users\Wolf\AppData\Local\BladesOfTime
    2012-05-28 22:56 - 2012-05-28 22:56 - 00298016 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
    2012-05-28 22:55 - 2012-05-28 22:55 - 00000000 ____D C:\Users\Wolf\AppData\Local\PunkBuster
    2012-05-28 22:53 - 2012-05-28 22:53 - 00001907 ____A C:\Users\Public\Desktop\ijji REACTOR.lnk
    2012-05-28 22:52 - 2012-05-28 22:52 - 07822632 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\IJJI_REACTOR_INST_EN.exe
    2012-05-28 21:12 - 2012-05-28 17:34 - 198654664 ____A C:\Users\Wolf\Downloads\U_AVA_SETUP_Jan2012.zip
    2012-05-28 20:12 - 2012-05-28 20:12 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
    2012-05-28 20:11 - 2012-05-28 18:03 - 00189248 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
    2012-05-28 19:58 - 2012-05-28 20:11 - 03130440 ____A C:\Windows\SysWOW64\pbsvc_blr.exe
    2012-05-28 19:12 - 2012-05-28 19:12 - 00000796 ____A C:\Users\Public\Desktop\Dragon Nest.lnk
    2012-05-28 18:40 - 2012-05-28 17:28 - 2536606647 ____A (Shanda Games International) C:\Users\Wolf\Downloads\DNClientVer60_20120423.exe
    2012-05-28 18:08 - 2012-05-28 18:05 - 00000000 ____D C:\Users\Wolf\Documents\Battlefield 3
  6. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    2012-05-28 18:05 - 2012-05-28 17:34 - 00000000 ____D C:\Games
    2012-05-28 17:19 - 2012-05-28 17:18 - 02072456 ____A C:\Users\Wolf\Downloads\BlacklightRetribution_Downloader_EN.exe
    2012-05-28 13:16 - 2012-05-26 15:47 - 00000000 ____D C:\Users\Wolf\AppData\Local\Adobe
    2012-05-28 13:14 - 2012-05-28 13:14 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
    2012-05-28 13:14 - 2012-05-28 13:14 - 00000725 ____A C:\Users\Wolf\Desktop\Dustforce.lnk
    2012-05-28 13:14 - 2012-05-28 13:14 - 00000000 ____D C:\Program Files (x86)\OpenAL
    2012-05-28 13:14 - 2012-05-28 03:12 - 00000000 ____D C:\Users\Wolf\Downloads\Crysis_2-FLT
    2012-05-28 12:31 - 2012-05-28 12:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CD0B5883-D705-4B3F-878D-1CEB81D6E307}
    2012-05-28 12:31 - 2012-05-28 12:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{466B1E6A-4A0C-4E36-8C2B-545561C19512}
    2012-05-28 00:30 - 2012-05-28 00:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3B0B234A-AD01-4412-A755-6F9EC247B549}
    2012-05-28 00:30 - 2012-05-28 00:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{38946F5D-E76A-4FAC-9F90-365593EAA120}
    2012-05-27 23:17 - 2012-05-27 22:51 - 00021225 ____A C:\Users\Wolf\Documents\Install Dragon Age Origins.log
    2012-05-27 23:05 - 2012-05-27 23:05 - 00000754 ____A C:\Users\Public\Desktop\Dragon Age Origins.lnk
    2012-05-27 23:05 - 2012-05-27 23:05 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP
    2012-05-27 19:36 - 2012-05-27 19:36 - 00001147 ____A C:\Users\Public\Desktop\Bamboo Dock.lnk
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Wacom
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Users\All Users\Wacom
    2012-05-27 19:36 - 2012-05-27 19:36 - 00000000 ____D C:\Program Files (x86)\Bamboo Dock
    2012-05-27 19:36 - 2012-05-26 16:12 - 00000002 ____A C:\Users\Wolf\.bdockinstall.log
    2012-05-27 19:34 - 2012-05-27 19:34 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WTablet
    2012-05-27 19:34 - 2012-05-27 19:34 - 00000000 ____D C:\Program Files\Tablet
    2012-05-27 19:34 - 2012-05-27 19:34 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
    2012-05-27 19:33 - 2012-05-27 19:33 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(2).exe
    2012-05-27 19:15 - 2012-05-27 19:15 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(1).exe
    2012-05-27 19:05 - 2012-05-27 19:05 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
    2012-05-27 13:40 - 2012-05-25 17:03 - 00000000 ____D C:\Users\Wolf\Documents\CAPCOM
    2012-05-27 13:22 - 2012-05-27 13:22 - 00001003 ____A C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
    2012-05-27 13:21 - 2012-05-27 13:21 - 00000000 ____D C:\Windows\SysWOW64\xlive
    2012-05-27 13:21 - 2012-05-27 13:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
    2012-05-27 13:00 - 2012-05-27 12:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\SniperV2
    2012-05-27 12:57 - 2012-05-27 12:57 - 00001095 ____A C:\Users\Public\Desktop\Sniper Elite V2.lnk
    2012-05-27 12:49 - 2012-05-27 12:44 - 00000000 ____D C:\Users\Wolf\AppData\Local\XBlades
    2012-05-27 12:48 - 2012-05-27 12:44 - 00000000 ____D C:\Users\All Users\XBlades
    2012-05-27 12:46 - 2012-05-27 12:44 - 00000422 ____A C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
    2012-05-27 12:32 - 2012-05-27 12:32 - 00000984 ____A C:\Users\Public\Desktop\Blades of Time.lnk
    2012-05-27 12:30 - 2012-05-27 12:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{452C3747-247D-49E6-92F9-FF22C9404000}
    2012-05-27 12:29 - 2012-05-27 12:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B2C1155D-6711-4A9A-BE54-8C430A6B998F}
    2012-05-27 04:22 - 2012-05-27 04:22 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
    2012-05-27 04:17 - 2012-05-27 04:17 - 00000999 ____A C:\Users\Public\Desktop\Magicka.lnk
    2012-05-26 23:40 - 2012-05-26 23:40 - 00000000 ____D C:\Windows\System32\Macromed
    2012-05-26 23:40 - 2012-05-26 23:40 - 00000000 ____D C:\Users\Wolf\AppData\Local\SplitMediaLabs
    2012-05-26 23:38 - 2012-05-26 23:38 - 00000000 ____D C:\Users\All Users\SplitMediaLabs
    2012-05-26 23:37 - 2012-05-26 23:37 - 24220864 ____A (SplitMediaLabs) C:\Users\Wolf\Downloads\xsplit_installer_v1.0.1204.1301.exe
    2012-05-26 23:37 - 2012-05-26 23:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SplitMediaLabs
    2012-05-26 23:07 - 2012-05-26 23:07 - 00000857 ____A C:\Users\Wolf\Desktop\League of Legends.lnk
    2012-05-26 21:47 - 2012-05-26 21:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{525FBECE-BEC1-4B0B-BCDD-A5CB91553E59}
    2012-05-26 21:46 - 2012-05-26 21:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CB91DDC8-FE7D-4956-A352-3D8415C5CF6F}
    2012-05-26 21:20 - 2012-05-26 21:20 - 00001727 ____A C:\Users\Wolf\Desktop\Photoshop - Shortcut.lnk
    2012-05-26 21:19 - 2012-05-26 21:11 - 00000000 ____D C:\Users\All Users\FLEXnet
    2012-05-26 21:18 - 2012-05-26 21:18 - 00000000 ____D C:\Users\Wolf\AdobeLicensingFilesBackup
    2012-05-26 21:12 - 2012-05-26 21:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\Microsoft Games
    2012-05-26 21:05 - 2012-05-26 20:29 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2012-05-26 21:04 - 2012-05-26 20:34 - 00000000 ____D C:\Program Files\Adobe
    2012-05-26 21:03 - 2012-02-01 15:21 - 00000000 ____D C:\Program Files (x86)\Adobe
    2012-05-26 21:02 - 2012-05-26 21:02 - 00000000 ____D C:\Windows\SysWOW64\spool
    2012-05-26 20:59 - 2012-05-26 20:59 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
    2012-05-26 20:45 - 2012-05-26 18:28 - 00000000 ____D C:\Users\All Users\regid.1986-12.com.adobe
    2012-05-26 20:30 - 2012-02-01 15:21 - 00000000 ____D C:\Users\All Users\Adobe
    2012-05-26 20:20 - 2012-05-26 20:20 - 00000000 ____D C:\Windows\SysWOW64\syncdb
    2012-05-26 18:17 - 2012-05-26 17:47 - 2119376047 ____A C:\Users\Wolf\Downloads\PSE9.zip
    2012-05-26 17:59 - 2012-05-26 17:59 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Ambient Design
    2012-05-26 17:44 - 2012-02-01 15:25 - 00000000 ____D C:\Users\All Users\Norton
    2012-05-26 17:43 - 2012-05-26 17:34 - 544160151 ____A C:\Users\Wolf\Downloads\PSE9.zip.part
    2012-05-26 17:36 - 2012-05-26 17:34 - 72725528 ____A (Ambient Design) C:\Users\Wolf\Downloads\install_artrage_studiopro.exe
    2012-05-26 17:35 - 2012-05-26 17:34 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final.exe
    2012-05-26 17:17 - 2012-05-26 17:17 - 00001181 ____A C:\Users\Public\Desktop\openCanvas5e.lnk
    2012-05-26 17:17 - 2012-05-26 17:17 - 00000000 ____D C:\Program Files (x86)\portalgraphics
    2012-05-26 17:13 - 2012-05-26 17:13 - 02330770 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04e.exe
    2012-05-26 17:11 - 2012-05-26 17:11 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\portalgraphics
    2012-05-26 17:10 - 2012-05-26 17:10 - 02271209 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04.exe
    2012-05-26 16:49 - 2012-05-26 16:25 - 00000000 ____D C:\Users\All Users\Alias
    2012-05-26 16:25 - 2012-05-26 16:25 - 00002156 ____A C:\Users\Public\Desktop\Autodesk SketchBookPro 2011.lnk
    2012-05-26 16:25 - 2012-05-26 16:25 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Autodesk
    2012-05-26 16:24 - 2012-05-26 16:24 - 00001152 ____A C:\Users\Wolf\Desktop\Play IW4M (Modern Warfare 2).lnk
    2012-05-26 16:24 - 2012-05-26 16:24 - 00000000 ____D C:\Program Files (x86)\Autodesk
    2012-05-26 16:23 - 2012-05-26 16:23 - 00001013 ____A C:\Users\Public\Desktop\Worms Ultimate Mayhem.lnk
    2012-05-26 16:12 - 2012-05-26 16:12 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2012-05-26 16:12 - 2012-05-26 16:12 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2012-05-26 12:00 - 2012-05-26 12:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\BigHugeEngine
    2012-05-26 11:58 - 2012-05-26 11:58 - 00001185 ____A C:\Users\Wolf\Desktop\Dead Island.lnk
    2012-05-26 10:15 - 2012-05-26 10:15 - 00001083 ____A C:\Users\Public\Desktop\Kingdoms of Amalur Reckoning.lnk
    2012-05-26 09:46 - 2012-05-26 09:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A5BF4313-036F-4A54-A8FA-9DA6C12A656C}
    2012-05-26 09:46 - 2012-05-26 09:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5634B62E-A929-4F3F-97F4-35CD08166140}
    2012-05-26 00:32 - 2012-05-26 00:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\.inapptracking
    2012-05-26 00:31 - 2012-05-26 00:31 - 00000786 ____A C:\Users\Public\Desktop\Sonic Generations.lnk
    2012-05-25 22:34 - 2012-05-25 21:44 - 00000000 ____D C:\Users\Wolf\AppData\Local\IW4M
    2012-05-25 21:44 - 2012-05-25 21:44 - 00156672 ____A (Microsoft) C:\Users\Wolf\Downloads\InstallIW4M.exe
    2012-05-25 21:29 - 2012-05-25 21:29 - 15556319 ____A C:\Users\Wolf\Downloads\4D1 Patcher(r88).zip
    2012-05-25 21:26 - 2012-05-25 21:26 - 07731209 ____A C:\Users\Wolf\Downloads\alterRevolution Client.rar
    2012-05-25 21:26 - 2012-05-25 21:26 - 02246711 ____A C:\Users\Wolf\Downloads\alterRevolution Dedicated 0.3c.rar
    2012-05-25 20:12 - 2012-05-25 20:12 - 00001309 ____A C:\Users\Wolf\Desktop\Devil May Cry 4.lnk
    2012-05-25 17:57 - 2012-05-25 17:57 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-05-25 17:49 - 2012-05-25 17:48 - 12621696 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe
    2012-05-25 17:48 - 2012-05-25 17:48 - 00523840 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe.part
    2012-05-25 17:03 - 2012-05-25 17:03 - 00000000 ____D C:\Users\Wolf\AppData\Local\CAPCOM
    2012-05-25 15:53 - 2012-05-25 15:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3157081A-C7D3-4452-9C7E-F0E660292DB2}
    2012-05-25 15:50 - 2012-05-25 15:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{93B44AF1-3B18-4C2A-B279-24923486D8F6}
    2012-05-25 15:50 - 2012-02-02 04:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A9A666FD-DBB0-4B68-B3C9-837B576965AA}
    2012-05-25 13:59 - 2012-05-25 13:59 - 00002213 ____A C:\Users\Public\Desktop\AION Free-To-Play.lnk
    2012-05-25 13:59 - 2012-05-25 13:59 - 00000000 ____D C:\Program Files (x86)\Gameforge
    2012-05-25 13:44 - 2012-05-25 13:39 - 145138568 ____A (Gameforge) C:\Users\Wolf\Downloads\setup_20120224.exe
    2012-05-25 13:31 - 2012-05-25 13:29 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WinRAR
    2012-05-25 13:30 - 2012-05-25 13:30 - 01639789 ____A C:\Users\Wolf\Downloads\winrar-x64-411.exe
    2012-05-25 13:30 - 2012-05-25 13:30 - 00000000 ____D C:\Program Files\WinRAR
    2012-05-25 13:29 - 2012-05-25 13:29 - 01506653 ____A C:\Users\Wolf\Downloads\wrar411.exe
    2012-05-25 13:29 - 2012-05-25 13:29 - 00000000 ____D C:\Program Files (x86)\WinRAR
    2012-05-25 12:44 - 2012-05-25 12:44 - 00000000 ____D C:\Program Files\7-Zip
    2012-05-25 12:43 - 2012-05-25 12:43 - 01376768 ____A C:\Users\Wolf\Downloads\7z920-x64.msi
    2012-05-20 09:49 - 2012-05-20 09:49 - 00071680 ____A (Beepa P/L) C:\Windows\System32\frapsv64.dll
    2012-05-20 09:49 - 2012-05-20 09:49 - 00065536 ____A (Beepa P/L) C:\Windows\SysWOW64\frapsvid.dll
    2012-05-18 04:47 - 2012-06-15 03:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-05-18 04:16 - 2012-06-15 03:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-05-18 04:06 - 2012-06-15 03:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-05-18 03:59 - 2012-06-15 03:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-05-18 03:59 - 2012-06-15 03:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-05-18 03:58 - 2012-06-15 03:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-05-18 03:58 - 2012-06-15 03:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-05-18 03:56 - 2012-06-15 03:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-05-18 03:55 - 2012-06-15 03:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-05-18 03:55 - 2012-06-15 03:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-05-18 03:54 - 2012-06-15 03:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-05-18 03:51 - 2012-06-15 03:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-05-18 03:51 - 2012-06-15 03:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-05-18 03:47 - 2012-06-15 03:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-05-18 01:11 - 2012-06-15 03:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-05-18 00:48 - 2012-06-15 03:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-05-18 00:45 - 2012-06-15 03:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-05-18 00:36 - 2012-06-15 03:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-05-18 00:35 - 2012-06-15 03:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-05-18 00:35 - 2012-06-15 03:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-05-18 00:33 - 2012-06-15 03:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-05-18 00:31 - 2012-06-15 03:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-05-18 00:29 - 2012-06-15 03:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-05-18 00:29 - 2012-06-15 03:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-05-18 00:27 - 2012-06-15 03:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-05-18 00:25 - 2012-06-15 03:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-05-18 00:24 - 2012-06-15 03:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-05-18 00:20 - 2012-06-15 03:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-05-15 12:48 - 2012-06-01 00:23 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-05-15 12:48 - 2012-06-01 00:23 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-05-15 12:48 - 2012-02-09 23:43 - 00949056 ____A (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll
    2012-05-15 12:48 - 2012-02-09 23:43 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-05-15 12:48 - 2012-02-09 23:43 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
    2012-05-15 12:48 - 2012-02-01 15:32 - 00014324 ____A C:\Windows\System32\nvinfo.pb
    2012-05-15 11:29 - 2012-02-01 17:40 - 02621723 ____A C:\Windows\System32\nvcoproc.bin
    2012-05-15 11:29 - 2012-02-01 15:32 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
    2012-05-15 11:29 - 2012-02-01 15:32 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    2012-05-15 11:29 - 2012-02-01 15:32 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
    2012-05-15 11:29 - 2012-02-01 15:32 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
    2012-05-15 11:28 - 2012-02-01 15:32 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
    2012-05-15 03:32 - 2012-06-14 12:34 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-05-15 02:21 - 2012-05-15 02:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
    2012-05-04 13:06 - 2012-06-14 12:34 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-05-04 13:00 - 2012-06-21 13:09 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-05-04 12:03 - 2012-06-14 12:34 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-05-04 12:03 - 2012-06-14 12:34 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-05-04 11:59 - 2012-06-21 13:09 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-05-01 07:40 - 2012-06-14 12:34 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-04-28 07:32 - 2012-06-14 12:34 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
    2012-04-28 05:55 - 2012-06-14 12:34 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-04-26 07:41 - 2012-06-14 12:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-04-26 07:41 - 2012-06-14 12:34 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-04-26 07:34 - 2012-06-14 12:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-04-24 07:37 - 2012-06-14 12:33 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-04-24 07:37 - 2012-06-14 12:33 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-04-24 07:37 - 2012-06-14 12:33 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-04-24 06:36 - 2012-06-14 12:33 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-04-24 06:36 - 2012-06-14 12:33 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-04-24 06:36 - 2012-06-14 12:33 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2012-04-18 19:08 - 2012-06-01 00:23 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
    2012-04-18 19:08 - 2012-06-01 00:23 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-04-18 19:08 - 2012-06-01 00:23 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-04-07 14:31 - 2012-06-14 12:34 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-04-07 13:26 - 2012-06-14 12:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-04-04 18:47 - 2012-06-01 00:18 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-04-04 18:47 - 2012-06-01 00:18 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-04-04 15:56 - 2012-06-23 05:19 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-03-30 13:35 - 2012-02-01 15:49 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys

    ZeroAccess:
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\@
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\L
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\n
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\00000001.@
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\80000000.@
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\800000cb.@

    ZeroAccess:
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\@
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\L
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U

    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ========================= Memory info ======================

    Percentage of memory in use: 23%
    Total physical RAM: 8170.99 MB
    Available physical RAM: 6287.45 MB
    Total Pagefile: 16340.17 MB
    Available Pagefile: 14211.89 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.88 MB

    ======================= Partitions =========================

    1 Drive c: () (Fixed) (Total:468.26 GB) (Free:296.53 GB) NTFS
    3 Drive e: () (Removable) (Total:7.39 GB) (Free:4.37 GB) FAT32
    5 Drive w: (Games) (Fixed) (Total:463.16 GB) (Free:194.47 GB) NTFS

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 931 GB 1024 KB
    Disk 1 Online 7580 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 468 GB 101 MB
    Partition 3 Primary 463 GB 468 GB

    ======================================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 System Rese NTFS Partition 100 MB Healthy System (partition with boot components)

    ======================================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 C NTFS Partition 468 GB Healthy Boot

    ======================================================================================================

    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 W Games NTFS Partition 463 GB Healthy

    ======================================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 7576 MB 4096 KB

    ======================================================================================================

    Disk: 1
    Partition 1
    Type : 0B
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 E FAT32 Removable 7576 MB Healthy

    ======================================================================================================

    ==========================================================

    Last Boot: 2012-06-18 15:15

    ======================= End Of Log ==========================
  7. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    We can't remove this type of an infection from within Windows so you have to boot to System Recovery Options and post new log from there.
  8. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    I see.. apologies for being stubborn.

    Scan result of Farbar Recovery Scan Tool Version: 22-06-2012
    Ran by SYSTEM at 23-06-2012 06:25:02
    Running from G:\
    Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ========================== Registry (Whitelisted) =============

    HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11855976 2011-05-18] (Realtek Semiconductor)
    HKLM\...\Run: [XFast LAN] C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe [1441152 2011-07-04] (cFos Software GmbH)
    HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [26624 2011-05-13] (Creative Technology Ltd.)
    HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [444856 2011-09-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [XFast USB] C:\Program Files (x86)\XFast USB\XFastUsb.exe [4878912 2012-02-01] (FNet Co., Ltd.)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [34672 2008-06-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r [909824 2011-05-19] (Creative Technology Ltd)
    HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-10] (Creative Technology Ltd.)
    HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1039872 2011-09-28] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2008-08-13] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646232 2011-09-26] ()
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
    HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
    HKU\Wolf\...\Run: [ASRockXTU] [x]
    HKU\Wolf\...\Run: [zASRockInstantBoot] [x]
    HKU\Wolf\...\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A [2248704 2011-08-02] ()
    HKU\Wolf\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2012-02-01] (Valve Corporation)
    HKU\Wolf\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17355912 2012-05-02] (Skype Technologies S.A.)
    HKU\Wolf\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
    HKU\Wolf\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3671872 2012-04-17] (DT Soft Ltd)
    HKU\Wolf\...\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [438272 2012-06-02] (NEXON Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\LOLRecorder.lnk
    ShortcutTarget: LOLRecorder.lnk -> C:\Program Files (x86)\LOLReplay\LOLRecorder.exe (LOL Replay)

    ==================== Services (Whitelisted) ======

    3 1394hub; C:\Windows\System32\svchost.exe -k netsvcs [27136 2009-07-13] (Microsoft Corporation)
    3 1394hub; C:\Windows\SysWow64\svchost.exe -k netsvcs [20992 2009-07-13] (Microsoft Corporation)
    2 cFosSpeedS; "C:\Program Files\ASRock\XFast LAN\spd.exe" -service [395136 2011-07-04] (cFos Software GmbH)
    3 FLEXnet Licensing Service 64; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe" [1038088 2012-05-26] (Acresso Software Inc.)
    2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
    2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2012-06-08] ()
    2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [107832 2012-06-08] ()
    2 TabletServicePen; C:\Program Files\Tablet\Pen\Pen_Tablet.exe [6583160 2011-09-08] (Wacom Technology, Corp.)
    2 TouchServicePen; C:\Program Files\Tablet\Pen\Pen_TouchService.exe [528760 2011-09-08] (Wacom Technology, Corp.)
    2 WCUService_STC_IE; C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [497480 2011-03-22] (Splashtop Inc.)
    2 XMouseButton Launcher; C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe [87040 2012-03-04] (Highresolution Enterprises)
    3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
    3 DAUpdaterSvc; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [x]

    ========================== Drivers (Whitelisted) =============

    1 AsrAppCharger; C:\Windows\System32\Drivers\AsrAppCharger.sys [17192 2011-05-10] (Windows (R) Win 7 DDK provider)
    1 cFosSpeed; C:\Windows\System32\DRIVERS\cfosspeed6.sys [1632128 2011-07-04] (cFos Software GmbH)
    3 DrvAgent64; C:\Windows\SysWow64\Drivers\DrvAgent64.sys [21712 2012-06-02] (Phoenix Technologies)
    1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-02-01] (DT Soft Ltd)
    3 FNETTBOH_305; C:\Windows\System32\Drivers\FNETTBOH_305.sys [32320 2012-06-22] (FNet Co., Ltd.)
    1 FNETURPX; C:\Windows\System32\Drivers\FNETURPX.sys [15936 2012-02-01] (FNet Co., Ltd.)
    3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
    3 MBfilt; C:\Windows\System32\drivers\MBfilt64.sys [32344 2009-11-17] (Creative Technology Ltd.)
    3 wacommousefilter; C:\Windows\System32\Drivers\wacommousefilter.sys [12848 2011-09-08] (Wacom Technology)
    3 wacomvhid; C:\Windows\System32\Drivers\wacomvhid.sys [16168 2011-09-08] (Wacom Technology)
    3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
    3 TBPanel; [x]
    3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============

    2012-06-22 19:55 - 2012-06-23 06:25 - 00000000 ____D C:\FRST
    2012-06-22 19:19 - 2012-06-22 19:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-22 19:19 - 2012-04-04 05:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-22 19:17 - 2012-06-22 19:17 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Wolf\Downloads\mbam-setup-1.61.0.1400.exe
    2012-06-22 19:15 - 2012-06-22 19:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BA2FCC45-41CF-4CE1-9A35-DF6C90610EC6}
    2012-06-22 19:15 - 2012-06-22 19:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A80C7E37-2C66-42EF-B700-CAD836E02A79}
    2012-06-22 18:46 - 2012-06-22 18:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CDDBEACB-4201-4A8D-AF2E-0DFB32D4E345}
    2012-06-22 18:46 - 2012-06-22 18:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C1819089-6D43-46EC-9F62-DF51C748EFE8}
    2012-06-22 18:37 - 2012-06-22 19:19 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-22 18:37 - 2012-06-22 18:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Malwarebytes
    2012-06-22 18:37 - 2012-06-22 18:37 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-06-22 06:43 - 2012-06-22 06:43 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77DABEC5-5C82-451E-9F08-AC88BC745E43}
    2012-06-22 06:42 - 2012-06-22 06:43 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3ED33445-25D4-4BB7-AA43-18DE6DA892B7}
    2012-06-22 04:38 - 2012-06-22 05:04 - 00003003 ____A C:\formatter.log
    2012-06-22 04:37 - 2012-06-22 04:37 - 00000000 ____D C:\Program Files (x86)\SDA
    2012-06-22 04:36 - 2012-06-22 05:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\Downloaded Installations
    2012-06-21 22:49 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-21 22:49 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-21 22:49 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-21 22:48 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-21 22:48 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-21 22:48 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-21 22:48 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-21 22:48 - 2012-06-02 05:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-21 22:48 - 2012-06-02 05:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-21 18:42 - 2012-06-21 18:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{904B9BEC-36D2-42B7-ABD5-6D0BD92B144E}
    2012-06-21 17:42 - 2012-06-21 17:48 - 56679244 ____A C:\Users\Wolf\Downloads\XXXX-PCPv2-U.rar
    2012-06-21 17:42 - 2012-06-21 17:42 - 00000617 ____A C:\Users\Public\Desktop\TERA-Launcher.lnk
    2012-06-21 17:42 - 2012-06-21 17:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\TERA
    2012-06-21 17:39 - 2012-06-21 17:41 - 90847904 ____A (En Masse Entertainment) C:\Users\Wolf\Downloads\TERA-Setup.exe
    2012-06-21 16:58 - 2012-06-21 19:58 - 00000000 ____D C:\Users\Wolf\Desktop\New folder (2)
    2012-06-21 16:57 - 2012-06-21 17:09 - 56701864 ____A C:\Users\Wolf\Downloads\6039 - Pokemon Conquest (U).rar
    2012-06-21 16:57 - 2012-06-21 16:57 - 00060136 ____A C:\Users\Wolf\Downloads\PMQ_USA_AP-Patch2.rar
    2012-06-21 16:46 - 2012-06-21 16:46 - 03095908 ____A C:\Users\Wolf\Downloads\AKAIO 1.8.9z.rar
    2012-06-21 16:46 - 2012-06-21 16:46 - 00984640 ____A C:\Users\Wolf\Downloads\USRCheat_4-11-12.7z
    2012-06-21 16:32 - 2012-06-21 16:34 - 57350521 ____A C:\Users\Wolf\Downloads\XXXX - Pok駑on Conquest (USA) (PATCHEDv2).rar
    2012-06-21 06:42 - 2012-06-21 06:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{8C33D810-B9B6-483E-B34E-118A76D469D3}
    2012-06-21 06:41 - 2012-06-21 18:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{18F95A37-F8CE-4FEE-A2FC-B0335E1C4D06}
    2012-06-21 05:44 - 2012-06-21 09:23 - 00000000 ____D C:\Users\Wolf\Downloads\The.Last.Remnant-RELOADED
    2012-06-21 05:42 - 2012-06-21 05:44 - 73520661 ____A C:\Users\Wolf\Downloads\minecraft.rar
    2012-06-21 05:20 - 2012-06-21 05:20 - 00955840 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-06-21 05:20 - 2012-06-21 05:20 - 00839096 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-06-21 05:20 - 2012-06-21 05:20 - 00268720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-06-21 05:20 - 2012-06-21 05:20 - 00189360 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-06-21 05:20 - 2012-06-21 05:20 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-06-21 05:20 - 2012-06-21 05:20 - 00000000 ____D C:\Program Files\Java
    2012-06-21 05:19 - 2012-06-21 05:19 - 21869488 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jre-7u5-windows-x64.exe
    2012-06-21 05:18 - 2012-06-21 07:02 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\.minecraft
    2012-06-21 05:17 - 2012-06-21 05:17 - 00278561 ____A C:\Users\Wolf\Downloads\Minecraft.exe
    2012-06-21 05:17 - 2012-06-21 05:17 - 00001063 ____A C:\Users\Wolf\Desktop\Minecraft - Shortcut.lnk
    2012-06-21 03:09 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-06-21 03:09 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-06-20 18:41 - 2012-06-20 18:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B258CAE5-67E1-4958-BE42-32FEE0B205DD}
    2012-06-20 17:56 - 2012-06-20 18:57 - 00004725 ____A C:\Users\Wolf\Desktop\New Text Document (3).txt
    2012-06-20 13:24 - 2012-06-20 13:24 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-06-20 06:41 - 2012-06-20 06:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9259AB6-1DC3-4E8B-8AC8-9ACCA67DB57F}
    2012-06-20 06:40 - 2012-06-20 18:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB8A37B4-6AE8-4614-9533-7AFD0F18838C}
    2012-06-19 16:12 - 2012-06-19 16:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{967CB5D5-3013-4872-9DFA-B2CBDE65073B}
    2012-06-19 07:16 - 2012-06-19 07:16 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Folding@home-x86
    2012-06-19 07:16 - 2012-06-19 07:16 - 00000000 ____D C:\Program Files (x86)\Folding@home
    2012-06-19 07:15 - 2012-06-19 07:15 - 02878976 ____A C:\Users\Wolf\Downloads\Folding@home-Win32-x86-systray-623.msi
    2012-06-19 06:55 - 2012-06-19 06:55 - 03793814 ____A C:\Users\Wolf\Downloads\KatawaShoujo_MomentOfDecision.mp3
    2012-06-19 04:11 - 2012-06-19 16:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E7495E72-311F-4F4E-9F23-312AE87026EA}
    2012-06-19 04:11 - 2012-06-19 04:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{34B56388-6578-42AB-9D56-59148B615D56}
    2012-06-18 06:54 - 2012-06-18 07:13 - 00006527 ____A C:\Users\Wolf\Desktop\New Text Document (2).txt
    2012-06-18 06:49 - 2012-06-18 06:49 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F7C8FF26-2A7C-44BA-A1BE-6E12077664B8}
    2012-06-17 13:33 - 2012-06-17 13:34 - 00000000 ____D C:\Users\Wolf\Desktop\New folder
    2012-06-17 06:09 - 2012-06-17 18:10 - 00000000 ____D C:\Users\Wolf\AppData\Local\{864C3DB0-747B-4FAB-9441-5A31AA087E0C}
    2012-06-16 07:18 - 2012-06-16 07:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{81C49DF4-92B8-4818-8C70-98075EAA9A99}
    2012-06-16 06:06 - 2012-06-16 06:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\Macromedia
    2012-06-15 18:42 - 2012-06-15 18:42 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
    2012-06-15 18:16 - 2012-06-15 18:16 - 00000000 ____D C:\Users\All Users\Rockstar Games
    2012-06-15 16:59 - 2012-06-15 17:04 - 161912074 ____A C:\Users\Wolf\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68].zip
    2012-06-15 15:07 - 2012-06-16 06:58 - 00000000 ____D C:\Users\Wolf\Documents\LOLReplay
    2012-06-15 15:07 - 2012-06-15 15:07 - 00001905 ____A C:\Users\Public\Desktop\LOL Recorder.lnk
    2012-06-15 15:07 - 2012-06-15 15:07 - 00000000 ____D C:\Program Files (x86)\LOLReplay
    2012-06-15 15:06 - 2012-06-15 15:06 - 01501409 ____A C:\Users\Wolf\Downloads\LOLReplay-0.7.9.1.exe
    2012-06-15 08:58 - 2012-06-15 08:58 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\RenPy
    2012-06-15 08:51 - 2012-06-15 08:51 - 00000797 ____A C:\Users\Wolf\Desktop\Katawa Shoujo.lnk
    2012-06-15 07:17 - 2012-06-15 19:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{56F6CB7D-2198-4E18-A4CB-DF4C266BC3FB}
    2012-06-14 17:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-14 17:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-14 17:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-14 17:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-14 17:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-14 17:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-14 17:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-14 17:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-14 17:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-14 17:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-14 17:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-14 17:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-14 17:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-14 17:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-14 17:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-14 17:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-14 17:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-14 17:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-14 17:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-14 17:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-14 17:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-14 17:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-14 17:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-14 17:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-14 17:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-14 17:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-14 17:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-14 17:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-14 14:28 - 2012-06-14 14:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{6221A1EF-FAC8-4A7D-AA70-6B5507BC541C}
    2012-06-14 13:43 - 2012-06-14 13:43 - 00000000 ____D C:\Users\Wolf\Documents\Hitman Blood Money
    2012-06-14 13:42 - 2012-06-14 13:42 - 00098304 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll
    2012-06-14 06:01 - 2012-06-14 10:23 - 00000000 ____D C:\Users\All Users\Firefly Studios
    2012-06-14 02:34 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-14 02:34 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-06-14 02:34 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-06-14 02:34 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-06-14 02:34 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-06-14 02:34 - 2012-04-27 21:32 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
    2012-06-14 02:34 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-06-14 02:34 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-06-14 02:34 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-06-14 02:34 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-06-14 02:34 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-06-14 02:34 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-06-14 02:33 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-06-14 02:33 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-06-14 02:33 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-06-14 02:33 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-06-14 02:33 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-06-14 02:33 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2012-06-14 02:28 - 2012-06-14 02:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E3238C17-E207-438F-82A3-EB89356E3DA8}
    2012-06-14 02:26 - 2012-06-14 14:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{31F9B074-5896-404F-9BF6-E4385BDDF5B3}
    2012-06-14 02:20 - 2012-06-14 02:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A6D7F2EE-D2D4-41F2-B3FC-8BD145B0A190}
    2012-06-14 02:19 - 2012-06-14 02:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BC331A7B-64D7-432F-82FD-9784E929841B}
    2012-06-13 19:13 - 2012-06-13 19:13 - 00001178 ____A C:\Users\Wolf\Desktop\Warriors Orochi (ToeD).lnk
    2012-06-13 19:13 - 2012-06-13 19:13 - 00000000 ____D C:\Users\Wolf\Documents\KOEI
    2012-06-13 18:55 - 2012-06-13 19:00 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold Crusader
    2012-06-13 14:19 - 2012-06-13 14:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{41DA6438-34AD-493B-B393-AAF7819B10BA}
    2012-06-13 14:18 - 2012-06-13 14:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5ED84925-45EB-494B-96A5-F5B3967C1BF8}
    2012-06-13 02:18 - 2012-06-13 02:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB1209B6-035D-4466-8757-B893040597D9}
    2012-06-13 02:18 - 2012-06-13 02:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69E680C4-A7DF-4C1A-9D8A-0BC66D71EB32}
    2012-06-12 18:11 - 2012-06-13 18:53 - 00005761 ____A C:\Users\Wolf\Desktop\New Text Document.txt
    2012-06-12 17:36 - 2012-06-12 17:36 - 00000019 ____A C:\Windows\D.ini
    2012-06-12 14:04 - 2012-06-12 14:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{78F62976-66E7-43ED-BB9F-D5DF3AC5F3AC}
    2012-06-12 14:04 - 2012-06-12 14:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1EBA75EF-77A7-44FE-8A9C-BB81E330A07D}
    2012-06-12 09:21 - 2012-06-12 09:21 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\ScummVM
    2012-06-12 09:12 - 2012-06-12 19:37 - 00000000 ____D C:\Sword
    2012-06-12 02:04 - 2012-06-12 02:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B33236EC-D70C-4821-8D05-10DB19CDFE07}
    2012-06-12 02:04 - 2012-06-12 02:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{29AB2770-F23A-4F39-B983-E42EF3988371}
    2012-06-11 18:17 - 2012-06-11 18:18 - 00000049 ____A C:\Users\Wolf\Desktop\Pinger.txt
    2012-06-11 10:27 - 2012-06-11 10:27 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold 3
    2012-06-11 07:08 - 2012-06-11 07:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A0EAE8F3-D293-482A-914A-4F450BE3CB89}
    2012-06-11 07:08 - 2012-06-11 07:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9C28CCC3-A5D0-480B-8B88-C5A40CA00C3B}
    2012-06-10 19:07 - 2012-06-10 19:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E3AD0B0-35C8-4E43-8572-BD0F9840F37A}
    2012-06-10 12:19 - 2012-06-10 12:19 - 01735565 ____A (Alexander Vigovsky ) C:\Users\Wolf\Downloads\ac3filter_2_4a_lite.exe
    2012-06-10 12:19 - 2012-06-10 12:19 - 00000000 ____D C:\Program Files (x86)\AC3Filter
    2012-06-10 11:27 - 2012-06-10 11:27 - 00000000 ____D C:\Users\Wolf\AppData\Local\DDMSettings
    2012-06-10 11:26 - 2012-06-10 12:18 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DivX
    2012-06-10 11:26 - 2012-06-10 11:26 - 00000000 ____D C:\Program Files\DivX
    2012-06-10 11:25 - 2012-06-10 11:26 - 00000000 ____D C:\Program Files (x86)\DivX
    2012-06-10 11:20 - 2012-06-10 11:26 - 00000000 ____D C:\Users\All Users\DivX
    2012-06-10 11:20 - 2012-06-10 11:20 - 00933256 ____A (DivX, LLC) C:\Users\Wolf\Downloads\DivXInstaller.exe
    2012-06-10 07:27 - 2012-06-10 07:49 - 00000000 ____D C:\Users\Wolf\Desktop\Snes
    2012-06-10 07:07 - 2012-06-10 07:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7958BFCE-14B8-4F0B-95C9-96460C9F6439}
    2012-06-10 07:06 - 2012-06-10 19:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B7E5E7DB-1CB1-4FDB-B085-C2C0D59F575D}
    2012-06-09 19:05 - 2012-06-09 19:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E7DF313-0B3B-4FD1-9C44-C7DF656F2830}
    2012-06-09 07:05 - 2012-06-09 07:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DA3EFC53-A72C-4455-BCD6-719EEBAC89AD}
    2012-06-09 07:04 - 2012-06-09 19:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5EF250FE-5D75-4BB1-AB3C-B195035F51DF}
    2012-06-08 18:00 - 2012-06-08 18:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\{74197D9F-12B8-4F93-A066-2A5D76826950}
    2012-06-08 15:46 - 2012-06-08 15:48 - 00000000 ____D C:\Users\Wolf\Documents\ArmA 2
    2012-06-08 15:46 - 2012-06-08 15:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\ArmA 2 Free
    2012-06-08 06:23 - 2012-06-08 06:23 - 00000885 ____A C:\Users\UpdatusUser\Desktop\Play Star Wars Republic Commando.lnk
    2012-06-08 05:59 - 2012-06-08 18:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEA05E89-8748-47D1-B07B-E8D794B8F9B1}
    2012-06-08 05:59 - 2012-06-08 05:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9D3BF70-4F64-48BB-A8F4-E611A769B662}
    2012-06-07 17:59 - 2012-06-07 17:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEFB5670-0786-498C-A1E1-F7243588A15A}
    2012-06-07 08:26 - 2012-06-07 08:26 - 00000000 ____D C:\Users\Wolf\Desktop\dolphin
    2012-06-07 05:58 - 2012-06-07 17:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AA46DBB4-DB4A-472F-82EB-FBDFC6556532}
    2012-06-07 05:58 - 2012-06-07 05:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FC53B60C-6F6E-4ED4-B40C-009BD43E92B4}
    2012-06-06 17:20 - 2012-06-06 17:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AC65E5A8-92D1-4634-946A-2E9F7E9A46FB}
    2012-06-06 16:06 - 2012-06-06 16:06 - 00000000 ____D C:\Nocturnal
    2012-06-06 16:05 - 2012-06-06 16:05 - 00000223 ____A C:\Windows\MugE.ini
    2012-06-06 15:07 - 2012-06-06 15:07 - 00188960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingde.dll
    2012-06-06 15:02 - 2012-06-06 15:02 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing32.dll
    2012-06-06 15:02 - 2012-06-06 15:02 - 00006736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingdib.drv
    2012-06-06 15:02 - 2012-06-06 15:02 - 00005024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingpal.wnd
    2012-06-06 15:01 - 2012-06-06 15:01 - 00092208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing.dll
    2012-06-06 05:19 - 2012-06-06 17:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{018EFAE0-DA5F-42D6-9FB4-F021E1130510}
    2012-06-06 05:19 - 2012-06-06 05:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7223F4E9-A6ED-4984-9F12-0553BE51A9FA}
    2012-06-05 17:19 - 2012-06-05 17:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AEBC6B16-FA61-472F-B178-7947B70D4644}
    2012-06-05 17:19 - 2012-06-05 17:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77EDE412-92A0-4FE2-B150-A38B2E91C713}
    2012-06-05 12:08 - 2012-06-05 12:08 - 00000000 ____D C:\Program Files (x86)\SplitMediaLabs
    2012-06-05 05:18 - 2012-06-05 05:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{396C4775-9424-4BB2-A423-6B2436410DE2}
    2012-06-05 05:18 - 2012-06-05 05:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2EE4F770-25FF-4D67-AE38-FF1ECCA34319}
    2012-06-04 17:18 - 2012-06-04 17:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{669C431C-59C4-4CFA-9965-6CCB0F8DD7E6}
    2012-06-04 05:17 - 2012-06-04 17:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9E2CB37D-DD5F-4DEC-9A37-4E8E73599B3F}
    2012-06-04 05:17 - 2012-06-04 05:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{4A04846C-C294-40F1-B047-C441C907CCF9}
    2012-06-03 16:34 - 2012-06-03 16:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D94B41B9-EF3A-4674-AE3A-1DADE4352553}
    2012-06-03 04:34 - 2012-06-03 16:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C91224FA-142A-404C-9C41-94A14AAB6355}
    2012-06-03 04:34 - 2012-06-03 04:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E64A22F0-D582-4DBC-BE24-0B861F843E90}
    2012-06-02 16:30 - 2012-06-02 16:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E9B1A525-2BB8-4999-A4FA-B4C972C0A7CF}
    2012-06-02 15:11 - 2012-06-02 15:11 - 00001234 ____A C:\Users\Wolf\Desktop\Vindictus - Shortcut.lnk
    2012-06-02 15:10 - 2012-06-06 12:35 - 00000000 ____D C:\Users\Wolf\Documents\Vindictus EU
    2012-06-02 15:08 - 2012-06-02 15:08 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
    2012-06-02 14:49 - 2012-06-02 14:52 - 130416408 ____A C:\Users\Wolf\Downloads\bmw_perfect_v97.rar
    2012-06-02 14:48 - 2012-06-02 14:48 - 00000000 ____D C:\Users\Wolf\Documents\bmw_english4V_95
    2012-06-02 14:41 - 2008-03-31 11:04 - 00249856 ____N (nobukichi) C:\Windows\eiunin21.exe
    2012-06-02 13:46 - 2012-06-02 15:08 - 00000000 ____D C:\Download
    2012-06-02 13:46 - 2012-06-02 13:46 - 00536576 ____A (Nexon) C:\Users\Wolf\Downloads\Vindictus_Downloader.exe
    2012-06-02 13:46 - 2012-06-02 13:46 - 00446464 ____A (NEXON Inc.) C:\Windows\NEXON_EU_DownloaderUpdater.exe
    2012-06-02 13:46 - 2012-06-02 13:46 - 00000235 ____A C:\Windows\SysWOW64\nxEuUninstall.bat
    2012-06-02 13:36 - 2012-06-02 15:11 - 00000000 ____D C:\Users\All Users\NexonEU
    2012-06-02 13:35 - 2012-06-02 13:35 - 03655576 ____A (Nexon) C:\Users\Wolf\Downloads\Setup.exe
    2012-06-02 11:06 - 2012-06-13 09:23 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\TeamViewer
    2012-06-02 08:21 - 2012-06-02 08:21 - 00621160 ____A (Copyright ゥ 2010 eSupport.com. All Rights Reserved.) C:\Users\Wolf\Downloads\driveragent_987.exe
    2012-06-02 08:21 - 2012-06-02 08:21 - 00021712 ____A (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
    2012-06-02 08:21 - 2012-06-02 08:21 - 00000000 ____D C:\Users\Wolf\AppData\Local\eSupport.com
    2012-06-02 08:20 - 2012-06-02 08:20 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SystemRequirementsLab
    2012-06-02 08:03 - 2012-06-02 15:07 - 00000000 ____D C:\Nexon
    2012-06-02 08:03 - 2012-06-02 08:03 - 00000000 ____D C:\Users\All Users\NexonUS
    2012-06-02 07:13 - 2012-06-02 07:13 - 00000000 ____D C:\Users\All Users\Nexon
    2012-06-02 07:08 - 2012-06-02 07:08 - 02013336 ____A C:\Users\Wolf\Downloads\MapleStoryDownloader.exe
    2012-06-02 06:11 - 2012-06-02 06:11 - 00000000 ____D C:\Users\Wolf\Documents\DragonSaga
    2012-06-02 06:10 - 2012-06-02 06:10 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DragonSaga
    2012-06-02 06:08 - 2012-06-02 06:27 - 113899850 ____A C:\Users\Wolf\Downloads\Bf3-mpcr.rar
    2012-06-02 04:29 - 2012-06-02 16:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2A798180-069D-448F-9C03-618665668D41}
    2012-06-02 04:29 - 2012-06-02 04:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F03D9EB4-CF0B-4A74-A47B-E056FEB39EDD}
    2012-06-01 16:29 - 2012-06-01 16:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{72BAC764-B627-4F15-A603-D553B12B02B6}
    2012-06-01 08:24 - 2012-06-01 08:24 - 04171406 ____A C:\Users\Wolf\Downloads\XMouseButtonControlSetup.2.4.exe
    2012-06-01 08:24 - 2012-06-01 08:24 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Highresolution Enterprises
    2012-06-01 08:24 - 2012-06-01 08:24 - 00000000 ____D C:\Program Files\Highresolution Enterprises
    2012-06-01 08:03 - 2012-06-01 08:03 - 00000000 ____D C:\Users\All Users\BioWare
    2012-06-01 08:01 - 2012-06-01 08:01 - 00000000 ____D C:\Users\Wolf\Documents\BioWare
    2012-06-01 07:49 - 2012-06-06 18:23 - 00000000 ____D C:\Users\Wolf\Documents\DepthHunter
    2012-06-01 04:28 - 2012-06-01 16:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{45C6FCE0-68C7-48EE-9121-BAEDFCA89588}
    2012-06-01 04:28 - 2012-06-01 04:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BDF956F0-D59B-4350-AFFF-357CAE62018C}
    2012-05-31 15:31 - 2012-05-31 15:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69CA7DA5-AAE2-4F3D-B062-F5ADF10EB800}
    2012-05-31 15:31 - 2012-05-31 15:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{30921632-D6C6-470F-8A0C-F20D93AE4ED0}
    2012-05-31 15:24 - 2012-05-31 15:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DFCEAD23-D76A-4193-B976-F76F825D9117}
    2012-05-31 15:24 - 2012-05-31 15:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{24380E14-2AF3-4C52-A2FC-7DAD465977B8}
    2012-05-31 15:20 - 2012-05-31 15:20 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{d49c2933-ab76-11e1-bc6a-bc5ff438e47c}.TxR.blf
    2012-05-31 15:14 - 2012-05-31 15:14 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{1aa4bd2d-ab76-11e1-8460-bc5ff438e47c}.TxR.blf
    2012-05-31 15:14 - 2012-05-31 15:14 - 00000092 ____A C:\Users\Wolf\AppData\Local\fusioncache.dat
    2012-05-31 15:14 - 2012-05-31 15:14 - 00000000 ____D C:\Users\Wolf\AppData\Local\GameSpy
    2012-05-31 14:40 - 2010-08-02 22:41 - 00819200 ____A C:\Windows\SysWOW64\xvidcore.dll
    2012-05-31 14:40 - 2010-08-02 22:41 - 00180224 ____A C:\Windows\SysWOW64\xvidvfw.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-05-31 14:23 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-05-31 14:23 - 2012-05-15 02:48 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-05-31 14:23 - 2012-04-18 09:08 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
    2012-05-31 14:23 - 2012-04-18 09:08 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-05-31 14:23 - 2012-04-18 09:08 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-05-31 14:19 - 2012-05-31 14:22 - 168454136 ____A (NVIDIA Corporation) C:\Users\Wolf\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
    2012-05-31 14:19 - 2012-05-31 14:19 - 00000000 ____D C:\Users\All Users\Sun
    2012-05-31 14:18 - 2012-05-31 14:18 - 00772552 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-05-31 14:18 - 2012-05-31 14:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-05-31 14:18 - 2012-05-31 14:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-05-31 14:18 - 2012-05-31 14:18 - 00000000 ____D C:\Program Files (x86)\Oracle
    2012-05-31 14:18 - 2012-05-31 14:18 - 00000000 ____D C:\Program Files (x86)\Java
    2012-05-31 14:18 - 2012-04-04 08:47 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-05-31 14:18 - 2012-04-04 08:47 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-05-31 14:17 - 2012-05-31 14:17 - 00892360 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jxpiinstall.exe
    2012-05-31 09:22 - 2012-05-31 09:22 - 00000000 ____D C:\Program Files (x86)\GameSpy
    2012-05-31 09:18 - 2012-05-31 09:18 - 00001298 ____A C:\Users\Public\Desktop\Crysis.lnk
    2012-05-31 05:37 - 2012-05-31 05:37 - 21503784 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HWSE_SE_v3.2.2.1.exe
    2012-05-31 05:37 - 2012-05-31 05:37 - 00000000 ____D C:\Program Files (x86)\Hercules
    2012-05-31 05:37 - 2006-08-01 02:31 - 03600384 ____A C:\Windows\ffmpeg.exe
    2012-05-31 05:36 - 2012-05-31 05:36 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(2).exe
    2012-05-31 05:29 - 2012-05-31 05:29 - 62444312 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v2.9.0.0.exe
    2012-05-31 05:28 - 2012-05-31 05:28 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(1).exe
    2012-05-31 05:06 - 2012-05-31 05:06 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\InstallShield
    2012-05-31 05:06 - 2009-10-19 07:39 - 00718632 ____A (Guillemot) C:\Windows\SysWOW64\WebCamPropertyWindow.dll
    2012-05-31 05:06 - 2009-10-19 07:39 - 00037672 ____A C:\Windows\SysWOW64\WebCamKSProxyPlugin.ax
    2012-05-31 05:06 - 2009-10-19 07:39 - 00029480 ____A (Guillemot Corporation S.A.) C:\Windows\SysWOW64\libcmmn.dll
    2012-05-31 05:05 - 2012-05-31 05:06 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1.exe
    2012-05-31 03:23 - 2012-05-31 03:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C33CF4EE-A3BE-4355-A681-463A8BE50A8B}
    2012-05-31 03:23 - 2012-05-31 03:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{47DD7949-55AC-4910-B63E-0625A8C88C07}
    2012-05-30 11:34 - 2012-05-30 11:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{308AC941-8DFC-4CE8-94F0-EB570AE23E93}
    2012-05-30 06:02 - 2012-05-30 06:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Chart Controls
    2012-05-30 04:28 - 2012-05-30 04:28 - 00001802 ____A C:\Users\Public\Desktop\Dragon Saga.lnk
    2012-05-30 03:48 - 2012-05-30 03:48 - 00330120 ____A (Gravity Interactive, Inc.) C:\Users\Wolf\Downloads\DragonSaga-Installer-0.2.5-20120330.exe
    2012-05-29 23:34 - 2012-05-29 23:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D9ED8115-E416-4B42-93EA-D62BFF6A48D3}
    2012-05-29 23:33 - 2012-05-30 11:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3BCE797B-4A95-4C3C-841B-891768931583}
    2012-05-29 06:49 - 2012-05-29 06:49 - 00001989 ____A C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
    2012-05-29 06:49 - 2012-05-29 06:49 - 00000000 ____D C:\Program Files (x86)\PCSX2 0.9.8
    2012-05-29 06:48 - 2012-05-29 06:48 - 12780479 ____A C:\Users\Wolf\Downloads\pcsx2-0.9.8-r4600-setup.exe
    2012-05-29 06:48 - 2012-05-29 06:48 - 04353259 ____A (Igor Pavlov) C:\Users\Wolf\Downloads\dolphin-3.0-win64.exe
    2012-05-29 05:41 - 2012-05-29 05:41 - 00002105 ____A C:\Users\Public\Desktop\A.V.A.lnk
    2012-05-29 05:41 - 2012-05-29 05:41 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
    2012-05-29 05:41 - 2012-03-06 07:19 - 03953632 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
    2012-05-29 05:41 - 2012-02-02 14:50 - 00005265 ____A C:\Windows\SysWOW64\nppt9x.vxd
    2012-05-29 05:41 - 2012-02-02 14:50 - 00004774 ____A (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
    2012-05-29 02:32 - 2012-05-29 02:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{65655CD4-236C-47ED-BF7C-D5B292418970}
    2012-05-29 02:32 - 2012-05-29 02:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1DA6169D-DEBF-47A1-B3DF-FC4F0D7EA61D}
    2012-05-28 14:48 - 2012-05-28 14:48 - 00002560 ____A C:\Users\Wolf\Documents\Register Vegas Pro.htm
    2012-05-28 14:48 - 2012-05-28 14:48 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Publish Providers
    2012-05-28 14:46 - 2012-05-28 14:48 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Sony
  9. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    2012-05-28 14:46 - 2012-05-28 14:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\Sony
    2012-05-28 14:44 - 2012-05-28 14:44 - 00001908 ____A C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
    2012-05-28 14:44 - 2012-05-28 14:44 - 00000000 ____D C:\Users\All Users\Sony
    2012-05-28 14:43 - 2012-05-28 14:43 - 00000000 ____D C:\Program Files (x86)\Sony
    2012-05-28 14:38 - 2012-05-30 17:50 - 00000000 ____D C:\Fraps
    2012-05-28 14:38 - 2012-05-28 14:38 - 00000562 ____A C:\Users\Wolf\Desktop\Fraps.lnk
    2012-05-28 14:31 - 2012-05-28 14:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FB225DD7-B02B-4BE6-8F32-D5F446DE2EAB}
    2012-05-28 14:31 - 2012-05-28 14:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{160F752A-7CFD-4058-914C-AEA7BDA6BF80}
    2012-05-28 12:56 - 2012-05-28 12:56 - 00298016 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
    2012-05-28 12:55 - 2012-05-28 12:55 - 00000000 ____D C:\Users\Wolf\AppData\Local\PunkBuster
    2012-05-28 12:53 - 2012-05-28 12:53 - 00001907 ____A C:\Users\Public\Desktop\ijji REACTOR.lnk
    2012-05-28 12:53 - 2010-03-24 06:57 - 00713312 ____A (NHN USA) C:\Windows\SysWOW64\ijjiSetup.exe
    2012-05-28 12:53 - 2010-03-24 06:56 - 00062048 ____A (NHN USA Inc.) C:\Windows\SysWOW64\ijjiProcessRestarter.exe
    2012-05-28 12:52 - 2012-05-29 05:41 - 00000000 ____D C:\Program Files (x86)\REACTOR
    2012-05-28 12:52 - 2012-05-28 12:52 - 07822632 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\IJJI_REACTOR_INST_EN.exe
    2012-05-28 12:44 - 2012-01-08 22:45 - 207767247 ____A C:\Users\Wolf\Downloads\data4.cab
    2012-05-28 12:44 - 2012-01-08 22:45 - 00239126 ____A C:\Users\Wolf\Downloads\setup.inx
    2012-05-28 12:44 - 2012-01-08 22:45 - 00002380 ____A C:\Users\Wolf\Downloads\setup.ini
    2012-05-28 12:44 - 2012-01-08 22:45 - 00000658 ____A C:\Users\Wolf\Downloads\layout.bin
    2012-05-28 12:43 - 2012-01-08 22:44 - 2147483648 ____A C:\Users\Wolf\Downloads\data3.cab
    2012-05-28 12:42 - 2012-01-09 04:01 - 00811520 ____A (ijji.com) C:\Users\Wolf\Downloads\U_AVA_SETUP.exe
    2012-05-28 12:42 - 2012-01-08 22:45 - 00579584 ____A (Flexera Software, Inc.) C:\Users\Wolf\Downloads\ISSetup.dll
    2012-05-28 12:42 - 2012-01-08 22:29 - 2145083392 ____A C:\Users\Wolf\Downloads\data2.cab
    2012-05-28 12:42 - 2012-01-08 22:14 - 00624307 ____A C:\Users\Wolf\Downloads\data1.cab
    2012-05-28 12:42 - 2012-01-08 22:14 - 00108193 ____A C:\Users\Wolf\Downloads\data1.hdr
    2012-05-28 12:42 - 2012-01-08 22:14 - 00022492 ____A C:\Users\Wolf\Downloads\0x0409.ini
    2012-05-28 10:12 - 2012-05-28 10:12 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
    2012-05-28 10:11 - 2012-05-28 09:58 - 03130440 ____A C:\Windows\SysWOW64\pbsvc_blr.exe
    2012-05-28 09:43 - 2012-05-28 17:52 - 00000000 ____D C:\Users\Wolf\Documents\DragonNest
    2012-05-28 09:12 - 2012-05-28 09:12 - 00000796 ____A C:\Users\Public\Desktop\Dragon Nest.lnk
    2012-05-28 08:05 - 2012-05-28 08:08 - 00000000 ____D C:\Users\Wolf\Documents\Battlefield 3
    2012-05-28 08:03 - 2012-06-08 18:02 - 00107832 ____A C:\Windows\SysWOW64\PnkBstrB.exe
    2012-05-28 08:03 - 2012-06-08 18:02 - 00066872 ____A C:\Windows\SysWOW64\PnkBstrA.exe
    2012-05-28 08:03 - 2012-05-28 10:11 - 00189248 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
    2012-05-28 07:34 - 2012-05-28 11:12 - 198654664 ____A C:\Users\Wolf\Downloads\U_AVA_SETUP_Jan2012.zip
    2012-05-28 07:34 - 2012-05-28 08:05 - 00000000 ____D C:\Games
    2012-05-28 07:34 - 2011-10-10 06:42 - 02580552 ___RA C:\Windows\SysWOW64\pbsvc.exe
    2012-05-28 07:28 - 2012-05-28 08:40 - 2536606647 ____A (Shanda Games International) C:\Users\Wolf\Downloads\DNClientVer60_20120423.exe
    2012-05-28 07:18 - 2012-05-28 07:19 - 02072456 ____A C:\Users\Wolf\Downloads\BlacklightRetribution_Downloader_EN.exe
    2012-05-28 03:14 - 2012-05-28 03:14 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00000725 ____A C:\Users\Wolf\Desktop\Dustforce.lnk
    2012-05-28 03:14 - 2012-05-28 03:14 - 00000000 ____D C:\Program Files (x86)\OpenAL
    2012-05-28 02:31 - 2012-05-28 02:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CD0B5883-D705-4B3F-878D-1CEB81D6E307}
    2012-05-28 02:31 - 2012-05-28 02:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{466B1E6A-4A0C-4E36-8C2B-545561C19512}
    2012-05-27 17:12 - 2012-05-28 03:14 - 00000000 ____D C:\Users\Wolf\Downloads\Crysis_2-FLT
    2012-05-27 14:30 - 2012-05-27 14:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3B0B234A-AD01-4412-A755-6F9EC247B549}
    2012-05-27 14:30 - 2012-05-27 14:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{38946F5D-E76A-4FAC-9F90-365593EAA120}
    2012-05-27 13:05 - 2012-05-27 13:05 - 00000754 ____A C:\Users\Public\Desktop\Dragon Age Origins.lnk
    2012-05-27 13:05 - 2012-05-27 13:05 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP
    2012-05-27 12:51 - 2012-05-27 13:17 - 00021225 ____A C:\Users\Wolf\Documents\Install Dragon Age Origins.log
    2012-05-27 09:36 - 2012-05-27 09:36 - 00001147 ____A C:\Users\Public\Desktop\Bamboo Dock.lnk
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Wacom
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Users\All Users\Wacom
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Program Files (x86)\Bamboo Dock
    2012-05-27 09:34 - 2012-05-27 09:34 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WTablet
    2012-05-27 09:34 - 2012-05-27 09:34 - 00000000 ____D C:\Program Files\Tablet
    2012-05-27 09:34 - 2012-05-27 09:34 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
    2012-05-27 09:34 - 2011-09-08 07:49 - 00016168 ____A (Wacom Technology) C:\Windows\System32\Drivers\wacomvhid.sys
    2012-05-27 09:34 - 2011-09-08 07:49 - 00012848 ____A (Wacom Technology) C:\Windows\System32\Drivers\wacommousefilter.sys
    2012-05-27 09:34 - 2011-09-08 07:48 - 01665400 ____A (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.dll
    2012-05-27 09:34 - 2011-09-08 07:48 - 01401208 ____A (Wacom Technology, Corp.) C:\Windows\System32\Wintab32.dll
    2012-05-27 09:34 - 2011-09-08 07:48 - 01392504 ____A (Wacom Technology, Corp.) C:\Windows\System32\WacomMT.dll
    2012-05-27 09:34 - 2011-09-08 07:48 - 01326456 ____A (Wacom Technology, Corp.) C:\Windows\System32\Pen_Touch_Tablet.dll
    2012-05-27 09:34 - 2011-09-08 07:48 - 01156472 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
    2012-05-27 09:34 - 2011-09-08 07:48 - 01152888 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
    2012-05-27 09:34 - 2011-09-08 07:48 - 01107832 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Touch_Tablet.dll
    2012-05-27 09:34 - 2011-06-15 14:00 - 00000488 ____A C:\Windows\System32\PenTabletUserDefaults.xml
    2012-05-27 09:33 - 2012-05-27 09:33 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(2).exe
    2012-05-27 09:17 - 2011-09-08 07:48 - 01369464 ____A (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Tablet.dll
    2012-05-27 09:15 - 2012-05-27 09:15 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(1).exe
    2012-05-27 09:05 - 2012-05-27 09:05 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
    2012-05-27 03:22 - 2012-05-27 03:22 - 00001003 ____A C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
    2012-05-27 03:21 - 2012-05-27 03:21 - 00000000 ____D C:\Windows\SysWOW64\xlive
    2012-05-27 03:21 - 2012-05-27 03:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
    2012-05-27 02:59 - 2012-05-27 03:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\SniperV2
    2012-05-27 02:57 - 2012-05-27 02:57 - 00001095 ____A C:\Users\Public\Desktop\Sniper Elite V2.lnk
    2012-05-27 02:44 - 2012-05-27 02:49 - 00000000 ____D C:\Users\Wolf\AppData\Local\XBlades
    2012-05-27 02:44 - 2012-05-27 02:48 - 00000000 ____D C:\Users\All Users\XBlades
    2012-05-27 02:44 - 2012-05-27 02:46 - 00000422 ____A C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
    2012-05-27 02:33 - 2012-05-28 13:25 - 00000000 ____D C:\Users\Wolf\AppData\Local\BladesOfTime
    2012-05-27 02:32 - 2012-05-27 02:32 - 00000984 ____A C:\Users\Public\Desktop\Blades of Time.lnk
    2012-05-27 02:29 - 2012-05-27 02:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{452C3747-247D-49E6-92F9-FF22C9404000}
    2012-05-27 02:29 - 2012-05-27 02:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B2C1155D-6711-4A9A-BE54-8C430A6B998F}
    2012-05-26 18:22 - 2012-05-26 18:22 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
    2012-05-26 18:17 - 2012-05-26 18:17 - 00000999 ____A C:\Users\Public\Desktop\Magicka.lnk
    2012-05-26 13:40 - 2012-05-26 13:40 - 00000000 ____D C:\Windows\System32\Macromed
    2012-05-26 13:40 - 2012-05-26 13:40 - 00000000 ____D C:\Users\Wolf\AppData\Local\SplitMediaLabs
    2012-05-26 13:38 - 2012-05-26 13:38 - 00000000 ____D C:\Users\All Users\SplitMediaLabs
    2012-05-26 13:37 - 2012-05-26 13:37 - 24220864 ____A (SplitMediaLabs) C:\Users\Wolf\Downloads\xsplit_installer_v1.0.1204.1301.exe
    2012-05-26 13:37 - 2012-05-26 13:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SplitMediaLabs
    2012-05-26 13:07 - 2012-05-26 13:07 - 00000857 ____A C:\Users\Wolf\Desktop\League of Legends.lnk
    2012-05-26 11:46 - 2012-05-26 11:47 - 00000000 ____D C:\Users\Wolf\AppData\Local\{525FBECE-BEC1-4B0B-BCDD-A5CB91553E59}
    2012-05-26 11:46 - 2012-05-26 11:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CB91DDC8-FE7D-4956-A352-3D8415C5CF6F}
    2012-05-26 11:20 - 2012-05-26 11:20 - 00001727 ____A C:\Users\Wolf\Desktop\Photoshop - Shortcut.lnk
    2012-05-26 11:18 - 2012-05-26 11:18 - 00000000 ____D C:\Users\Wolf\AdobeLicensingFilesBackup
    2012-05-26 11:11 - 2012-05-26 11:19 - 00000000 ____D C:\Users\All Users\FLEXnet
    2012-05-26 11:04 - 2012-05-26 11:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\Microsoft Games
    2012-05-26 11:02 - 2012-05-26 11:02 - 00000000 ____D C:\Windows\SysWOW64\spool
    2012-05-26 10:59 - 2012-05-26 10:59 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
    2012-05-26 10:34 - 2012-05-26 11:04 - 00000000 ____D C:\Program Files\Adobe
    2012-05-26 10:29 - 2012-05-26 11:05 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2012-05-26 10:20 - 2012-05-26 10:20 - 00000000 ____D C:\Windows\SysWOW64\syncdb
    2012-05-26 08:28 - 2012-05-26 10:45 - 00000000 ____D C:\Users\All Users\regid.1986-12.com.adobe
    2012-05-26 07:59 - 2012-05-26 07:59 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Ambient Design
    2012-05-26 07:47 - 2012-05-26 08:17 - 2119376047 ____A C:\Users\Wolf\Downloads\PSE9.zip
    2012-05-26 07:34 - 2012-05-26 07:43 - 544160151 ____A C:\Users\Wolf\Downloads\PSE9.zip.part
    2012-05-26 07:34 - 2012-05-26 07:36 - 72725528 ____A (Ambient Design) C:\Users\Wolf\Downloads\install_artrage_studiopro.exe
    2012-05-26 07:34 - 2012-05-26 07:35 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final.exe
    2012-05-26 07:17 - 2012-05-26 07:17 - 00001181 ____A C:\Users\Public\Desktop\openCanvas5e.lnk
    2012-05-26 07:17 - 2012-05-26 07:17 - 00000000 ____D C:\Program Files (x86)\portalgraphics
    2012-05-26 07:13 - 2012-05-26 07:13 - 02330770 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04e.exe
    2012-05-26 07:11 - 2012-05-26 07:11 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\portalgraphics
    2012-05-26 07:10 - 2012-05-26 07:10 - 02271209 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04.exe
    2012-05-26 06:25 - 2012-05-26 06:49 - 00000000 ____D C:\Users\All Users\Alias
    2012-05-26 06:25 - 2012-05-26 06:25 - 00002156 ____A C:\Users\Public\Desktop\Autodesk SketchBookPro 2011.lnk
    2012-05-26 06:25 - 2012-05-26 06:25 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Autodesk
    2012-05-26 06:24 - 2012-05-26 06:24 - 00001152 ____A C:\Users\Wolf\Desktop\Play IW4M (Modern Warfare 2).lnk
    2012-05-26 06:24 - 2012-05-26 06:24 - 00000000 ____D C:\Program Files (x86)\Autodesk
    2012-05-26 06:23 - 2012-05-26 06:23 - 00001013 ____A C:\Users\Public\Desktop\Worms Ultimate Mayhem.lnk
    2012-05-26 06:12 - 2012-05-27 09:36 - 00000002 ____A C:\Users\Wolf\.bdockinstall.log
    2012-05-26 06:12 - 2012-05-26 06:12 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2012-05-26 06:12 - 2012-05-26 06:12 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2012-05-26 06:10 - 2011-06-15 14:00 - 00000488 ____A C:\Windows\System32\PenTouchTabletUserDefaults.xml
    2012-05-26 05:47 - 2012-05-28 03:16 - 00000000 ____D C:\Users\Wolf\AppData\Local\Adobe
    2012-05-26 02:00 - 2012-06-14 15:02 - 00000000 ____D C:\Users\Wolf\AppData\Local\SKIDROW
    2012-05-26 02:00 - 2012-05-26 02:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\BigHugeEngine
    2012-05-26 01:58 - 2012-05-26 01:58 - 00001185 ____A C:\Users\Wolf\Desktop\Dead Island.lnk
    2012-05-26 00:15 - 2012-05-26 00:15 - 00001083 ____A C:\Users\Public\Desktop\Kingdoms of Amalur Reckoning.lnk
    2012-05-25 23:46 - 2012-05-25 23:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A5BF4313-036F-4A54-A8FA-9DA6C12A656C}
    2012-05-25 23:46 - 2012-05-25 23:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5634B62E-A929-4F3F-97F4-35CD08166140}
    2012-05-25 14:32 - 2012-05-25 14:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\.inapptracking
    2012-05-25 14:31 - 2012-05-25 14:31 - 00000786 ____A C:\Users\Public\Desktop\Sonic Generations.lnk
    2012-05-25 11:44 - 2012-05-25 12:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\IW4M
    2012-05-25 11:44 - 2012-05-25 11:44 - 00156672 ____A (Microsoft) C:\Users\Wolf\Downloads\InstallIW4M.exe
    2012-05-25 11:29 - 2012-05-25 11:29 - 15556319 ____A C:\Users\Wolf\Downloads\4D1 Patcher(r88).zip
    2012-05-25 11:26 - 2012-05-25 11:26 - 07731209 ____A C:\Users\Wolf\Downloads\alterRevolution Client.rar
    2012-05-25 11:26 - 2012-05-25 11:26 - 02246711 ____A C:\Users\Wolf\Downloads\alterRevolution Dedicated 0.3c.rar
    2012-05-25 10:12 - 2012-05-25 10:12 - 00001309 ____A C:\Users\Wolf\Desktop\Devil May Cry 4.lnk
    2012-05-25 07:57 - 2012-05-31 09:21 - 03475636 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-05-25 07:57 - 2012-05-25 07:57 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-05-25 07:56 - 2012-06-23 05:12 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-05-25 07:56 - 2012-06-23 05:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-05-25 07:48 - 2012-05-25 07:49 - 12621696 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe
    2012-05-25 07:48 - 2012-05-25 07:48 - 00523840 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe.part
    2012-05-25 07:03 - 2012-05-27 03:40 - 00000000 ____D C:\Users\Wolf\Documents\CAPCOM
    2012-05-25 07:03 - 2012-05-25 07:03 - 00000000 ____D C:\Users\Wolf\AppData\Local\CAPCOM
    2012-05-25 05:50 - 2012-05-25 05:53 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3157081A-C7D3-4452-9C7E-F0E660292DB2}
    2012-05-25 05:50 - 2012-05-25 05:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{93B44AF1-3B18-4C2A-B279-24923486D8F6}
    2012-05-25 03:59 - 2012-05-25 03:59 - 00002213 ____A C:\Users\Public\Desktop\AION Free-To-Play.lnk
    2012-05-25 03:59 - 2012-05-25 03:59 - 00000000 ____D C:\Program Files (x86)\Gameforge
    2012-05-25 03:39 - 2012-05-25 03:44 - 145138568 ____A (Gameforge) C:\Users\Wolf\Downloads\setup_20120224.exe
    2012-05-25 03:30 - 2012-05-25 03:30 - 01639789 ____A C:\Users\Wolf\Downloads\winrar-x64-411.exe
    2012-05-25 03:30 - 2012-05-25 03:30 - 00000000 ____D C:\Program Files\WinRAR
    2012-05-25 03:29 - 2012-05-25 03:31 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WinRAR
    2012-05-25 03:29 - 2012-05-25 03:29 - 01506653 ____A C:\Users\Wolf\Downloads\wrar411.exe
    2012-05-25 03:29 - 2012-05-25 03:29 - 00000000 ____D C:\Program Files (x86)\WinRAR
    2012-05-25 02:44 - 2012-05-25 02:44 - 00000000 ____D C:\Program Files\7-Zip
    2012-05-25 02:43 - 2012-05-25 02:43 - 01376768 ____A C:\Users\Wolf\Downloads\7z920-x64.msi

    ============ 3 Months Modified Files and Folders =============

    2012-06-23 06:25 - 2012-06-22 19:55 - 00000000 ____D C:\FRST
    2012-06-23 05:12 - 2012-05-25 07:56 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-06-23 05:12 - 2012-05-25 07:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-06-23 05:12 - 2012-02-01 06:11 - 00000000 ___RD C:\Program Files (x86)\Skype
    2012-06-23 05:12 - 2012-02-01 06:11 - 00000000 ____D C:\Users\All Users\Skype
    2012-06-23 05:12 - 2012-02-01 05:58 - 00000000 ____D C:\Users\All Users\PMB Files
    2012-06-23 05:12 - 2012-02-01 05:52 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\uTorrent
    2012-06-23 05:12 - 2012-02-01 05:20 - 00000000 ____D C:\Users\All Users\FNET
    2012-06-23 05:12 - 2011-04-12 00:28 - 00000000 ___RD C:\Users\Public\Recorded TV
    2012-06-23 05:12 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
    2012-06-22 20:13 - 2012-02-01 06:11 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Skype
    2012-06-22 20:02 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-06-22 20:02 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-06-22 19:59 - 2012-02-01 06:01 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-06-22 19:59 - 2012-02-01 06:01 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-06-22 19:59 - 2012-02-01 06:01 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-06-22 19:57 - 2012-02-01 05:40 - 00032320 ____A (FNet Co., Ltd.) C:\Windows\System32\Drivers\FNETTBOH_305.SYS
    2012-06-22 19:55 - 2012-02-01 06:07 - 00000000 ____D C:\Program Files (x86)\Steam
    2012-06-22 19:55 - 2012-02-01 05:33 - 00000000 ____D C:\Users\All Users\NVIDIA
    2012-06-22 19:55 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-06-22 19:55 - 2009-07-13 20:51 - 00030874 ____A C:\Windows\setupact.log
    2012-06-22 19:49 - 2012-02-01 14:03 - 01680065 ____A C:\Windows\WindowsUpdate.log
    2012-06-22 19:24 - 2010-11-20 19:47 - 00320732 ____A C:\Windows\PFRO.log
    2012-06-22 19:19 - 2012-06-22 19:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-22 19:19 - 2012-06-22 18:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-22 19:17 - 2012-06-22 19:17 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Wolf\Downloads\mbam-setup-1.61.0.1400.exe
    2012-06-22 19:15 - 2012-06-22 19:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BA2FCC45-41CF-4CE1-9A35-DF6C90610EC6}
    2012-06-22 19:15 - 2012-06-22 19:15 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A80C7E37-2C66-42EF-B700-CAD836E02A79}
    2012-06-22 19:15 - 2012-02-01 06:35 - 00000000 ____D C:\Users\Wolf\AppData\Local\Windows Live
    2012-06-22 19:13 - 2012-02-01 05:14 - 00000000 ____D C:\users\Wolf
    2012-06-22 18:46 - 2012-06-22 18:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CDDBEACB-4201-4A8D-AF2E-0DFB32D4E345}
    2012-06-22 18:46 - 2012-06-22 18:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C1819089-6D43-46EC-9F62-DF51C748EFE8}
    2012-06-22 18:41 - 2012-02-01 05:49 - 00000000 __SHD C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}
    2012-06-22 18:37 - 2012-06-22 18:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Malwarebytes
    2012-06-22 18:37 - 2012-06-22 18:37 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-06-22 14:47 - 2012-02-01 06:02 - 00000000 ____D C:\Users\Wolf\AppData\Local\PMB Files
    2012-06-22 13:29 - 2012-02-01 08:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\CrashDumps
    2012-06-22 06:43 - 2012-06-22 06:43 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77DABEC5-5C82-451E-9F08-AC88BC745E43}
    2012-06-22 06:43 - 2012-06-22 06:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3ED33445-25D4-4BB7-AA43-18DE6DA892B7}
    2012-06-22 05:06 - 2012-06-22 04:36 - 00000000 ____D C:\Users\Wolf\AppData\Local\Downloaded Installations
    2012-06-22 05:04 - 2012-06-22 04:38 - 00003003 ____A C:\formatter.log
    2012-06-22 04:37 - 2012-06-22 04:37 - 00000000 ____D C:\Program Files (x86)\SDA
    2012-06-21 22:50 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sk-SK
    2012-06-21 19:58 - 2012-06-21 16:58 - 00000000 ____D C:\Users\Wolf\Desktop\New folder (2)
    2012-06-21 18:42 - 2012-06-21 18:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{904B9BEC-36D2-42B7-ABD5-6D0BD92B144E}
    2012-06-21 18:42 - 2012-06-21 06:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{18F95A37-F8CE-4FEE-A2FC-B0335E1C4D06}
    2012-06-21 17:48 - 2012-06-21 17:42 - 56679244 ____A C:\Users\Wolf\Downloads\XXXX-PCPv2-U.rar
    2012-06-21 17:42 - 2012-06-21 17:42 - 00000617 ____A C:\Users\Public\Desktop\TERA-Launcher.lnk
    2012-06-21 17:42 - 2012-06-21 17:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\TERA
    2012-06-21 17:42 - 2012-02-01 05:30 - 00259771 ____A C:\Windows\DirectX.log
    2012-06-21 17:41 - 2012-06-21 17:39 - 90847904 ____A (En Masse Entertainment) C:\Users\Wolf\Downloads\TERA-Setup.exe
    2012-06-21 17:09 - 2012-06-21 16:57 - 56701864 ____A C:\Users\Wolf\Downloads\6039 - Pokemon Conquest (U).rar
    2012-06-21 16:57 - 2012-06-21 16:57 - 00060136 ____A C:\Users\Wolf\Downloads\PMQ_USA_AP-Patch2.rar
    2012-06-21 16:46 - 2012-06-21 16:46 - 03095908 ____A C:\Users\Wolf\Downloads\AKAIO 1.8.9z.rar
    2012-06-21 16:46 - 2012-06-21 16:46 - 00984640 ____A C:\Users\Wolf\Downloads\USRCheat_4-11-12.7z
    2012-06-21 16:37 - 2012-02-01 09:40 - 00403016 ____A C:\Windows\System32\perfh011.dat
    2012-06-21 16:37 - 2012-02-01 09:40 - 00111342 ____A C:\Windows\System32\perfc011.dat
    2012-06-21 16:37 - 2012-02-01 09:19 - 00414324 ____A C:\Windows\System32\perfh012.dat
    2012-06-21 16:37 - 2012-02-01 09:19 - 00109630 ____A C:\Windows\System32\perfc012.dat
    2012-06-21 16:37 - 2012-02-01 09:12 - 00711326 ____A C:\Windows\System32\perfh013.dat
    2012-06-21 16:37 - 2012-02-01 09:12 - 00138788 ____A C:\Windows\System32\perfc013.dat
    2012-06-21 16:37 - 2012-02-01 08:44 - 00664336 ____A C:\Windows\System32\perfh007.dat
    2012-06-21 16:37 - 2012-02-01 08:44 - 00135232 ____A C:\Windows\System32\perfc007.dat
    2012-06-21 16:37 - 2009-07-13 21:13 - 03396364 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-06-21 16:34 - 2012-06-21 16:32 - 57350521 ____A C:\Users\Wolf\Downloads\XXXX - Pok駑on Conquest (USA) (PATCHEDv2).rar
    2012-06-21 09:23 - 2012-06-21 05:44 - 00000000 ____D C:\Users\Wolf\Downloads\The.Last.Remnant-RELOADED
    2012-06-21 07:02 - 2012-06-21 05:18 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\.minecraft
    2012-06-21 06:42 - 2012-06-21 06:42 - 00000000 ____D C:\Users\Wolf\AppData\Local\{8C33D810-B9B6-483E-B34E-118A76D469D3}
    2012-06-21 05:44 - 2012-06-21 05:42 - 73520661 ____A C:\Users\Wolf\Downloads\minecraft.rar
    2012-06-21 05:20 - 2012-06-21 05:20 - 00955840 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-06-21 05:20 - 2012-06-21 05:20 - 00839096 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-06-21 05:20 - 2012-06-21 05:20 - 00268720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-06-21 05:20 - 2012-06-21 05:20 - 00189360 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-06-21 05:20 - 2012-06-21 05:20 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-06-21 05:20 - 2012-06-21 05:20 - 00000000 ____D C:\Program Files\Java
    2012-06-21 05:19 - 2012-06-21 05:19 - 21869488 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jre-7u5-windows-x64.exe
    2012-06-21 05:17 - 2012-06-21 05:17 - 00278561 ____A C:\Users\Wolf\Downloads\Minecraft.exe
    2012-06-21 05:17 - 2012-06-21 05:17 - 00001063 ____A C:\Users\Wolf\Desktop\Minecraft - Shortcut.lnk
    2012-06-20 18:57 - 2012-06-20 17:56 - 00004725 ____A C:\Users\Wolf\Desktop\New Text Document (3).txt
    2012-06-20 18:41 - 2012-06-20 18:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B258CAE5-67E1-4958-BE42-32FEE0B205DD}
    2012-06-20 18:41 - 2012-06-20 06:40 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB8A37B4-6AE8-4614-9533-7AFD0F18838C}
    2012-06-20 13:24 - 2012-06-20 13:24 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-06-20 06:41 - 2012-06-20 06:41 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9259AB6-1DC3-4E8B-8AC8-9ACCA67DB57F}
    2012-06-19 16:12 - 2012-06-19 16:12 - 00000000 ____D C:\Users\Wolf\AppData\Local\{967CB5D5-3013-4872-9DFA-B2CBDE65073B}
    2012-06-19 16:12 - 2012-06-19 04:11 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E7495E72-311F-4F4E-9F23-312AE87026EA}
    2012-06-19 07:16 - 2012-06-19 07:16 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Folding@home-x86
    2012-06-19 07:16 - 2012-06-19 07:16 - 00000000 ____D C:\Program Files (x86)\Folding@home
    2012-06-19 07:15 - 2012-06-19 07:15 - 02878976 ____A C:\Users\Wolf\Downloads\Folding@home-Win32-x86-systray-623.msi
    2012-06-19 06:55 - 2012-06-19 06:55 - 03793814 ____A C:\Users\Wolf\Downloads\KatawaShoujo_MomentOfDecision.mp3
    2012-06-19 04:12 - 2012-06-19 04:11 - 00000000 ____D C:\Users\Wolf\AppData\Local\{34B56388-6578-42AB-9D56-59148B615D56}
    2012-06-18 07:13 - 2012-06-18 06:54 - 00006527 ____A C:\Users\Wolf\Desktop\New Text Document (2).txt
    2012-06-18 06:49 - 2012-06-18 06:49 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F7C8FF26-2A7C-44BA-A1BE-6E12077664B8}
    2012-06-18 05:22 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
    2012-06-17 18:10 - 2012-06-17 06:09 - 00000000 ____D C:\Users\Wolf\AppData\Local\{864C3DB0-747B-4FAB-9441-5A31AA087E0C}
    2012-06-17 13:34 - 2012-06-17 13:33 - 00000000 ____D C:\Users\Wolf\Desktop\New folder
    2012-06-17 06:08 - 2012-02-01 05:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2012-06-16 07:18 - 2012-06-16 07:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{81C49DF4-92B8-4818-8C70-98075EAA9A99}
    2012-06-16 06:58 - 2012-06-15 15:07 - 00000000 ____D C:\Users\Wolf\Documents\LOLReplay
    2012-06-16 06:06 - 2012-06-16 06:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\Macromedia
    2012-06-16 05:44 - 2012-02-01 05:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2012-06-15 19:17 - 2012-06-15 07:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{56F6CB7D-2198-4E18-A4CB-DF4C266BC3FB}
    2012-06-15 18:42 - 2012-06-15 18:42 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
    2012-06-15 18:16 - 2012-06-15 18:16 - 00000000 ____D C:\Users\All Users\Rockstar Games
    2012-06-15 18:16 - 2012-02-01 05:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2012-06-15 17:04 - 2012-06-15 16:59 - 161912074 ____A C:\Users\Wolf\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68].zip
    2012-06-15 15:07 - 2012-06-15 15:07 - 00001905 ____A C:\Users\Public\Desktop\LOL Recorder.lnk
    2012-06-15 15:07 - 2012-06-15 15:07 - 00000000 ____D C:\Program Files (x86)\LOLReplay
    2012-06-15 15:06 - 2012-06-15 15:06 - 01501409 ____A C:\Users\Wolf\Downloads\LOLReplay-0.7.9.1.exe
    2012-06-15 08:58 - 2012-06-15 08:58 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\RenPy
    2012-06-15 08:51 - 2012-06-15 08:51 - 00000797 ____A C:\Users\Wolf\Desktop\Katawa Shoujo.lnk
    2012-06-15 07:15 - 2009-07-13 20:45 - 04903968 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-06-14 17:57 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
    2012-06-14 17:07 - 2012-02-01 06:15 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-06-14 15:02 - 2012-05-26 02:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\SKIDROW
    2012-06-14 14:28 - 2012-06-14 14:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{6221A1EF-FAC8-4A7D-AA70-6B5507BC541C}
    2012-06-14 14:28 - 2012-06-14 02:26 - 00000000 ____D C:\Users\Wolf\AppData\Local\{31F9B074-5896-404F-9BF6-E4385BDDF5B3}
    2012-06-14 13:43 - 2012-06-14 13:43 - 00000000 ____D C:\Users\Wolf\Documents\Hitman Blood Money
    2012-06-14 13:42 - 2012-06-14 13:42 - 00098304 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll
    2012-06-14 13:01 - 2012-02-01 05:33 - 00060984 ____A C:\Users\Wolf\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-06-14 10:23 - 2012-06-14 06:01 - 00000000 ____D C:\Users\All Users\Firefly Studios
    2012-06-14 02:28 - 2012-06-14 02:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E3238C17-E207-438F-82A3-EB89356E3DA8}
    2012-06-14 02:20 - 2012-06-14 02:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A6D7F2EE-D2D4-41F2-B3FC-8BD145B0A190}
    2012-06-14 02:20 - 2012-06-14 02:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BC331A7B-64D7-432F-82FD-9784E929841B}
    2012-06-13 19:13 - 2012-06-13 19:13 - 00001178 ____A C:\Users\Wolf\Desktop\Warriors Orochi (ToeD).lnk
    2012-06-13 19:13 - 2012-06-13 19:13 - 00000000 ____D C:\Users\Wolf\Documents\KOEI
    2012-06-13 19:00 - 2012-06-13 18:55 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold Crusader
    2012-06-13 18:53 - 2012-06-12 18:11 - 00005761 ____A C:\Users\Wolf\Desktop\New Text Document.txt
    2012-06-13 14:19 - 2012-06-13 14:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{41DA6438-34AD-493B-B393-AAF7819B10BA}
    2012-06-13 14:19 - 2012-06-13 14:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5ED84925-45EB-494B-96A5-F5B3967C1BF8}
    2012-06-13 09:23 - 2012-06-02 11:06 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\TeamViewer
    2012-06-13 02:18 - 2012-06-13 02:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DB1209B6-035D-4466-8757-B893040597D9}
    2012-06-13 02:18 - 2012-06-13 02:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69E680C4-A7DF-4C1A-9D8A-0BC66D71EB32}
    2012-06-12 19:37 - 2012-06-12 09:12 - 00000000 ____D C:\Sword
    2012-06-12 17:36 - 2012-06-12 17:36 - 00000019 ____A C:\Windows\D.ini
    2012-06-12 14:05 - 2012-06-12 14:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{78F62976-66E7-43ED-BB9F-D5DF3AC5F3AC}
    2012-06-12 14:04 - 2012-06-12 14:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1EBA75EF-77A7-44FE-8A9C-BB81E330A07D}
    2012-06-12 09:21 - 2012-06-12 09:21 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\ScummVM
    2012-06-12 09:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system
    2012-06-12 02:04 - 2012-06-12 02:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B33236EC-D70C-4821-8D05-10DB19CDFE07}
    2012-06-12 02:04 - 2012-06-12 02:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{29AB2770-F23A-4F39-B983-E42EF3988371}
    2012-06-11 18:18 - 2012-06-11 18:17 - 00000049 ____A C:\Users\Wolf\Desktop\Pinger.txt
    2012-06-11 10:27 - 2012-06-11 10:27 - 00000000 ____D C:\Users\Wolf\Documents\Stronghold 3
    2012-06-11 07:08 - 2012-06-11 07:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A0EAE8F3-D293-482A-914A-4F450BE3CB89}
    2012-06-11 07:08 - 2012-06-11 07:08 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9C28CCC3-A5D0-480B-8B88-C5A40CA00C3B}
    2012-06-10 19:07 - 2012-06-10 19:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E3AD0B0-35C8-4E43-8572-BD0F9840F37A}
    2012-06-10 19:07 - 2012-06-10 07:06 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B7E5E7DB-1CB1-4FDB-B085-C2C0D59F575D}
    2012-06-10 12:19 - 2012-06-10 12:19 - 01735565 ____A (Alexander Vigovsky ) C:\Users\Wolf\Downloads\ac3filter_2_4a_lite.exe
    2012-06-10 12:19 - 2012-06-10 12:19 - 00000000 ____D C:\Program Files (x86)\AC3Filter
    2012-06-10 12:18 - 2012-06-10 11:26 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DivX
    2012-06-10 11:27 - 2012-06-10 11:27 - 00000000 ____D C:\Users\Wolf\AppData\Local\DDMSettings
    2012-06-10 11:26 - 2012-06-10 11:26 - 00000000 ____D C:\Program Files\DivX
    2012-06-10 11:26 - 2012-06-10 11:25 - 00000000 ____D C:\Program Files (x86)\DivX
    2012-06-10 11:26 - 2012-06-10 11:20 - 00000000 ____D C:\Users\All Users\DivX
    2012-06-10 11:20 - 2012-06-10 11:20 - 00933256 ____A (DivX, LLC) C:\Users\Wolf\Downloads\DivXInstaller.exe
    2012-06-10 07:49 - 2012-06-10 07:27 - 00000000 ____D C:\Users\Wolf\Desktop\Snes
    2012-06-10 07:07 - 2012-06-10 07:07 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7958BFCE-14B8-4F0B-95C9-96460C9F6439}
    2012-06-09 19:05 - 2012-06-09 19:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5E7DF313-0B3B-4FD1-9C44-C7DF656F2830}
    2012-06-09 19:05 - 2012-06-09 07:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5EF250FE-5D75-4BB1-AB3C-B195035F51DF}
    2012-06-09 07:05 - 2012-06-09 07:05 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DA3EFC53-A72C-4455-BCD6-719EEBAC89AD}
    2012-06-08 18:23 - 2012-02-01 12:07 - 00000000 ____D C:\Users\Wolf\Documents\My Games
    2012-06-08 18:02 - 2012-05-28 08:03 - 00107832 ____A C:\Windows\SysWOW64\PnkBstrB.exe
    2012-06-08 18:02 - 2012-05-28 08:03 - 00066872 ____A C:\Windows\SysWOW64\PnkBstrA.exe
    2012-06-08 18:02 - 2012-02-01 22:28 - 00000000 ____D C:\Users\All Users\Ubisoft
    2012-06-08 18:00 - 2012-06-08 18:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\{74197D9F-12B8-4F93-A066-2A5D76826950}
    2012-06-08 18:00 - 2012-06-08 05:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEA05E89-8748-47D1-B07B-E8D794B8F9B1}
    2012-06-08 15:48 - 2012-06-08 15:46 - 00000000 ____D C:\Users\Wolf\Documents\ArmA 2
    2012-06-08 15:46 - 2012-06-08 15:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\ArmA 2 Free
    2012-06-08 06:23 - 2012-06-08 06:23 - 00000885 ____A C:\Users\UpdatusUser\Desktop\Play Star Wars Republic Commando.lnk
    2012-06-08 05:59 - 2012-06-08 05:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F9D3BF70-4F64-48BB-A8F4-E611A769B662}
    2012-06-07 17:59 - 2012-06-07 17:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DEFB5670-0786-498C-A1E1-F7243588A15A}
    2012-06-07 17:59 - 2012-06-07 05:58 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AA46DBB4-DB4A-472F-82EB-FBDFC6556532}
    2012-06-07 08:26 - 2012-06-07 08:26 - 00000000 ____D C:\Users\Wolf\Desktop\dolphin
    2012-06-07 05:59 - 2012-06-07 05:58 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FC53B60C-6F6E-4ED4-B40C-009BD43E92B4}
    2012-06-06 18:23 - 2012-06-01 07:49 - 00000000 ____D C:\Users\Wolf\Documents\DepthHunter
    2012-06-06 17:20 - 2012-06-06 17:20 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AC65E5A8-92D1-4634-946A-2E9F7E9A46FB}
    2012-06-06 17:20 - 2012-06-06 05:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{018EFAE0-DA5F-42D6-9FB4-F021E1130510}
    2012-06-06 16:06 - 2012-06-06 16:06 - 00000000 ____D C:\Nocturnal
    2012-06-06 16:05 - 2012-06-06 16:05 - 00000223 ____A C:\Windows\MugE.ini
    2012-06-06 15:07 - 2012-06-06 15:07 - 00188960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingde.dll
    2012-06-06 15:02 - 2012-06-06 15:02 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing32.dll
  10. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    2012-06-06 15:02 - 2012-06-06 15:02 - 00006736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingdib.drv
    2012-06-06 15:02 - 2012-06-06 15:02 - 00005024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wingpal.wnd
    2012-06-06 15:01 - 2012-06-06 15:01 - 00092208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wing.dll
    2012-06-06 12:35 - 2012-06-02 15:10 - 00000000 ____D C:\Users\Wolf\Documents\Vindictus EU
    2012-06-06 11:32 - 2012-02-01 05:22 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Adobe
    2012-06-06 05:19 - 2012-06-06 05:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{7223F4E9-A6ED-4984-9F12-0553BE51A9FA}
    2012-06-05 17:19 - 2012-06-05 17:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{AEBC6B16-FA61-472F-B178-7947B70D4644}
    2012-06-05 17:19 - 2012-06-05 17:19 - 00000000 ____D C:\Users\Wolf\AppData\Local\{77EDE412-92A0-4FE2-B150-A38B2E91C713}
    2012-06-05 12:08 - 2012-06-05 12:08 - 00000000 ____D C:\Program Files (x86)\SplitMediaLabs
    2012-06-05 05:18 - 2012-06-05 05:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{396C4775-9424-4BB2-A423-6B2436410DE2}
    2012-06-05 05:18 - 2012-06-05 05:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2EE4F770-25FF-4D67-AE38-FF1ECCA34319}
    2012-06-04 17:18 - 2012-06-04 17:18 - 00000000 ____D C:\Users\Wolf\AppData\Local\{669C431C-59C4-4CFA-9965-6CCB0F8DD7E6}
    2012-06-04 17:18 - 2012-06-04 05:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{9E2CB37D-DD5F-4DEC-9A37-4E8E73599B3F}
    2012-06-04 05:17 - 2012-06-04 05:17 - 00000000 ____D C:\Users\Wolf\AppData\Local\{4A04846C-C294-40F1-B047-C441C907CCF9}
    2012-06-03 16:34 - 2012-06-03 16:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D94B41B9-EF3A-4674-AE3A-1DADE4352553}
    2012-06-03 16:34 - 2012-06-03 04:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C91224FA-142A-404C-9C41-94A14AAB6355}
    2012-06-03 04:34 - 2012-06-03 04:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E64A22F0-D582-4DBC-BE24-0B861F843E90}
    2012-06-02 16:30 - 2012-06-02 16:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{E9B1A525-2BB8-4999-A4FA-B4C972C0A7CF}
    2012-06-02 16:30 - 2012-06-02 04:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{2A798180-069D-448F-9C03-618665668D41}
    2012-06-02 15:11 - 2012-06-02 15:11 - 00001234 ____A C:\Users\Wolf\Desktop\Vindictus - Shortcut.lnk
    2012-06-02 15:11 - 2012-06-02 13:36 - 00000000 ____D C:\Users\All Users\NexonEU
    2012-06-02 15:08 - 2012-06-02 15:08 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
    2012-06-02 15:08 - 2012-06-02 13:46 - 00000000 ____D C:\Download
    2012-06-02 15:07 - 2012-06-02 08:03 - 00000000 ____D C:\Nexon
    2012-06-02 14:52 - 2012-06-02 14:49 - 130416408 ____A C:\Users\Wolf\Downloads\bmw_perfect_v97.rar
    2012-06-02 14:48 - 2012-06-02 14:48 - 00000000 ____D C:\Users\Wolf\Documents\bmw_english4V_95
    2012-06-02 14:19 - 2012-06-21 22:49 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-21 22:49 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:19 - 2012-06-21 22:48 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-21 22:48 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 14:19 - 2012-06-21 22:48 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 14:15 - 2012-06-21 22:49 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 14:15 - 2012-06-21 22:48 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 13:46 - 2012-06-02 13:46 - 00536576 ____A (Nexon) C:\Users\Wolf\Downloads\Vindictus_Downloader.exe
    2012-06-02 13:46 - 2012-06-02 13:46 - 00446464 ____A (NEXON Inc.) C:\Windows\NEXON_EU_DownloaderUpdater.exe
    2012-06-02 13:46 - 2012-06-02 13:46 - 00000235 ____A C:\Windows\SysWOW64\nxEuUninstall.bat
    2012-06-02 13:35 - 2012-06-02 13:35 - 03655576 ____A (Nexon) C:\Users\Wolf\Downloads\Setup.exe
    2012-06-02 08:21 - 2012-06-02 08:21 - 00621160 ____A (Copyright ゥ 2010 eSupport.com. All Rights Reserved.) C:\Users\Wolf\Downloads\driveragent_987.exe
    2012-06-02 08:21 - 2012-06-02 08:21 - 00021712 ____A (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
    2012-06-02 08:21 - 2012-06-02 08:21 - 00000000 ____D C:\Users\Wolf\AppData\Local\eSupport.com
    2012-06-02 08:20 - 2012-06-02 08:20 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SystemRequirementsLab
    2012-06-02 08:03 - 2012-06-02 08:03 - 00000000 ____D C:\Users\All Users\NexonUS
    2012-06-02 07:13 - 2012-06-02 07:13 - 00000000 ____D C:\Users\All Users\Nexon
    2012-06-02 07:08 - 2012-06-02 07:08 - 02013336 ____A C:\Users\Wolf\Downloads\MapleStoryDownloader.exe
    2012-06-02 06:27 - 2012-06-02 06:08 - 113899850 ____A C:\Users\Wolf\Downloads\Bf3-mpcr.rar
    2012-06-02 06:11 - 2012-06-02 06:11 - 00000000 ____D C:\Users\Wolf\Documents\DragonSaga
    2012-06-02 06:10 - 2012-06-02 06:10 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\DragonSaga
    2012-06-02 05:19 - 2012-06-21 22:48 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 05:15 - 2012-06-21 22:48 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-02 04:29 - 2012-06-02 04:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{F03D9EB4-CF0B-4A74-A47B-E056FEB39EDD}
    2012-06-01 16:29 - 2012-06-01 16:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{72BAC764-B627-4F15-A603-D553B12B02B6}
    2012-06-01 16:29 - 2012-06-01 04:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{45C6FCE0-68C7-48EE-9121-BAEDFCA89588}
    2012-06-01 08:24 - 2012-06-01 08:24 - 04171406 ____A C:\Users\Wolf\Downloads\XMouseButtonControlSetup.2.4.exe
    2012-06-01 08:24 - 2012-06-01 08:24 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Highresolution Enterprises
    2012-06-01 08:24 - 2012-06-01 08:24 - 00000000 ____D C:\Program Files\Highresolution Enterprises
    2012-06-01 08:03 - 2012-06-01 08:03 - 00000000 ____D C:\Users\All Users\BioWare
    2012-06-01 08:03 - 2012-02-01 22:27 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\NVIDIA
    2012-06-01 08:01 - 2012-06-01 08:01 - 00000000 ____D C:\Users\Wolf\Documents\BioWare
    2012-06-01 04:28 - 2012-06-01 04:28 - 00000000 ____D C:\Users\Wolf\AppData\Local\{BDF956F0-D59B-4350-AFFF-357CAE62018C}
    2012-05-31 15:31 - 2012-05-31 15:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{69CA7DA5-AAE2-4F3D-B062-F5ADF10EB800}
    2012-05-31 15:31 - 2012-05-31 15:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{30921632-D6C6-470F-8A0C-F20D93AE4ED0}
    2012-05-31 15:24 - 2012-05-31 15:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{DFCEAD23-D76A-4193-B976-F76F825D9117}
    2012-05-31 15:24 - 2012-05-31 15:24 - 00000000 ____D C:\Users\Wolf\AppData\Local\{24380E14-2AF3-4C52-A2FC-7DAD465977B8}
    2012-05-31 15:20 - 2012-05-31 15:20 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{d49c2933-ab76-11e1-bc6a-bc5ff438e47c}.TxR.blf
    2012-05-31 15:14 - 2012-05-31 15:14 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{1aa4bd2d-ab76-11e1-8460-bc5ff438e47c}.TxR.blf
    2012-05-31 15:14 - 2012-05-31 15:14 - 00000092 ____A C:\Users\Wolf\AppData\Local\fusioncache.dat
    2012-05-31 15:14 - 2012-05-31 15:14 - 00000000 ____D C:\Users\Wolf\AppData\Local\GameSpy
    2012-05-31 15:14 - 2012-02-01 05:14 - 00000000 ____D C:\Users\Wolf\AppData\Local\VirtualStore
    2012-05-31 14:25 - 2012-02-01 05:32 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2012-05-31 14:25 - 2012-02-01 05:31 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2012-05-31 14:22 - 2012-05-31 14:19 - 168454136 ____A (NVIDIA Corporation) C:\Users\Wolf\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
    2012-05-31 14:19 - 2012-05-31 14:19 - 00000000 ____D C:\Users\All Users\Sun
    2012-05-31 14:18 - 2012-05-31 14:18 - 00772552 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-05-31 14:18 - 2012-05-31 14:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-05-31 14:18 - 2012-05-31 14:18 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-05-31 14:18 - 2012-05-31 14:18 - 00000000 ____D C:\Program Files (x86)\Oracle
    2012-05-31 14:18 - 2012-05-31 14:18 - 00000000 ____D C:\Program Files (x86)\Java
    2012-05-31 14:17 - 2012-05-31 14:17 - 00892360 ____A (Oracle Corporation) C:\Users\Wolf\Downloads\jxpiinstall.exe
    2012-05-31 09:22 - 2012-05-31 09:22 - 00000000 ____D C:\Program Files (x86)\GameSpy
    2012-05-31 09:21 - 2012-05-25 07:57 - 03475636 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-05-31 09:18 - 2012-05-31 09:18 - 00001298 ____A C:\Users\Public\Desktop\Crysis.lnk
    2012-05-31 05:37 - 2012-05-31 05:37 - 21503784 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HWSE_SE_v3.2.2.1.exe
    2012-05-31 05:37 - 2012-05-31 05:37 - 00000000 ____D C:\Program Files (x86)\Hercules
    2012-05-31 05:36 - 2012-05-31 05:36 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(2).exe
    2012-05-31 05:29 - 2012-05-31 05:29 - 62444312 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v2.9.0.0.exe
    2012-05-31 05:28 - 2012-05-31 05:28 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1(1).exe
    2012-05-31 05:06 - 2012-05-31 05:06 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\InstallShield
    2012-05-31 05:06 - 2012-05-31 05:05 - 13387288 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\HCLINK_v3.2.2.1.exe
    2012-05-31 03:23 - 2012-05-31 03:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{C33CF4EE-A3BE-4355-A681-463A8BE50A8B}
    2012-05-31 03:23 - 2012-05-31 03:23 - 00000000 ____D C:\Users\Wolf\AppData\Local\{47DD7949-55AC-4910-B63E-0625A8C88C07}
    2012-05-30 17:50 - 2012-05-28 14:38 - 00000000 ____D C:\Fraps
    2012-05-30 11:34 - 2012-05-30 11:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{308AC941-8DFC-4CE8-94F0-EB570AE23E93}
    2012-05-30 11:34 - 2012-05-29 23:33 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3BCE797B-4A95-4C3C-841B-891768931583}
    2012-05-30 06:02 - 2012-05-30 06:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Chart Controls
    2012-05-30 04:28 - 2012-05-30 04:28 - 00001802 ____A C:\Users\Public\Desktop\Dragon Saga.lnk
    2012-05-30 03:48 - 2012-05-30 03:48 - 00330120 ____A (Gravity Interactive, Inc.) C:\Users\Wolf\Downloads\DragonSaga-Installer-0.2.5-20120330.exe
    2012-05-29 23:34 - 2012-05-29 23:34 - 00000000 ____D C:\Users\Wolf\AppData\Local\{D9ED8115-E416-4B42-93EA-D62BFF6A48D3}
    2012-05-29 06:49 - 2012-05-29 06:49 - 00001989 ____A C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
    2012-05-29 06:49 - 2012-05-29 06:49 - 00000000 ____D C:\Program Files (x86)\PCSX2 0.9.8
    2012-05-29 06:48 - 2012-05-29 06:48 - 12780479 ____A C:\Users\Wolf\Downloads\pcsx2-0.9.8-r4600-setup.exe
    2012-05-29 06:48 - 2012-05-29 06:48 - 04353259 ____A (Igor Pavlov) C:\Users\Wolf\Downloads\dolphin-3.0-win64.exe
    2012-05-29 05:41 - 2012-05-29 05:41 - 00002105 ____A C:\Users\Public\Desktop\A.V.A.lnk
    2012-05-29 05:41 - 2012-05-29 05:41 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
    2012-05-29 05:41 - 2012-05-28 12:52 - 00000000 ____D C:\Program Files (x86)\REACTOR
    2012-05-29 02:32 - 2012-05-29 02:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{65655CD4-236C-47ED-BF7C-D5B292418970}
    2012-05-29 02:32 - 2012-05-29 02:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\{1DA6169D-DEBF-47A1-B3DF-FC4F0D7EA61D}
    2012-05-28 17:52 - 2012-05-28 09:43 - 00000000 ____D C:\Users\Wolf\Documents\DragonNest
    2012-05-28 14:48 - 2012-05-28 14:48 - 00002560 ____A C:\Users\Wolf\Documents\Register Vegas Pro.htm
    2012-05-28 14:48 - 2012-05-28 14:48 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Publish Providers
    2012-05-28 14:48 - 2012-05-28 14:46 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Sony
    2012-05-28 14:46 - 2012-05-28 14:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\Sony
    2012-05-28 14:44 - 2012-05-28 14:44 - 00001908 ____A C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
    2012-05-28 14:44 - 2012-05-28 14:44 - 00000000 ____D C:\Users\All Users\Sony
    2012-05-28 14:43 - 2012-05-28 14:43 - 00000000 ____D C:\Program Files (x86)\Sony
    2012-05-28 14:38 - 2012-05-28 14:38 - 00000562 ____A C:\Users\Wolf\Desktop\Fraps.lnk
    2012-05-28 14:32 - 2012-05-28 14:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{FB225DD7-B02B-4BE6-8F32-D5F446DE2EAB}
    2012-05-28 14:31 - 2012-05-28 14:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{160F752A-7CFD-4058-914C-AEA7BDA6BF80}
    2012-05-28 13:25 - 2012-05-27 02:33 - 00000000 ____D C:\Users\Wolf\AppData\Local\BladesOfTime
    2012-05-28 12:56 - 2012-05-28 12:56 - 00298016 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
    2012-05-28 12:55 - 2012-05-28 12:55 - 00000000 ____D C:\Users\Wolf\AppData\Local\PunkBuster
    2012-05-28 12:53 - 2012-05-28 12:53 - 00001907 ____A C:\Users\Public\Desktop\ijji REACTOR.lnk
    2012-05-28 12:52 - 2012-05-28 12:52 - 07822632 ____A (Macrovision Corporation) C:\Users\Wolf\Downloads\IJJI_REACTOR_INST_EN.exe
    2012-05-28 11:12 - 2012-05-28 07:34 - 198654664 ____A C:\Users\Wolf\Downloads\U_AVA_SETUP_Jan2012.zip
    2012-05-28 10:12 - 2012-05-28 10:12 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
    2012-05-28 10:11 - 2012-05-28 08:03 - 00189248 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
    2012-05-28 09:58 - 2012-05-28 10:11 - 03130440 ____A C:\Windows\SysWOW64\pbsvc_blr.exe
    2012-05-28 09:12 - 2012-05-28 09:12 - 00000796 ____A C:\Users\Public\Desktop\Dragon Nest.lnk
    2012-05-28 08:40 - 2012-05-28 07:28 - 2536606647 ____A (Shanda Games International) C:\Users\Wolf\Downloads\DNClientVer60_20120423.exe
    2012-05-28 08:08 - 2012-05-28 08:05 - 00000000 ____D C:\Users\Wolf\Documents\Battlefield 3
    2012-05-28 08:05 - 2012-05-28 07:34 - 00000000 ____D C:\Games
    2012-05-28 07:19 - 2012-05-28 07:18 - 02072456 ____A C:\Users\Wolf\Downloads\BlacklightRetribution_Downloader_EN.exe
    2012-05-28 03:16 - 2012-05-26 05:47 - 00000000 ____D C:\Users\Wolf\AppData\Local\Adobe
    2012-05-28 03:14 - 2012-05-28 03:14 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
    2012-05-28 03:14 - 2012-05-28 03:14 - 00000725 ____A C:\Users\Wolf\Desktop\Dustforce.lnk
    2012-05-28 03:14 - 2012-05-28 03:14 - 00000000 ____D C:\Program Files (x86)\OpenAL
    2012-05-28 03:14 - 2012-05-27 17:12 - 00000000 ____D C:\Users\Wolf\Downloads\Crysis_2-FLT
    2012-05-28 02:31 - 2012-05-28 02:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CD0B5883-D705-4B3F-878D-1CEB81D6E307}
    2012-05-28 02:31 - 2012-05-28 02:31 - 00000000 ____D C:\Users\Wolf\AppData\Local\{466B1E6A-4A0C-4E36-8C2B-545561C19512}
    2012-05-27 14:30 - 2012-05-27 14:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3B0B234A-AD01-4412-A755-6F9EC247B549}
    2012-05-27 14:30 - 2012-05-27 14:30 - 00000000 ____D C:\Users\Wolf\AppData\Local\{38946F5D-E76A-4FAC-9F90-365593EAA120}
    2012-05-27 13:17 - 2012-05-27 12:51 - 00021225 ____A C:\Users\Wolf\Documents\Install Dragon Age Origins.log
    2012-05-27 13:05 - 2012-05-27 13:05 - 00000754 ____A C:\Users\Public\Desktop\Dragon Age Origins.lnk
    2012-05-27 13:05 - 2012-05-27 13:05 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP
    2012-05-27 09:36 - 2012-05-27 09:36 - 00001147 ____A C:\Users\Public\Desktop\Bamboo Dock.lnk
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Wacom
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Users\All Users\Wacom
    2012-05-27 09:36 - 2012-05-27 09:36 - 00000000 ____D C:\Program Files (x86)\Bamboo Dock
    2012-05-27 09:36 - 2012-05-26 06:12 - 00000002 ____A C:\Users\Wolf\.bdockinstall.log
    2012-05-27 09:34 - 2012-05-27 09:34 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WTablet
    2012-05-27 09:34 - 2012-05-27 09:34 - 00000000 ____D C:\Program Files\Tablet
    2012-05-27 09:34 - 2012-05-27 09:34 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
    2012-05-27 09:33 - 2012-05-27 09:33 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(2).exe
    2012-05-27 09:15 - 2012-05-27 09:15 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final(1).exe
    2012-05-27 09:05 - 2012-05-27 09:05 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
    2012-05-27 03:40 - 2012-05-25 07:03 - 00000000 ____D C:\Users\Wolf\Documents\CAPCOM
    2012-05-27 03:22 - 2012-05-27 03:22 - 00001003 ____A C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
    2012-05-27 03:21 - 2012-05-27 03:21 - 00000000 ____D C:\Windows\SysWOW64\xlive
    2012-05-27 03:21 - 2012-05-27 03:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
    2012-05-27 03:00 - 2012-05-27 02:59 - 00000000 ____D C:\Users\Wolf\AppData\Local\SniperV2
    2012-05-27 02:57 - 2012-05-27 02:57 - 00001095 ____A C:\Users\Public\Desktop\Sniper Elite V2.lnk
    2012-05-27 02:49 - 2012-05-27 02:44 - 00000000 ____D C:\Users\Wolf\AppData\Local\XBlades
    2012-05-27 02:48 - 2012-05-27 02:44 - 00000000 ____D C:\Users\All Users\XBlades
    2012-05-27 02:46 - 2012-05-27 02:44 - 00000422 ____A C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
    2012-05-27 02:32 - 2012-05-27 02:32 - 00000984 ____A C:\Users\Public\Desktop\Blades of Time.lnk
    2012-05-27 02:30 - 2012-05-27 02:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{452C3747-247D-49E6-92F9-FF22C9404000}
    2012-05-27 02:29 - 2012-05-27 02:29 - 00000000 ____D C:\Users\Wolf\AppData\Local\{B2C1155D-6711-4A9A-BE54-8C430A6B998F}
    2012-05-26 18:22 - 2012-05-26 18:22 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
    2012-05-26 18:17 - 2012-05-26 18:17 - 00000999 ____A C:\Users\Public\Desktop\Magicka.lnk
    2012-05-26 13:40 - 2012-05-26 13:40 - 00000000 ____D C:\Windows\System32\Macromed
    2012-05-26 13:40 - 2012-05-26 13:40 - 00000000 ____D C:\Users\Wolf\AppData\Local\SplitMediaLabs
    2012-05-26 13:38 - 2012-05-26 13:38 - 00000000 ____D C:\Users\All Users\SplitMediaLabs
    2012-05-26 13:37 - 2012-05-26 13:37 - 24220864 ____A (SplitMediaLabs) C:\Users\Wolf\Downloads\xsplit_installer_v1.0.1204.1301.exe
    2012-05-26 13:37 - 2012-05-26 13:37 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\SplitMediaLabs
    2012-05-26 13:07 - 2012-05-26 13:07 - 00000857 ____A C:\Users\Wolf\Desktop\League of Legends.lnk
    2012-05-26 11:47 - 2012-05-26 11:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{525FBECE-BEC1-4B0B-BCDD-A5CB91553E59}
    2012-05-26 11:46 - 2012-05-26 11:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{CB91DDC8-FE7D-4956-A352-3D8415C5CF6F}
    2012-05-26 11:20 - 2012-05-26 11:20 - 00001727 ____A C:\Users\Wolf\Desktop\Photoshop - Shortcut.lnk
    2012-05-26 11:19 - 2012-05-26 11:11 - 00000000 ____D C:\Users\All Users\FLEXnet
    2012-05-26 11:18 - 2012-05-26 11:18 - 00000000 ____D C:\Users\Wolf\AdobeLicensingFilesBackup
    2012-05-26 11:12 - 2012-05-26 11:04 - 00000000 ____D C:\Users\Wolf\AppData\Local\Microsoft Games
    2012-05-26 11:05 - 2012-05-26 10:29 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2012-05-26 11:04 - 2012-05-26 10:34 - 00000000 ____D C:\Program Files\Adobe
    2012-05-26 11:03 - 2012-02-01 05:21 - 00000000 ____D C:\Program Files (x86)\Adobe
    2012-05-26 11:02 - 2012-05-26 11:02 - 00000000 ____D C:\Windows\SysWOW64\spool
    2012-05-26 10:59 - 2012-05-26 10:59 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
    2012-05-26 10:45 - 2012-05-26 08:28 - 00000000 ____D C:\Users\All Users\regid.1986-12.com.adobe
    2012-05-26 10:30 - 2012-02-01 05:21 - 00000000 ____D C:\Users\All Users\Adobe
    2012-05-26 10:20 - 2012-05-26 10:20 - 00000000 ____D C:\Windows\SysWOW64\syncdb
    2012-05-26 08:17 - 2012-05-26 07:47 - 2119376047 ____A C:\Users\Wolf\Downloads\PSE9.zip
    2012-05-26 07:59 - 2012-05-26 07:59 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Ambient Design
    2012-05-26 07:44 - 2012-02-01 05:25 - 00000000 ____D C:\Users\All Users\Norton
    2012-05-26 07:43 - 2012-05-26 07:34 - 544160151 ____A C:\Users\Wolf\Downloads\PSE9.zip.part
    2012-05-26 07:36 - 2012-05-26 07:34 - 72725528 ____A (Ambient Design) C:\Users\Wolf\Downloads\install_artrage_studiopro.exe
    2012-05-26 07:35 - 2012-05-26 07:34 - 07434944 ____A C:\Users\Wolf\Downloads\bamboo_setup_web0407final.exe
    2012-05-26 07:17 - 2012-05-26 07:17 - 00001181 ____A C:\Users\Public\Desktop\openCanvas5e.lnk
    2012-05-26 07:17 - 2012-05-26 07:17 - 00000000 ____D C:\Program Files (x86)\portalgraphics
    2012-05-26 07:13 - 2012-05-26 07:13 - 02330770 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04e.exe
    2012-05-26 07:11 - 2012-05-26 07:11 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\portalgraphics
    2012-05-26 07:10 - 2012-05-26 07:10 - 02271209 ____A (portalgraphics.net ) C:\Users\Wolf\Downloads\setup_oC51_04.exe
    2012-05-26 06:49 - 2012-05-26 06:25 - 00000000 ____D C:\Users\All Users\Alias
    2012-05-26 06:25 - 2012-05-26 06:25 - 00002156 ____A C:\Users\Public\Desktop\Autodesk SketchBookPro 2011.lnk
    2012-05-26 06:25 - 2012-05-26 06:25 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\Autodesk
    2012-05-26 06:24 - 2012-05-26 06:24 - 00001152 ____A C:\Users\Wolf\Desktop\Play IW4M (Modern Warfare 2).lnk
    2012-05-26 06:24 - 2012-05-26 06:24 - 00000000 ____D C:\Program Files (x86)\Autodesk
    2012-05-26 06:23 - 2012-05-26 06:23 - 00001013 ____A C:\Users\Public\Desktop\Worms Ultimate Mayhem.lnk
    2012-05-26 06:12 - 2012-05-26 06:12 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
    2012-05-26 06:12 - 2012-05-26 06:12 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
    2012-05-26 02:00 - 2012-05-26 02:00 - 00000000 ____D C:\Users\Wolf\AppData\Local\BigHugeEngine
    2012-05-26 01:58 - 2012-05-26 01:58 - 00001185 ____A C:\Users\Wolf\Desktop\Dead Island.lnk
    2012-05-26 00:15 - 2012-05-26 00:15 - 00001083 ____A C:\Users\Public\Desktop\Kingdoms of Amalur Reckoning.lnk
    2012-05-25 23:46 - 2012-05-25 23:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A5BF4313-036F-4A54-A8FA-9DA6C12A656C}
    2012-05-25 23:46 - 2012-05-25 23:46 - 00000000 ____D C:\Users\Wolf\AppData\Local\{5634B62E-A929-4F3F-97F4-35CD08166140}
    2012-05-25 14:32 - 2012-05-25 14:32 - 00000000 ____D C:\Users\Wolf\AppData\Local\.inapptracking
    2012-05-25 14:31 - 2012-05-25 14:31 - 00000786 ____A C:\Users\Public\Desktop\Sonic Generations.lnk
    2012-05-25 12:34 - 2012-05-25 11:44 - 00000000 ____D C:\Users\Wolf\AppData\Local\IW4M
    2012-05-25 11:44 - 2012-05-25 11:44 - 00156672 ____A (Microsoft) C:\Users\Wolf\Downloads\InstallIW4M.exe
    2012-05-25 11:29 - 2012-05-25 11:29 - 15556319 ____A C:\Users\Wolf\Downloads\4D1 Patcher(r88).zip
    2012-05-25 11:26 - 2012-05-25 11:26 - 07731209 ____A C:\Users\Wolf\Downloads\alterRevolution Client.rar
    2012-05-25 11:26 - 2012-05-25 11:26 - 02246711 ____A C:\Users\Wolf\Downloads\alterRevolution Dedicated 0.3c.rar
    2012-05-25 10:12 - 2012-05-25 10:12 - 00001309 ____A C:\Users\Wolf\Desktop\Devil May Cry 4.lnk
    2012-05-25 07:57 - 2012-05-25 07:57 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-05-25 07:49 - 2012-05-25 07:48 - 12621696 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe
    2012-05-25 07:48 - 2012-05-25 07:48 - 00523840 ____A (Microsoft Corporation) C:\Users\Wolf\Downloads\mseinstall.exe.part
    2012-05-25 07:03 - 2012-05-25 07:03 - 00000000 ____D C:\Users\Wolf\AppData\Local\CAPCOM
    2012-05-25 05:53 - 2012-05-25 05:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{3157081A-C7D3-4452-9C7E-F0E660292DB2}
    2012-05-25 05:50 - 2012-05-25 05:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{93B44AF1-3B18-4C2A-B279-24923486D8F6}
    2012-05-25 05:50 - 2012-02-01 18:50 - 00000000 ____D C:\Users\Wolf\AppData\Local\{A9A666FD-DBB0-4B68-B3C9-837B576965AA}
    2012-05-25 03:59 - 2012-05-25 03:59 - 00002213 ____A C:\Users\Public\Desktop\AION Free-To-Play.lnk
    2012-05-25 03:59 - 2012-05-25 03:59 - 00000000 ____D C:\Program Files (x86)\Gameforge
    2012-05-25 03:44 - 2012-05-25 03:39 - 145138568 ____A (Gameforge) C:\Users\Wolf\Downloads\setup_20120224.exe
    2012-05-25 03:31 - 2012-05-25 03:29 - 00000000 ____D C:\Users\Wolf\AppData\Roaming\WinRAR
    2012-05-25 03:30 - 2012-05-25 03:30 - 01639789 ____A C:\Users\Wolf\Downloads\winrar-x64-411.exe
    2012-05-25 03:30 - 2012-05-25 03:30 - 00000000 ____D C:\Program Files\WinRAR
    2012-05-25 03:29 - 2012-05-25 03:29 - 01506653 ____A C:\Users\Wolf\Downloads\wrar411.exe
    2012-05-25 03:29 - 2012-05-25 03:29 - 00000000 ____D C:\Program Files (x86)\WinRAR
    2012-05-25 02:44 - 2012-05-25 02:44 - 00000000 ____D C:\Program Files\7-Zip
    2012-05-25 02:43 - 2012-05-25 02:43 - 01376768 ____A C:\Users\Wolf\Downloads\7z920-x64.msi
    2012-05-19 23:49 - 2012-05-19 23:49 - 00071680 ____A (Beepa P/L) C:\Windows\System32\frapsv64.dll
    2012-05-19 23:49 - 2012-05-19 23:49 - 00065536 ____A (Beepa P/L) C:\Windows\SysWOW64\frapsvid.dll
    2012-05-17 18:47 - 2012-06-14 17:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-05-17 18:16 - 2012-06-14 17:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-05-17 18:06 - 2012-06-14 17:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-05-17 17:59 - 2012-06-14 17:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-05-17 17:59 - 2012-06-14 17:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-05-17 17:58 - 2012-06-14 17:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-05-17 17:58 - 2012-06-14 17:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-05-17 17:56 - 2012-06-14 17:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-05-17 17:55 - 2012-06-14 17:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-05-17 17:55 - 2012-06-14 17:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-05-17 17:54 - 2012-06-14 17:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-05-17 17:51 - 2012-06-14 17:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-05-17 17:51 - 2012-06-14 17:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-05-17 17:47 - 2012-06-14 17:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-05-17 15:11 - 2012-06-14 17:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-05-17 14:48 - 2012-06-14 17:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-05-17 14:45 - 2012-06-14 17:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-05-17 14:36 - 2012-06-14 17:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-05-17 14:35 - 2012-06-14 17:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-05-17 14:35 - 2012-06-14 17:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-05-17 14:33 - 2012-06-14 17:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-05-17 14:31 - 2012-06-14 17:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-05-17 14:29 - 2012-06-14 17:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-05-17 14:29 - 2012-06-14 17:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-05-17 14:27 - 2012-06-14 17:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-05-17 14:25 - 2012-06-14 17:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-05-17 14:24 - 2012-06-14 17:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-05-17 14:20 - 2012-06-14 17:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-05-15 02:48 - 2012-05-31 14:23 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-05-15 02:48 - 2012-05-31 14:23 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-05-15 02:48 - 2012-02-09 13:43 - 00949056 ____A (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll
    2012-05-15 02:48 - 2012-02-09 13:43 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-05-15 02:48 - 2012-02-09 13:43 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
    2012-05-15 02:48 - 2012-02-01 05:32 - 00014324 ____A C:\Windows\System32\nvinfo.pb
    2012-05-15 01:29 - 2012-02-01 07:40 - 02621723 ____A C:\Windows\System32\nvcoproc.bin
    2012-05-15 01:29 - 2012-02-01 05:32 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
    2012-05-15 01:29 - 2012-02-01 05:32 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    2012-05-15 01:29 - 2012-02-01 05:32 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
    2012-05-15 01:29 - 2012-02-01 05:32 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
    2012-05-15 01:28 - 2012-02-01 05:32 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
    2012-05-14 17:32 - 2012-06-14 02:34 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-05-14 16:21 - 2012-05-14 16:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
    2012-05-04 03:06 - 2012-06-14 02:34 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-05-04 03:00 - 2012-06-21 03:09 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-05-04 02:03 - 2012-06-14 02:34 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-05-04 02:03 - 2012-06-14 02:34 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-05-04 01:59 - 2012-06-21 03:09 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-04-30 21:40 - 2012-06-14 02:34 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-04-27 21:32 - 2012-06-14 02:34 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
    2012-04-27 19:55 - 2012-06-14 02:34 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-04-25 21:41 - 2012-06-14 02:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-04-25 21:41 - 2012-06-14 02:34 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-04-25 21:34 - 2012-06-14 02:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-04-23 21:37 - 2012-06-14 02:33 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-04-23 21:37 - 2012-06-14 02:33 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-04-23 21:37 - 2012-06-14 02:33 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-04-23 20:36 - 2012-06-14 02:33 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-04-23 20:36 - 2012-06-14 02:33 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-04-23 20:36 - 2012-06-14 02:33 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2012-04-18 09:08 - 2012-05-31 14:23 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
    2012-04-18 09:08 - 2012-05-31 14:23 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-04-18 09:08 - 2012-05-31 14:23 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-04-07 04:31 - 2012-06-14 02:34 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-04-07 03:26 - 2012-06-14 02:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-04-04 08:47 - 2012-05-31 14:18 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-04-04 08:47 - 2012-05-31 14:18 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-04-04 05:56 - 2012-06-22 19:19 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-03-30 03:35 - 2012-02-01 05:49 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys

    ZeroAccess:
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\@
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\L
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\n
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\00000001.@
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\80000000.@
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\800000cb.@

    ZeroAccess:
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\@
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\L
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U

    ========================= Known DLLs (Whitelisted) ============


    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ========================= Memory info ======================

    Percentage of memory in use: 10%
    Total physical RAM: 8171 MB
    Available physical RAM: 7318.64 MB
    Total Pagefile: 8169.2 MB
    Available Pagefile: 7310.26 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.91 MB

    ======================= Partitions =========================

    1 Drive c: () (Fixed) (Total:468.26 GB) (Free:296.45 GB) NTFS
    2 Drive e: (Games) (Fixed) (Total:463.16 GB) (Free:194.47 GB) NTFS
    3 Drive f: (GSP1RMCULXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
    4 Drive g: () (Removable) (Total:7.39 GB) (Free:4.37 GB) FAT32
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 931 GB 1024 KB
    Disk 1 Online 7580 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 468 GB 101 MB
    Partition 3 Primary 463 GB 468 GB

    ======================================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 Y System Rese NTFS Partition 100 MB Healthy

    ======================================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C NTFS Partition 468 GB Healthy

    ======================================================================================================

    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 E Games NTFS Partition 463 GB Healthy

    ======================================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 7576 MB 4096 KB

    ======================================================================================================

    Disk: 1
    Partition 1
    Type : 0B
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 G FAT32 Removable 7576 MB Healthy

    ======================================================================================================

    ==========================================================

    Last Boot: 2012-06-18 05:15

    ======================= End Of Log ==========================
  11. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    In Vista or Windows 7: Boot to System Recovery Options and run FRST.
    In Windows XP: Please boot to UBCD and run FRST.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes to your reply.
     
  12. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    Farbar Recovery Scan Tool Version: 22-06-2012
    Ran by SYSTEM at 2012-06-23 06:43:14
    Running from G:\

    ================== Search: "services.exe" ===================

    C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows.old\Windows\System32\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows\System32\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06

    ====== End Of Search ======
  13. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    Next...

    See if you can boot normally.

    If so....

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

    Attached Files:

  14. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    Good afternoon Broni,

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 22-06-2012
    Ran by SYSTEM at 2012-06-23 18:00:13 Run:1
    Running from G:\

    ==============================================

    HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows Value was restored successfully .
    C:\Windows\System32\consrv.dll not found.
    C:\Windows\Installer\{52665dca-b9ce-8bb0-6373-a2219d8ad522} moved successfully.
    C:\Users\Wolf\AppData\Local\{52665dca-b9ce-8bb0-6373-a2219d8ad522} moved successfully.
    C:\Windows\System32\services.exe moved successfully.
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe

    ==== End of Fixlog ====

    --

    ComboFix 12-06-23.05 - Wolf 06/23/2012 18:09:29.1.8 - x64
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8172.6310 [GMT 2:00]
    Running from: c:\users\Wolf\Downloads\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\EF31A2CD-2585-4E97-B7E0-C9FB1D405477
    c:\programdata\F2BDD61C-7F20-44BD-A1DB-F510E492AB22
    c:\programdata\ntuser.dat
    c:\windows\d.ini
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-05-23 to 2012-06-23 )))))))))))))))))))))))))))))))
    .
    .
    2012-06-23 03:55 . 2012-06-23 14:25 -------- d-----w- C:\FRST
    2012-06-23 03:19 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-06-23 02:37 . 2012-06-23 02:37 -------- d-----w- c:\users\Wolf\AppData\Roaming\Malwarebytes
    2012-06-23 02:37 . 2012-06-23 02:37 -------- d-----w- c:\programdata\Malwarebytes
    2012-06-23 02:37 . 2012-06-23 03:19 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-06-22 12:37 . 2012-06-22 12:37 -------- d-----w- c:\program files (x86)\SDA
    2012-06-22 12:36 . 2012-06-22 13:06 -------- d-----w- c:\users\Wolf\AppData\Local\Downloaded Installations
    2012-06-22 06:49 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
    2012-06-22 06:49 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
    2012-06-22 06:49 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
    2012-06-22 06:48 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
    2012-06-22 06:48 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
    2012-06-22 06:48 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
    2012-06-22 06:48 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
    2012-06-22 06:48 . 2012-06-02 13:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
    2012-06-22 06:48 . 2012-06-02 13:15 36864 ----a-w- c:\windows\system32\wuapp.exe
    2012-06-22 01:42 . 2012-06-22 01:42 -------- d-----w- c:\users\Wolf\AppData\Local\TERA
    2012-06-21 13:20 . 2012-06-21 13:20 839096 ----a-w- c:\windows\system32\deployJava1.dll
    2012-06-21 13:20 . 2012-06-21 13:20 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-06-21 13:20 . 2012-06-21 13:20 -------- d-----w- c:\program files\Java
    2012-06-21 13:18 . 2012-06-21 15:02 -------- d-----w- c:\users\Wolf\AppData\Roaming\.minecraft
    2012-06-21 11:09 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
    2012-06-21 11:09 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
    2012-06-20 21:24 . 2012-06-20 21:24 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2012-06-19 15:16 . 2012-06-19 15:16 -------- d-----w- c:\users\Wolf\AppData\Roaming\Folding@home-x86
    2012-06-19 15:16 . 2012-06-19 15:16 -------- d-----w- c:\program files (x86)\Folding@home
    2012-06-16 14:06 . 2012-06-16 14:06 -------- d-----w- c:\users\Wolf\AppData\Local\Macromedia
    2012-06-16 02:42 . 2012-06-16 02:42 -------- d-----w- c:\program files (x86)\Rockstar Games
    2012-06-16 02:16 . 2012-06-16 02:16 -------- d-----w- c:\programdata\Rockstar Games
    2012-06-15 23:07 . 2012-06-15 23:07 -------- d-----w- c:\program files (x86)\LOLReplay
    2012-06-15 16:58 . 2012-06-15 16:58 -------- d-----w- c:\users\Wolf\AppData\Roaming\RenPy
    2012-06-14 21:42 . 2012-06-14 21:42 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll
    2012-06-14 14:01 . 2012-06-14 18:23 -------- d-----w- c:\programdata\Firefly Studios
    2012-06-14 10:34 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
    2012-06-14 10:34 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
    2012-06-14 10:34 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
    2012-06-14 10:34 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
    2012-06-14 10:34 . 2012-05-04 11:06 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
    2012-06-14 10:34 . 2012-05-04 10:03 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
    2012-06-14 10:34 . 2012-05-04 10:03 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
    2012-06-14 10:34 . 2012-05-15 01:32 3146752 ----a-w- c:\windows\system32\win32k.sys
    2012-06-14 10:34 . 2012-04-28 05:32 1112064 ----a-w- c:\windows\system32\rdpcorets.dll
    2012-06-14 10:34 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
    2012-06-14 10:34 . 2012-04-07 12:31 3216384 ----a-w- c:\windows\system32\msi.dll
    2012-06-14 10:34 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\SysWow64\msi.dll
    2012-06-14 10:33 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
    2012-06-14 10:33 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
    2012-06-14 10:33 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
    2012-06-14 10:33 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
    2012-06-14 10:33 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
    2012-06-14 10:33 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
    2012-06-12 17:21 . 2012-06-12 17:21 -------- d-----w- c:\users\Wolf\AppData\Roaming\ScummVM
    2012-06-12 17:13 . 2012-06-06 23:02 12800 ----a-w- c:\windows\system\wing32.dll
    2012-06-12 17:13 . 2012-06-06 23:01 92208 ----a-w- c:\windows\system\wing.dll
    2012-06-12 17:12 . 2012-06-13 03:37 -------- d-----w- C:\Sword
    2012-06-10 20:19 . 2012-06-10 20:19 -------- d-----w- c:\program files (x86)\AC3Filter
    2012-06-10 19:27 . 2012-06-10 19:27 -------- d-----w- c:\users\Wolf\AppData\Local\DDMSettings
    2012-06-10 19:26 . 2012-06-10 20:18 -------- d-----w- c:\users\Wolf\AppData\Roaming\DivX
    2012-06-10 19:26 . 2012-06-10 19:26 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
    2012-06-10 19:26 . 2012-06-10 19:26 -------- d-----w- c:\program files\DivX
    2012-06-10 19:26 . 2012-06-10 19:26 -------- d-----w- c:\program files (x86)\Common Files\DivX Shared
    2012-06-10 19:25 . 2012-06-10 19:26 -------- d-----w- c:\program files (x86)\DivX
    2012-06-10 19:20 . 2012-06-10 19:26 -------- d-----w- c:\programdata\DivX
    2012-06-08 23:46 . 2012-06-08 23:46 -------- d-----w- c:\users\Wolf\AppData\Local\ArmA 2 Free
    2012-06-08 14:21 . 2002-12-05 12:10 155648 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
    2012-06-08 14:21 . 2003-02-27 14:12 696320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
    2012-06-08 14:21 . 2002-12-02 13:22 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
    2012-06-08 14:21 . 2002-12-02 11:33 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
    2012-06-08 14:21 . 2002-12-02 11:33 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
    2012-06-08 14:21 . 2012-06-08 14:21 282756 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
    2012-06-08 14:21 . 2012-06-08 14:21 163972 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
    2012-06-07 00:06 . 2012-06-07 00:06 -------- d-----w- C:\Nocturnal
    2012-06-06 23:07 . 2012-06-06 23:07 188960 ----a-w- c:\windows\SysWow64\wingde.dll
    2012-06-06 23:02 . 2012-06-06 23:02 6736 ----a-w- c:\windows\SysWow64\wingdib.drv
    2012-06-06 23:02 . 2012-06-06 23:02 5024 ----a-w- c:\windows\SysWow64\wingpal.wnd
    2012-06-06 23:02 . 2012-06-06 23:02 12800 ----a-w- c:\windows\SysWow64\wing32.dll
    2012-06-06 23:01 . 2012-06-06 23:01 92208 ----a-w- c:\windows\SysWow64\wing.dll
    2012-06-06 13:10 . 2012-06-06 13:10 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
    2012-06-06 13:10 . 2012-06-06 13:10 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
    2012-06-05 20:08 . 2012-06-05 20:08 -------- d-----w- c:\program files (x86)\SplitMediaLabs
    2012-06-02 23:08 . 2012-06-02 23:08 -------- d-----w- c:\program files (x86)\BandiMPEG1
    2012-06-02 22:41 . 2008-03-31 19:04 249856 ------w- c:\windows\eiunin21.exe
    2012-06-02 21:46 . 2012-06-02 23:08 -------- d-----w- C:\Download
    2012-06-02 21:46 . 2012-06-02 21:46 446464 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
    2012-06-02 21:46 . 2012-06-02 21:46 235 ----a-w- c:\windows\SysWow64\nxEuUninstall.bat
    2012-06-02 19:06 . 2012-06-13 17:23 -------- d-----w- c:\users\Wolf\AppData\Roaming\TeamViewer
    2012-06-02 16:21 . 2012-06-02 16:21 -------- d-----w- c:\users\Wolf\AppData\Local\eSupport.com
    2012-06-02 16:21 . 2012-06-02 16:21 21712 ----a-w- c:\windows\SysWow64\drivers\DrvAgent64.SYS
    2012-06-02 16:20 . 2012-06-02 16:20 -------- d-----w- c:\users\Wolf\AppData\Roaming\SystemRequirementsLab
    2012-06-02 16:03 . 2012-06-02 23:07 -------- d-----w- C:\Nexon
    2012-06-02 15:13 . 2012-06-02 15:13 -------- d-----w- c:\programdata\Nexon
    2012-06-02 14:10 . 2012-06-02 14:10 -------- d-----w- c:\users\Wolf\AppData\Roaming\DragonSaga
    2012-06-01 16:24 . 2012-06-01 16:24 -------- d-----w- c:\users\Wolf\AppData\Roaming\Highresolution Enterprises
    2012-06-01 16:24 . 2012-06-01 16:24 -------- d-----w- c:\program files\Highresolution Enterprises
    2012-06-01 16:03 . 2012-06-01 16:03 -------- d-----w- c:\programdata\BioWare
    2012-05-31 23:14 . 2012-05-31 23:14 -------- d-----w- c:\users\Wolf\AppData\Local\GameSpy
    2012-05-31 23:14 . 2012-05-31 23:31 -------- d-----w- c:\users\Wolf\AppData\Local\ApplicationHistory
    2012-05-31 22:40 . 2010-08-03 06:41 819200 ----a-w- c:\windows\SysWow64\xvidcore.dll
    2012-05-31 22:40 . 2010-08-03 06:41 180224 ----a-w- c:\windows\SysWow64\xvidvfw.dll
    2012-05-31 22:19 . 2012-05-31 22:19 -------- d-----w- c:\program files (x86)\Common Files\Java
    2012-05-31 22:18 . 2012-05-31 22:18 -------- d-----w- c:\program files (x86)\Oracle
    2012-05-31 22:18 . 2012-05-31 22:18 772552 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
    2012-05-31 22:18 . 2012-04-04 16:47 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2012-05-31 22:18 . 2012-05-31 22:18 -------- d-----w- c:\program files (x86)\Java
    2012-05-31 17:22 . 2012-05-31 17:22 -------- d-----w- c:\program files (x86)\GameSpy
    2012-05-31 17:20 . 2012-05-31 17:20 -------- d-----w- c:\windows\SysWow64\URTTEMP
    2012-05-31 13:37 . 2012-05-31 13:37 -------- d-----w- c:\program files (x86)\Hercules
    2012-05-31 13:37 . 2006-08-01 10:31 3600384 ----a-w- c:\windows\ffmpeg.exe
    2012-05-31 13:06 . 2009-10-19 15:39 29480 ----a-w- c:\windows\SysWow64\libcmmn.dll
    2012-05-31 13:06 . 2009-10-19 15:39 718632 ----a-w- c:\windows\SysWow64\WebCamPropertyWindow.dll
    2012-05-31 13:06 . 2009-10-19 15:39 37672 ----a-w- c:\windows\SysWow64\WebCamKSProxyPlugin.ax
    2012-05-31 13:06 . 2012-05-31 13:06 -------- d-----w- c:\users\Wolf\AppData\Roaming\InstallShield
    2012-05-30 14:02 . 2012-05-30 14:02 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
    2012-05-29 14:49 . 2012-05-29 14:49 -------- d-----w- c:\program files (x86)\PCSX2 0.9.8
    2012-05-29 13:41 . 2012-03-06 15:19 3953632 ----a-w- c:\windows\SysWow64\GameMon.des
    2012-05-29 13:41 . 2012-02-02 22:50 4774 ----a-w- c:\windows\SysWow64\npptNT2.sys
    2012-05-29 13:41 . 2012-02-02 22:50 5265 ----a-w- c:\windows\SysWow64\nppt9x.vxd
    2012-05-29 13:41 . 2012-05-29 13:41 -------- d-----w- c:\program files\Common Files\INCA Shared
    2012-05-28 22:48 . 2012-05-28 22:48 -------- d-----w- c:\users\Wolf\AppData\Roaming\Publish Providers
    2012-05-28 22:46 . 2012-05-28 22:48 -------- d-----w- c:\users\Wolf\AppData\Roaming\Sony
    2012-05-28 22:46 . 2012-05-28 22:46 -------- d-----w- c:\users\Wolf\AppData\Local\Sony
    2012-05-28 22:44 . 2012-05-28 22:44 -------- d-----w- c:\programdata\Sony
    2012-05-28 22:43 . 2012-05-28 22:43 -------- d-----w- c:\program files (x86)\Sony
    2012-05-28 22:38 . 2012-05-31 01:50 -------- d-----w- C:\Fraps
    2012-05-28 20:56 . 2012-05-28 20:56 298016 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-06-23 03:59 . 2012-02-01 14:01 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-06-23 03:59 . 2012-02-01 14:01 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-06-23 03:57 . 2012-02-01 13:40 32320 ----a-w- c:\windows\system32\drivers\FNETTBOH_305.SYS
    2012-05-20 07:49 . 2012-05-20 07:49 71680 ----a-w- c:\windows\system32\frapsv64.dll
    2012-05-20 07:49 . 2012-05-20 07:49 65536 ----a-w- c:\windows\SysWow64\frapsvid.dll
    2012-05-15 10:48 . 2012-02-09 21:43 949056 ----a-w- c:\windows\system32\nvumdshimx.dll
    2012-05-15 10:48 . 2012-02-09 21:43 68928 ----a-w- c:\windows\system32\OpenCL.dll
    2012-05-15 10:48 . 2012-02-09 21:43 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
    2012-05-15 10:48 . 2012-02-01 13:32 8105280 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
    2012-05-15 10:48 . 2012-02-01 13:32 2741568 ----a-w- c:\windows\system32\nvapi64.dll
    2012-05-15 10:48 . 2012-02-01 13:32 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll
    2012-05-15 10:48 . 2012-02-01 13:32 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
    2012-05-15 10:48 . 2012-02-01 13:32 15322432 ----a-w- c:\windows\SysWow64\nvd3dum.dll
    2012-05-15 10:48 . 2012-02-01 13:32 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
    2012-05-15 10:48 . 2012-02-01 13:32 10194752 ----a-w- c:\windows\system32\nvwgf2umx.dll
    2012-05-15 09:29 . 2012-02-01 13:32 889664 ----a-w- c:\windows\system32\nvvsvc.exe
    2012-05-15 09:29 . 2012-02-01 13:32 63296 ----a-w- c:\windows\system32\nvshext.dll
    2012-05-15 09:29 . 2012-02-01 13:32 118080 ----a-w- c:\windows\system32\nvmctray.dll
    2012-05-15 09:29 . 2012-02-01 15:40 2621723 ----a-w- c:\windows\system32\nvcoproc.bin
    2012-05-15 09:29 . 2012-02-01 13:32 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
    2012-05-15 09:28 . 2012-02-01 13:32 6151488 ----a-w- c:\windows\system32\nvcpl.dll
    2012-05-15 00:41 . 2012-02-02 11:06 8955792 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{286F3DF7-F802-42F2-B26B-D46E1B40C69A}\mpengine.dll
    2012-05-15 00:21 . 2012-05-15 00:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe
    2012-03-30 11:35 . 2012-02-01 13:49 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TBPanel"="c:\program files (x86)\Vtune\TBPanel.exe" [2011-08-02 2248704]
    "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-02-01 1242448]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-05-03 17355912]
    "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
    "KPeerNexonEU"="c:\nexon\NEXON_EU_Downloader\nxEULauncher.exe" [2012-06-02 438272]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "XFast USB"="c:\program files (x86)\XFast USB\XFastUsb.exe" [2012-02-01 4878912]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-05-19 909824]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
    "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2011-09-28 1039872]
    "AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
    "BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2011-09-27 646232]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
    "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    LOLRecorder.lnk - c:\program files (x86)\LOLReplay\LOLRecorder.exe [2012-6-12 512000]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "mixer3"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]
    R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 27136]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-23 250056]
    R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;w:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
    R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [2012-06-02 21712]
    R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
    R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-05-26 1038088]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
    R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
    R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x]
    S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
    S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
    S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160]
    S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
    S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760]
    S2 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
    S2 XMouseButton Launcher;XMouseButton Launcher;c:\program files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe [2012-03-04 87040]
    S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x]
    S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x]
    S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [x]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
    S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
    S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-02-01 03:59]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-18 11855976]
    "XFast LAN"="c:\program files\ASRock\XFast LAN\cFosSpeed.exe" [2011-07-04 1441152]
    "THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
    "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-09-03 444856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\Wolf\AppData\Roaming\Mozilla\Firefox\Profiles\sp5n7cz4.default\
    FF - prefs.js: network.proxy.ftp - 107.22.89.10
    FF - prefs.js: network.proxy.ftp_port - 80
    FF - prefs.js: network.proxy.http - 107.22.89.10
    FF - prefs.js: network.proxy.http_port - 80
    FF - prefs.js: network.proxy.socks - 107.22.89.10
    FF - prefs.js: network.proxy.socks_port - 80
    FF - prefs.js: network.proxy.ssl - 107.22.89.10
    FF - prefs.js: network.proxy.ssl_port - 80
    FF - prefs.js: network.proxy.type - 0
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-ASRockXTU - (no file)
    Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file)
    AddRemove-BattlEye A2 Free - c:\program files (x86)\steam\steamapps\common\arma 2 freeBattlEye\UnInstallBE.exe
    AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
    "ImagePath"="c:\windows\system32\GameMon.des -service"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-3201196492-3593950166-1926669991-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    .
    [HKEY_USERS\S-1-5-21-3201196492-3593950166-1926669991-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\SysWOW64\PnkBstrA.exe
    c:\windows\SysWOW64\PnkBstrB.exe
    c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
    .
    **************************************************************************
    .
    Completion time: 2012-06-23 18:24:48 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-06-23 16:24
    .
    Pre-Run: 318,369,976,320 bytes free
    Post-Run: 318,579,556,352 bytes free
    .
    - - End Of File - - 8A864622FC01912CEA1E43995406BBB0
  15. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Looks good :)

    How is computer doing?

    Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/products/malwarebytes_free to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    ===============================================================

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\tasks\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /I " " /c
    dir /b "%systemroot%\*.exe" | find /I " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
  16. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    So far my computer is doing fine, thank you.

    Malwarebytes Anti-Malware (Trial) 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.06.23.01

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Wolf :: WOLF-PC [administrator]

    Protection: Enabled

    6/23/2012 10:15:32 PM
    mbam-log-2012-06-23 (22-15-32).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 227479
    Time elapsed: 1 minute(s), 38 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
    ------------------------------------------------------------------------------------

    OTL logfile created on: 6/23/2012 9:46:17 PM - Run 1
    OTL by OldTimer - Version 3.2.52.0 Folder = C:\Users\Wolf\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    7.98 Gb Total Physical Memory | 5.96 Gb Available Physical Memory | 74.74% Memory free
    15.96 Gb Paging File | 13.60 Gb Available in Paging File | 85.24% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 468.26 Gb Total Space | 296.29 Gb Free Space | 63.27% Space Free | Partition Type: NTFS
    Drive D: | 3.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
    Drive W: | 463.16 Gb Total Space | 194.54 Gb Free Space | 42.00% Space Free | Partition Type: NTFS

    Computer Name: WOLF-PC | User Name: Wolf | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/06/23 21:39:51 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Wolf\Desktop\OTL.exe
    PRC - [2012/06/23 05:59:13 | 001,535,176 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
    PRC - [2012/06/16 15:44:18 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2012/06/12 07:38:14 | 000,512,000 | ---- | M] (LOL Replay) -- C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
    PRC - [2012/06/09 04:02:16 | 000,107,832 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
    PRC - [2012/06/09 04:02:11 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
    PRC - [2012/06/02 23:46:44 | 001,064,960 | ---- | M] () -- C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
    PRC - [2012/05/27 19:36:15 | 000,225,792 | ---- | M] () -- C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe
    PRC - [2012/05/15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    PRC - [2012/05/15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/03/19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
    PRC - [2012/02/01 15:20:59 | 004,878,912 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFast USB\XFastUsb.exe
    PRC - [2011/09/27 05:45:40 | 000,646,232 | ---- | M] () -- C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
    PRC - [2011/08/02 16:38:20 | 002,248,704 | ---- | M] () -- C:\Program Files (x86)\Vtune\TBPANEL.exe
    PRC - [2011/07/29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    PRC - [2011/05/19 12:10:22 | 000,909,824 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe
    PRC - [2011/03/22 10:37:16 | 000,497,480 | ---- | M] (Splashtop Inc.) -- C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/06/23 05:59:13 | 009,459,912 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
    MOD - [2012/06/16 15:44:17 | 002,042,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    MOD - [2012/06/15 17:49:28 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
    MOD - [2012/06/15 17:19:54 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
    MOD - [2012/06/15 17:19:42 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
    MOD - [2012/06/15 17:19:36 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
    MOD - [2012/06/15 17:19:34 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
    MOD - [2012/06/12 07:38:10 | 001,033,728 | ---- | M] () -- C:\Program Files (x86)\LOLReplay\LOLUtils.dll
    MOD - [2012/06/02 23:46:44 | 001,064,960 | ---- | M] () -- C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
    MOD - [2012/05/27 19:36:15 | 000,225,792 | ---- | M] () -- C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe
    MOD - [2012/05/19 08:53:30 | 000,040,448 | ---- | M] () -- C:\Program Files (x86)\LOLReplay\Compression.dll
    MOD - [2012/05/15 02:21:26 | 000,368,448 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
    MOD - [2012/02/02 01:23:18 | 001,707,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll
    MOD - [2012/02/02 01:22:38 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
    MOD - [2012/02/02 01:22:01 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
    MOD - [2012/02/02 01:21:53 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
    MOD - [2012/02/02 01:21:44 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
    MOD - [2012/02/02 01:21:18 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
    MOD - [2012/02/02 01:21:17 | 000,256,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll
    MOD - [2012/02/02 01:21:16 | 017,478,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\107779ca2708d2b31b2e1560e47f6d15\System.ServiceModel.ni.dll
    MOD - [2012/02/02 01:20:50 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
    MOD - [2012/02/02 01:20:15 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
    MOD - [2012/02/02 01:20:13 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
    MOD - [2012/02/02 01:20:12 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
    MOD - [2012/02/02 01:20:07 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
    MOD - [2011/09/27 05:45:40 | 000,646,232 | ---- | M] () -- C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
    MOD - [2011/09/27 05:45:40 | 000,060,504 | ---- | M] () -- C:\Program Files (x86)\Bamboo Dock\BambooWinTab.dll
    MOD - [2011/08/02 16:38:20 | 002,248,704 | ---- | M] () -- C:\Program Files (x86)\Vtune\TBPANEL.exe
    MOD - [2011/07/29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
    MOD - [2011/07/29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    MOD - [1998/10/31 05:55:56 | 000,005,120 | ---- | M] () -- C:\Program Files (x86)\Vtune\TBMANAGE.DLL


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2012/05/26 20:59:41 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
    SRV:64bit: - [2012/03/04 17:40:02 | 000,087,040 | ---- | M] (Highresolution Enterprises) [Auto | Running] -- C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe -- (XMouseButton Launcher)
    SRV:64bit: - [2011/09/08 17:48:36 | 006,583,160 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
    SRV:64bit: - [2011/09/08 17:48:36 | 000,528,760 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
    SRV:64bit: - [2011/07/04 16:19:30 | 000,395,136 | R--- | M] (cFos Software GmbH) [Auto | Running] -- C:\Program Files\ASRock\XFast LAN\spd.exe -- (cFosSpeedS)
    SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV - [2012/06/23 05:59:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/06/20 16:39:19 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2012/06/16 15:44:18 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/06/09 04:02:16 | 000,107,832 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)
    SRV - [2012/06/09 04:02:11 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
    SRV - [2012/05/26 20:59:31 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2012/05/15 12:48:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
    SRV - [2012/05/15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
    SRV - [2012/05/03 09:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/03/19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
    SRV - [2012/03/06 17:19:00 | 003,953,632 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
    SRV - [2011/03/22 10:37:16 | 000,497,480 | ---- | M] (Splashtop Inc.) [Auto | Running] -- C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe -- (WCUService_STC_IE)
    SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
    SRV - [2009/07/26 06:43:14 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- w:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
    SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/06/23 05:57:25 | 000,032,320 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305)
    DRV:64bit: - [2012/04/18 19:08:03 | 000,188,736 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
    DRV:64bit: - [2012/04/04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/03/01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/01 21:53:21 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
    DRV:64bit: - [2012/02/01 15:20:59 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX)
    DRV:64bit: - [2011/09/08 17:49:26 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
    DRV:64bit: - [2011/09/08 17:49:24 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
    DRV:64bit: - [2011/07/29 05:40:57 | 000,079,104 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)
    DRV:64bit: - [2011/07/29 05:40:56 | 000,056,960 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)
    DRV:64bit: - [2011/07/04 16:19:34 | 001,632,128 | ---- | M] (cFos Software GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cfosspeed6.sys -- (cFosSpeed) cFosSpeed for faster Internet connections (NDIS 6)
    DRV:64bit: - [2011/05/10 17:28:48 | 000,017,192 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger)
    DRV:64bit: - [2011/04/21 20:17:04 | 000,471,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/25 07:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
    DRV:64bit: - [2010/11/21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
    DRV:64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
    DRV:64bit: - [2010/11/21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
    DRV:64bit: - [2010/11/21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
    DRV:64bit: - [2010/11/21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
    DRV:64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV:64bit: - [2009/11/18 01:12:00 | 000,032,344 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBfilt64.sys -- (MBfilt)
    DRV:64bit: - [2009/10/19 15:45:54 | 000,039,480 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
    DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (1394hub)
    DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2008/06/27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
    DRV - [2012/06/02 18:21:36 | 000,021,712 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS -- (DrvAgent64)
    DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
    IE - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6C 40 E2 06 51 3E CD 01 [binary data]
    IE - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
    IE - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\..\SearchScopes\{48CF26F1-B732-4809-8172-B0E8236D95A2}: "URL" = http://www.google.com/cse?cx=partne...b-3794288947762788:6976579318&q={searchTerms}
    IE - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    ========== FireFox ==========

    FF - prefs.js..network.proxy.backup.ftp: "200.124.225.230"
    FF - prefs.js..network.proxy.backup.ftp_port: 8080
    FF - prefs.js..network.proxy.backup.socks: "200.124.225.230"
    FF - prefs.js..network.proxy.backup.socks_port: 8080
    FF - prefs.js..network.proxy.backup.ssl: "200.124.225.230"
    FF - prefs.js..network.proxy.backup.ssl_port: 8080
    FF - prefs.js..network.proxy.ftp: "107.22.89.10"
    FF - prefs.js..network.proxy.ftp_port: 80
    FF - prefs.js..network.proxy.http: "107.22.89.10"
    FF - prefs.js..network.proxy.http_port: 80
    FF - prefs.js..network.proxy.share_proxy_settings: true
    FF - prefs.js..network.proxy.socks: "107.22.89.10"
    FF - prefs.js..network.proxy.socks_port: 80
    FF - prefs.js..network.proxy.ssl: "107.22.89.10"
    FF - prefs.js..network.proxy.ssl_port: 80
    FF - prefs.js..network.proxy.type: 0
    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
    FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
    FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/06/10 21:26:46 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/16 15:44:18 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/28 22:53:03 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/16 15:44:18 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/28 22:53:03 | 000,000,000 | ---D | M]

    [2012/02/01 15:46:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wolf\AppData\Roaming\Mozilla\Extensions
    [2012/05/29 17:43:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wolf\AppData\Roaming\Mozilla\Firefox\Profiles\sp5n7cz4.default\extensions
    [2012/02/01 15:46:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2012/06/10 21:26:46 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
    [2012/02/01 16:32:20 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\WOLF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SP5N7CZ4.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
    [2012/05/29 17:43:59 | 000,211,071 | ---- | M] () (No name found) -- C:\USERS\WOLF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SP5N7CZ4.DEFAULT\EXTENSIONS\THEPIRATEBAY@MAFIAAFIRE.COM.XPI
    [2012/06/16 15:44:18 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2010/07/27 16:13:46 | 000,027,136 | ---- | M] (NHN USA Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
    [2012/04/21 03:18:25 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2012/04/21 03:18:25 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    O1 HOSTS File: ([2012/06/23 18:18:58 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [THXCfg64] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
    O4:64bit: - HKLM..\Run: [XFast LAN] C:\Program Files\ASRock\XFast LAN\cfosspeed.exe (cFos Software GmbH)
    O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
    O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [THX TruStudio NB Settings] C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe (Creative Technology Ltd)
    O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
    O4 - HKLM..\Run: [XFast USB] C:\Program Files (x86)\XFast USB\XFastUsb.exe (FNet Co., Ltd.)
    O4 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
    O4 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.)
    O4 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
    O4 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe ()
    O4 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\S-1-5-21-3201196492-3593950166-1926669991-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab (SysInfo Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37BED863-1574-4F28-B793-E62C344B4DB3}: DhcpNameServer = 192.168.1.254
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2011/04/12 11:38:58 | 000,000,122 | R--- | M] () - D:\autorun.inf -- [ UDF ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

    Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
    Drivers32:64bit: vidc.mjpg - bdmjpeg64.dll ()
    Drivers32:64bit: vidc.mpeg - bdmpegv64.dll ()
    Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
    Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
    Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
    Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
    Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
    Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
    Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

    CREATERESTOREPOINT
    System Restore Service not available.
  17. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/06/23 21:39:49 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Wolf\Desktop\OTL.exe
    [2012/06/23 18:27:24 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/06/23 18:24:50 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/06/23 18:07:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/06/23 18:07:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/06/23 18:07:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/06/23 18:07:12 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/06/23 18:06:51 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/06/23 17:16:10 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{8F9356F6-CE63-43B5-83D6-45A507FF9D79}
    [2012/06/23 17:15:59 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{5F058FAA-C157-4A9F-A777-7838376FA504}
    [2012/06/23 05:55:59 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/06/23 05:19:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/06/23 05:19:45 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/06/23 05:15:33 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{BA2FCC45-41CF-4CE1-9A35-DF6C90610EC6}
    [2012/06/23 05:15:23 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{A80C7E37-2C66-42EF-B700-CAD836E02A79}
    [2012/06/23 04:46:50 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{CDDBEACB-4201-4A8D-AF2E-0DFB32D4E345}
    [2012/06/23 04:46:38 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{C1819089-6D43-46EC-9F62-DF51C748EFE8}
    [2012/06/23 04:37:29 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Malwarebytes
    [2012/06/23 04:37:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/06/23 04:37:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/06/23 04:34:20 | 000,000,000 | ---D | C] -- C:\Config.Msi
    [2012/06/22 16:43:06 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{77DABEC5-5C82-451E-9F08-AC88BC745E43}
    [2012/06/22 16:42:53 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{3ED33445-25D4-4BB7-AA43-18DE6DA892B7}
    [2012/06/22 14:37:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter
    [2012/06/22 14:37:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SDA
    [2012/06/22 14:36:29 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\Downloaded Installations
    [2012/06/22 04:42:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{904B9BEC-36D2-42B7-ABD5-6D0BD92B144E}
    [2012/06/22 03:42:11 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\TERA
    [2012/06/22 03:42:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
    [2012/06/22 02:58:23 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Desktop\New folder (2)
    [2012/06/21 16:42:04 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{8C33D810-B9B6-483E-B34E-118A76D469D3}
    [2012/06/21 16:41:54 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{18F95A37-F8CE-4FEE-A2FC-B0335E1C4D06}
    [2012/06/21 15:20:02 | 000,000,000 | ---D | C] -- C:\Program Files\Java
    [2012/06/21 15:18:05 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\.minecraft
    [2012/06/21 04:41:29 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{B258CAE5-67E1-4958-BE42-32FEE0B205DD}
    [2012/06/20 23:24:14 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
    [2012/06/20 16:41:05 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{F9259AB6-1DC3-4E8B-8AC8-9ACCA67DB57F}
    [2012/06/20 16:40:54 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{DB8A37B4-6AE8-4614-9533-7AFD0F18838C}
    [2012/06/20 02:12:15 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{967CB5D5-3013-4872-9DFA-B2CBDE65073B}
    [2012/06/19 17:16:22 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Folding@home-x86
    [2012/06/19 17:16:22 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Folding@home-x86
    [2012/06/19 17:16:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Folding@home
    [2012/06/19 14:11:45 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{34B56388-6578-42AB-9D56-59148B615D56}
    [2012/06/19 14:11:31 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{E7495E72-311F-4F4E-9F23-312AE87026EA}
    [2012/06/18 16:49:37 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{F7C8FF26-2A7C-44BA-A1BE-6E12077664B8}
    [2012/06/17 23:33:46 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Desktop\New folder
    [2012/06/17 16:09:52 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{864C3DB0-747B-4FAB-9441-5A31AA087E0C}
    [2012/06/16 17:18:09 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{81C49DF4-92B8-4818-8C70-98075EAA9A99}
    [2012/06/16 16:06:51 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\Macromedia
    [2012/06/16 04:42:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games
    [2012/06/16 04:41:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
    [2012/06/16 04:16:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Rockstar Games
    [2012/06/16 01:07:38 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\LOLReplay
    [2012/06/16 01:07:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LOLReplay
    [2012/06/15 18:58:14 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\RenPy
    [2012/06/15 18:51:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Katawa Shoujo
    [2012/06/15 17:17:35 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{56F6CB7D-2198-4E18-A4CB-DF4C266BC3FB}
    [2012/06/15 00:28:50 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{6221A1EF-FAC8-4A7D-AA70-6B5507BC541C}
    [2012/06/14 23:43:01 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\Hitman Blood Money
    [2012/06/14 23:42:06 | 000,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt.dll
    [2012/06/14 23:37:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eidos
    [2012/06/14 16:01:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Firefly Studios
    [2012/06/14 12:28:26 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{E3238C17-E207-438F-82A3-EB89356E3DA8}
    [2012/06/14 12:26:49 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{31F9B074-5896-404F-9BF6-E4385BDDF5B3}
    [2012/06/14 12:20:09 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{A6D7F2EE-D2D4-41F2-B3FC-8BD145B0A190}
    [2012/06/14 12:19:31 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{BC331A7B-64D7-432F-82FD-9784E929841B}
    [2012/06/14 05:13:51 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\KOEI
    [2012/06/14 04:55:54 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\Stronghold Crusader
    [2012/06/14 00:19:03 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{41DA6438-34AD-493B-B393-AAF7819B10BA}
    [2012/06/14 00:18:53 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{5ED84925-45EB-494B-96A5-F5B3967C1BF8}
    [2012/06/13 12:18:25 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{69E680C4-A7DF-4C1A-9D8A-0BC66D71EB32}
    [2012/06/13 12:18:08 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{DB1209B6-035D-4466-8757-B893040597D9}
    [2012/06/13 00:04:54 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{78F62976-66E7-43ED-BB9F-D5DF3AC5F3AC}
    [2012/06/13 00:04:44 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{1EBA75EF-77A7-44FE-8A9C-BB81E330A07D}
    [2012/06/12 19:21:01 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\ScummVM
    [2012/06/12 19:12:34 | 000,000,000 | ---D | C] -- C:\Sword
    [2012/06/12 12:04:16 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{B33236EC-D70C-4821-8D05-10DB19CDFE07}
    [2012/06/12 12:04:03 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{29AB2770-F23A-4F39-B983-E42EF3988371}
    [2012/06/11 20:27:26 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\Stronghold 3
    [2012/06/11 20:24:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefly Studios
    [2012/06/11 17:08:10 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{A0EAE8F3-D293-482A-914A-4F450BE3CB89}
    [2012/06/11 17:08:00 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{9C28CCC3-A5D0-480B-8B88-C5A40CA00C3B}
    [2012/06/11 05:07:32 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{5E3AD0B0-35C8-4E43-8572-BD0F9840F37A}
    [2012/06/10 22:19:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3Filter
    [2012/06/10 22:19:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AC3Filter
    [2012/06/10 21:27:44 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\DDMSettings
    [2012/06/10 21:26:37 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\DivX
    [2012/06/10 21:26:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
    [2012/06/10 21:26:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
    [2012/06/10 21:26:06 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
    [2012/06/10 21:26:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
    [2012/06/10 21:25:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
    [2012/06/10 21:20:52 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
    [2012/06/10 17:27:08 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Desktop\Snes
    [2012/06/10 17:07:09 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{7958BFCE-14B8-4F0B-95C9-96460C9F6439}
    [2012/06/10 17:06:59 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{B7E5E7DB-1CB1-4FDB-B085-C2C0D59F575D}
    [2012/06/10 05:05:25 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{5E7DF313-0B3B-4FD1-9C44-C7DF656F2830}
    [2012/06/09 17:05:01 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{DA3EFC53-A72C-4455-BCD6-719EEBAC89AD}
    [2012/06/09 17:04:50 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{5EF250FE-5D75-4BB1-AB3C-B195035F51DF}
    [2012/06/09 04:00:33 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{74197D9F-12B8-4F93-A066-2A5D76826950}
    [2012/06/09 01:46:36 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\ArmA 2 Free
    [2012/06/09 01:46:36 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\ArmA 2
    [2012/06/09 01:46:35 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2012/06/09 01:46:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2012/06/08 16:23:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts
    [2012/06/08 15:59:50 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{F9D3BF70-4F64-48BB-A8F4-E611A769B662}
    [2012/06/08 15:59:40 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{DEA05E89-8748-47D1-B07B-E8D794B8F9B1}
    [2012/06/08 03:59:15 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{DEFB5670-0786-498C-A1E1-F7243588A15A}
    [2012/06/08 02:33:01 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
    [2012/06/07 18:26:32 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Desktop\dolphin
    [2012/06/07 15:58:49 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{FC53B60C-6F6E-4ED4-B40C-009BD43E92B4}
    [2012/06/07 15:58:09 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{AA46DBB4-DB4A-472F-82EB-FBDFC6556532}
    [2012/06/07 03:20:11 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{AC65E5A8-92D1-4634-946A-2E9F7E9A46FB}
    [2012/06/07 02:06:01 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nocturnal Illusion for Windows95
    [2012/06/07 02:06:01 | 000,000,000 | ---D | C] -- C:\Nocturnal
    [2012/06/06 15:19:49 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{7223F4E9-A6ED-4984-9F12-0553BE51A9FA}
    [2012/06/06 15:19:39 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{018EFAE0-DA5F-42D6-9FB4-F021E1130510}
    [2012/06/06 03:19:14 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{77EDE412-92A0-4FE2-B150-A38B2E91C713}
    [2012/06/06 03:19:03 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{AEBC6B16-FA61-472F-B178-7947B70D4644}
    [2012/06/05 22:08:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
    [2012/06/05 22:08:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SplitMediaLabs
    [2012/06/05 15:18:39 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{396C4775-9424-4BB2-A423-6B2436410DE2}
    [2012/06/05 15:18:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{2EE4F770-25FF-4D67-AE38-FF1ECCA34319}
    [2012/06/05 03:18:05 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{669C431C-59C4-4CFA-9965-6CCB0F8DD7E6}
    [2012/06/04 15:17:40 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{4A04846C-C294-40F1-B047-C441C907CCF9}
    [2012/06/04 15:17:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{9E2CB37D-DD5F-4DEC-9A37-4E8E73599B3F}
    [2012/06/04 02:34:49 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{D94B41B9-EF3A-4674-AE3A-1DADE4352553}
    [2012/06/03 14:34:24 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{E64A22F0-D582-4DBC-BE24-0B861F843E90}
    [2012/06/03 14:34:09 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{C91224FA-142A-404C-9C41-94A14AAB6355}
    [2012/06/03 02:30:04 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{E9B1A525-2BB8-4999-A4FA-B4C972C0A7CF}
    [2012/06/03 01:10:57 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\Vindictus EU
    [2012/06/03 01:08:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BandiMPEG1
    [2012/06/03 00:48:24 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\bmw_english4V_95
    [2012/06/03 00:42:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattleMoonWars‹â
    [2012/06/03 00:41:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattleMoonWars‹â ‘æˆê•”
    [2012/06/03 00:41:01 | 000,249,856 | ---- | C] (nobukichi) -- C:\Windows\eiunin21.exe
    [2012/06/02 23:46:48 | 000,000,000 | ---D | C] -- C:\Download
    [2012/06/02 23:46:42 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
    [2012/06/02 23:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
    [2012/06/02 21:06:22 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\TeamViewer
    [2012/06/02 18:21:36 | 000,021,712 | ---- | C] (Phoenix Technologies) -- C:\Windows\SysWow64\drivers\DrvAgent64.SYS
    [2012/06/02 18:21:36 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\eSupport.com
    [2012/06/02 18:20:16 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\SystemRequirementsLab
    [2012/06/02 18:07:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
    [2012/06/02 18:03:09 | 000,000,000 | ---D | C] -- C:\Nexon
    [2012/06/02 18:03:08 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonUS
    [2012/06/02 17:13:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
    [2012/06/02 16:11:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\DragonSaga
    [2012/06/02 16:10:27 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\DragonSaga
    [2012/06/02 14:29:42 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{F03D9EB4-CF0B-4A74-A47B-E056FEB39EDD}
    [2012/06/02 14:29:31 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{2A798180-069D-448F-9C03-618665668D41}
    [2012/06/02 02:29:06 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{72BAC764-B627-4F15-A603-D553B12B02B6}
    [2012/06/01 18:24:59 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Highresolution Enterprises
    [2012/06/01 18:24:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Highresolution Enterprises
    [2012/06/01 18:24:58 | 000,000,000 | ---D | C] -- C:\Program Files\Highresolution Enterprises
    [2012/06/01 18:03:50 | 000,000,000 | ---D | C] -- C:\ProgramData\BioWare
    [2012/06/01 18:01:07 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\BioWare
    [2012/06/01 17:49:05 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\DepthHunter
    [2012/06/01 14:28:43 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{BDF956F0-D59B-4350-AFFF-357CAE62018C}
    [2012/06/01 14:28:31 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{45C6FCE0-68C7-48EE-9121-BAEDFCA89588}
    [2012/06/01 01:31:32 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{30921632-D6C6-470F-8A0C-F20D93AE4ED0}
    [2012/06/01 01:31:14 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{69CA7DA5-AAE2-4F3D-B062-F5ADF10EB800}
    [2012/06/01 01:24:17 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{DFCEAD23-D76A-4193-B976-F76F825D9117}
    [2012/06/01 01:24:07 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{24380E14-2AF3-4C52-A2FC-7DAD465977B8}
    [2012/06/01 01:14:49 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\GameSpy
    [2012/06/01 01:14:04 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\ApplicationHistory
    [2012/06/01 00:24:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    [2012/06/01 00:19:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
    [2012/06/01 00:19:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2012/06/01 00:18:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
    [2012/06/01 00:18:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
    [2012/05/31 19:22:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy
    [2012/05/31 19:22:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameSpy
    [2012/05/31 19:20:55 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\URTTEMP
    [2012/05/31 19:18:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
    [2012/05/31 15:38:15 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\Hercules webcam
    [2012/05/31 15:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hercules
    [2012/05/31 15:37:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hercules
    [2012/05/31 15:06:50 | 000,718,632 | ---- | C] (Guillemot) -- C:\Windows\SysWow64\WebCamPropertyWindow.dll
    [2012/05/31 15:06:50 | 000,029,480 | ---- | C] (Guillemot Corporation S.A.) -- C:\Windows\SysWow64\libcmmn.dll
    [2012/05/31 15:06:23 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\InstallShield
    [2012/05/31 13:23:39 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{47DD7949-55AC-4910-B63E-0625A8C88C07}
    [2012/05/31 13:23:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{C33CF4EE-A3BE-4355-A681-463A8BE50A8B}
    [2012/05/30 21:34:27 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{308AC941-8DFC-4CE8-94F0-EB570AE23E93}
    [2012/05/30 16:02:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Chart Controls
    [2012/05/30 14:28:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon Saga
    [2012/05/30 09:34:02 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{D9ED8115-E416-4B42-93EA-D62BFF6A48D3}
    [2012/05/30 09:33:48 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{3BCE797B-4A95-4C3C-841B-891768931583}
    [2012/05/29 16:49:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
    [2012/05/29 16:49:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PCSX2 0.9.8
    [2012/05/29 15:41:44 | 003,953,632 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\GameMon.des
    [2012/05/29 15:41:39 | 000,004,774 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\npptNT2.sys
    [2012/05/29 15:41:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared
    [2012/05/29 12:32:29 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{1DA6169D-DEBF-47A1-B3DF-FC4F0D7EA61D}
    [2012/05/29 12:32:18 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{65655CD4-236C-47ED-BF7C-D5B292418970}
    [2012/05/29 00:48:34 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Publish Providers
    [2012/05/29 00:46:06 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Sony
    [2012/05/29 00:46:06 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\Sony
    [2012/05/29 00:44:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
    [2012/05/29 00:44:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
    [2012/05/29 00:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
    [2012/05/29 00:38:41 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
    [2012/05/29 00:38:38 | 000,000,000 | ---D | C] -- C:\Fraps
    [2012/05/29 00:31:54 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{FB225DD7-B02B-4BE6-8F32-D5F446DE2EAB}
    [2012/05/29 00:31:43 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{160F752A-7CFD-4058-914C-AEA7BDA6BF80}
    [2012/05/28 22:55:59 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\PunkBuster
    [2012/05/28 22:53:02 | 000,713,312 | ---- | C] (NHN USA) -- C:\Windows\SysWow64\ijjiSetup.exe
    [2012/05/28 22:53:02 | 000,062,048 | ---- | C] (NHN USA Inc.) -- C:\Windows\SysWow64\ijjiProcessRestarter.exe
    [2012/05/28 22:52:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\REACTOR
    [2012/05/28 22:45:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ijji
    [2012/05/28 19:43:36 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\DragonNest
    [2012/05/28 19:12:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cherry De Games
    [2012/05/28 18:05:52 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\Battlefield 3
    [2012/05/28 17:34:52 | 000,000,000 | ---D | C] -- C:\Games
    [2012/05/28 13:14:21 | 000,466,456 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
    [2012/05/28 13:14:21 | 000,444,952 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
    [2012/05/28 13:14:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
    [2012/05/28 13:14:21 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dustforce
    [2012/05/28 12:31:18 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{466B1E6A-4A0C-4E36-8C2B-545561C19512}
    [2012/05/28 12:31:06 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{CD0B5883-D705-4B3F-878D-1CEB81D6E307}
    [2012/05/28 03:32:15 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
    [2012/05/28 00:30:39 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{38946F5D-E76A-4FAC-9F90-365593EAA120}
    [2012/05/28 00:30:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{3B0B234A-AD01-4412-A755-6F9EC247B549}
    [2012/05/27 23:05:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
    [2012/05/27 23:05:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
    [2012/05/27 23:05:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon Age Origins
    [2012/05/27 22:53:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BioWare
    [2012/05/27 19:36:31 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    [2012/05/27 19:36:28 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Wacom
    [2012/05/27 19:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Wacom
    [2012/05/27 19:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bamboo Dock
    [2012/05/27 19:36:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bamboo Dock
    [2012/05/27 19:34:51 | 001,326,456 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Pen_Touch_Tablet.dll
    [2012/05/27 19:34:51 | 001,107,832 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Pen_Touch_Tablet.dll
    [2012/05/27 19:34:51 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\WTablet
    [2012/05/27 19:34:43 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bamboo
    [2012/05/27 19:34:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TabletPlugins
    [2012/05/27 19:34:35 | 000,012,848 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacommousefilter.sys
    [2012/05/27 19:34:29 | 000,016,168 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacomvhid.sys
    [2012/05/27 19:34:27 | 001,392,504 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\WacomMT.dll
    [2012/05/27 19:34:27 | 001,156,472 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wintab32.dll
    [2012/05/27 19:34:27 | 001,152,888 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\WacomMT.dll
    [2012/05/27 19:34:26 | 001,665,400 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Pen_Tablet.dll
    [2012/05/27 19:34:26 | 001,401,208 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wintab32.dll
    [2012/05/27 19:34:23 | 000,000,000 | ---D | C] -- C:\Program Files\Tablet
    [2012/05/27 19:17:14 | 001,369,464 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Pen_Tablet.dll
    [2012/05/27 19:05:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
    [2012/05/27 13:21:27 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\xlive
    [2012/05/27 13:21:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
    [2012/05/27 13:21:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
    [2012/05/27 12:59:33 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\SniperV2
    [2012/05/27 12:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rebellion
    [2012/05/27 12:44:58 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\XBlades
    [2012/05/27 12:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\XBlades
    [2012/05/27 12:33:05 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\BladesOfTime
    [2012/05/27 12:32:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Konami
    [2012/05/27 12:29:57 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{452C3747-247D-49E6-92F9-FF22C9404000}
    [2012/05/27 12:29:46 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{B2C1155D-6711-4A9A-BE54-8C430A6B998F}
    [2012/05/27 04:22:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA
    [2012/05/27 04:17:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paradox Interactive
    [2012/05/26 23:40:31 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\SplitMediaLabs
    [2012/05/26 23:40:02 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
    [2012/05/26 23:38:51 | 000,000,000 | ---D | C] -- C:\ProgramData\SplitMediaLabs
    [2012/05/26 23:37:56 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\SplitMediaLabs
    [2012/05/26 21:46:54 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{525FBECE-BEC1-4B0B-BCDD-A5CB91553E59}
    [2012/05/26 21:46:43 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{CB91DDC8-FE7D-4956-A352-3D8415C5CF6F}
    [2012/05/26 21:18:03 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AdobeLicensingFilesBackup
    [2012/05/26 21:11:40 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
    [2012/05/26 21:04:37 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\Microsoft Games
    [2012/05/26 21:02:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
    [2012/05/26 20:59:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
    [2012/05/26 20:59:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
    [2012/05/26 20:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
    [2012/05/26 20:29:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
    [2012/05/26 20:20:29 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\syncdb
    [2012/05/26 18:28:34 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
    [2012/05/26 17:59:04 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Ambient Design
    [2012/05/26 17:17:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\portalgraphics
    [2012/05/26 17:17:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\portalgraphics
    [2012/05/26 17:11:03 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\portalgraphics
    [2012/05/26 16:25:26 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Autodesk
    [2012/05/26 16:25:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Alias
    [2012/05/26 16:25:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
    [2012/05/26 16:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Autodesk
    [2012/05/26 16:23:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
    [2012/05/26 15:47:37 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\Adobe
    [2012/05/26 12:00:04 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\SKIDROW
    [2012/05/26 12:00:04 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\BigHugeEngine
    [2012/05/26 10:15:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
    [2012/05/26 09:46:18 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{5634B62E-A929-4F3F-97F4-35CD08166140}
    [2012/05/26 09:46:07 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{A5BF4313-036F-4A54-A8FA-9DA6C12A656C}
    [2012/05/26 00:32:55 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\.inapptracking
    [2012/05/26 00:31:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Generations
    [2012/05/25 22:30:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
    [2012/05/25 21:44:42 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\IW4M
    [2012/05/25 17:03:42 | 000,000,000 | ---D | C] -- C:\Users\Wolf\Documents\CAPCOM
    [2012/05/25 17:03:42 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\CAPCOM
    [2012/05/25 15:50:33 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{93B44AF1-3B18-4C2A-B279-24923486D8F6}
    [2012/05/25 15:50:21 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Local\{3157081A-C7D3-4452-9C7E-F0E660292DB2}
    [2012/05/25 13:59:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge
    [2012/05/25 13:59:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gameforge
    [2012/05/25 13:30:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2012/05/25 13:30:50 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2012/05/25 13:30:44 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2012/05/25 13:29:56 | 000,000,000 | ---D | C] -- C:\Users\Wolf\AppData\Roaming\WinRAR
    [2012/05/25 13:29:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
    [2012/05/25 12:44:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2012/05/25 12:44:21 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  18. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    ========== Files - Modified Within 30 Days ==========

    [2012/06/23 21:59:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/06/23 21:39:51 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Wolf\Desktop\OTL.exe
    [2012/06/23 18:34:25 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/06/23 18:34:25 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/06/23 18:27:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/06/23 18:26:55 | 2131,460,095 | -HS- | M] () -- C:\hiberfil.sys
    [2012/06/23 18:18:58 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/06/23 18:05:21 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2012/06/23 18:05:13 | 000,709,226 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
    [2012/06/23 18:05:13 | 000,632,708 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/06/23 18:05:13 | 000,412,224 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat
    [2012/06/23 18:05:13 | 000,400,916 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
    [2012/06/23 18:05:13 | 000,137,788 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
    [2012/06/23 18:05:13 | 000,110,342 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
    [2012/06/23 18:05:13 | 000,110,342 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/06/23 18:05:13 | 000,108,630 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat
    [2012/06/23 18:05:12 | 000,662,236 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
    [2012/06/23 18:05:12 | 000,134,232 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
    [2012/06/23 05:57:25 | 000,032,320 | ---- | M] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS
    [2012/06/23 05:19:47 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/06/22 03:42:11 | 000,000,617 | ---- | M] () -- C:\Users\Public\Desktop\TERA-Launcher.lnk
    [2012/06/22 02:37:10 | 003,396,364 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/06/21 15:17:40 | 000,001,063 | ---- | M] () -- C:\Users\Wolf\Desktop\Minecraft - Shortcut.lnk
    [2012/06/16 01:07:38 | 000,001,997 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
    [2012/06/16 01:07:38 | 000,001,905 | ---- | M] () -- C:\Users\Public\Desktop\LOL Recorder.lnk
    [2012/06/15 18:51:28 | 000,000,797 | ---- | M] () -- C:\Users\Wolf\Desktop\Katawa Shoujo.lnk
    [2012/06/15 17:15:29 | 004,903,968 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/06/14 23:42:06 | 000,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt.dll
    [2012/06/09 04:02:16 | 000,107,832 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
    [2012/06/09 04:02:11 | 000,066,872 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
    [2012/06/07 02:05:59 | 000,000,223 | ---- | M] () -- C:\Windows\MugE.ini
    [2012/06/03 01:11:06 | 000,001,234 | ---- | M] () -- C:\Users\Wolf\Desktop\Vindictus - Shortcut.lnk
    [2012/06/02 23:46:42 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
    [2012/06/02 23:46:42 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
    [2012/06/02 18:21:36 | 000,021,712 | ---- | M] (Phoenix Technologies) -- C:\Windows\SysWow64\drivers\DrvAgent64.SYS
    [2012/06/01 01:14:28 | 000,000,092 | ---- | M] () -- C:\Users\Wolf\AppData\Local\fusioncache.dat
    [2012/05/31 19:22:17 | 000,001,995 | ---- | M] () -- C:\Users\Wolf\Application Data\Microsoft\Internet Explorer\Quick Launch\GameSpy Comrade.lnk
    [2012/05/31 19:21:26 | 003,475,636 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/05/31 19:18:07 | 000,001,298 | ---- | M] () -- C:\Users\Public\Desktop\Crysis.lnk
    [2012/05/30 14:28:06 | 000,001,802 | ---- | M] () -- C:\Users\Public\Desktop\Dragon Saga.lnk
    [2012/05/29 16:49:14 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
    [2012/05/29 15:41:14 | 000,002,105 | ---- | M] () -- C:\Users\Public\Desktop\A.V.A.lnk
    [2012/05/29 00:48:06 | 000,002,560 | ---- | M] () -- C:\Users\Wolf\Documents\Register Vegas Pro.htm
    [2012/05/29 00:44:09 | 000,001,908 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
    [2012/05/29 00:38:41 | 000,000,562 | ---- | M] () -- C:\Users\Wolf\Desktop\Fraps.lnk
    [2012/05/28 22:56:05 | 000,298,016 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
    [2012/05/28 22:53:37 | 000,001,933 | ---- | M] () -- C:\Users\Wolf\Application Data\Microsoft\Internet Explorer\Quick Launch\ijji REACTOR.lnk
    [2012/05/28 22:53:37 | 000,001,907 | ---- | M] () -- C:\Users\Public\Desktop\ijji REACTOR.lnk
    [2012/05/28 20:11:43 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
    [2012/05/28 19:58:49 | 003,130,440 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_blr.exe
    [2012/05/28 19:12:12 | 000,000,796 | ---- | M] () -- C:\Users\Public\Desktop\Dragon Nest.lnk
    [2012/05/28 13:14:22 | 000,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
    [2012/05/28 13:14:21 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
    [2012/05/28 13:14:21 | 000,000,725 | ---- | M] () -- C:\Users\Wolf\Desktop\Dustforce.lnk
    [2012/05/27 23:05:28 | 000,000,754 | ---- | M] () -- C:\Users\Public\Desktop\Dragon Age Origins.lnk
    [2012/05/27 19:36:22 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Bamboo Dock.lnk
    [2012/05/27 13:22:10 | 000,001,003 | ---- | M] () -- C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
    [2012/05/27 12:57:41 | 000,001,095 | ---- | M] () -- C:\Users\Public\Desktop\Sniper Elite V2.lnk
    [2012/05/27 12:46:47 | 000,000,422 | ---- | M] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
    [2012/05/27 12:32:25 | 000,000,984 | ---- | M] () -- C:\Users\Public\Desktop\Blades of Time.lnk
    [2012/05/27 04:17:21 | 000,000,999 | ---- | M] () -- C:\Users\Public\Desktop\Magicka.lnk
    [2012/05/26 23:07:14 | 000,000,857 | ---- | M] () -- C:\Users\Wolf\Desktop\League of Legends.lnk
    [2012/05/26 21:20:24 | 000,001,727 | ---- | M] () -- C:\Users\Wolf\Desktop\Photoshop - Shortcut.lnk
    [2012/05/26 17:17:56 | 000,001,181 | ---- | M] () -- C:\Users\Public\Desktop\openCanvas5e.lnk
    [2012/05/26 16:25:26 | 000,002,180 | ---- | M] () -- C:\Users\Wolf\Application Data\Microsoft\Internet Explorer\Quick Launch\Autodesk SketchBookPro 2011.lnk
    [2012/05/26 16:25:26 | 000,002,156 | ---- | M] () -- C:\Users\Public\Desktop\Autodesk SketchBookPro 2011.lnk
    [2012/05/26 16:24:03 | 000,001,152 | ---- | M] () -- C:\Users\Wolf\Desktop\Play IW4M (Modern Warfare 2).lnk
    [2012/05/26 16:23:29 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Worms Ultimate Mayhem.lnk
    [2012/05/26 11:58:41 | 000,001,185 | ---- | M] () -- C:\Users\Wolf\Desktop\Dead Island.lnk
    [2012/05/26 10:15:15 | 000,001,083 | ---- | M] () -- C:\Users\Public\Desktop\Kingdoms of Amalur Reckoning.lnk
    [2012/05/26 00:31:27 | 000,000,786 | ---- | M] () -- C:\Users\Public\Desktop\Sonic Generations.lnk
    [2012/05/25 20:12:09 | 000,001,309 | ---- | M] () -- C:\Users\Wolf\Desktop\Devil May Cry 4.lnk
    [2012/05/25 13:59:46 | 000,002,213 | ---- | M] () -- C:\Users\Public\Desktop\AION Free-To-Play.lnk
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/06/23 18:07:21 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/06/23 18:07:21 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/06/23 18:07:21 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/06/23 18:07:21 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/06/23 18:07:21 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/06/23 05:19:47 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/06/22 03:42:11 | 000,000,617 | ---- | C] () -- C:\Users\Public\Desktop\TERA-Launcher.lnk
    [2012/06/21 15:17:40 | 000,001,063 | ---- | C] () -- C:\Users\Wolf\Desktop\Minecraft - Shortcut.lnk
    [2012/06/16 01:07:38 | 000,001,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
    [2012/06/16 01:07:38 | 000,001,917 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk
    [2012/06/16 01:07:38 | 000,001,905 | ---- | C] () -- C:\Users\Public\Desktop\LOL Recorder.lnk
    [2012/06/15 18:51:28 | 000,000,797 | ---- | C] () -- C:\Users\Wolf\Desktop\Katawa Shoujo.lnk
    [2012/06/07 02:05:59 | 000,000,223 | ---- | C] () -- C:\Windows\MugE.ini
    [2012/06/03 01:11:06 | 000,001,234 | ---- | C] () -- C:\Users\Wolf\Desktop\Vindictus - Shortcut.lnk
    [2012/06/02 23:46:42 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
    [2012/06/01 01:14:28 | 000,000,092 | ---- | C] () -- C:\Users\Wolf\AppData\Local\fusioncache.dat
    [2012/06/01 00:40:24 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2012/06/01 00:40:24 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2012/05/31 19:22:17 | 000,001,995 | ---- | C] () -- C:\Users\Wolf\Application Data\Microsoft\Internet Explorer\Quick Launch\GameSpy Comrade.lnk
    [2012/05/31 19:18:07 | 000,001,298 | ---- | C] () -- C:\Users\Public\Desktop\Crysis.lnk
    [2012/05/31 15:37:47 | 003,600,384 | ---- | C] () -- C:\Windows\ffmpeg.exe
    [2012/05/31 15:06:50 | 000,037,672 | ---- | C] () -- C:\Windows\SysWow64\WebCamKSProxyPlugin.ax
    [2012/05/30 14:28:06 | 000,001,802 | ---- | C] () -- C:\Users\Public\Desktop\Dragon Saga.lnk
    [2012/05/29 16:49:14 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
    [2012/05/29 15:41:38 | 000,005,265 | ---- | C] () -- C:\Windows\SysWow64\nppt9x.vxd
    [2012/05/29 15:41:14 | 000,002,105 | ---- | C] () -- C:\Users\Public\Desktop\A.V.A.lnk
    [2012/05/29 00:48:06 | 000,002,560 | ---- | C] () -- C:\Users\Wolf\Documents\Register Vegas Pro.htm
    [2012/05/29 00:44:09 | 000,001,908 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
    [2012/05/29 00:38:41 | 000,000,562 | ---- | C] () -- C:\Users\Wolf\Desktop\Fraps.lnk
    [2012/05/28 22:56:04 | 000,298,016 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
    [2012/05/28 22:53:37 | 000,001,933 | ---- | C] () -- C:\Users\Wolf\Application Data\Microsoft\Internet Explorer\Quick Launch\ijji REACTOR.lnk
    [2012/05/28 22:53:37 | 000,001,907 | ---- | C] () -- C:\Users\Public\Desktop\ijji REACTOR.lnk
    [2012/05/28 20:11:36 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
    [2012/05/28 19:12:12 | 000,000,796 | ---- | C] () -- C:\Users\Public\Desktop\Dragon Nest.lnk
    [2012/05/28 18:03:59 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
    [2012/05/28 18:03:59 | 000,107,832 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
    [2012/05/28 18:03:58 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
    [2012/05/28 17:34:57 | 002,580,552 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
    [2012/05/28 13:14:21 | 000,000,725 | ---- | C] () -- C:\Users\Wolf\Desktop\Dustforce.lnk
    [2012/05/27 23:05:28 | 000,000,754 | ---- | C] () -- C:\Users\Public\Desktop\Dragon Age Origins.lnk
    [2012/05/27 19:36:22 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Bamboo Dock.lnk
    [2012/05/27 19:34:23 | 000,000,488 | ---- | C] () -- C:\Windows\SysNative\PenTabletUserDefaults.xml
    [2012/05/27 13:22:10 | 000,001,003 | ---- | C] () -- C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
    [2012/05/27 12:57:41 | 000,001,095 | ---- | C] () -- C:\Users\Public\Desktop\Sniper Elite V2.lnk
    [2012/05/27 12:44:56 | 000,000,422 | ---- | C] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
    [2012/05/27 12:32:25 | 000,000,984 | ---- | C] () -- C:\Users\Public\Desktop\Blades of Time.lnk
    [2012/05/27 04:17:21 | 000,000,999 | ---- | C] () -- C:\Users\Public\Desktop\Magicka.lnk
    [2012/05/26 23:07:14 | 000,000,857 | ---- | C] () -- C:\Users\Wolf\Desktop\League of Legends.lnk
    [2012/05/26 21:20:24 | 000,001,727 | ---- | C] () -- C:\Users\Wolf\Desktop\Photoshop - Shortcut.lnk
    [2012/05/26 21:05:15 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4 (64 Bit).lnk
    [2012/05/26 21:03:24 | 000,001,099 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS4.lnk
    [2012/05/26 20:59:56 | 000,001,407 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS4.lnk
    [2012/05/26 20:36:56 | 000,001,075 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
    [2012/05/26 20:36:00 | 000,001,211 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
    [2012/05/26 20:34:50 | 000,001,037 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
    [2012/05/26 20:34:20 | 000,001,173 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
    [2012/05/26 20:30:56 | 000,001,357 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
    [2012/05/26 20:30:51 | 000,001,523 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
    [2012/05/26 18:26:44 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
    [2012/05/26 17:17:56 | 000,001,181 | ---- | C] () -- C:\Users\Public\Desktop\openCanvas5e.lnk
    [2012/05/26 16:25:26 | 000,002,180 | ---- | C] () -- C:\Users\Wolf\Application Data\Microsoft\Internet Explorer\Quick Launch\Autodesk SketchBookPro 2011.lnk
    [2012/05/26 16:25:26 | 000,002,156 | ---- | C] () -- C:\Users\Public\Desktop\Autodesk SketchBookPro 2011.lnk
    [2012/05/26 16:24:03 | 000,001,152 | ---- | C] () -- C:\Users\Wolf\Desktop\Play IW4M (Modern Warfare 2).lnk
    [2012/05/26 16:23:29 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Worms Ultimate Mayhem.lnk
    [2012/05/26 16:10:13 | 000,000,488 | ---- | C] () -- C:\Windows\SysNative\PenTouchTabletUserDefaults.xml
    [2012/05/26 11:58:41 | 000,001,185 | ---- | C] () -- C:\Users\Wolf\Desktop\Dead Island.lnk
    [2012/05/26 10:15:15 | 000,001,083 | ---- | C] () -- C:\Users\Public\Desktop\Kingdoms of Amalur Reckoning.lnk
    [2012/05/26 00:31:27 | 000,000,786 | ---- | C] () -- C:\Users\Public\Desktop\Sonic Generations.lnk
    [2012/05/25 21:44:47 | 000,001,152 | ---- | C] () -- C:\Users\Wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play IW4M (Modern Warfare 2).lnk
    [2012/05/25 20:12:09 | 000,001,309 | ---- | C] () -- C:\Users\Wolf\Desktop\Devil May Cry 4.lnk
    [2012/05/25 17:57:32 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
    [2012/05/25 17:57:04 | 003,475,636 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/05/25 13:59:44 | 000,002,213 | ---- | C] () -- C:\Users\Public\Desktop\AION Free-To-Play.lnk
    [2012/05/15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
    [2012/02/01 20:17:09 | 000,000,017 | ---- | C] () -- C:\Users\Wolf\AppData\Local\resmon.resmoncfg
    [2012/02/01 15:22:24 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
    [2012/02/01 15:22:24 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
    [2012/02/01 15:22:24 | 000,001,424 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
    [2012/02/01 15:22:24 | 000,001,323 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
    [2012/02/01 15:22:24 | 000,001,323 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
    [2012/02/01 15:21:12 | 000,000,003 | ---- | C] () -- C:\Users\Wolf\AppData\Local\user_data.ini
    [2011/05/31 08:39:50 | 000,058,368 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
    [2011/05/31 08:38:18 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
    [2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat

    ========== LOP Check ==========

    [2012/06/21 17:02:21 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\.minecraft
    [2012/05/26 17:59:04 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Ambient Design
    [2012/05/26 16:25:26 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Autodesk
    [2012/02/01 21:58:45 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\DAEMON Tools Lite
    [2012/02/01 17:27:18 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\DeviceVm
    [2012/06/02 16:10:27 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\DragonSaga
    [2012/06/19 17:16:22 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Folding@home-x86
    [2012/06/01 18:24:59 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Highresolution Enterprises
    [2012/02/01 18:00:41 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\LolClient2
    [2012/05/26 17:11:03 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\portalgraphics
    [2012/05/29 00:48:34 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Publish Providers
    [2012/06/15 18:58:14 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\RenPy
    [2012/06/12 19:21:01 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\ScummVM
    [2012/05/29 00:48:32 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Sony
    [2012/05/26 23:37:56 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\SplitMediaLabs
    [2012/06/02 18:20:16 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\SystemRequirementsLab
    [2012/06/13 19:23:32 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\TeamViewer
    [2012/02/02 08:28:23 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Ubisoft
    [2012/06/23 15:12:14 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\uTorrent
    [2012/05/27 19:36:28 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\Wacom
    [2012/05/27 19:36:31 | 000,000,000 | ---D | M] -- C:\Users\Wolf\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    [2009/07/14 07:08:49 | 000,015,352 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========

    < %SYSTEMDRIVE%\*.* >
    [2012/06/23 18:24:48 | 000,027,840 | ---- | M] () -- C:\ComboFix.txt
    [2012/06/22 15:04:31 | 000,003,003 | ---- | M] () -- C:\formatter.log
    [2012/06/23 18:26:55 | 2131,460,095 | -HS- | M] () -- C:\hiberfil.sys
    [2006/12/01 23:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
    [2012/06/23 18:26:58 | 4273,602,559 | -HS- | M] () -- C:\pagefile.sys

    < %systemroot%\Fonts\*.com >
    [2009/07/14 07:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2009/07/14 07:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2009/07/14 07:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/07/14 07:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2009/06/10 22:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2009/07/14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2012/02/01 17:39:49 | 000,000,221 | -HS- | M] () -- C:\Users\Wolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2012/06/23 21:39:51 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Wolf\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\tasks\*.* >
    [2012/06/23 21:59:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/06/23 18:27:07 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2009/07/14 07:08:49 | 000,015,352 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >
    [2009/06/10 23:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2012/02/01 16:20:37 | 000,000,402 | -HS- | M] () -- C:\Users\Wolf\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /I " " /c >

    < dir /b "%systemroot%\*.exe" | find /I " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >

    < End of report >
     
  19. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    OTL Extras logfile created on: 6/23/2012 9:46:17 PM - Run 1
    OTL by OldTimer - Version 3.2.52.0 Folder = C:\Users\Wolf\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    7.98 Gb Total Physical Memory | 5.96 Gb Available Physical Memory | 74.74% Memory free
    15.96 Gb Paging File | 13.60 Gb Available in Paging File | 85.24% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 468.26 Gb Total Space | 296.29 Gb Free Space | 63.27% Space Free | Partition Type: NTFS
    Drive D: | 3.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
    Drive W: | 463.16 Gb Total Space | 194.54 Gb Free Space | 42.00% Space Free | Partition Type: NTFS

    Computer Name: WOLF-PC | User Name: Wolf | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-3201196492-3593950166-1926669991-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
    "{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
    "{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
    "{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
    "{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
    "{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
    "{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
    "{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
    "{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
    "{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "TCP Query User{0E539D30-2F66-4F91-9DD3-CAB769666F00}C:\program files (x86)\pando networks\media booster\pmb.exe" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "TCP Query User{ABC05356-D752-4C0E-9A81-3B549909168D}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
    "TCP Query User{CD7A3A33-5914-4D96-BC69-20FFB256FAC3}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "UDP Query User{53A1CEC3-7135-43BA-AA63-B65B89887DC7}C:\program files (x86)\pando networks\media booster\pmb.exe" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "UDP Query User{E165CBBF-A934-4EE8-9477-7D7772C99251}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "UDP Query User{E9704D4F-ABC1-4953-BC6B-6FAE0EF2DC41}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
    "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
    "{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
    "{2770B8D8-701A-1D22-635F-8711DFC06B92}" = ATI Catalyst Install Manager
    "{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
    "{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
    "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
    "{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
    "{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
    "{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
    "{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
    "{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
    "{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
    "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
    "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
    "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 301.42
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 301.42
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 301.42
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 301.42
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.16.0
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
    "{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
    "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
    "{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "ASRock App Charger_is1" = ASRock App Charger v1.0.5
    "DriverAgent.exe" = DriverAgent by eSupport.com
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Pen Tablet Driver" = Bamboo
    "WinRAR archiver" = WinRAR 4.11 (64-bit)
    "XFast LAN" = XFast LAN v6.61

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
    "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
    "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
    "{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
    "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
    "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
    "{0FCDA0F8-F3E5-402E-B9B6-13CB2B01182B}" = TERA
    "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
    "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
    "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
    "{1AA94747-3BF6-4237-9E1A-7B3067738FE1}" = Max Payne 3
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4
    "{27018D57-D152-44EF-BCE0-5E3B3445EABE}" = X-Blades
    "{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager
    "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
    "{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
    "{3566D7DB-EA10-49DE-A95B-F4AB41FC0A93}" = Dragon Nest SEA
    "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
    "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
    "{3AF8C37F-696E-871C-0851-CDE980FD665E}" = Bamboo Dock
    "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
    "{43430FA5-AF68-4A2D-A7D4-891000008200}" = Street Fighter X Tekken
    "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
    "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{5BDA2F58-1F21-4D10-9910-92B01EBCC958}" = AMD USB Filter Driver
    "{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
    "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
    "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
    "{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
    "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}" = AION Free-To-Play
    "{6B755EC3-C709-4F5C-BC58-BC0D3967B6B6}" = Folding@home-x86
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{73E80655-FB3C-46F4-BE00-62D248BC490A}" = Visual C++ 2008 Runtime (x64)
    "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
    "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
    "{807D33FC-2F92-413D-BA30-96CE5AA6C38C}" = Dragon Saga
    "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
    "{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
    "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader Extreme
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}" = REACTOR
    "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
    "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
    "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
    "{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
    "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
    "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{A5355F15-F98B-4704-9BAE-E53B9FE48F48}" = SDFormatter
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}" = Hitman Blood Money
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
    "{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
    "{AFB907F5-C0E6-4753-8284-DE955EF86AC2}" = THX TruStudio
    "{B1549CC1-EB81-4E7C-9C7C-8B97CD9FD37A}" = Classic Link Drivers
    "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
    "{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
    "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
    "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
    "{C3C44248-B8F7-4B20-A5C7-994870B60F55}" = Hercules Webcam Station Evolution SE
    "{C3DE64C5-5621-4A75-B44D-FBDEF8DE0ADB}" = WARRIORS OROCHI
    "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
    "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D4E5A687-797D-44B1-8F96-4FD7A24166A9}" = DEVIL MAY CRY 4
    "{D586BF67-0A61-4572-BE25-07B40C4CEDA1}" = Adobe Photoshop CS6
    "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
    "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
    "{DC785DB7-D389-48C3-B146-96FE99BF4E2B}" = Vegas Pro 9.0
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
    "{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
    "{E00F999C-80D1-460F-BCE1-CD0140215CBC}}_is1" = openCanvas 5.1.04
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E3F2803C-B6FA-4D36-8CFE-A8AE92683E92}" = XSplit
    "{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
    "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
    "{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
    "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9
    "{F0B27584-72DD-4CED-A329-57C7F91586C0}" = Autodesk SketchBookPro 2011
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
    "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
    "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
    "{FD416706-875C-4B0B-A23A-9E740DAE029E}" = Tom Clancy's Rainbow Six Vegas 2
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "AC3Filter_is1" = AC3Filter 2.4a
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
    "ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.122
    "ASRock InstantBoot_is1" = ASRock InstantBoot v1.29
    "Bamboo Dock" = Bamboo Dock
    "BandiMPEG1" = Bandisoft MPEG-1 Decoder
    "BattleMoonWars‹â ‘æˆê•”" = BattleMoonWars‹â ‘æˆê•”
    "BattleMoonWars‹â ‘æƒj•”" = BattleMoonWars‹â ‘æ“ñ•”
    "BattleMoonWars‹â ‘æŽl•”" = BattleMoonWars‹â ‘æŽl•”
    "BattleMoonWars‹â ‘æŽO•”" = BattleMoonWars‹â ‘æŽO•”
    "BattlEye A2 Free" = BattlEye (A2Free) Uninstall
    "Blades of Time_is1" = Blades of Time
    "Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2
    "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "DAEMON Tools Lite" = DAEMON Tools Lite
    "Diablo III" = Diablo III
    "DivX Setup" = DivX Setup
    "Fraps" = Fraps (remove only)
    "InstallShield_{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}" = AION Free-To-Play
    "Katawa Shoujo" = Katawa Shoujo
    "Kingdoms of Amalur Reckoning_is1" = Kingdoms of Amalur Reckoning
    "LOLReplay" = LOLReplay
    "Magicka_is1" = Magicka
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
    "MapleStory" = MapleStory
    "Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "MySSID_is1" = Vtune 7.21
    "NCLauncher_GameForge" = NC Launcher (GameForge)
    "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "OpenAL" = OpenAL
    "pcsx2-r4600" = PCSX2 - Playstation 2 Emulator
    "PunkBusterSvc" = PunkBuster Services
    "Rockstar Games Social Club" = Rockstar Games Social Club
    "Sniper Elite V2_is1" = Sniper Elite V2
    "Sonic Generations_is1" = Sonic Generations
    "Steam App 1250" = Killing Floor
    "Steam App 24200" = DC Universe Online
    "Stronghold 3_is1" = Stronghold 3
    "TeamViewer 7" = TeamViewer 7
    "Tomb Raider: Underworld" = Tomb Raider: Underworld 1.0
    "uTorrent" = µTorrent
    "Vindictus EU" = Vindictus EU
    "Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
    "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin
    "Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
    "wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1" = Bamboo Dock
    "WinLiveSuite" = Windows Live Essentials
    "WinRAR archiver" = WinRAR 4.11 (32-bit)
    "Worms Ultimate Mayhem_is1" = Worms Ultimate Mayhem
    "XFast USB" = XFast USB
    "X-Mouse Button Control" = X-Mouse Button Control 2.4

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 6/22/2012 10:25:40 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/22/2012 10:42:08 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/22/2012 10:46:09 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/22/2012 10:53:33 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/22/2012 11:15:12 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/22/2012 11:26:31 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/22/2012 11:56:46 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/23/2012 9:33:32 AM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/23/2012 12:03:05 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/23/2012 12:19:49 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 6/23/2012 12:28:46 PM | Computer Name = Wolf-PC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 6/23/2012 9:32:38 AM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7023
    Description = The Function Discovery Resource Publication service terminated with
    the following error: %%-2147024891

    Error - 6/23/2012 12:01:27 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7003
    Description = The IKE and AuthIP IPsec Keying Modules service depends the following
    service: BFE. This service might not be installed.

    Error - 6/23/2012 12:01:28 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7003
    Description = The IPsec Policy Agent service depends the following service: BFE.
    This service might not be installed.

    Error - 6/23/2012 12:01:32 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7023
    Description = The Computer Browser service terminated with the following error:
    %%1060

    Error - 6/23/2012 12:02:01 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7001
    Description = The HomeGroup Provider service depends on the Function Discovery Resource
    Publication service which failed to start because of the following error: %%-2147024891

    Error - 6/23/2012 12:02:01 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7023
    Description = The Function Discovery Resource Publication service terminated with
    the following error: %%-2147024891

    Error - 6/23/2012 12:13:52 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 6/23/2012 12:16:20 PM | Computer Name = Wolf-PC | Source = Application Popup | ID = 1060
    Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility
    with this system. Please contact your software vendor for a compatible version
    of the driver.

    Error - 6/23/2012 12:16:54 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 6/23/2012 12:18:11 PM | Computer Name = Wolf-PC | Source = Service Control Manager | ID = 7023
    Description = The Windows Defender service terminated with the following error:
    %%126


    < End of report >
  20. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    OTL logs look good.

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.


    3. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    4. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  21. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    Results of screen317's Security Check version 0.99.24
    Windows 7 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    JavaFX 2.1.0
    Java(TM) 7 Update 4
    Out of date Java installed!
    Adobe Flash Player 11.3.300.262
    Mozilla Firefox (x86 en-US..)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Malwarebytes' Anti-Malware mbamservice.exe
    Malwarebytes' Anti-Malware mbamgui.exe
    ``````````End of Log````````````


    -------------



    Farbar Service Scanner Version: 23-06-2012
    Ran by Wolf (administrator) on 24-06-2012 at 05:21:10
    Running from "C:\Users\Wolf\Downloads"
    Microsoft Windows 7 Ultimate Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo IP is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============

    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============

    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => MD5 is legit
    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\System32\dhcpcore.dll => MD5 is legit
    C:\Windows\System32\drivers\afd.sys => MD5 is legit
    C:\Windows\System32\drivers\tdx.sys => MD5 is legit
    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\System32\dnsrslvr.dll => MD5 is legit
    C:\Windows\System32\mpssvc.dll => MD5 is legit
    C:\Windows\System32\bfe.dll => MD5 is legit
    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\System32\SDRSVC.dll => MD5 is legit
    C:\Windows\System32\vssvc.exe => MD5 is legit
    C:\Windows\System32\wscsvc.dll => MD5 is legit
    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\System32\wuaueng.dll => MD5 is legit
    C:\Windows\System32\qmgr.dll => MD5 is legit
    C:\Windows\System32\es.dll => MD5 is legit
    C:\Windows\System32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit


    **** End of log ****
  22. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    Right now its doing the ESET free online scanner, it found 4 threats so far:
    Win64/Sirefef.AE Trojan
    Win64/Sirefef.AI Trojan
    Win64/Sirefef.W Trojan
    Win64/Patched.B.Gen.trojan

    Malwarebytes anti-malware gave me a popup
    "Malwarebytes Anti-Malware has detected a malicious process attempting to start and has blocked the execution attemp. Please select an option below.

    C:\FRST\QUARENTINE\{52665DCA-B9CE-8BB0-6373-A2219D8AD522}\U\800000CB.@ROOTKIT.0ACCESS

    Option 1: Disable protection
    Option 2: Ignore
    Option 3: Quarantine
  23. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    You can quarantine it. That item is already in FRST quarantined folder so it's not active.
  24. Rick van Ginkel

    Rick van Ginkel Newcomer, in training Topic Starter Posts: 41

    C:\FRST\Quarantine\services.exe Win64/Patched.B.Gen trojan deleted - quarantined
    C:\FRST\Quarantine\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\n Win64/Sirefef.W trojan cleaned by deleting - quarantined
    C:\FRST\Quarantine\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\00000001.@ Win64/Sirefef.AI trojan cleaned by deleting - quarantined
    C:\FRST\Quarantine\{52665dca-b9ce-8bb0-6373-a2219d8ad522}\U\80000000.@ Win64/Sirefef.AE trojan cleaned by deleting - quarantined
    C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\ubiorbitapi_r2.dll a variant of Win32/Packed.VMProtect.AAA trojan cleaned by deleting - quarantined
    W:\Program Files (x86)\Rockstar Games\Max Payne 3\gsrld.dll a variant of Win32/Packed.VMProtect.AAH trojan cleaned by deleting - quarantined
    W:\Program Files (x86)\Ubisoft\Assassin's Creed II\ubiorbitapi_r2.dll a variant of Win32/Packed.VMProtect.AAA trojan cleaned by deleting - quarantined
  25. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    ===================================================

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.