OTL logfile created on: 22/03/2010 09:47:18 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\USER\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 54,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 73,00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 33,79 Gb Free Space | 22,67% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC-DE-USER
Current User Name: USER
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Users\USER\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Soft2PC\soft2pc.exe (Soft2PC)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\SuperCopier2\SuperCopier2.exe (SFX TEAM)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\System32\sdclt.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe (VIA.)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Windows\System32\s3trayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\Windows\vsnpstd3.exe ()
PRC - C:\Windows\tsnpstd3.exe ()
PRC - C:\Windows\FixCamera.exe ()
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
========== Modules (SafeList) ========== MOD - C:\Users\USER\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (CLTNetCnService) -- File not found
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Boonty Games) -- C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe (BOONTY)
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
========== Driver Services (SafeList) ========== DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (fssfltr) -- C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (FETND6V) -- C:\Windows\System32\drivers\fetnd6v.sys (VIA Technologies, Inc. )
DRV - (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) -- C:\Windows\System32\drivers\s0016unic.sys (MCCI Corporation)
DRV - (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) -- C:\Windows\System32\drivers\s0016nd5.sys (MCCI Corporation)
DRV - (s0016mdfl) -- C:\Windows\System32\drivers\s0016mdfl.sys (MCCI Corporation)
DRV - (s0016mdm) -- C:\Windows\System32\drivers\s0016mdm.sys (MCCI Corporation)
DRV - (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\s0016mgmt.sys (MCCI Corporation)
DRV - (s0016obex) -- C:\Windows\System32\drivers\s0016obex.sys (MCCI Corporation)
DRV - (s0016bus) Sony Ericsson Device 0016 driver (WDM) -- C:\Windows\System32\drivers\s0016bus.sys (MCCI Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (a016obex) -- C:\Windows\System32\drivers\a016obex.sys (MCCI Corporation)
DRV - (a016mdm) -- C:\Windows\System32\drivers\a016mdm.sys (MCCI Corporation)
DRV - (a016mgmt) Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\a016mgmt.sys (MCCI Corporation)
DRV - (a016mdfl) -- C:\Windows\System32\drivers\a016mdfl.sys (MCCI Corporation)
DRV - (a016bus) Sony Ericsson Device A016 driver (WDM) -- C:\Windows\System32\drivers\a016bus.sys (MCCI Corporation)
DRV - (VIAHdAudAddService) -- C:\Windows\System32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (s117obex) -- C:\Windows\System32\drivers\s117obex.sys (MCCI Corporation)
DRV - (s117mdm) -- C:\Windows\System32\drivers\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM) -- C:\Windows\System32\drivers\s117unic.sys (MCCI Corporation)
DRV - (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS) -- C:\Windows\System32\drivers\s117nd5.sys (MCCI Corporation)
DRV - (s117mdfl) -- C:\Windows\System32\drivers\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM) -- C:\Windows\System32\drivers\s117bus.sys (MCCI Corporation)
DRV - (S3GIGP) -- C:\Windows\System32\drivers\VTGKModeDX32.sys (S3 Graphics Co., Ltd.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\Windows\System32\drivers\snpstd3.sys (Sonix Co. Ltd.)
DRV - (JRAID) -- C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (SIS163u) -- C:\Windows\System32\drivers\sis163u.sys (Silicon Integrated Systems Corp.)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) NVIDIA nForce(tm) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (sfvfs02) StarForce Protection VFS Driver (version 2.x) -- C:\Windows\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (eusk2par) -- C:\Windows\System32\drivers\eusk2par.sys (EUTRON)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/av ... x_homepageIE - HKLM\..\URLSearchHook: {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeF1.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/av ... x_homepageIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 64 1F 7B 00 03 14 E6 41 80 CC 16 A6 78 7C A6 76 [binary data]
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/av ... x_homepageIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 64 1F 7B 00 03 14 E6 41 80 CC 16 A6 78 7C A6 76 [binary data]
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/av ... x_homepageIE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 64 1F 7B 00 03 14 E6 41 80 CC 16 A6 78 7C A6 76 [binary data]
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/av ... x_homepageIE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 64 1F 7B 00 03 14 E6 41 80 CC 16 A6 78 7C A6 76 [binary data]
IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://y.lo.stIE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://badoo.com/ [binary data]
IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 64 1F 7B 00 03 14 E6 41 80 CC 16 A6 78 7C A6 76 [binary data]
IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\..\URLSearchHook: {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeF1.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yoog Search"
FF - prefs.js..browser.search.defaultthis.engineName: "MyPlayCity Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www5.yoog.com/search.php?q="
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.fr/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems:
autopager@mozilla.org:0.6.0.20
FF - prefs.js..extensions.enabledItems:
piclens@cooliris.com:1.11.6
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.3
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems:
treestyletab@piro.sakura.ne.jp:0.8.2009122501
FF - prefs.js..extensions.enabledItems: {0b4ba5c3-4945-40d7-bd28-f1c6f98c415e}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {e4d0a527-ed76-404d-9731-26a498801779}:2.5.6.0
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=GRfox000&fl=0&ptb=M6mvNopDABMwPnyyCwjXxQ&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor="
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/01 19:57:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/17 01:41:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/22 09:32:01 | 000,000,000 | ---D | M]
[2009/03/31 11:05:39 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Extensions
[2009/03/31 11:05:39 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2010/03/21 19:10:15 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions
[2010/03/10 06:06:24 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{0b4ba5c3-4945-40d7-bd28-f1c6f98c415e}
[2009/09/07 10:51:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/09 10:32:20 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/10/25 10:43:24 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009/09/18 01:19:45 | 000,000,000 | ---D | M] (MyPlayCity Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}
[2010/02/19 11:19:08 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/02/09 17:52:16 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/03/21 16:23:28 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/09/13 17:15:26 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/03/21 16:23:21 | 000,000,000 | ---D | M] (compliance 54328 Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{e4d0a527-ed76-404d-9731-26a498801779}
[2009/09/18 21:44:28 | 000,000,000 | ---D | M] (WeFi Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}
[2010/02/09 17:52:28 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2009/10/25 10:43:02 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\anycolor.pavlos256@gmail.com
[2010/03/06 23:57:11 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\autopager@mozilla.org
[2009/09/30 13:55:30 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\OberonGameHost@OberonGames.com
[2010/02/09 17:52:34 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\piclens@cooliris.com
[2010/02/17 10:48:28 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\support@lastpass.com
[2010/02/09 17:52:23 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\ga50zrw3.default\extensions\treestyletab@piro.sakura.ne.jp
[2009/06/23 18:38:24 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Sunbird\Profiles\6dct87k1.default\extensions
[2009/06/23 18:38:24 | 000,000,000 | ---D | M] (Sunbird (default)) -- C:\Users\USER\AppData\Roaming\mozilla\Sunbird\Profiles\6dct87k1.default\extensions\{8af2d0a7-e394-4de2-ae55-2dae532a7a9b}
[2010/02/13 15:36:54 | 000,002,650 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\FireFox\Profiles\ga50zrw3.default\searchplugins\bing.xml
[2009/01/15 06:58:20 | 000,000,882 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\FireFox\Profiles\ga50zrw3.default\searchplugins\conduit.xml
[2009/02/03 08:16:11 | 000,002,921 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\FireFox\Profiles\ga50zrw3.default\searchplugins\daemon-search.xml
[2009/10/06 00:46:33 | 000,009,941 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\FireFox\Profiles\ga50zrw3.default\searchplugins\mywebsearch.xml
[2009/07/22 15:23:05 | 000,000,246 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\FireFox\Profiles\ga50zrw3.default\searchplugins\Yoog Search.xml
[2010/03/22 09:39:33 | 000,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2008/12/12 19:02:02 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/04/07 14:52:04 | 000,028,672 | ---- | M] () -- C:\Program Files\mozilla firefox\components\GooglePlusVideosXPCOM.dll
[2009/12/19 12:12:32 | 000,281,600 | ---- | M] () -- C:\Program Files\mozilla firefox\components\krxfbmupcjfiqp.dll
[2009/08/09 17:14:12 | 000,049,152 | ---- | M] () -- C:\Program Files\mozilla firefox\components\SuperSearchXPCOM.dll
[2006/09/26 06:03:14 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files\mozilla firefox\plugins\npzylomgamesplayer.dll
[2010/01/15 21:10:07 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2010/01/15 21:10:07 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010/01/15 21:10:07 | 000,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2010/02/18 14:01:37 | 000,002,642 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\SiteVacuum.xml
[2010/01/15 21:10:07 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2010/01/15 21:10:07 | 000,000,652 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Google Plus) - {01677B4B-0610-4814-94A0-5F570DD7A88F} - C:\PROGRA~1\GOOGLE~1\17GOOG~1.DLL ()
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Super-Search -Find more of what you need) - {0286A85D-CD62-43bb-B7A9-A87D1D027160} - C:\PROGRA~1\EASYSE~1\BHO\12SUPE~1.DLL File not found
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (WeFiBar Toolbar) - {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeF1.dll (Conduit Ltd.)
O2 - BHO: (SOFT2PCBHO Class) - {3475D2C4-BBD1-4255-A70D-4125A4D30956} - C:\Program Files\Soft2PC\soft2pcBHO.dll (Soft2PC)
O2 - BHO: (no name) - {4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (CescrtHlpr Object) - {D286E828-E6B9-484d-A058-D7323666DE33} - C:\Program Files\RecFree.com\RecFreeToolbar\1.1.4.0\escort.dll (RecFree)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (RecFree Toolbar) - {0508F8F1-08E3-43EE-AAA8-09AD09803084} - C:\Program Files\RecFree.com\RecFreeToolbar\1.1.4.0\escorTlbr.dll (RecFree)
O3 - HKLM\..\Toolbar: (WeFiBar Toolbar) - {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeF1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\..\Toolbar\WebBrowser: (WeFiBar Toolbar) - {0B876028-B388-4F6D-922F-F52FAEC8535F} - C:\Program Files\WeFiBar\tbWeF1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Amazing3DAquariumWallpaper] File not found
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe (VIA.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [S3Trayp] C:\Windows\System32\s3trayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [soft2PC] C:\Program Files\Soft2PC\soft2pc.exe (Soft2PC)
O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\Run: [EleFunAnimatedWallpaper] File not found
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe File not found
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe (SFX TEAM)
O4 - HKU\.DEFAULT..\RunOnce: [] File not found
O4 - HKU\S-1-5-18..\RunOnce: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [] File not found
O4 - HKU\S-1-5-20..\RunOnce: [] File not found
O4 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1150595.exe -Update -1150595 -Mozilla\5.0_( File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-21-2835029756-2867514213-1702218136-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21}
https://static.impots.gouv.fr/abos/stat ... rtdgi1.cab (Module de délivrance de certificat MINEFI)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/ms ... b56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65}
https://plugins.valueactive.eu/flashax/iefax.cab (Flash Casino Helper Control)
O16 - DPF: CabBuilder
http://kiw.imgag.com/imgag/kiw/toolbar/ ... ontrol.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/Windows/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 0.0.0.0
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - AppInit_DLLs: (C:\Windows\System32\dpnet32.dll) - C:\Windows\System32\dpnet32.dll File not found
O20 - AppInit_DLLs: (C:\Windows\System32\dpnet32.dll) - C:\Windows\System32\dpnet32.dll File not found
O20 - AppInit_DLLs: (C:\Windows\System32\dimsroam32.dll) - C:\Windows\System32\dimsroam32.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\30cf2dae509: DllName - C:\Windows\System32\dpnet32.dll - C:\Windows\System32\dpnet32.dll File not found
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Autumn Leaves.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Autumn Leaves.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/01/22 22:33:50 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{05803d9c-2c1e-11de-a1a6-00a0d1c76a7e}\Shell\Auto\command - "" = F:\Start.exe -- File not found
O33 - MountPoints2\{06832100-8255-11de-9a70-00199910b455}\Shell\AutoRun\command - "" = F:\cv8j.exe -- File not found
O33 - MountPoints2\{06832100-8255-11de-9a70-00199910b455}\Shell\open\Command - "" = F:\cv8j.exe -- File not found
O33 - MountPoints2\{085d78fc-6961-11de-8a38-00199910b455}\Shell\Auto\command - "" = F:\Start.exe -- File not found
O33 - MountPoints2\{0f2e0c71-8bf0-11de-b31a-00199910b455}\Shell\AutoRun\command - "" = 6rxt26.exe
O33 - MountPoints2\{0f2e0c71-8bf0-11de-b31a-00199910b455}\Shell\open\Command - "" = 6rxt26.exe
O33 - MountPoints2\{1859a111-7f1d-11da-85d6-00a0d1c76a7e}\Shell\Auto\command - "" = F:\Start.exe -- File not found
O33 - MountPoints2\{2a7e15a9-36ec-11de-9daf-00a0d1c76a7e}\Shell\AutoRun\command - "" = F:\tfk8.exe -- File not found
O33 - MountPoints2\{2a7e15a9-36ec-11de-9daf-00a0d1c76a7e}\Shell\explore\Command - "" = F:\tfk8.exe -- File not found
O33 - MountPoints2\{2a7e15a9-36ec-11de-9daf-00a0d1c76a7e}\Shell\open\Command - "" = F:\tfk8.exe -- File not found
O33 - MountPoints2\{3ffd8a19-6464-11de-ad20-00199910b455}\Shell\AutoRun\command - "" = G:\pagefile.pif -- File not found
O33 - MountPoints2\{3ffd8a19-6464-11de-ad20-00199910b455}\Shell\explore\Command - "" = G:\pagefile.pif -- File not found
O33 - MountPoints2\{3ffd8a19-6464-11de-ad20-00199910b455}\Shell\open\Command - "" = G:\pagefile.pif -- File not found
O33 - MountPoints2\{72716315-f1eb-11dd-a393-00199910b455}\Shell - "" = AutoRun
O33 - MountPoints2\{72716315-f1eb-11dd-a393-00199910b455}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\{86ac6ee7-3be7-11de-935b-00a0d1c76a7e}\Shell\AutoRun\command - "" = F:\pagefile.pif -- File not found
O33 - MountPoints2\{86ac6ee7-3be7-11de-935b-00a0d1c76a7e}\Shell\explore\Command - "" = F:\pagefile.pif -- File not found
O33 - MountPoints2\{86ac6ee7-3be7-11de-935b-00a0d1c76a7e}\Shell\open\Command - "" = F:\pagefile.pif -- File not found
O33 - MountPoints2\{9deff6e8-59c3-11de-8f52-00199910b455}\Shell\AutoRun\command - "" = F:\pagefile.pif -- File not found
O33 - MountPoints2\{9deff6e8-59c3-11de-8f52-00199910b455}\Shell\explore\Command - "" = F:\pagefile.pif -- File not found
O33 - MountPoints2\{9deff6e8-59c3-11de-8f52-00199910b455}\Shell\open\Command - "" = F:\pagefile.pif -- File not found
O33 - MountPoints2\{c1d5feb6-7158-11de-a6d0-00a0d1c76a7e}\Shell\Auto\command - "" = F:\Start.exe -- File not found
O33 - MountPoints2\{c1d5febb-7158-11de-a6d0-00a0d1c76a7e}\Shell\Auto\command - "" = G:\Start.exe -- File not found
O33 - MountPoints2\{ce93a69f-80b9-11de-83a7-00199910b455}\Shell\AutoRun\command - "" = F:\3j2h0tf.bat -- File not found
O33 - MountPoints2\{ce93a69f-80b9-11de-83a7-00199910b455}\Shell\open\Command - "" = F:\3j2h0tf.bat -- File not found
O33 - MountPoints2\{ce93aa1e-80b9-11de-83a7-00199910b455}\Shell\AutoRun\command - "" = F:\tyktjfww.exe -- File not found
O33 - MountPoints2\{ce93aa1e-80b9-11de-83a7-00199910b455}\Shell\explore\Command - "" = F:\tyktjfww.exe -- File not found
O33 - MountPoints2\{ce93aa1e-80b9-11de-83a7-00199910b455}\Shell\open\Command - "" = F:\tyktjfww.exe -- File not found
O33 - MountPoints2\{cec62a8c-b80b-11de-8741-00a0d1c76a7e}\Shell\AutoRun\command - "" = F:\3c.exe -- File not found
O33 - MountPoints2\{cec62a8c-b80b-11de-8741-00a0d1c76a7e}\Shell\open\Command - "" = F:\3c.exe -- File not found
O33 - MountPoints2\{dbce52c5-54c3-11de-9057-00a0d1c76a7e}\Shell\AutoRun\command - "" = F:\start.exe -- File not found
O33 - MountPoints2\{dbce52c5-54c3-11de-9057-00a0d1c76a7e}\Shell\guadeloupe\command - "" = F:\start.exe -- File not found
O33 - MountPoints2\{e52962ee-5a5f-11de-9576-00199910b455}\Shell\AutoRun\command - "" = F:\rcukd.cmd -- File not found
O33 - MountPoints2\{e52962ee-5a5f-11de-9576-00199910b455}\Shell\explore\Command - "" = F:\rcukd.cmd -- File not found
O33 - MountPoints2\{e52962ee-5a5f-11de-9576-00199910b455}\Shell\open\Command - "" = F:\rcukd.cmd -- File not found
O33 - MountPoints2\{ea3acc25-a1e9-11dd-8f3c-00199910b455}\Shell\AutoRun\command - "" = f2kmj.exe
O33 - MountPoints2\{ea3acc25-a1e9-11dd-8f3c-00199910b455}\Shell\open\Command - "" = f2kmj.exe
O33 - MountPoints2\{ea3acc2b-a1e9-11dd-8f3c-00199910b455}\Shell\AutoRun\command - "" = f2kmj.exe
O33 - MountPoints2\{ea3acc2b-a1e9-11dd-8f3c-00199910b455}\Shell\open\Command - "" = f2kmj.exe
O33 - MountPoints2\{f424ad0e-bebc-11dd-956b-00a0d1c76a7e}\Shell\Auto\command - "" = Start.exe
O33 - MountPoints2\{f424ad14-bebc-11dd-956b-00a0d1c76a7e}\Shell\Auto\command - "" = Start.exe
O33 - MountPoints2\{f6a58d85-8d84-11de-8113-00199910b455}\Shell\AutoRun\command - "" = F:\3c.exe -- File not found
O33 - MountPoints2\{f6a58d85-8d84-11de-8113-00199910b455}\Shell\open\Command - "" = F:\3c.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\F:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\H:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/11/21 15:17:51 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ========== [2010/03/22 09:03:09 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\Malwarebytes
[2010/03/22 09:02:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/22 09:02:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/03/22 09:02:42 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/03/22 09:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/22 01:17:22 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010/03/21 18:06:16 | 000,000,000 | ---D | C] -- C:\Ad-Remover
[2010/03/21 18:03:53 | 001,324,250 | ---- | C] (C_XX) -- C:\Users\USER\Desktop\AD-R.exe
[2010/03/17 14:24:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Micro Application
[2010/03/17 14:24:09 | 000,000,000 | ---D | C] -- C:\Program Files\Micro Application
[2010/03/17 13:50:01 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\Soft2PC
[2010/03/17 13:49:53 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Local\Soft2PC
[2010/03/17 13:49:52 | 000,000,000 | ---D | C] -- C:\Program Files\Soft2PC
[2010/03/17 01:53:22 | 000,000,000 | ---D | C] -- C:\Users\USER\Documents\UseNeXT
[2010/03/17 01:49:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2010/03/16 23:28:00 | 000,000,000 | ---D | C] -- C:\Program Files\adslTV
[2010/03/09 20:01:26 | 000,000,000 | -HSD | C] -- C:\ProgramData\SysWoW32
[2010/03/09 20:00:40 | 000,000,000 | ---D | C] -- C:\System Volume Data
[2010/03/08 23:54:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Games-Attack
[2010/03/08 23:54:21 | 000,000,000 | ---D | C] -- C:\Program Files\Games-Attack
[2010/03/08 23:25:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Ironclad Games
[2010/03/08 19:59:35 | 000,000,000 | R--D | C] -- C:\Users\USER\Pictures
[2010/03/08 19:24:09 | 000,000,000 | ---D | C] -- C:\Users\USER\Desktop\sins of a solar empire
[2010/03/07 18:02:50 | 000,000,000 | ---D | C] -- C:\Users\USER\Documents\My Albums
[2010/03/07 17:58:21 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Local\ArcSoft
[2010/03/07 17:58:15 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\ArcSoft
[2010/03/07 17:58:13 | 000,000,000 | ---D | C] -- C:\ProgramData\ArcSoft
[2010/03/07 17:57:09 | 000,018,688 | ---- | C] (Arcsoft, Inc.) -- C:\Windows\System32\drivers\afc.sys
[2010/03/07 17:57:08 | 000,499,712 | R--- | C] (Microsoft Corporation) -- C:\Windows\System32\msvc7452.rra
[2010/03/07 17:57:08 | 000,245,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unicows.dll
[2010/03/07 17:57:07 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvc7368.rra
[2010/03/07 17:55:51 | 000,212,480 | ---- | C] (Eastman Kodak) -- C:\Windows\PCDLIB32.DLL
[2010/03/07 17:55:40 | 000,000,000 | ---D | C] -- C:\Program Files\ArcSoft
[2010/03/07 17:55:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ArcSoft
[2010/03/07 00:08:40 | 000,000,000 | ---D | C] -- C:\Users\USER\Documents\Mes téléchargements
[2010/03/06 05:44:12 | 000,000,000 | ---D | C] -- C:\ProgramData\ESTsoft
[2010/03/06 05:44:09 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\ESTsoft
[2010/03/06 05:44:09 | 000,000,000 | ---D | C] -- C:\Program Files\ESTsoft
[2010/03/06 04:22:00 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\igraal
[2010/03/06 03:44:01 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\Passware
[2010/03/06 03:26:22 | 000,000,000 | ---D | C] -- C:\Program Files\RAR Password Unlocker
[2010/03/06 02:19:49 | 000,000,000 | ---D | C] -- C:\Users\USER\Documents\My Downloads
[2010/03/05 23:28:03 | 000,000,000 | ---D | C] -- C:\Program Files\Pcsx2
[2010/03/05 13:52:48 | 000,000,000 | ---D | C] -- C:\Program Files\SuperCopier2
[2010/03/05 12:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/03/03 20:13:13 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2010/03/03 20:13:12 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2010/03/03 20:13:11 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2010/03/03 20:13:10 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2010/03/03 20:13:08 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010/03/03 20:13:08 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010/03/03 20:13:06 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010/03/03 20:13:04 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010/03/03 20:12:59 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010/03/03 20:12:58 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010/03/03 20:12:58 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010/03/03 20:12:57 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010/03/03 20:12:55 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2010/03/03 20:12:55 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2010/03/03 20:12:52 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2010/03/03 20:12:49 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2010/03/03 20:12:48 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2010/03/03 20:12:48 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2010/03/03 20:12:47 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2010/03/03 20:12:46 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2010/03/03 20:12:44 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2010/03/03 20:12:39 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010/03/03 20:12:39 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010/03/03 20:12:36 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010/03/03 20:12:35 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2010/03/03 20:12:35 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010/03/03 20:12:34 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2010/03/03 20:12:31 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2010/03/03 20:12:22 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2010/03/03 20:12:22 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2010/03/03 20:12:13 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2010/03/03 20:12:10 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2010/03/03 20:12:10 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2010/03/03 20:12:07 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2010/03/03 20:12:06 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2010/03/03 20:12:05 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2010/03/03 20:12:05 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2010/03/03 20:11:55 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2010/03/03 20:11:53 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2010/03/03 20:11:51 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2010/03/03 20:11:51 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2010/03/03 20:11:49 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2010/03/03 20:11:49 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2010/03/03 20:11:45 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2010/03/03 20:07:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2010/03/03 20:02:13 | 000,000,000 | ---D | C] -- C:\Program Files\RomStation
[2010/03/02 18:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Wakfu
[2010/03/02 17:13:30 | 000,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\HPAppData
[2010/03/01 19:52:31 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2010/02/25 19:02:39 | 000,000,000 | ---D | C] -- C:\Users\USER\Page vierge de PERT
[2010/02/24 01:10:21 | 000,000,000 | ---D | C] -- C:\Users\USER\dwhelper
[2010/02/23 17:14:53 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010/02/23 17:14:13 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/02/23 17:11:57 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2010/02/23 17:11:56 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2010/02/23 17:11:48 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2010/02/23 17:11:46 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2010/02/23 17:11:46 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/02/23 17:11:45 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2010/02/23 17:11:43 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2010/02/23 17:11:43 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2010/02/23 17:11:42 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2010/02/23 17:08:28 | 001,696,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2010/02/23 17:08:23 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2010/02/23 17:08:21 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/02/22 08:19:54 | 000,405,504 | ---- | C] (pion) -- C:\Users\USER\AppData\Local\jesgkg.exe
[2009/12/23 18:11:23 | 000,352,256 | ---- | C] (amoldáis) -- C:\Users\USER\AppData\Local\kimchm.exe
[2009/10/27 09:58:43 | 000,385,024 | ---- | C] (Rousseau) -- C:\Users\USER\AppData\Local\vvvvdfdl.exe
[2008/12/18 13:12:39 | 000,172,032 | ---- | C] ( ) -- C:\Windows\System32\rsnpstd3.dll
[2008/12/18 13:12:39 | 000,057,344 | ---- | C] ( ) -- C:\Windows\System32\vsnpstd3.dll
[2008/12/18 13:12:38 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnpstd3.dll
[2008/12/18 13:12:38 | 000,053,248 | ---- | C] ( ) -- C:\Windows\csnpstd3.dll
[2 C:\Users\USER\AppData\Roaming\*.tmp files -> C:\Users\USER\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/03/22 09:56:09 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{334A4BE3-F41F-44AD-887E-AFD029110187}.job
[2010/03/22 09:56:08 | 006,291,456 | -HS- | M] () -- C:\Users\USER\ntuser.dat
[2010/03/22 09:56:08 | 000,000,400 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E06C9524-D4BE-4048-BC8E-FA1C4EEFDE4C}.job
[2010/03/22 09:36:43 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/22 09:36:43 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/22 09:34:21 | 000,003,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/22 09:34:20 | 000,003,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/22 09:33:03 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/22 09:32:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/22 09:31:08 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/03/22 09:30:56 | 000,524,288 | -HS- | M] () -- C:\Users\USER\ntuser.dat{64da0c68-2d1c-11df-876b-00a0d1c76a7e}.TMContainer00000000000000000001.regtrans-ms
[2010/03/22 09:30:56 | 000,065,536 | -HS- | M] () -- C:\Users\USER\ntuser.dat{64da0c68-2d1c-11df-876b-00a0d1c76a7e}.TM.blf
[2010/03/22 09:30:54 | 002,384,856 | -H-- | M] () -- C:\Users\USER\AppData\Local\IconCache.db
[2010/03/22 09:02:57 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/22 08:50:31 | 000,000,089 | ---- | M] () -- C:\Users\USER\AppData\Local\nghhiy.bat
[2010/03/21 18:04:15 | 001,324,250 | ---- | M] (C_XX) -- C:\Users\USER\Desktop\AD-R.exe
[2010/03/21 17:56:04 | 000,147,456 | ---- | M] () -- C:\Users\USER\Desktop\catchme.exe
[2010/03/21 17:46:22 | 000,525,824 | ---- | M] () -- C:\Users\USER\Desktop\dds.scr
[2010/03/21 00:46:22 | 000,145,408 | ---- | M] () -- C:\Users\USER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/20 07:54:15 | 000,000,017 | ---- | M] () -- C:\Windows\System32\package.lst
[2010/03/19 06:41:14 | 000,000,089 | ---- | M] () -- C:\Users\USER\AppData\Local\esqgdt.bat
[2010/03/18 23:09:28 | 000,004,226 | ---- | M] () -- C:\Users\USER\Documents\Untitled.irp
[2010/03/17 22:55:41 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2010/03/17 14:27:17 | 000,002,138 | ---- | M] () -- C:\Users\USER\Desktop\Code de la Route Pratic.lnk
[2010/03/17 01:49:03 | 000,001,670 | ---- | M] () -- C:\Users\USER\Desktop\CCleaner.lnk
[2010/03/17 01:32:38 | 000,000,050 | ---- | M] () -- C:\Windows\MegaManager.INI
[2010/03/16 23:35:44 | 000,000,776 | ---- | M] () -- C:\Users\USER\Desktop\adsl TV.lnk
[2010/03/11 22:30:17 | 000,393,216 | ---- | M] () -- C:\Users\USER\AppData\Local\ldcri.exe
[2010/03/11 15:21:22 | 000,524,288 | -HS- | M] () -- C:\Users\USER\ntuser.dat{64da0c68-2d1c-11df-876b-00a0d1c76a7e}.TMContainer00000000000000000002.regtrans-ms
[2010/03/11 10:55:15 | 000,399,928 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/03/11 10:49:26 | 000,524,288 | -HS- | M] () -- C:\Users\USER\NTUSER.DAT{c1d5ff02-7158-11de-a6d0-00a0d1c76a7e}.TMContainer00000000000000000001.regtrans-ms
[2010/03/11 10:49:26 | 000,065,536 | -HS- | M] () -- C:\Users\USER\NTUSER.DAT{c1d5ff02-7158-11de-a6d0-00a0d1c76a7e}.TM.blf
[2010/03/11 10:02:03 | 000,000,000 | ---- | M] () -- C:\Users\USER\AppData\Roaming\b78fe37
[2010/03/10 22:18:38 | 000,001,282 | -HS- | M] () -- C:\ProgramData\1621065214
[2010/03/10 21:25:48 | 000,000,817 | ---- | M] () -- C:\ProgramData\818884014
[2010/03/08 00:53:52 | 000,000,826 | ---- | M] () -- C:\Windows\win.ini
[2010/03/07 17:57:07 | 000,001,767 | ---- | M] () -- C:\Users\Public\Desktop\Video Impression 2.lnk
[2010/03/07 17:56:06 | 003,108,864 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/03/07 17:56:06 | 000,963,174 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/03/07 17:56:05 | 001,364,716 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/03/07 17:56:05 | 000,848,068 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/03/07 17:56:05 | 000,004,926 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/03/05 19:08:47 | 000,108,768 | ---- | M] () -- C:\Users\USER\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/05 16:13:04 | 000,446,464 | ---- | M] () -- C:\Users\USER\AppData\Local\aouicbw.exe
[2010/03/05 12:17:37 | 000,001,726 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/04 18:11:09 | 000,013,166 | ---- | M] () -- C:\Users\USER\Documents\POLION Laura.docx
[2010/03/04 16:14:26 | 000,284,828 | ---- | M] () -- C:\Users\USER\Documents\téléphone.docx
[2010/03/02 20:20:37 | 000,001,027 | ---- | M] () -- C:\Users\USER\Desktop\VisualBoyAdvance.exe - Raccourci.lnk
[2010/03/02 18:47:40 | 000,000,789 | ---- | M] () -- C:\Users\USER\Desktop\Wakfu.lnk
[2010/03/01 20:10:56 | 000,230,424 | ---- | M] () -- C:\img2-001.raw
[2010/03/01 19:59:53 | 000,023,798 | ---- | M] () -- C:\Windows\hpqins15.dat
[2010/03/01 19:54:31 | 000,078,310 | ---- | M] () -- C:\Windows\hpqins05.dat
[2010/03/01 19:50:42 | 000,001,270 | ---- | M] () -- C:\Users\Public\Desktop\Centre de solutions HP.lnk
[2010/03/01 15:07:18 | 000,063,343 | ---- | M] () -- C:\Users\USER\Documents\bubu.wma
[2010/03/01 15:04:05 | 000,103,753 | ---- | M] () -- C:\Users\USER\Documents\lolo.wma
[2010/03/01 14:50:33 | 000,314,783 | ---- | M] () -- C:\Users\USER\Documents\uu.wma
[2010/03/01 14:43:04 | 000,085,793 | ---- | M] () -- C:\Users\USER\Documents\ii.wma
[2010/02/27 10:22:56 | 000,339,968 | ---- | M] () -- C:\Users\USER\AppData\Local\ieokfhd.exe
[2010/02/24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/02/22 08:19:54 | 000,405,504 | ---- | M] (pion) -- C:\Users\USER\AppData\Local\jesgkg.exe
[2 C:\Users\USER\AppData\Roaming\*.tmp files -> C:\Users\USER\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/03/22 09:02:57 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/21 17:55:59 | 000,147,456 | ---- | C] () -- C:\Users\USER\Desktop\catchme.exe
[2010/03/21 17:45:47 | 000,525,824 | ---- | C] () -- C:\Users\USER\Desktop\dds.scr
[2010/03/18 23:09:28 | 000,004,226 | ---- | C] () -- C:\Users\USER\Documents\Untitled.irp
[2010/03/17 14:27:17 | 000,002,138 | ---- | C] () -- C:\Users\USER\Desktop\Code de la Route Pratic.lnk
[2010/03/16 23:35:44 | 000,000,776 | ---- | C] () -- C:\Users\USER\Desktop\adsl TV.lnk
[2010/03/11 22:30:17 | 000,393,216 | ---- | C] () -- C:\Users\USER\AppData\Local\ldcri.exe
[2010/03/11 10:55:21 | 000,524,288 | -HS- | C] () -- C:\Users\USER\ntuser.dat{64da0c68-2d1c-11df-876b-00a0d1c76a7e}.TMContainer00000000000000000002.regtrans-ms
[2010/03/11 10:55:19 | 000,524,288 | -HS- | C] () -- C:\Users\USER\ntuser.dat{64da0c68-2d1c-11df-876b-00a0d1c76a7e}.TMContainer00000000000000000001.regtrans-ms
[2010/03/11 10:55:17 | 000,065,536 | -HS- | C] () -- C:\Users\USER\ntuser.dat{64da0c68-2d1c-11df-876b-00a0d1c76a7e}.TM.blf
[2010/03/09 20:02:44 | 000,001,282 | -HS- | C] () -- C:\ProgramData\1621065214
[2010/03/09 20:02:43 | 000,000,817 | ---- | C] () -- C:\ProgramData\818884014
[2010/03/09 20:00:41 | 000,000,000 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b78fe37
[2010/03/07 17:57:07 | 000,001,767 | ---- | C] () -- C:\Users\Public\Desktop\Video Impression 2.lnk
[2010/03/06 02:03:05 | 000,000,050 | ---- | C] () -- C:\Windows\MegaManager.INI
[2010/03/05 16:13:04 | 000,446,464 | ---- | C] () -- C:\Users\USER\AppData\Local\aouicbw.exe
[2010/03/05 13:52:16 | 000,507,564 | ---- | C] () -- C:\Users\USER\Desktop\SuperCopier22beta.exe
[2010/03/05 12:17:37 | 000,001,726 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/04 18:11:02 | 000,013,166 | ---- | C] () -- C:\Users\USER\Documents\POLION Laura.docx
[2010/03/04 16:14:17 | 000,284,828 | ---- | C] () -- C:\Users\USER\Documents\téléphone.docx
[2010/03/02 20:20:37 | 000,001,027 | ---- | C] () -- C:\Users\USER\Desktop\VisualBoyAdvance.exe - Raccourci.lnk
[2010/03/02 18:47:40 | 000,000,789 | ---- | C] () -- C:\Users\USER\Desktop\Wakfu.lnk
[2010/03/01 19:55:50 | 000,023,798 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/03/01 19:50:42 | 000,001,270 | ---- | C] () -- C:\Users\Public\Desktop\Centre de solutions HP.lnk
[2010/03/01 19:47:36 | 000,078,310 | ---- | C] () -- C:\Windows\hpqins05.dat
[2010/03/01 15:07:15 | 000,063,343 | ---- | C] () -- C:\Users\USER\Documents\bubu.wma
[2010/03/01 15:04:03 | 000,103,753 | ---- | C] () -- C:\Users\USER\Documents\lolo.wma
[2010/03/01 14:50:29 | 000,314,783 | ---- | C] () -- C:\Users\USER\Documents\uu.wma
[2010/03/01 14:43:02 | 000,085,793 | ---- | C] () -- C:\Users\USER\Documents\ii.wma
[2010/02/27 10:22:56 | 000,339,968 | ---- | C] () -- C:\Users\USER\AppData\Local\ieokfhd.exe
[2010/02/01 21:32:20 | 000,000,000 | ---- | C] () -- C:\Users\USER\AppData\Roaming\wklnhst.dat
[2010/01/14 11:38:28 | 000,000,552 | ---- | C] () -- C:\Users\USER\AppData\Local\d3d8caps.dat
[2010/01/09 09:22:08 | 000,001,372 | ---- | C] () -- C:\Users\USER\AppData\Roaming\N1PqRpBz8wDw3Sk.vbs
[2010/01/09 09:13:52 | 000,000,089 | ---- | C] () -- C:\Users\USER\AppData\Local\esqgdt.bat
[2009/10/19 15:09:10 | 000,005,609 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef687C.manifest
[2009/10/19 15:09:10 | 000,002,381 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef687P.manifest
[2009/10/19 15:09:10 | 000,000,079 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef687O.manifest
[2009/10/19 15:09:10 | 000,000,011 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef687S.manifest
[2009/09/30 11:28:11 | 000,000,000 | ---- | C] () -- C:\Users\USER\AppData\Local\oeuky_s2m.zl
[2009/09/30 10:08:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/25 01:07:11 | 000,000,088 | ---- | C] () -- C:\Users\USER\AppData\Local\ogioe.bat
[2009/09/14 21:54:25 | 000,005,609 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef669C.manifest
[2009/09/14 21:54:25 | 000,002,493 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef669P.manifest
[2009/09/14 21:54:25 | 000,000,352 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef669O.manifest
[2009/09/14 21:54:25 | 000,000,011 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef669S.manifest
[2009/09/04 22:50:25 | 000,000,008 | ---- | C] () -- C:\Users\USER\AppData\Local\.mpid
[2009/09/04 18:54:38 | 000,524,288 | -HS- | C] () -- C:\ProgramData\ntuser.dat{f2c39869-997b-11de-a01f-00a0d1c76a7e}.TMContainer00000000000000000002.regtrans-ms
[2009/09/04 18:54:38 | 000,524,288 | -HS- | C] () -- C:\ProgramData\ntuser.dat{f2c39869-997b-11de-a01f-00a0d1c76a7e}.TMContainer00000000000000000001.regtrans-ms
[2009/09/04 18:54:37 | 000,262,144 | ---- | C] () -- C:\ProgramData\ntuser.dat
[2009/09/04 18:54:37 | 000,065,536 | -HS- | C] () -- C:\ProgramData\ntuser.dat{f2c39869-997b-11de-a01f-00a0d1c76a7e}.TM.blf
[2009/09/04 18:54:37 | 000,005,120 | -H-- | C] () -- C:\ProgramData\ntuser.dat.LOG1
[2009/09/04 18:54:37 | 000,000,000 | -H-- | C] () -- C:\ProgramData\ntuser.dat.LOG2
[2009/09/01 09:37:55 | 000,000,089 | ---- | C] () -- C:\Users\USER\AppData\Local\nghhiy.bat
[2009/08/18 09:05:34 | 000,000,040 | ---- | C] () -- C:\Windows\NAVIGMA.INI
[2009/08/13 17:59:50 | 000,021,504 | ---- | C] () -- C:\Users\USER\AppData\Roaming\CDRusersDB.v12
[2009/08/04 07:20:06 | 000,000,026 | ---- | C] () -- C:\Windows\System32\satsukidecodersettings.ini
[2009/05/22 10:48:25 | 000,000,088 | ---- | C] () -- C:\Users\USER\AppData\Local\qcuis.bat
[2009/05/04 18:45:56 | 000,005,740 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef583C.manifest
[2009/05/04 18:45:56 | 000,001,517 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef583P.manifest
[2009/05/04 18:45:56 | 000,000,011 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef583S.manifest
[2009/05/04 18:45:56 | 000,000,011 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef583O.manifest
[2009/04/28 13:44:25 | 000,000,007 | ---- | C] () -- C:\Users\USER\AppData\Local\oeuky_navup.dat
[2009/04/28 13:42:48 | 000,000,087 | ---- | C] () -- C:\Users\USER\AppData\Local\oeuky.bat
[2009/04/15 09:43:23 | 000,000,087 | ---- | C] () -- C:\Users\USER\AppData\Local\uwmas.bat
[2009/03/30 14:26:15 | 000,000,087 | ---- | C] () -- C:\Users\USER\AppData\Local\ewgimcs.bat
[2009/02/03 08:05:01 | 000,717,296 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/01/15 08:59:55 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/01/12 12:49:07 | 000,000,090 | ---- | C] () -- C:\Users\USER\AppData\Local\novwdg.bat
[2008/12/19 01:41:13 | 000,001,064 | ---- | C] () -- C:\Windows\Sol.ini
[2008/12/19 01:41:12 | 000,000,982 | ---- | C] () -- C:\Windows\Fa.ini
[2008/12/18 13:12:41 | 000,015,498 | ---- | C] () -- C:\Windows\snpstd3.ini
[2008/12/05 17:18:42 | 000,315,408 | ---- | C] () -- C:\ProgramData\ElseFaceFace.geoscy
[2008/12/05 16:56:33 | 000,090,128 | ---- | C] () -- C:\ProgramData\ElseFaceFace.cjf3uy5
[2008/12/05 16:33:38 | 000,155,664 | ---- | C] () -- C:\ProgramData\ElseFaceFace.jgdllq
[2008/12/05 16:10:34 | 000,126,992 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ouqiwk
[2008/12/05 15:48:21 | 000,016,400 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8hjzj
[2008/12/05 15:26:17 | 000,004,112 | ---- | C] () -- C:\ProgramData\ElseFaceFace.yvpoe7
[2008/12/05 15:04:20 | 000,393,232 | ---- | C] () -- C:\ProgramData\ElseFaceFace.73yav
[2008/12/05 14:42:17 | 000,192,528 | ---- | C] () -- C:\ProgramData\ElseFaceFace.fjeg2f
[2008/12/05 14:20:14 | 000,393,232 | ---- | C] () -- C:\ProgramData\ElseFaceFace.zu7pp
[2008/12/05 13:58:15 | 000,249,872 | ---- | C] () -- C:\ProgramData\ElseFaceFace.6gnj9v3
[2008/12/05 13:36:21 | 000,061,456 | ---- | C] () -- C:\ProgramData\ElseFaceFace.s8vflzc
[2008/12/05 13:14:28 | 000,213,008 | ---- | C] () -- C:\ProgramData\ElseFaceFace.bn5c9g
[2008/12/05 12:52:32 | 000,126,992 | ---- | C] () -- C:\ProgramData\ElseFaceFace.gh5gi
[2008/12/05 12:30:37 | 000,147,472 | ---- | C] () -- C:\ProgramData\ElseFaceFace.54tnnl
[2008/12/05 12:08:45 | 000,368,656 | ---- | C] () -- C:\ProgramData\ElseFaceFace.mg3c28
[2008/12/05 11:46:53 | 000,380,944 | ---- | C] () -- C:\ProgramData\ElseFaceFace.3xoye
[2008/12/05 11:25:00 | 000,229,392 | ---- | C] () -- C:\ProgramData\ElseFaceFace.z9ev4
[2008/12/05 11:03:07 | 000,159,760 | ---- | C] () -- C:\ProgramData\ElseFaceFace.dpse74h
[2008/12/05 10:41:14 | 000,081,936 | ---- | C] () -- C:\ProgramData\ElseFaceFace.6dtvy83
[2008/12/05 10:19:18 | 000,311,312 | ---- | C] () -- C:\ProgramData\ElseFaceFace.2gd30l
[2008/12/05 09:57:22 | 000,237,584 | ---- | C] () -- C:\ProgramData\ElseFaceFace.jhd9zk
[2008/12/05 09:35:21 | 000,139,280 | ---- | C] () -- C:\ProgramData\ElseFaceFace.c62gi
[2008/12/05 09:13:03 | 000,102,416 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ekehpb
[2008/12/05 08:50:43 | 000,282,640 | ---- | C] () -- C:\ProgramData\ElseFaceFace.jyh6j
[2008/12/05 08:28:39 | 000,192,528 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ygzcx
[2008/12/05 08:06:40 | 000,319,504 | ---- | C] () -- C:\ProgramData\ElseFaceFace.nu9isun
[2008/12/05 07:44:33 | 000,065,552 | ---- | C] () -- C:\ProgramData\ElseFaceFace.tnykn
[2008/12/05 07:22:31 | 000,126,992 | ---- | C] () -- C:\ProgramData\ElseFaceFace.zmtdh
[2008/12/05 07:00:33 | 000,360,464 | ---- | C] () -- C:\ProgramData\ElseFaceFace.lmj6he
[2008/12/05 06:38:34 | 000,245,776 | ---- | C] () -- C:\ProgramData\ElseFaceFace.305fb9
[2008/12/05 06:16:31 | 000,262,160 | ---- | C] () -- C:\ProgramData\ElseFaceFace.9lkggq
[2008/12/05 05:54:37 | 000,053,264 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ocuufh
[2008/12/05 05:32:29 | 000,352,272 | ---- | C] () -- C:\ProgramData\ElseFaceFace.wyfhbp
[2008/12/05 05:10:29 | 000,159,760 | ---- | C] () -- C:\ProgramData\ElseFaceFace.mva3r
[2008/12/05 04:48:26 | 000,053,264 | ---- | C] () -- C:\ProgramData\ElseFaceFace.mzjbosq
[2008/12/05 04:26:34 | 000,262,160 | ---- | C] () -- C:\ProgramData\ElseFaceFace.eun5iv
[2008/12/05 04:04:41 | 000,163,856 | ---- | C] () -- C:\ProgramData\ElseFaceFace.0cn2xi7
[2008/12/05 03:42:48 | 000,303,120 | ---- | C] () -- C:\ProgramData\ElseFaceFace.hq4qq1
[2008/12/05 03:20:56 | 000,143,376 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ampj4c
[2008/12/05 02:59:03 | 000,040,976 | ---- | C] () -- C:\ProgramData\ElseFaceFace.eghqwo
[2008/12/05 02:37:11 | 000,323,600 | ---- | C] () -- C:\ProgramData\ElseFaceFace.9fw58
[2008/12/05 02:15:18 | 000,049,168 | ---- | C] () -- C:\ProgramData\ElseFaceFace.3w1e9
[2008/12/05 01:53:26 | 000,294,928 | ---- | C] () -- C:\ProgramData\ElseFaceFace.b38f1
[2008/12/05 01:31:34 | 000,299,024 | ---- | C] () -- C:\ProgramData\ElseFaceFace.r2tjb
[2008/12/05 01:09:41 | 000,262,160 | ---- | C] () -- C:\ProgramData\ElseFaceFace.cd9wj77
[2008/12/05 00:47:42 | 000,032,784 | ---- | C] () -- C:\ProgramData\ElseFaceFace.lpz00
[2008/12/05 00:25:46 | 000,016,400 | ---- | C] () -- C:\ProgramData\ElseFaceFace.6pail
[2008/12/04 21:52:47 | 000,335,888 | ---- | C] () -- C:\ProgramData\ElseFaceFace.slp9sni
[2008/12/04 21:30:31 | 000,262,160 | ---- | C] () -- C:\ProgramData\ElseFaceFace.3r0ysb3
[2008/12/04 21:08:37 | 000,360,464 | ---- | C] () -- C:\ProgramData\ElseFaceFace.t3q7xv
[2008/12/04 20:46:44 | 000,053,264 | ---- | C] () -- C:\ProgramData\ElseFaceFace.67je0
[2008/12/04 20:24:33 | 000,032,784 | ---- | C] () -- C:\ProgramData\ElseFaceFace.l3qcor
[2008/12/04 20:02:37 | 000,311,312 | ---- | C] () -- C:\ProgramData\ElseFaceFace.16unasi
[2008/12/04 19:40:32 | 000,016,400 | ---- | C] () -- C:\ProgramData\ElseFaceFace.w7n3esr
[2008/12/04 19:16:49 | 000,081,936 | ---- | C] () -- C:\ProgramData\ElseFaceFace.38d8dt
[2008/12/04 18:54:09 | 000,094,224 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ex40kap
[2008/12/04 18:31:23 | 000,380,944 | ---- | C] () -- C:\ProgramData\ElseFaceFace.j1nkqe
[2008/12/04 18:08:57 | 000,225,296 | ---- | C] () -- C:\ProgramData\ElseFaceFace.2m4zh2z
[2008/12/04 17:46:53 | 000,352,272 | ---- | C] () -- C:\ProgramData\ElseFaceFace.tn2qi
[2008/12/04 17:24:49 | 000,360,464 | ---- | C] () -- C:\ProgramData\ElseFaceFace.kl2p4o
[2008/12/04 17:24:18 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\8ae53219b1eed16
[2008/12/04 17:24:13 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a4aa909277f05902
[2008/12/04 17:24:08 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\63748b7d2b6a3a01
[2008/12/04 17:24:03 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c27cbd49e0593881
[2008/12/04 17:23:58 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\bfc7de68dd119e54
[2008/12/04 17:23:53 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\dee3fc7f8527d0b
[2008/12/04 17:23:48 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ac981666fc7e19ba
[2008/12/04 17:23:43 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\23f24f37844e129
[2008/12/04 17:23:38 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\455684d9ac97afeb
[2008/12/04 17:23:33 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e72946d2b6e66723
[2008/12/04 17:23:28 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b28d1a6893f522a3
[2008/12/04 17:23:23 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a6eef0b317873ff
[2008/12/04 17:23:18 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4a583c3f18ce7599
[2008/12/04 17:23:13 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ffdb1fd48f6810b8
[2008/12/04 17:23:08 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5f7cc7c04fec9228
[2008/12/04 17:23:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\66eb6ca31a0ecea0
[2008/12/04 17:22:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5de7b8c4db83779f
[2008/12/04 17:22:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\94119a4d861604b9
[2008/12/04 17:22:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\439f3b1b58212554
[2008/12/04 17:22:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7d3078ffd7892197
[2008/12/04 17:22:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7943c4a2493487d6
[2008/12/04 17:22:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\16e9455483666708
[2008/12/04 17:22:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\3a99cce6c8ba595d
[2008/12/04 17:22:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a246c9722939aaa0
[2008/12/04 17:22:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\541677ea5c785984
[2008/12/04 17:22:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\443ca76a215599c6
[2008/12/04 17:22:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4dfb11e78b364215
[2008/12/04 17:22:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e57516d26016ae5d
[2008/12/04 17:21:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\85b7dcfbae225d42
[2008/12/04 17:21:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e304b69479921f1f
[2008/12/04 17:21:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\8045f51617523ce1
[2008/12/04 17:02:47 | 000,057,360 | ---- | C] () -- C:\ProgramData\ElseFaceFace.g7b8ww
[2008/12/04 16:40:38 | 000,258,064 | ---- | C] () -- C:\ProgramData\ElseFaceFace.pm4kwy
[2008/12/04 16:18:39 | 000,008,208 | ---- | C] () -- C:\ProgramData\ElseFaceFace.tmh4kgs
[2008/12/04 15:56:38 | 000,155,664 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8ewfdrw
[2008/12/04 15:34:27 | 000,016,400 | ---- | C] () -- C:\ProgramData\ElseFaceFace.vhsc3sx
[2008/12/04 15:12:23 | 000,040,976 | ---- | C] () -- C:\ProgramData\ElseFaceFace.494hg
[2008/12/04 14:50:26 | 000,094,224 | ---- | C] () -- C:\ProgramData\ElseFaceFace.oxhuah
[2008/12/04 14:28:29 | 000,233,488 | ---- | C] () -- C:\ProgramData\ElseFaceFace.82cou
[2008/12/04 14:06:33 | 000,397,328 | ---- | C] () -- C:\ProgramData\ElseFaceFace.o3860
[2008/12/04 13:44:36 | 000,360,464 | ---- | C] () -- C:\ProgramData\ElseFaceFace.tl69au
[2008/12/04 13:22:38 | 000,303,120 | ---- | C] () -- C:\ProgramData\ElseFaceFace.tucoj
[2008/12/04 13:00:43 | 000,221,200 | ---- | C] () -- C:\ProgramData\ElseFaceFace.071ko1v
[2008/12/04 12:38:39 | 000,335,888 | ---- | C] () -- C:\ProgramData\ElseFaceFace.nm3hcby
[2008/12/04 12:16:37 | 000,274,448 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8qvu0u
[2008/12/04 11:54:25 | 000,208,912 | ---- | C] () -- C:\ProgramData\ElseFaceFace.t9r3l
[2008/12/04 11:32:04 | 000,385,040 | ---- | C] () -- C:\ProgramData\ElseFaceFace.juwb1
[2008/12/04 11:10:03 | 000,299,024 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8e2vuob
[2008/12/04 10:48:05 | 000,081,936 | ---- | C] () -- C:\ProgramData\ElseFaceFace.r27p4q0
[2008/12/04 10:26:01 | 000,253,968 | ---- | C] () -- C:\ProgramData\ElseFaceFace.m1llv
[2008/12/04 10:04:02 | 000,323,600 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ae6fi
[2008/12/04 09:42:01 | 000,069,648 | ---- | C] () -- C:\ProgramData\ElseFaceFace.bw6h00s
[2008/12/04 09:13:55 | 000,086,032 | ---- | C] () -- C:\ProgramData\ElseFaceFace.fruljw
[2008/12/04 08:51:46 | 000,180,240 | ---- | C] () -- C:\ProgramData\ElseFaceFace.plee9
[2008/12/04 08:29:41 | 000,053,264 | ---- | C] () -- C:\ProgramData\ElseFaceFace.l2u6jl
[2008/12/04 08:07:39 | 000,024,592 | ---- | C] () -- C:\ProgramData\ElseFaceFace.k77sj5q
[2008/12/04 07:45:35 | 000,389,136 | ---- | C] () -- C:\ProgramData\ElseFaceFace.alxcn
[2008/12/04 07:23:37 | 000,380,944 | ---- | C] () -- C:\ProgramData\ElseFaceFace.m74ic
[2008/12/04 07:01:38 | 000,303,120 | ---- | C] () -- C:\ProgramData\ElseFaceFace.erx5p
[2008/12/04 06:39:39 | 000,098,320 | ---- | C] () -- C:\ProgramData\ElseFaceFace.luj5g1
[2008/12/04 06:16:08 | 000,278,544 | ---- | C] () -- C:\ProgramData\ElseFaceFace.874lwiq
[2008/12/04 05:54:02 | 000,102,416 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ui51j
[2008/12/04 05:32:05 | 000,180,240 | ---- | C] () -- C:\ProgramData\ElseFaceFace.sdiotm
[2008/12/04 05:09:57 | 000,118,800 | ---- | C] () -- C:\ProgramData\ElseFaceFace.n7d8tx
[2008/12/04 04:47:57 | 000,143,376 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8i9x2
[2008/12/04 04:26:00 | 000,405,520 | ---- | C] () -- C:\ProgramData\ElseFaceFace.fzpzeax
[2008/12/04 04:04:04 | 000,380,944 | ---- | C] () -- C:\ProgramData\ElseFaceFace.mkh1f
[2008/12/04 03:42:02 | 000,188,432 | ---- | C] () -- C:\ProgramData\ElseFaceFace.f0e9x0
[2008/12/04 03:20:07 | 000,151,568 | ---- | C] () -- C:\ProgramData\ElseFaceFace.2vr4n
[2008/12/04 02:58:14 | 000,020,496 | ---- | C] () -- C:\ProgramData\ElseFaceFace.h0oetim
[2008/12/04 02:36:21 | 000,348,176 | ---- | C] () -- C:\ProgramData\ElseFaceFace.wtojhw
[2008/12/04 02:14:28 | 000,278,544 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ggd5eoa
[2008/12/04 01:52:35 | 000,258,064 | ---- | C] () -- C:\ProgramData\ElseFaceFace.0k627
[2008/12/04 01:30:42 | 000,196,624 | ---- | C] () -- C:\ProgramData\ElseFaceFace.lr3vvf
[2008/12/04 01:08:48 | 000,135,184 | ---- | C] () -- C:\ProgramData\ElseFaceFace.9x55bs8
[2008/12/04 00:46:47 | 000,270,352 | ---- | C] () -- C:\ProgramData\ElseFaceFace.3njq9o
[2008/12/04 00:24:48 | 000,303,120 | ---- | C] () -- C:\ProgramData\ElseFaceFace.dwumvs
[2008/12/03 21:39:10 | 000,180,240 | ---- | C] () -- C:\ProgramData\ElseFaceFace.mhkyiq
[2008/12/03 21:17:15 | 000,196,624 | ---- | C] () -- C:\ProgramData\ElseFaceFace.0ih1k
[2008/12/03 20:55:20 | 000,376,848 | ---- | C] () -- C:\ProgramData\ElseFaceFace.swi6c36
[2008/12/03 20:33:21 | 000,028,688 | ---- | C] () -- C:\ProgramData\ElseFaceFace.q2d51
[2008/12/03 20:11:18 | 000,155,664 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ungi4sq
[2008/12/03 19:49:19 | 000,249,872 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8j6qcu7
[2008/12/03 19:27:24 | 000,327,696 | ---- | C] () -- C:\ProgramData\ElseFaceFace.vqbt7t
[2008/12/03 19:05:28 | 000,106,512 | ---- | C] () -- C:\ProgramData\ElseFaceFace.h97oi6r
[2008/12/03 18:43:17 | 000,241,680 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ugqyij
[2008/12/03 18:21:23 | 000,000,016 | ---- | C] () -- C:\ProgramData\ElseFaceFace.afu6yv
[2008/12/03 17:59:28 | 000,294,928 | ---- | C] () -- C:\ProgramData\ElseFaceFace.g8wfama
[2008/12/03 17:37:30 | 000,069,648 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ac2pf
[2008/12/03 17:15:28 | 000,057,360 | ---- | C] () -- C:\ProgramData\ElseFaceFace.3cdvf
[2008/12/03 16:53:26 | 000,323,600 | ---- | C] () -- C:\ProgramData\ElseFaceFace.8li6a
[2008/12/03 16:45:41 | 000,213,008 | ---- | C] () -- C:\ProgramData\axis enc body.33qk5id
[2008/12/03 16:44:42 | 000,348,176 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ou7pqvr
[2008/12/03 16:44:41 | 000,196,624 | ---- | C] () -- C:\ProgramData\ElseFaceFace.yuwwwcy
[2008/12/03 16:31:24 | 000,303,120 | ---- | C] () -- C:\ProgramData\ElseFaceFace.qjqvqw7
[2008/12/03 16:09:09 | 000,270,352 | ---- | C] () -- C:\ProgramData\ElseFaceFace.hzwsn
[2008/12/03 15:46:54 | 000,004,112 | ---- | C] () -- C:\ProgramData\ElseFaceFace.hyzys
[2008/12/01 22:36:43 | 000,114,704 | ---- | C] () -- C:\ProgramData\ElseFaceFace.gfkel2
[2008/12/01 15:04:54 | 000,077,840 | ---- | C] () -- C:\ProgramData\ElseFaceFace.quf5j
[2008/12/01 14:43:49 | 000,225,296 | ---- | C] () -- C:\ProgramData\ElseFaceFace.sc6ot
[2008/12/01 14:23:56 | 000,356,368 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ta82lbe
[2008/12/01 14:00:45 | 000,118,800 | ---- | C] () -- C:\ProgramData\ElseFaceFace.ud08hjx
[2008/12/01 11:20:09 | 000,000,079 | ---- | C] () -- C:\Windows\few-oneclick-repertoire.ini
[2008/12/01 11:19:57 | 000,000,079 | ---- | C] () -- C:\Windows\few-repertoire-1024.ini
[2008/11/30 22:23:06 | 000,058,792 | ---- | C] () -- C:\Windows\System32\wbload.dll
[2008/11/29 14:05:08 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\81000b0a3e1b5479
[2008/11/29 14:05:03 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c8a308c8296a230
[2008/11/29 14:04:28 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5e723a73a4a5025a
[2008/11/29 14:04:23 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\cdbc80166fcf9641
[2008/11/29 14:04:18 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b3e1f6b621bde6cc
[2008/11/29 14:04:13 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7d77870e5cfb5237
[2008/11/29 14:04:08 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\62cc9819fd6ccc1f
[2008/11/29 14:04:03 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9153140e6cf778ee
[2008/11/29 14:03:58 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7e38d3a28d2da224
[2008/11/29 14:03:53 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\226fdc4c43913361
[2008/11/29 14:03:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a8bbb26068d04ec4
[2008/11/29 14:03:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7147d737a238a936
[2008/11/29 14:03:33 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a8f3b8552939c9ef
[2008/11/29 14:03:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\96736d621498270f
[2008/11/29 14:03:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5cab63de464afef0
[2008/11/29 14:03:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d6d30338c05225f
[2008/11/29 14:03:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2f63163b8f715a4f
[2008/11/29 14:03:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d9d7b3eb5b513024
[2008/11/29 14:03:03 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ca570e929b61843a
[2008/11/29 14:03:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\bd04fc2999f797a2
[2008/11/29 13:53:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f96f47983ea947c7
[2008/11/29 13:53:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\607383dbccb59b2e
[2008/11/29 13:53:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\fef12f37dcb948ad
[2008/11/29 13:53:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\40223987c0cebab7
[2008/11/29 13:53:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d3b7710c893b3306
[2008/11/29 13:53:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\95d5a7cb9a6e79c5
[2008/11/29 13:53:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b30c98a2ff27c30e
[2008/11/29 13:52:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9c6ae86324a061b1
[2008/11/29 13:52:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a155e66e3aab6ad9
[2008/11/29 13:52:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d3f427fa42be82f3
[2008/11/29 13:52:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6e4b6a442fe0e193
[2008/11/29 13:52:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e3036fbf5aae0bfe
[2008/11/29 13:49:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d4213771cb3525c1
[2008/11/29 13:48:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a3346eda4b0cfd4
[2008/11/29 13:48:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c7b35d06af4bfb8d
[2008/11/29 13:48:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\831b208a88e93360
[2008/11/29 13:48:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a985ccb733c25101
[2008/11/29 13:48:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2bfae833c7fc1064
[2008/11/29 13:48:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\37213bd7aaad2c35
[2008/11/29 13:48:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\41f8481da531d0be
[2008/11/29 13:48:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\28aa687f8110de6
[2008/11/29 13:48:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2bd50dd748c183a5
[2008/11/29 13:48:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6711ecaa1d825f6b
[2008/11/29 13:48:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\efdb813b65a9cee4
[2008/11/29 13:47:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d1f34e9ecd359e21
[2008/11/29 13:47:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f58978b65c6d65cc
[2008/11/29 13:47:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4bb18495e17576b3
[2008/11/29 13:47:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\87fb543eb0412b5
[2008/11/29 13:47:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f8668ca0a9e1d131
[2008/11/29 13:47:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\dd8e81e4fedb3430
[2008/11/29 13:47:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\64d7ccaa8130fb5f
[2008/11/29 13:47:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5997e9adac5f0635
[2008/11/29 13:47:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9e9a66a88bf33f0
[2008/11/29 13:47:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d4c55b0d4dc57b8e
[2008/11/29 13:47:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\df14af5f167b0200
[2008/11/29 13:47:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9719e94dd2b95c9
[2008/11/29 13:46:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\40fb8eaf21bf5131
[2008/11/29 13:46:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4365ceb689db76b7
[2008/11/29 13:46:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d7dc1d79cc6c3732
[2008/11/29 13:46:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5f05a3654f9bf3d9
[2008/11/29 13:44:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9e15c94812b106eb
[2008/11/29 13:44:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c85b04e14f0a4258
[2008/11/29 13:44:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d9ce5d3e945f7d2e
[2008/11/29 13:44:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f20c5eb8c3a40b
[2008/11/29 13:44:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9b62ee65d0d84035
[2008/11/29 13:44:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4e1bffeedd341166
[2008/11/29 13:43:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a12bbe72ff31b169
[2008/11/29 13:43:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e6ed99d7dffe300c
[2008/11/29 13:43:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\df2be60059e8dfd8
[2008/11/29 13:43:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\afd7c747f81f9f23
[2008/11/29 13:43:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\70042177892a4e9c
[2008/11/29 13:43:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\30917d2e58b7327a
[2008/11/29 13:43:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\42be9fd7c4471cf9
[2008/11/29 13:43:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\158f3657a04ab2e
[2008/11/29 13:43:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a963a81567f2b7ed
[2008/11/29 13:43:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a71eb07adcdf08b2
[2008/11/29 13:43:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\49a8d5c820219a19
[2008/11/29 13:42:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5f3cb3f74c1f9f76
[2008/11/29 13:42:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a9d6154efe318fb0
[2008/11/29 13:42:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c034723b90e4e009
[2008/11/29 13:42:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5426b210899405e5
[2008/11/29 13:42:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9e0780f17c0291bb
[2008/11/29 13:42:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b00c9f79c33a1b63
[2008/11/29 13:42:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6ae4f97c1c97afe6
[2008/11/29 13:42:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5cd6e9d637cd1fcb
[2008/11/29 13:42:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f3717a7a2dca1b40
[2008/11/29 13:42:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\932c8bbeb7795c87
[2008/11/29 13:42:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\496defadf08ee227
[2008/11/29 13:41:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c7245dc4af2a06bd
[2008/11/29 13:41:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c19731da185601a2
[2008/11/29 13:41:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\bc9b86c370399662
[2008/11/29 13:41:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9002cb1dcf613c87
[2008/11/29 13:41:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\32b98aa5c4ceb68d
[2008/11/29 13:41:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\df2a491171043ae0
[2008/11/29 13:41:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f526c83cf511cb6b
[2008/11/29 13:41:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\eddeaaeb754dcbfa
[2008/11/29 13:41:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e213366115a84aa9
[2008/11/29 13:41:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b0999dcac3a66073
[2008/11/29 13:41:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\64f8c16ecdd270f4
[2008/11/29 13:41:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c57445598e43466c
[2008/11/29 13:40:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\95111046d0d304c1
[2008/11/29 13:40:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7962a6edb2f537ad
[2008/11/29 13:40:48 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\632fc5dd2e07218d
[2008/11/29 13:39:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d0de657e686e3b43
[2008/11/29 13:39:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\84bdac14aba299e
[2008/11/29 13:39:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\3fde5be5c3ce6b1b
[2008/11/29 13:39:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6c08d988874a2200
[2008/11/29 13:38:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9f3e768bbe9b067e
[2008/11/29 13:38:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\84949b0d1d3b5d5
[2008/11/29 13:38:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\94803ae16c7d076f
[2008/11/29 13:38:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\693bdb6f4a5603f6
[2008/11/29 13:38:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\bbd6c33be8bcb4f9
[2008/11/29 13:38:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a45e1bcab32bf3a2
[2008/11/29 13:38:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7829c672969947cd
[2008/11/29 13:38:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c672d4a2d1edcc74
[2008/11/29 13:38:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ec94ab6994cdef5d
[2008/11/29 13:38:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\19b75171f4a946d1
[2008/11/29 13:38:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d9fa1368a991a610
[2008/11/29 13:38:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\25f30a79d9ea960e
[2008/11/29 13:37:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\cf9e147692b5a229
[2008/11/29 13:37:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\82ccbe49fdc23519
[2008/11/29 13:37:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\571d64ffa12ad06d
[2008/11/29 13:37:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\16f9263f268ad3df
[2008/11/29 13:37:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\997abb3a2234a6c9
[2008/11/29 13:37:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\678326e9af28a6d1
[2008/11/29 13:37:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\64b765d6d79b199
[2008/11/29 13:37:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4e6afa1a3323b86
[2008/11/29 13:37:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5f8d03d2ff70c096
[2008/11/29 13:37:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b57910d21bd9eb35
[2008/11/29 13:37:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\64e6c896722a582e
[2008/11/29 13:36:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4c60ac4f7b2a8d72
[2008/11/29 13:36:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\97a429078c9f418b
[2008/11/29 13:36:48 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\eb1cab14f460f9ce
[2008/11/29 13:35:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\de3dc8b97df2db20
[2008/11/29 13:34:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7ee99a63c590d75a
[2008/11/29 13:34:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e304e64ba36b9540
[2008/11/29 13:34:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6b11e149124a34b5
[2008/11/29 13:34:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1342a7ee9dc2c00
[2008/11/29 13:34:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5d6eb93719638f21
[2008/11/29 13:34:37 | 000,001,006 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef509C.manifest
[2008/11/29 13:34:37 | 000,000,011 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef509S.manifest
[2008/11/29 13:34:37 | 000,000,011 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef509O.manifest
[2008/11/29 13:34:36 | 000,000,799 | -HS- | C] () -- C:\Users\USER\AppData\Roaming\020000000e3e68ef509P.manifest
[2008/11/29 13:34:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5709554123b2b5db
[2008/11/29 13:34:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\71b937d425f041ba
[2008/11/29 13:34:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6b09baf3d1431dba
[2008/11/29 13:34:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\fd712e7f41b73f4e
[2008/11/29 13:34:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\8f1cf5fa567a5bb9
[2008/11/29 13:34:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c748aa5094abe140
[2008/11/29 13:34:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c9405b3dd4f2e16e
[2008/11/29 13:33:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\211c25d295e34c41
[2008/11/29 13:33:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c02aff622a077c93
[2008/11/29 13:33:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\90f807bed1ff3633
[2008/11/29 13:33:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5c7bf7bbc2922c81
[2008/11/29 13:33:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f0bba271186ba3a4
[2008/11/29 13:33:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b350ecfe33fe942d
[2008/11/29 13:33:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\183124fab7d6d386
[2008/11/29 13:33:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\55326966926e809
[2008/11/29 13:33:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\607560457b2a79b7
[2008/11/29 13:33:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a3028b173f84abfa
[2008/11/29 13:33:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\71c948d57de9c1da
[2008/11/29 13:33:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\95615a1c50af2930
[2008/11/29 13:32:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\97bee691cb88c40d
[2008/11/29 13:32:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\90f61ffa2ab46973
[2008/11/29 13:32:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1654dfd01562b4bb
[2008/11/29 13:32:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\22a055e54fad2234
[2008/11/29 13:32:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c065a6fd3e0101a1
[2008/11/29 13:32:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\514637d29895303e
[2008/11/29 13:32:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ad75888fb368abf0
[2008/11/29 13:31:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4c3ac91a8d3c5c67
[2008/11/29 13:31:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7ce9a8fd21a5f866
[2008/11/29 13:31:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\81666ab8e8ccfdfc
[2008/11/29 13:31:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9c8e0576a1ce41d9
[2008/11/29 13:31:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\202a4b489b915b6f
[2008/11/29 13:31:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2f2b2927f3cd0d63
[2008/11/29 13:31:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\34afa5d0b6134931
[2008/11/29 13:31:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6b0c2283a4670d4c
[2008/11/29 13:31:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ea9ca2ac1c5be192
[2008/11/29 13:31:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4148a5cbafa84866
[2008/11/29 13:31:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5a2cb362f4ee318c
[2008/11/29 13:31:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7bdbf60e9b94c076
[2008/11/29 13:30:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\249e8293eb0d7fbf
[2008/11/29 13:30:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\51955b9dd2a0b97c
[2008/11/29 13:30:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\851bbfbfc58b4b2
[2008/11/29 13:30:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b92aec11e808ad45
[2008/11/29 13:30:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a59af8adc1732d53
[2008/11/29 13:30:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7d69ed4cc597d32e
[2008/11/29 13:30:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a14e10aab9c12130
[2008/11/29 13:30:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e950b70c7e0d77f4
[2008/11/29 13:30:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\f82875f89c4238c7
[2008/11/29 13:30:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1efcd075191c813f
[2008/11/29 13:30:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\175f22d3772b7138
[2008/11/29 13:30:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\850f0a9491941057
[2008/11/29 13:29:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\dcba4698878d6e
[2008/11/29 13:29:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ce252cdaa8c30fc
[2008/11/29 13:29:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\fbc3090944e42ecc
[2008/11/29 13:29:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\63d4155249ab0c16
[2008/11/29 13:29:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\60ffd288e1053a57
[2008/11/29 13:29:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\bb57cc0374d4d737
[2008/11/29 13:29:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1fbf1acfb76638ac
[2008/11/29 13:28:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ddf6cd83d824b7c8
[2008/11/29 13:28:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9ad40c6c20ab6560
[2008/11/29 13:28:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2b6ecaff50646d2
[2008/11/29 13:28:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\3b1565f097fe7506
[2008/11/29 13:28:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\773c10b7b60c00b8
[2008/11/29 13:28:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2b1f8babd0e2f51d
[2008/11/29 13:28:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\857da7d1d020e27d
[2008/11/29 13:28:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1dd7e2701c1d0278
[2008/11/29 13:28:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6fffb7aa771b887
[2008/11/29 13:27:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\91d430f635efc2f4
[2008/11/29 13:27:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5a7820e6a1b123dd
[2008/11/29 13:27:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c23e28f5f5177915
[2008/11/29 13:27:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9cfc4f6bf13b8b1c
[2008/11/29 13:27:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\121cec4d48f4672c
[2008/11/29 13:27:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b292b294d238410e
[2008/11/29 13:27:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\dccec97b9b4f6d83
[2008/11/29 13:27:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b993c3f1a1865a6d
[2008/11/29 13:27:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\baa67626feaf5313
[2008/11/29 13:26:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\58eb79fa8b7e5a49
[2008/11/29 13:26:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\cfe2c94aa76a879e
[2008/11/29 13:26:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1c13f2c2ed466037
[2008/11/29 13:26:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\41fd8baf4c989b57
[2008/11/29 13:26:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\602bded9b93c79b
[2008/11/29 13:26:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1638af5739b7668f
[2008/11/29 13:26:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\8ecde917efae92ea
[2008/11/29 13:26:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4397ebb898f18c02
[2008/11/29 13:26:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\44cf44449658d6e2
[2008/11/29 13:26:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7292e95413e193ee
[2008/11/29 13:26:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\39ba158b23762ee6
[2008/11/29 13:25:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\d6e8a89b56427767
[2008/11/29 13:25:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b0596280536b364
[2008/11/29 13:25:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7dd532461b0b061e
[2008/11/29 13:25:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1cd91b942a6e58dc
[2008/11/29 13:25:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4c84dc85907e64d
[2008/11/29 13:24:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4e8c2182f0c81563
[2008/11/29 13:24:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\fa271e12429cbb8
[2008/11/29 13:24:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6c4268aa7fb500c6
[2008/11/29 13:24:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9c6dd0792afccd45
[2008/11/29 13:24:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4b22e99e16cf8e12
[2008/11/29 13:24:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2ac1e342a2899350
[2008/11/29 13:24:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\8210bea8f436bac0
[2008/11/29 13:24:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\968f9d7c8e0ca650
[2008/11/29 13:24:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\825e3b8ccd8eae
[2008/11/29 13:24:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6ccc688b78b7ba93
[2008/11/29 13:24:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6f38e9ac7e80959c
[2008/11/29 13:23:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\88b69beaaa23c92e
[2008/11/29 13:23:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\547480cc81fd0305
[2008/11/29 13:23:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b5ef6c0e6487eab6
[2008/11/29 13:23:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4b35ed0a7639b445
[2008/11/29 13:23:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a2b1f7c2a1932b3b
[2008/11/29 13:23:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\43ac3b87b6282f6e
[2008/11/29 13:23:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\da91f306c228a0a7
[2008/11/29 13:23:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4915ad929379195
[2008/11/29 13:23:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\ca3e99288120348
[2008/11/29 13:23:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\6544c7261e491d5
[2008/11/29 13:23:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\403606b932c1a5d0
[2008/11/29 13:23:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\298d3e0da54faac0
[2008/11/29 13:22:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\5f6801efce392878
[2008/11/29 13:22:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c99b81a5914b1806
[2008/11/29 13:22:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9fe66e7d69e7634
[2008/11/29 13:22:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1d0df36b4499fc9f
[2008/11/29 13:22:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\936a24359273c99b
[2008/11/29 13:22:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\82154fb8ee96da80
[2008/11/29 13:22:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\16e4d3a901855a7
[2008/11/29 13:22:26 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b18b717f2dd2d98a
[2008/11/29 13:22:25 | 000,000,062 | -H-- | C] () -- C:\Users\USER\AppData\Local\Thumbs.db
[2008/11/29 13:22:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\22ea20dec720b648
[2008/11/29 13:22:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\e63c9ee3e79ab40a
[2008/11/29 13:21:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\94d778aa18f5408
[2008/11/29 13:21:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4144045d1fddfdee
[2008/11/29 13:21:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\1907f7d24e654a7c
[2008/11/29 13:21:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\a9db0a08e95168b2
[2008/11/29 13:21:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\de8ad9a6c8cc903
[2008/11/29 13:21:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\597a09811ead352
[2008/11/29 13:21:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\30b950a5926376d2
[2008/11/29 13:21:22 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\8f072f9d807bb955
[2008/11/29 13:21:17 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7ec9a8e09f959a17
[2008/11/29 13:21:12 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\b3c751a27ff5338c
[2008/11/29 13:21:07 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\afa3124e1d2eda5
[2008/11/29 13:21:02 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\2d5cf18fce46cf19
[2008/11/29 13:20:57 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\c9d7ce0a578200cd
[2008/11/29 13:20:52 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\9aa7954066aa5e50
[2008/11/29 13:20:47 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\10e36a4c1c7517af
[2008/11/29 13:20:42 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\785f6e01a77828d
[2008/11/29 13:20:37 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\100515f68ccd45ee
[2008/11/29 13:20:32 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\7765b015ef1b2228
[2008/11/29 13:20:27 | 000,003,262 | ---- | C] () -- C:\Users\USER\AppData\Roaming\4111af44b0f9246d
[2008/11/21 02:51:05 | 000,000,064 | ---- | C] () -- C:\Windows\yesmessenger.ini
[2008/11/08 21:36:04 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2008/10/28 12:23:40 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2008/10/28 12:23:40 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2008/10/28 12:23:40 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2008/10/22 09:03:28 | 000,003,660 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008/03/05 09:28:28 | 000,286,208 | ---- | C] () -- C:\Windows\System32\cncs232.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/10/22 04:40:06 | 000,145,408 | ---- | C] () -- C:\Users\USER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/01/01 11:51:22 | 000,069,632 | ---- | C] () -- C:\Windows\System32\vuins32.dll
[2006/01/01 11:51:21 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2006/01/01 11:24:31 | 000,000,680 | ---- | C] () -- C:\Users\USER\AppData\Local\d3d9caps.dat
[1999/01/22 08:46:58 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL
========== LOP Check ========== [2009/01/11 12:51:07 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\.wyzo
[2009/10/20 22:20:29 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\2020 Fusion
[2008/12/01 20:46:43 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\AD ON Multimedia
[2009/09/01 10:09:39 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\CVitae
[2009/02/03 08:20:03 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\DAEMON Tools
[2009/02/03 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\DAEMON Tools Lite
[2009/02/03 08:20:02 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\DAEMON Tools Pro
[2008/12/01 23:47:19 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\EleFun Desktops
[2009/04/23 11:10:09 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Flood Light Games
[2009/07/02 17:06:14 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\fltk.org
[2008/11/28 09:56:39 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\funkitron
[2009/08/03 14:59:07 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Gearbox Software
[2008/11/23 05:48:50 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\GetRightToGo
[2010/03/06 04:22:01 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\igraal
[2009/08/23 21:06:12 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\InfraRecorder
[2009/06/23 18:33:42 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\iPodder
[2008/10/23 08:41:26 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Leadertech
[2010/03/17 14:02:47 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\LimeWire
[2010/02/03 18:29:31 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\LiveCAD3
[2009/01/03 18:11:33 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\NetMedia Providers
[2008/12/01 21:19:33 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Nubs
[2009/09/18 21:41:06 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\OpenCandy
[2008/11/11 16:35:58 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\opencity
[2006/10/21 20:12:40 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\OpenOffice.org
[2010/03/06 03:44:01 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Passware
[2009/01/03 18:11:33 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Publish Providers
[2009/10/22 16:54:25 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\recfree.com
[2009/09/18 21:49:12 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Regensoft
[2009/09/08 16:47:30 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\SecondLife
[2009/10/01 14:57:30 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Serif
[2009/03/24 15:45:28 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Shareaza
[2010/03/17 13:50:01 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Soft2PC
[2009/05/24 09:20:19 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Sony
[2008/12/10 11:46:43 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\streamripper
[2010/02/01 21:32:24 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Template
[2010/03/17 14:08:46 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\UseNeXT
[2009/09/13 02:23:32 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Windows Live Writer
[2009/04/23 09:42:14 | 000,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\Zylom
[2010/03/22 09:31:05 | 000,032,572 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/03/22 09:56:09 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{334A4BE3-F41F-44AD-887E-AFD029110187}.job
[2010/03/22 09:56:08 | 000,000,400 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{E06C9524-D4BE-4048-BC8E-FA1C4EEFDE4C}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: AGP440.SYS >[2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/01/01 11:49:43 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2006/01/01 11:49:43 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2006/01/01 11:49:43 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2006/11/02 05:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 05:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: AHCIX86S.SYS >[2008/04/02 15:40:48 | 000,175,632 | ---- | M] (AMD Technologies Inc.) MD5=844A6734E8BB3530FB1444ED698087BD -- C:\ATI\SUPPORT\8-6_vista32_dd_ccc_wdm_enu_64789\Packages\Drivers\SBDrv\SB7xx\RAID\LH\ahcix86s.sys
[2007/04/16 18:16:34 | 000,119,296 | ---- | M] (ATI Technologies Inc.) MD5=A5AC7B705166BF7CD07BB054BEEA8D03 -- C:\ATI\SUPPORT\8-6_vista32_dd_ccc_wdm_enu_64789\Packages\Drivers\SBDrv\SB6xx\RAID\LH64A\ahcix86s.sys
< MD5 for: ATAPI.SYS >[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 03:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/19 03:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 05:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007/05/30 11:01:31 | 000,021,688 | ---- | M] (Microsoft Corporation) MD5=78620BDA3EC87816E5D1FA86F920BC3A -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c2a1b5ae\atapi.sys
[2007/05/30 11:01:31 | 000,021,688 | ---- | M] (Microsoft Corporation) MD5=78620BDA3EC87816E5D1FA86F920BC3A -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20518_none_dbd8b4d73d81c9d0\atapi.sys
[2008/10/23 21:25:14 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/10/23 21:25:14 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/10/23 21:25:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2008/10/23 21:25:13 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: CNGAUDIT.DLL >[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >[2008/01/19 03:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/19 03:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 05:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 05:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >[2006/11/02 05:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 03:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >[2007/01/05 16:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\drivers\nvstor.sys
[2007/01/05 16:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys
[2006/11/02 05:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 03:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/19 03:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >[2008/01/19 03:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 05:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2009/04/11 02:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009/04/11 02:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
< %systemroot%\Tasks\*.job /lockedfiles > ========== Alternate Data Streams ========== @Alternate Data Stream - 16 bytes -> C:\Users\USER\Documents\Shareaza Downloads:Shareaza.GUID
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:B623B5B8
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:7F66BF58
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:ADF211B1
< End of report >