Please find the scan logs you requested below;
Also, what exactly did that custom scan do, it took about 15min to complete...lol.
Farbar Service Scanner Version: 19-10-2012
Ran by Dan (administrator) on 21-10-2012 at 11:43:57
Running from "D:\Users\Dan\Desktop"
Microsoft Windows 7 Professional Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
OTL logfile created on: 21/10/2012 12:02:35 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Users\Dan\Desktop\Scan Results from GeekstoGo
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
17.99 Gb Total Physical Memory | 11.61 Gb Available Physical Memory | 64.53% Memory free
21.99 Gb Paging File | 15.56 Gb Available in Paging File | 70.75% Paging File free
Paging file location(s): c:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 874.75 Gb Free Space | 93.91% Space Free | Partition Type: NTFS
Drive D: | 1863.01 Gb Total Space | 1200.09 Gb Free Space | 64.42% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 132.81 Gb Free Space | 14.26% Space Free | Partition Type: NTFS
Drive H: | 279.46 Gb Total Space | 89.76 Gb Free Space | 32.12% Space Free | Partition Type: NTFS
Drive J: | 3.99 Gb Total Space | 3.99 Gb Free Space | 99.96% Space Free | Partition Type: FAT32
Drive X: | 223.57 Gb Total Space | 58.82 Gb Free Space | 26.31% Space Free | Partition Type: NTFS
Computer Name: WIN7-DP | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/10/05 20:42:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\Dan\Desktop\Scan Results from GeekstoGo\OTL.exe
PRC - [2012/09/09 22:45:24 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/03/04 14:56:56 | 005,016,064 | ---- | M] (abelhadigital.com) -- D:\Utilities\HostsMan_4.0.82_beta3\hm.exe
PRC - [2011/09/22 12:03:30 | 000,974,944 | ---- | M] (ESET) -- D:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2010/08/12 20:03:02 | 000,923,072 | ---- | M] (Cyber Power Systems, Inc.) -- D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe
PRC - [2010/08/03 11:02:08 | 000,349,632 | ---- | M] (Cyber Power Systems, Inc.) -- D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
PRC - [2009/12/13 21:23:12 | 000,092,848 | ---- | M] (Binary Fortress Software) -- D:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe
PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/03/12 21:18:48 | 000,602,624 | ---- | M] () -- D:\Program Files (x86)\Everything\Everything.exe
========== Modules (No Company Name) ========== MOD - [2009/03/12 21:18:48 | 000,602,624 | ---- | M] () -- D:\Program Files (x86)\Everything\Everything.exe
========== Services (SafeList) ========== SRV:
64bit: - [2011/09/27 15:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:
64bit: - [2010/08/08 22:04:10 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV:
64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/10/19 11:49:12 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/03 20:46:51 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/09/09 22:45:24 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/09/08 17:20:05 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/09/08 17:19:49 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/04/26 15:03:36 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2011/09/22 12:03:30 | 000,974,944 | ---- | M] (ESET) [Auto | Running] -- D:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV - [2010/08/12 20:03:02 | 000,923,072 | ---- | M] (Cyber Power Systems, Inc.) [Auto | Running] -- D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe -- (ppped)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2012/07/03 11:25:18 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:
64bit: - [2012/03/09 10:57:36 | 000,023,816 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:
64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012/01/20 11:00:46 | 000,106,496 | ---- | M] (SteelSeries Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SteelBus64.sys -- (busenum)
DRV:
64bit: - [2012/01/20 11:00:46 | 000,034,944 | ---- | M] (SteelSeries Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SAlpham64.sys -- (SAlphamHid)
DRV:
64bit: - [2011/12/24 08:45:30 | 000,071,464 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RAMDiskVE.sys -- (RAMDiskVE)
DRV:
64bit: - [2011/11/01 08:23:25 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:
64bit: - [2011/11/01 08:23:25 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:
64bit: - [2011/10/30 23:08:44 | 000,272,448 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2011/09/02 02:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:
64bit: - [2011/09/02 02:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:
64bit: - [2011/08/09 14:24:52 | 000,202,576 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:
64bit: - [2011/08/04 14:13:46 | 001,650,264 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha20x22k.sys -- (ha20x22k)
DRV:
64bit: - [2011/08/04 14:13:32 | 001,605,208 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k)
DRV:
64bit: - [2011/08/04 14:13:22 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)
DRV:
64bit: - [2011/08/04 14:13:12 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:
64bit: - [2011/08/04 14:13:00 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:
64bit: - [2011/08/04 14:12:50 | 000,179,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)
DRV:
64bit: - [2011/08/04 14:12:40 | 000,697,432 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k)
DRV:
64bit: - [2011/08/04 14:12:28 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)
DRV:
64bit: - [2011/08/04 14:12:18 | 001,494,104 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS)
DRV:
64bit: - [2011/08/04 14:12:18 | 001,494,104 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV:
64bit: - [2011/08/04 14:12:06 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS)
DRV:
64bit: - [2011/08/04 14:12:06 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV:
64bit: - [2011/08/04 14:11:56 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS)
DRV:
64bit: - [2011/08/04 14:11:56 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT)
DRV:
64bit: - [2011/08/04 09:20:38 | 000,146,432 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:
64bit: - [2011/08/04 09:20:38 | 000,137,144 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:
64bit: - [2011/07/25 18:44:46 | 000,074,752 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:
64bit: - [2011/07/20 15:58:22 | 000,044,032 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:
64bit: - [2011/05/20 22:04:32 | 000,017,496 | ---- | M] (CH Products) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\chdrvr03.sys -- (chdrvr03)
DRV:
64bit: - [2011/05/20 22:04:30 | 000,013,016 | ---- | M] (CH Products) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\chdrvr02.sys -- (chdrvr02)
DRV:
64bit: - [2011/05/20 22:04:28 | 000,251,224 | ---- | M] (CH Products) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\chdrvr01.sys -- (chdrvr01)
DRV:
64bit: - [2011/04/23 21:30:18 | 000,033,160 | ---- | M] (WeOnlyDo Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wod0205.sys -- (wod0205)
DRV:
64bit: - [2011/03/31 16:01:50 | 000,126,464 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RzSynapse.sys -- (RzSynapse)
DRV:
64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/20 09:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/11/20 09:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2009/11/23 21:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:
64bit: - [2009/11/23 21:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:
64bit: - [2009/10/16 21:09:14 | 000,029,952 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Lachesis.sys -- (VaneFltr)
DRV:
64bit: - [2009/08/21 02:52:10 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:
64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/07/13 20:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:
64bit: - [2009/07/13 20:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV:
64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/06/04 18:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:
64bit: - [2009/05/20 05:10:00 | 000,393,728 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:
64bit: - [2009/05/11 18:49:10 | 000,178,728 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv61xx.sys -- (mv61xx)
DRV - [2010/11/01 06:08:46 | 000,014,544 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- D:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys -- (WinRing0_1_2_0)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-CA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 2D 68 85 11 AE CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{ABF532CA-D32C-4D8F-9333-5242CF180093}: "URL" =
http://open-search.eu/google.phpIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://flvdirect.iamwired.net/"FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.0.2
FF - prefs.js..extensions.enabledItems:
[email protected]:0.5.5
FF - prefs.js..extensions.enabledItems: {4776510a-a1f4-41f3-a3c8-35b474ecef23}:1.0.7
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..keyword.URL: "
http://flvdirect.iam...c=tops&search="FF - prefs.js..keyword.enabled: true
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "
http://flvdirect.iam...c=tops&search=" FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dan\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dan\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: D:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD [2011/10/31 08:57:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components [2012/10/19 11:49:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins [2012/10/19 11:49:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: D:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/10/31 08:57:23 | 000,000,000 | ---D | M]
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
[2010/10/04 12:58:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/23 08:25:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\
[email protected][2012/10/20 02:14:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\extensions
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (Stealther) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\{4776510a-a1f4-41f3-a3c8-35b474ecef23}
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\
[email protected][2012/10/20 02:30:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] (Stealther) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{4776510a-a1f4-41f3-a3c8-35b474ecef23}
[2012/10/20 02:30:03 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/04/15 21:53:49 | 000,000,000 | ---D | M] (ActiveGS) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected][2011/07/09 11:55:38 | 000,330,316 | ---- | M] () (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected][2011/11/25 12:46:20 | 000,255,318 | ---- | M] () (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected][2012/07/25 22:33:07 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2008/09/21 14:55:14 | 000,002,749 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\cuil.xml
[2008/06/22 23:02:53 | 000,000,908 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\imdb.xml
[2010/07/04 02:47:50 | 000,000,266 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\Search.xml
[2008/06/22 23:02:53 | 000,001,108 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\wikipedia-en.xml
File not found (No name found) -- D:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
File not found (No name found) -- D:\PROGRAM FILES (X86)\ORBITDOWNLOADER\ADDONS\ORBITFF
========== Chrome ========== CHR - homepage:
http://www.gamespot.com/CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.gamespot.com/CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Dan\AppData\Local\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Dan\AppData\Local\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Dan\AppData\Local\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_221.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Pando Web Installer (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
CHR - plugin: Adobe Acrobat (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Dan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
O1 HOSTS File: ([2012/10/20 18:24:03 | 001,123,304 | ---- | M]) - C:\Windows\SysNative\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #IPv6 localhost
O1 - Hosts: 127.0.0.1 005.free-counter.co.uk 006.free-counter.co.uk 007.free-counter.co.uk 008.free-counter.co.uk 060810131024.c.mystat-in.net 08.185.87.0.liveadvert.com 08.185.87.00.liveadvert.com 08.185.87.01.liveadvert.com 08.185.87.02.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.03.liveadvert.com 08.185.87.04.liveadvert.com 08.185.87.05.liveadvert.com 08.185.87.06.liveadvert.com 08.185.87.07.liveadvert.com 08.185.87.08.liveadvert.com 08.185.87.09.liveadvert.com 08.185.87.1.liveadvert.com 08.185.87.10.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.100.liveadvert.com 08.185.87.101.liveadvert.com 08.185.87.103.liveadvert.com 08.185.87.104.liveadvert.com 08.185.87.105.liveadvert.com 08.185.87.106.liveadvert.com 08.185.87.107.liveadvert.com 08.185.87.108.liveadvert.com 08.185.87.109.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.11.liveadvert.com 08.185.87.110.liveadvert.com 08.185.87.111.liveadvert.com 08.185.87.113.liveadvert.com 08.185.87.114.liveadvert.com 08.185.87.115.liveadvert.com 08.185.87.116.liveadvert.com 08.185.87.117.liveadvert.com 08.185.87.118.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.119.liveadvert.com 08.185.87.13.liveadvert.com 08.185.87.130.liveadvert.com 08.185.87.131.liveadvert.com 08.185.87.133.liveadvert.com 08.185.87.134.liveadvert.com 08.185.87.135.liveadvert.com 08.185.87.136.liveadvert.com 08.185.87.137.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.138.liveadvert.com 08.185.87.139.liveadvert.com 08.185.87.14.liveadvert.com 08.185.87.140.liveadvert.com 08.185.87.141.liveadvert.com 08.185.87.143.liveadvert.com 08.185.87.144.liveadvert.com 08.185.87.145.liveadvert.com 08.185.87.146.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.147.liveadvert.com 08.185.87.148.liveadvert.com 08.185.87.149.liveadvert.com 08.185.87.15.liveadvert.com 08.185.87.150.liveadvert.com 08.185.87.151.liveadvert.com 08.185.87.153.liveadvert.com 08.185.87.154.liveadvert.com 08.185.87.155.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.156.liveadvert.com 08.185.87.157.liveadvert.com 08.185.87.158.liveadvert.com 08.185.87.159.liveadvert.com 08.185.87.16.liveadvert.com 08.185.87.160.liveadvert.com 08.185.87.161.liveadvert.com 08.185.87.163.liveadvert.com 08.185.87.164.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.165.liveadvert.com 08.185.87.166.liveadvert.com 08.185.87.167.liveadvert.com 08.185.87.168.liveadvert.com 08.185.87.169.liveadvert.com 08.185.87.17.liveadvert.com 08.185.87.170.liveadvert.com 08.185.87.171.liveadvert.com 08.185.87.173.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.174.liveadvert.com 08.185.87.175.liveadvert.com 08.185.87.176.liveadvert.com 08.185.87.177.liveadvert.com 08.185.87.178.liveadvert.com 08.185.87.179.liveadvert.com 08.185.87.18.liveadvert.com 08.185.87.180.liveadvert.com 08.185.87.181.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.183.liveadvert.com 08.185.87.184.liveadvert.com 08.185.87.185.liveadvert.com 08.185.87.186.liveadvert.com 08.185.87.187.liveadvert.com 08.185.87.188.liveadvert.com 08.185.87.189.liveadvert.com 08.185.87.19.liveadvert.com 08.185.87.190.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.191.liveadvert.com 08.185.87.193.liveadvert.com 08.185.87.194.liveadvert.com 08.185.87.195.liveadvert.com 08.185.87.196.liveadvert.com 08.185.87.197.liveadvert.com 08.185.87.198.liveadvert.com 08.185.87.199.liveadvert.com 08.185.87.3.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.30.liveadvert.com 08.185.87.31.liveadvert.com 08.185.87.33.liveadvert.com 08.185.87.34.liveadvert.com 08.185.87.35.liveadvert.com 08.185.87.36.liveadvert.com 08.185.87.37.liveadvert.com 08.185.87.38.liveadvert.com 08.185.87.39.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.4.liveadvert.com 08.185.87.40.liveadvert.com 08.185.87.41.liveadvert.com 08.185.87.43.liveadvert.com 08.185.87.44.liveadvert.com 08.185.87.45.liveadvert.com 08.185.87.46.liveadvert.com 08.185.87.47.liveadvert.com 08.185.87.48.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.49.liveadvert.com 08.185.87.5.liveadvert.com 08.185.87.50.liveadvert.com 08.185.87.51.liveadvert.com 08.185.87.53.liveadvert.com 08.185.87.54.liveadvert.com 08.185.87.55.liveadvert.com 08.185.87.56.liveadvert.com 08.185.87.57.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.58.liveadvert.com 08.185.87.59.liveadvert.com 08.185.87.6.liveadvert.com 08.185.87.60.liveadvert.com 08.185.87.61.liveadvert.com 08.185.87.63.liveadvert.com 08.185.87.64.liveadvert.com 08.185.87.65.liveadvert.com 08.185.87.66.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.67.liveadvert.com 08.185.87.68.liveadvert.com 08.185.87.69.liveadvert.com 08.185.87.7.liveadvert.com 08.185.87.70.liveadvert.com 08.185.87.71.liveadvert.com 08.185.87.73.liveadvert.com 08.185.87.74.liveadvert.com 08.185.87.75.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.76.liveadvert.com 08.185.87.77.liveadvert.com 08.185.87.78.liveadvert.com 08.185.87.79.liveadvert.com 08.185.87.8.liveadvert.com 08.185.87.80.liveadvert.com 08.185.87.81.liveadvert.com 08.185.87.83.liveadvert.com 08.185.87.84.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.85.liveadvert.com 08.185.87.86.liveadvert.com 08.185.87.87.liveadvert.com 08.185.87.88.liveadvert.com 08.185.87.89.liveadvert.com 08.185.87.9.liveadvert.com 08.185.87.90.liveadvert.com 08.185.87.91.liveadvert.com 08.185.87.93.liveadvert.com
O1 - Hosts: 127.0.0.1 08.185.87.94.liveadvert.com 08.185.87.95.liveadvert.com 08.185.87.96.liveadvert.com 08.185.87.97.liveadvert.com 08.185.87.98.liveadvert.com 08.185.87.99.liveadvert.com 0latfee.ero-advertising.com 1.adbrite.com 1.im.cz
O1 - Hosts: 127.0.0.1 1.marketbanker.com 1.servedby.netshelter.net 10.6.87.194.dynamic.dol.ru 100.6.87.194.dynamic.dol.ru 101.6.87.194.dynamic.dol.ru 102.112.2o7.net 102.122.2o7.net 102.6.87.194.dynamic.dol.ru 103.6.87.194.dynamic.dol.ru
O1 - Hosts: 127.0.0.1 104.6.87.194.dynamic.dol.ru 105.6.87.194.dynamic.dol.ru 106.6.87.194.dynamic.dol.ru 107.6.87.194.dynamic.dol.ru 108.6.87.194.dynamic.dol.ru 109.6.87.194.dynamic.dol.ru 11.6.87.194.dynamic.dol.ru 110.6.87.194.dynamic.dol.ru 1100i.com
O1 - Hosts: 127.0.0.1 111.6.87.194.dynamic.dol.ru 112.6.87.194.dynamic.dol.ru 11233.bodisparking.com 113.6.87.194.dynamic.dol.ru 114.6.87.194.dynamic.dol.ru 115.6.87.194.dynamic.dol.ru 116.6.87.194.dynamic.dol.ru 117.6.87.194.dynamic.dol.ru 118.6.87.194.dynamic.dol.ru
O1 - Hosts: 6081 more lines...
O2:
64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:
64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [egui] D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:
64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:
64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Everything] D:\Program Files (x86)\Everything\Everything.exe ()
O4 - HKLM..\Run: [PowerPanel Personal Edition User Interaction] D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe (Cyber Power Systems, Inc.)
O4 - HKCU..\Run: [DisplayFusion] D:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [HostsMan] D:\Utilities\HostsMan_4.0.82_beta3\hm.exe (abelhadigital.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:
64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_04)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16:
64bit: - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_04)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.25 192.168.0.1 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = porter.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{271FC4E1-0192-4AA4-BC2E-86FE092558D2}: DhcpNameServer = 127.0.0.1 192.168.0.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F25B8A8-1564-47B0-82C6-E45C88A57F2B}: DhcpNameServer = 192.168.0.25 192.168.0.1 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F25B8A8-1564-47B0-82C6-E45C88A57F2B}: NameServer = 64.71.255.198,192.168.0.25
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ========== [2012/10/21 01:02:48 | 000,000,000 | -HSD | C] -- C:\found.000
[2012/10/20 16:32:35 | 000,000,000 | ---D | C] -- C:\Users\Dan\Temp
[2012/10/20 15:17:30 | 000,000,000 | ---D | C] -- C:\.Trash-999
[2012/10/20 02:30:07 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\QuickScan
[2012/10/19 23:15:42 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/10/19 23:15:42 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Temp
[2012/10/19 23:13:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/10/19 21:41:49 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/19 21:41:49 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/19 21:41:49 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/19 21:41:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/19 21:41:40 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/19 00:44:34 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Scan Results from GeekstoGo
[2012/10/13 14:09:06 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Games I am Testing
[2012/10/07 02:37:16 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/10/07 02:37:16 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/10/07 02:37:16 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/10/07 02:37:15 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/10/07 02:37:15 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/10/07 02:37:15 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/10/07 02:37:15 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/10/07 02:37:15 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/10/07 02:37:15 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/10/07 02:37:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/10/07 02:37:15 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/10/07 02:37:15 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/10/07 02:37:14 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/10/07 02:37:14 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/10/07 02:37:13 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/10/07 02:31:21 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2012/10/07 02:31:21 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/10/07 02:31:21 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2012/10/07 02:31:21 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2012/10/07 02:31:21 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2012/10/07 02:31:17 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2012/10/06 12:31:09 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Sherlock_Holmes_-_The_Case_of_the_Serrated_Scalpel(ISO)
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Texture_PackCombiner LITE
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Texture_PackCombiner FULL_HD
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\TEMP_TPC_FILES
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Temp_Sharp
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\TEMP Web Sites
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Temp Movies - TV Shows
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\MOVE TO MY DOCUMENTS
[2012/10/06 00:01:49 | 000,000,000 | ---D | C] -- D:\Users\Dan\Desktop\Misc Web Sites - New Unsorted
[2012/10/05 19:48:57 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Stardock
[2012/10/05 13:01:11 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2012/10/05 12:57:58 | 006,193,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2012/10/05 12:57:58 | 003,266,920 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2012/10/05 12:57:58 | 002,557,800 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2012/10/05 12:57:58 | 000,118,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2012/10/05 12:57:58 | 000,063,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2012/10/05 12:57:38 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012/10/05 12:57:00 | 027,577,704 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2012/10/05 12:57:00 | 025,256,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2012/10/05 12:57:00 | 020,817,256 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2012/10/05 12:57:00 | 018,230,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2012/10/05 12:57:00 | 017,559,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2012/10/05 12:57:00 | 015,292,264 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2012/10/05 12:57:00 | 014,879,080 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2012/10/05 12:57:00 | 012,465,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2012/10/05 12:57:00 | 009,066,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2012/10/05 12:57:00 | 007,626,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2012/10/05 12:57:00 | 007,387,496 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2012/10/05 12:57:00 | 006,100,328 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2012/10/05 12:57:00 | 002,745,192 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2012/10/05 12:57:00 | 002,725,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2012/10/05 12:57:00 | 002,573,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2012/10/05 12:57:00 | 002,422,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2012/10/05 12:57:00 | 002,216,808 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2012/10/05 12:57:00 | 001,866,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2012/10/05 12:57:00 | 001,760,104 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2012/10/05 12:57:00 | 001,482,600 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco64.dll
[2012/10/05 12:57:00 | 000,970,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll
[2012/10/05 12:57:00 | 000,829,288 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll
[2012/10/05 12:57:00 | 000,355,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll
[2012/10/05 12:57:00 | 000,308,072 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll
[2012/10/05 12:57:00 | 000,247,144 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll
[2012/10/05 12:57:00 | 000,202,600 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll
[2012/10/05 12:55:58 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012/10/05 02:09:47 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Solid State Networks
[2012/09/29 11:32:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BOSS
[2012/09/28 23:54:37 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2012/09/24 21:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nicolas Games
[2012/09/22 19:20:15 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Runic Games
[2012/09/22 19:20:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Torchlight 2
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/10/21 11:59:09 | 000,000,083 | ---- | M] () -- D:\Users\Dan\Desktop\E3 2012- John Carmack Interview - YouTube.url
[2012/10/21 01:12:35 | 000,025,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/21 01:12:35 | 000,025,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/21 01:11:05 | 000,792,182 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/21 01:11:05 | 000,673,088 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/10/21 01:11:05 | 000,129,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/10/21 01:05:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/21 01:04:58 | 1603,620,861 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/21 01:00:28 | 000,062,836 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/10/21 01:00:28 | 000,000,904 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/10/21 01:00:27 | 000,062,836 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/10/21 00:55:52 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/10/21 00:55:52 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/10/20 18:24:03 | 001,123,304 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\HOSTS
[2012/10/20 18:16:55 | 001,696,502 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\HOSTS.bak
[2012/10/19 13:46:01 | 000,043,999 | ---- | M] () -- D:\Users\Dan\Documents\Visa_Payment_$200_19-Oct-2012.pdf
[2012/10/16 22:50:11 | 206,637,508 | ---- | M] () -- D:\Users\Dan\Desktop\live_user_obsidian_1350414362.flv
[2012/10/16 22:19:28 | 000,336,739 | ---- | M] () -- D:\Users\Dan\Documents\Rogers-HomePhone_Internet__$168.58_16-Oct-2012.pdf
[2012/10/16 21:44:30 | 000,071,245 | ---- | M] () -- D:\Users\Dan\Documents\Visa_Payment_$200_16-Oct-2012.pdf
[2012/10/16 21:43:05 | 000,090,038 | ---- | M] () -- D:\Users\Dan\Documents\Rent_Dad_$218_16-Oct-2012.pdf
[2012/10/16 01:05:08 | 696,057,077 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 21.mp4
[2012/10/16 01:04:04 | 637,331,763 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 20.mp4
[2012/10/15 09:03:15 | 1277,038,155 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 19.mp4
[2012/10/14 15:48:12 | 000,000,650 | ---- | M] () -- D:\Users\Dan\Desktop\temp - Shortcut.lnk
[2012/10/14 00:28:25 | 191,404,660 | ---- | M] () -- D:\Users\Dan\Desktop\Making a simple Fallout 3 mod Automatic Karma Perks.mp4
[2012/10/12 02:33:17 | 092,654,704 | ---- | M] () -- D:\Users\Dan\Desktop\Fallout 3 Mod Clinic part 1 ENCORE Remastered, Blackened and Merged.mp4
[2012/10/10 23:17:27 | 2105,658,793 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 18.mp4
[2012/10/10 22:29:42 | 2044,077,624 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 16.mp4
[2012/10/10 22:26:23 | 1925,541,204 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 15.mp4
[2012/10/10 22:23:56 | 1153,071,429 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 17.mp4
[2012/10/10 22:05:01 | 1725,287,262 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 11.mp4
[2012/10/10 02:14:42 | 1302,548,695 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 Part 13.mp4
[2012/10/10 01:56:40 | 000,000,166 | ---- | M] () -- D:\Users\Dan\Desktop\Network Location Awareness (NLA) and how it relates to Windows Firewall Profiles - Microsoft Enterprise Networking Team - Si.URL
[2012/10/10 01:52:03 | 1334,240,711 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 Part 14.mp4
[2012/10/08 08:37:03 | 1148,753,160 | ---- | M] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 10.mp4
[2012/10/08 01:48:54 | 1163,265,683 | ---- | M] () -- D:\Users\Dan\Desktop\vf_dishonored_ql_100512_zvx_3500.mp4
[2012/10/07 17:45:21 | 1175,900,144 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 12.mp4
[2012/10/07 14:01:45 | 000,000,126 | ---- | M] () -- D:\Users\Dan\Desktop\AGP Texture Acceleration Enabled.reg
[2012/10/07 14:01:12 | 000,000,126 | ---- | M] () -- D:\Users\Dan\Desktop\AGP Texture Acceleration Disabled.reg
[2012/10/07 09:48:42 | 000,412,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/10/07 02:36:48 | 000,777,306 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/06 19:49:49 | 000,071,098 | ---- | M] () -- D:\Users\Dan\Documents\Visa_Payment_$40_06-Oct-2012.pdf
[2012/10/06 12:50:56 | 853,916,999 | ---- | M] () -- D:\Users\Dan\Desktop\Quoted for TruthCliffy B leaves Epic Games.mp4
[2012/10/04 22:26:02 | 1395,766,598 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 8.mp4
[2012/10/04 22:25:52 | 1380,838,861 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 9.mp4
[2012/10/04 02:49:17 | 1607,115,555 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 7.mp4
[2012/10/04 02:47:00 | 1386,365,463 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 6.mp4
[2012/10/02 22:53:05 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settingsbkup.sfm
[2012/10/02 22:53:05 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settings.sfm
[2012/10/02 19:25:48 | 2253,952,302 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 5.mp4
[2012/10/02 13:18:43 | 935,639,840 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 4.mp4
[2012/10/01 17:32:09 | 1913,044,538 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 3.mp4
[2012/09/30 16:23:54 | 000,075,510 | ---- | M] () -- D:\Users\Dan\Documents\Chieftain_Insurance_$163_30-Sep-2012.pdf
[2012/09/30 16:22:08 | 000,076,294 | ---- | M] () -- D:\Users\Dan\Documents\ScotiaLine_$50_30-Sep-2012.pdf
[2012/09/30 16:21:22 | 000,071,647 | ---- | M] () -- D:\Users\Dan\Documents\Visa_Payment_$200_30-Sep-2012.pdf
[2012/09/30 16:20:27 | 000,090,295 | ---- | M] () -- D:\Users\Dan\Documents\Rent_Dad_$270_30-Sep-2012.pdf
[2012/09/28 08:35:40 | 774,414,598 | ---- | M] () -- D:\Users\Dan\Desktop\Borderlands 2_Gamespot_hardware_comparison.mp4
[2012/09/25 02:21:54 | 1150,511,496 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 2.mp4
[2012/09/24 22:46:55 | 1184,335,437 | ---- | M] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 1.mp4
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/10/21 11:59:09 | 000,000,083 | ---- | C] () -- D:\Users\Dan\Desktop\E3 2012- John Carmack Interview - YouTube.url
[2012/10/19 21:41:49 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/19 21:41:49 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/19 21:41:49 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/19 21:41:49 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/19 21:41:49 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/19 13:45:13 | 000,043,999 | ---- | C] () -- D:\Users\Dan\Documents\Visa_Payment_$200_19-Oct-2012.pdf
[2012/10/16 22:48:51 | 206,637,508 | ---- | C] () -- D:\Users\Dan\Desktop\live_user_obsidian_1350414362.flv
[2012/10/16 22:19:27 | 000,336,739 | ---- | C] () -- D:\Users\Dan\Documents\Rogers-HomePhone_Internet__$168.58_16-Oct-2012.pdf
[2012/10/16 21:44:30 | 000,071,245 | ---- | C] () -- D:\Users\Dan\Documents\Visa_Payment_$200_16-Oct-2012.pdf
[2012/10/16 21:43:05 | 000,090,038 | ---- | C] () -- D:\Users\Dan\Documents\Rent_Dad_$218_16-Oct-2012.pdf
[2012/10/16 01:00:03 | 696,057,077 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 21.mp4
[2012/10/16 00:59:25 | 637,331,763 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 20.mp4
[2012/10/15 08:57:34 | 1277,038,155 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 19.mp4
[2012/10/14 15:48:12 | 000,000,650 | ---- | C] () -- D:\Users\Dan\Desktop\temp - Shortcut.lnk
[2012/10/14 00:27:39 | 191,404,660 | ---- | C] () -- D:\Users\Dan\Desktop\Making a simple Fallout 3 mod Automatic Karma Perks.mp4
[2012/10/12 02:32:55 | 092,654,704 | ---- | C] () -- D:\Users\Dan\Desktop\Fallout 3 Mod Clinic part 1 ENCORE Remastered, Blackened and Merged.mp4
[2012/10/10 23:08:15 | 2105,658,793 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 18.mp4
[2012/10/10 22:09:24 | 1153,071,429 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 17.mp4
[2012/10/10 22:08:47 | 2044,077,624 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 16.mp4
[2012/10/10 22:07:56 | 1925,541,204 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 15.mp4
[2012/10/10 21:57:47 | 1725,287,262 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 11.mp4
[2012/10/10 02:04:02 | 1302,548,695 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 Part 13.mp4
[2012/10/10 01:56:40 | 000,000,166 | ---- | C] () -- D:\Users\Dan\Desktop\Network Location Awareness (NLA) and how it relates to Windows Firewall Profiles - Microsoft Enterprise Networking Team - Si.URL
[2012/10/10 01:46:35 | 1334,240,711 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 Part 14.mp4
[2012/10/08 08:32:05 | 1148,753,160 | ---- | C] () -- D:\Users\Dan\Desktop\Lets Play Fallout 3 (modded) - Part 10.mp4
[2012/10/08 01:26:24 | 1163,265,683 | ---- | C] () -- D:\Users\Dan\Desktop\vf_dishonored_ql_100512_zvx_3500.mp4
[2012/10/07 17:32:01 | 1175,900,144 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 12.mp4
[2012/10/07 14:01:45 | 000,000,126 | ---- | C] () -- D:\Users\Dan\Desktop\AGP Texture Acceleration Enabled.reg
[2012/10/07 14:01:12 | 000,000,126 | ---- | C] () -- D:\Users\Dan\Desktop\AGP Texture Acceleration Disabled.reg
[2012/10/06 19:49:49 | 000,071,098 | ---- | C] () -- D:\Users\Dan\Documents\Visa_Payment_$40_06-Oct-2012.pdf
[2012/10/06 12:47:15 | 853,916,999 | ---- | C] () -- D:\Users\Dan\Desktop\Quoted for TruthCliffy B leaves Epic Games.mp4
[2012/10/06 00:05:51 | 000,000,185 | ---- | C] () -- D:\Users\Dan\Desktop\Why would anyone ever want to be a AAA game developer - GameSpot.com.URL
[2012/10/06 00:05:38 | 1606,619,565 | ---- | C] () -- D:\Users\Dan\Desktop\videoplayback.mp4
[2012/10/06 00:05:38 | 080,782,913 | ---- | C] () -- D:\Users\Dan\Desktop\videoplayback.flv
[2012/10/06 00:05:38 | 000,001,716 | ---- | C] () -- D:\Users\Dan\Desktop\RPGs.lnk
[2012/10/06 00:05:38 | 000,000,683 | ---- | C] () -- D:\Users\Dan\Desktop\Utilities.lnk
[2012/10/06 00:05:12 | 1380,838,861 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 9.mp4
[2012/10/06 00:04:47 | 1395,766,598 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 8.mp4
[2012/10/06 00:04:17 | 1607,115,555 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 7.mp4
[2012/10/06 00:03:51 | 1386,365,463 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 6.mp4
[2012/10/06 00:03:26 | 2253,952,302 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 5.mp4
[2012/10/06 00:03:17 | 935,639,840 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 4.mp4
[2012/10/06 00:03:01 | 1913,044,538 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 3.mp4
[2012/10/06 00:02:49 | 1150,511,496 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 2.mp4
[2012/10/06 00:02:40 | 1184,335,437 | ---- | C] () -- D:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 1.mp4
[2012/10/06 00:02:40 | 000,000,160 | ---- | C] () -- D:\Users\Dan\Desktop\Game Masters Behind the Talent - GameSpot.com.URL
[2012/10/06 00:02:34 | 774,414,598 | ---- | C] () -- D:\Users\Dan\Desktop\Borderlands 2_Gamespot_hardware_comparison.mp4
[2012/10/06 00:02:21 | 1177,751,522 | ---- | C] () -- D:\Users\Dan\Desktop\169_qft_ep13_090712_hd.mp4
[2012/10/06 00:02:01 | 2500,086,421 | ---- | C] () -- D:\Users\Dan\Desktop\169_lastofus_panel_ps3_071412_1_hd.mp4
[2012/10/06 00:02:00 | 061,892,011 | ---- | C] () -- D:\Users\Dan\Desktop\160_ArnoldLines.flv
[2012/10/06 00:01:59 | 119,798,821 | ---- | C] () -- D:\Users\Dan\Desktop\14-day-rfl-new.mp4
[2012/10/05 18:39:20 | 1603,620,861 | -HS- | C] () -- C:\hiberfil.sys
[2012/10/05 12:57:58 | 003,499,215 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012/10/05 12:57:00 | 000,016,054 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2012/09/30 16:23:54 | 000,075,510 | ---- | C] () -- D:\Users\Dan\Documents\Chieftain_Insurance_$163_30-Sep-2012.pdf
[2012/09/30 16:22:08 | 000,076,294 | ---- | C] () -- D:\Users\Dan\Documents\ScotiaLine_$50_30-Sep-2012.pdf
[2012/09/30 16:21:22 | 000,071,647 | ---- | C] () -- D:\Users\Dan\Documents\Visa_Payment_$200_30-Sep-2012.pdf
[2012/09/30 16:20:27 | 000,090,295 | ---- | C] () -- D:\Users\Dan\Documents\Rent_Dad_$270_30-Sep-2012.pdf
[2012/09/08 17:20:17 | 000,207,872 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012/09/08 17:20:17 | 000,074,240 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2012/09/08 17:09:47 | 000,390,609 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat
[2012/09/08 17:09:47 | 000,051,979 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat
[2012/09/08 17:09:47 | 000,028,411 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2012/09/08 17:09:47 | 000,014,336 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll
[2012/09/08 17:09:47 | 000,012,800 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe
[2012/09/08 17:09:47 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe
[2012/09/08 17:09:47 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CTXFIRES.DLL
[2012/09/08 17:09:47 | 000,000,287 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2012/09/08 17:09:47 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2012/08/26 23:06:58 | 000,000,213 | ---- | C] () -- C:\Windows\PCWGXDRV.INI
[2012/08/26 23:06:58 | 000,000,057 | ---- | C] () -- C:\Windows\LOGINPUT.INI
[2012/08/12 21:26:44 | 000,000,040 | ---- | C] () -- C:\Windows\RUNAWAY2.INI
[2012/07/25 16:01:16 | 000,002,081 | ---- | C] () -- C:\ProgramData\ENG.2012-07.pl.nicolasgames_B05A5A11-F525-40DF-AE67-58228603B921.swidtag
[2012/07/21 00:03:09 | 000,000,036 | ---- | C] () -- C:\Windows\wininit.ini
[2012/03/05 00:28:53 | 000,000,079 | ---- | C] () -- C:\Users\Dan\AppData\Local\CrystalDiskMark30.ini
[2012/02/25 21:55:54 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2012/02/25 18:29:56 | 000,000,119 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\Network Monitor II_Traffic.ini
[2012/02/22 22:53:47 | 000,001,765 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\System Monitor II_CPU0_Settings.ini
[2012/02/22 22:53:39 | 000,000,513 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\GPU Monitor_GPU0_Settings.ini
[2012/02/03 22:53:39 | 000,777,306 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/12/18 17:56:43 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/11/13 00:25:28 | 000,111,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/11/13 00:25:09 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/11/12 18:42:04 | 000,000,535 | ---- | C] () -- C:\Windows\eReg.dat
[2011/10/30 23:57:41 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/10/30 11:07:56 | 000,258,864 | ---- | C] () -- C:\Windows\SUPDRun.exe
[2011/10/30 07:53:21 | 000,003,084 | R-S- | C] () -- C:\ProgramData\ntuser.pol
[2011/10/26 22:35:05 | 000,081,456 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\icarus-dxdiag.xml
[2011/10/26 22:35:05 | 000,001,702 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\System Monitor II_Settings.ini
[2011/10/26 22:35:05 | 000,000,601 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\Network Monitor II_Settings.ini
[2011/10/26 22:35:05 | 000,000,485 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\GPU Monitor_Settings.ini
[2011/10/26 22:35:05 | 000,000,424 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\Drives Monitor_Settings.ini
[2011/10/26 22:33:37 | 000,007,618 | ---- | C] () -- C:\Users\Dan\AppData\Local\Resmon.ResmonCfg
[2011/10/26 22:33:37 | 000,000,091 | ---- | C] () -- C:\Users\Dan\AppData\Local\fusioncache.dat
[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
========== ZeroAccess Check ========== [2012/05/01 08:44:22 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Dropbox\l
[2012/05/01 08:32:42 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Dropbox\installer\l
[2012/10/21 11:59:07 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Dropbox\shellext\l
[2011/10/26 22:42:53 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\WinUAE\Hard Drives\HD-Games\Dynamix - Sierra\AdventuresOfWillyBeamish\data\l
[2011/10/26 22:42:59 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\WinUAE\Hard Drives\Programs\Temp\AmiCDROM\l
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Custom Scans ========== < %systemdrive%\$Recycle.Bin|@;true;true;true /fp >File not found --
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\SocialNews
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\SocialNews
[2011/02/05 00:00:14 | 000,004,087 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected] backup.log
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected][2011/10/26 06:26:22 | 062,997,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\Backups\
[email protected] backup.pst
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2010/10/19 10:27:59 | 000,000,419 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Opera\Opera\icons\https%3A%2F%2Fbugs.launchpad.net%2F@@%2Flaunchpad.png
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\SocialNews
[2011/02/05 00:00:14 | 000,004,087 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected] backup.log
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected][2011/10/26 06:26:22 | 062,997,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\Backups\
[email protected] backup.pst
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2010/10/19 10:27:59 | 000,000,419 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Opera\Opera\icons\https%3A%2F%2Fbugs.launchpad.net%2F@@%2Flaunchpad.png
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Messenger\
[email protected]\SocialNews
[2011/02/05 00:00:14 | 000,004,087 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected] backup.log
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Outlook\
[email protected][2011/10/26 06:26:22 | 062,997,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Outlook\Backups\
[email protected] backup.pst
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2010/10/19 10:27:59 | 000,000,419 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Opera\Opera\icons\https%3A%2F%2Fbugs.launchpad.net%2F@@%2Flaunchpad.png
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Messenger\
[email protected]\SocialNews
[2011/02/05 00:00:14 | 000,004,087 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Outlook\
[email protected] backup.log
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Outlook\
[email protected][2011/10/26 06:26:22 | 062,997,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Outlook\Backups\
[email protected] backup.pst
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2010/10/19 10:27:59 | 000,000,419 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Opera\Opera\icons\https%3A%2F%2Fbugs.launchpad.net%2F@@%2Flaunchpad.png
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Messenger\
[email protected]\SocialNews
[2011/02/05 00:00:14 | 000,004,087 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Outlook\
[email protected] backup.log
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Outlook\
[email protected][2011/10/26 06:26:22 | 062,997,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Outlook\Backups\
[email protected] backup.pst
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2010/10/19 10:27:59 | 000,000,419 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Opera\Opera\icons\https%3A%2F%2Fbugs.launchpad.net%2F@@%2Flaunchpad.png
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Application Data\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2012/04/14 22:33:03 | 000,001,092 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Google\Google Talk\avatars\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Messenger\
[email protected][2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Messenger\
[email protected]\ObjectStore
[2011/10/26 22:33:54 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Messenger\
[email protected]\SocialNews
[2011/02/05 00:00:14 | 000,004,087 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Outlook\
[email protected] backup.log
[2011/04/23 08:44:14 | 104,899,584 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Outlook\
[email protected][2011/10/26 06:26:22 | 062,997,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Outlook\Backups\
[email protected] backup.pst
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Windows Live\Contacts\
[email protected][2011/10/26 22:34:28 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Microsoft\Windows Live\Contacts\
[email protected]\15.4
[2010/10/19 10:27:59 | 000,000,419 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Opera\Opera\icons\https%3A%2F%2Fbugs.launchpad.net%2F@@%2Flaunchpad.png
[2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Zimbra\Zimbra Desktop\profile\extensions\
[email protected][2011/10/26 22:34:53 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Local\Zimbra\Zimbra Desktop\profile\extensions\
[email protected]\chrome
[2011/10/27 22:36:46 | 000,000,113 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Microsoft\Windows\Cookies\dan@microsoft[2].txt
[2011/03/23 08:25:02 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Extensions\
[email protected][2009/08/30 22:13:50 | 000,000,053 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\orbit_ffext@orbitdownloader
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\
[email protected][2011/10/26 22:35:55 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\
[email protected]\chrome
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\
[email protected]\defaults
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\
[email protected]\extra
[2011/07/09 11:55:38 | 000,330,316 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected][2011/11/25 12:46:20 | 000,255,318 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected][2012/04/15 21:53:49 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected][2012/04/15 21:53:49 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\
[email protected]\plugins
[2011/10/26 22:36:06 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Thunderbird\Profiles\avaxzqet.default\extensions\
[email protected][2011/10/26 22:36:06 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Thunderbird\Profiles\avaxzqet.default\extensions\
[email protected]\dictionaries
[2011/10/26 22:37:06 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Thunderbird\Profiles\ncme30d4.default\extensions\
[email protected][2011/10/26 22:37:07 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Thunderbird\Profiles\ncme30d4.default\extensions\
[email protected]\dictionaries
[2012/06/18 15:46:19 | 000,012,574 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\uTorrent\3DMark 11 Advanced Edition 1.0.3 Multilingual Incl Serial @ Only By THE RAIN.torrent
[2012/04/15 03:45:08 | 000,014,488 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\uTorrent\PC » BONETOWN v1.0.4 Full Game directplay by
[email protected][2012/02/15 01:07:15 | 000,004,364 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Wippien\Images\
[email protected][2012/02/15 00:53:57 | 000,004,661 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Wippien\Images\
[email protected][2012/02/15 00:53:57 | 000,005,703 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Wippien\Images\
[email protected][2012/02/15 00:53:57 | 000,004,050 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Wippien\Images\
[email protected][2012/02/15 01:21:03 | 000,016,716 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\AppData\Roaming\Wippien\Images\
[email protected][2011/08/05 22:49:26 | 000,000,083 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Desktop\Misc Web Sites - Game Developers - blogs - articles\RPG\Dungeon Siege II\Dungeon Siege II @ GameBanshee.URL
[2009/10/12 10:08:17 | 000,000,073 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Desktop\MMORPG\World Of Warcraft\WOW Links\Rogue (19220) - Rogue @ lvl 69.URL
[2009/10/12 10:07:48 | 000,000,065 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Desktop\MMORPG\World Of Warcraft\WOW Links\Rogue (7140) - Rogue @ lvl 40.URL
[2011/08/05 00:24:55 | 000,013,190 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGGShaders\
[email protected][2011/08/04 22:25:52 | 000,032,824 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGGShaders\
[email protected][2011/08/03 20:10:36 | 000,002,818 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:25:33 | 000,206,603 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/04 23:20:29 | 000,083,227 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/01 21:53:59 | 000,001,757 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/04 00:27:37 | 000,059,195 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:53:15 | 000,052,390 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/04 23:18:43 | 000,015,869 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/04 23:18:41 | 000,016,018 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:53:19 | 000,173,105 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:54:39 | 000,857,622 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:53:19 | 000,417,830 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/04 23:34:25 | 000,013,358 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:53:17 | 000,314,379 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:53:17 | 000,006,649 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/05 00:54:39 | 000,131,807 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGPShaders\
[email protected][2011/08/04 00:27:43 | 000,012,230 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/04 23:20:57 | 000,104,368 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/04 23:24:17 | 000,060,699 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/01 21:53:59 | 000,002,127 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/04 00:27:37 | 000,030,178 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/05 00:50:17 | 000,025,468 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/04 23:18:37 | 000,018,778 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/05 00:53:19 | 000,142,620 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/05 00:54:31 | 000,365,513 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/04 23:26:21 | 000,254,214 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/03 20:09:56 | 000,006,754 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/05 00:53:17 | 000,097,801 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/04 22:55:31 | 000,008,332 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2011/08/05 00:53:23 | 000,551,210 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Documents\My Games\Crysis\Shaders\Cache\D3D10\CGVShaders\
[email protected][2010/01/17 23:02:52 | 000,053,124 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-21-496535518-2861806089-638670642-1108\$RHHUPDS.old\Pictures\Pics of Dan\
[email protected] < %USERPROFILE%\..|smtmp;true;true;true /FP >< End of report >