Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Undetectable Browser Adware / Hijacker [Solved]


  • This topic is locked This topic is locked

#1
RLS0812

RLS0812

    Banned

  • Banned
  • PipPip
  • 12 posts
I have scanned my system ( full scan, updated ) with the following programs: Spybot Search & Destroy, Ad-Aware, Malwarebytes, AVG, Avast, Windows Defender .... and have found nothing.
This adware / hijacker affects all browsers I have installed ( IE, Firefox, Chrome, Steam ) the same way - it displays random ads on the bottom left of the screen, and randomly redirects link clicks.
Here are some screen shots from Steam
Posted Image .


Using Windows Process Explorer, I have found nothing out of the ordinary. Looking at the start up menu ( msconfig ) shows nothing out of the ordinary.

Only thing I have found is that Firefox will block the displayed ad, but leave an invisible box behind ... Here is the specific Java Script code that calls the window ( I have no idea what injects it into the page ).
Posted Image
  • 0

Advertisements


#2
RPMcMurphy

RPMcMurphy

    Trusted Helper

  • Malware Removal
  • 930 posts
Hello and welcome. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
Posted Image Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:
    netsvcs
  • Click the Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and paste them into your next post.
Posted Image Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it
  • You will be asked if you want to use Avast! Free anti virus for scanning - select No
  • Click the "Scan" button to start scan
  • On completion of the scan click save log, save it to your desktop and post in your next reply.
Please include the following in your next post:
  • OTL.txt and Extras.txt logs
  • aswMBR log

  • 1

#3
RLS0812

RLS0812

    Banned

  • Topic Starter
  • Banned
  • PipPip
  • 12 posts
Since my last post I have found the bug uses java script injection, though I have no clue how. Disabling java script on my browsers, also stops the ads and redirects.
Here are the logs ...

==========Scan Log===========

OTL logfile created on: 11/18/2012 5:21:46 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\RICK\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 48.89% Memory free
7.61 Gb Paging File | 5.60 Gb Available in Paging File | 73.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.42 Gb Total Space | 459.26 Gb Free Space | 78.99% Space Free | Partition Type: NTFS

Computer Name: COMPUTER | User Name: RICK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (All) ==========

PRC - [2012/11/18 15:19:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\RICK\Downloads\OTL.exe
PRC - [2012/10/26 16:25:03 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
PRC - [2012/01/04 13:22:40 | 000,822,624 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
PRC - [2011/10/01 07:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 07:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/03/07 08:33:08 | 000,089,456 | ---- | M] (Elaborate Bytes AG) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
PRC - [2010/06/08 11:49:30 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2010/03/03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe


========== Modules (All) ==========

MOD - [2012/11/18 15:19:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\RICK\Downloads\OTL.exe
MOD - [2012/10/26 16:25:03 | 014,676,448 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\xul.dll
MOD - [2012/10/26 16:25:03 | 002,560,480 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
MOD - [2012/10/26 16:25:03 | 002,295,264 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/10/26 16:25:03 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
MOD - [2012/10/26 16:25:03 | 000,816,608 | ---- | M] (sqlite.org) -- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll
MOD - [2012/10/26 16:25:03 | 000,638,432 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nss3.dll
MOD - [2012/10/26 16:25:03 | 000,370,656 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll
MOD - [2012/10/26 16:25:03 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
MOD - [2012/10/26 16:25:03 | 000,258,528 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
MOD - [2012/10/26 16:25:03 | 000,172,000 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nspr4.dll
MOD - [2012/10/26 16:25:03 | 000,155,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\softokn3.dll
MOD - [2012/10/26 16:25:03 | 000,145,376 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\ssl3.dll
MOD - [2012/10/26 16:25:03 | 000,124,384 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
MOD - [2012/10/26 16:25:03 | 000,096,224 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
MOD - [2012/10/26 16:25:03 | 000,092,640 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll
MOD - [2012/10/26 16:25:03 | 000,091,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\smime3.dll
MOD - [2012/10/26 16:25:03 | 000,021,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\plc4.dll
MOD - [2012/10/26 16:25:03 | 000,020,960 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\plds4.dll
MOD - [2012/10/26 16:25:03 | 000,019,424 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\xpcom.dll
MOD - [2012/10/26 16:25:03 | 000,015,840 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
MOD - [2012/10/08 02:48:51 | 001,103,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll
MOD - [2012/10/08 02:48:03 | 001,129,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll
MOD - [2012/10/08 02:41:28 | 001,793,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll
MOD - [2012/08/24 11:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll
MOD - [2012/08/20 12:37:18 | 001,114,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll
MOD - [2012/08/20 12:37:18 | 000,274,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll
MOD - [2012/07/13 19:16:36 | 000,770,384 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Mozilla Firefox\msvcr100.dll
MOD - [2012/07/13 19:16:36 | 000,421,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Mozilla Firefox\msvcp100.dll
MOD - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
MOD - [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll
MOD - [2012/06/01 23:40:42 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll
MOD - [2012/06/01 23:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll
MOD - [2012/06/01 23:34:09 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll
MOD - [2012/05/05 02:46:52 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll
MOD - [2012/03/03 00:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\DWrite.dll
MOD - [2012/01/13 02:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll
MOD - [2011/12/16 02:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll
MOD - [2011/11/17 00:38:39 | 001,292,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll
MOD - [2011/08/31 12:37:18 | 012,340,224 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\igd10umd32.dll
MOD - [2011/08/26 23:26:27 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll
MOD - [2011/05/24 05:40:05 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll
MOD - [2011/05/24 05:39:38 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll
MOD - [2011/03/28 19:31:14 | 000,145,280 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL
MOD - [2011/03/07 08:33:08 | 000,089,456 | ---- | M] (Elaborate Bytes AG) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
MOD - [2011/03/06 21:08:13 | 000,093,552 | ---- | M] (Elaborate Bytes AG) -- C:\Windows\SysWOW64\ElbyCDIO.dll
MOD - [2011/03/06 19:52:09 | 000,134,512 | ---- | M] (Elaborate Bytes AG) -- C:\Windows\SysWOW64\ElbyVCD.dll
MOD - [2011/03/03 00:38:01 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dnsapi.dll
MOD - [2011/02/19 01:30:50 | 000,739,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d2d1.dll
MOD - [2011/01/17 00:47:13 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10_1.dll
MOD - [2010/11/20 07:21:39 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wshbth.dll
MOD - [2010/11/20 07:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll
MOD - [2010/11/20 07:21:36 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll
MOD - [2010/11/20 07:21:36 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll
MOD - [2010/11/20 07:21:34 | 001,128,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll
MOD - [2010/11/20 07:21:33 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll
MOD - [2010/11/20 07:21:33 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll
MOD - [2010/11/20 07:21:24 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll
MOD - [2010/11/20 07:21:19 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll
MOD - [2010/11/20 07:21:15 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll
MOD - [2010/11/20 07:21:14 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll
MOD - [2010/11/20 07:21:04 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll
MOD - [2010/11/20 07:21:03 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\RpcRtRemote.dll
MOD - [2010/11/20 07:20:57 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll
MOD - [2010/11/20 07:20:49 | 001,414,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll
MOD - [2010/11/20 07:20:49 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll
MOD - [2010/11/20 07:20:29 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll
MOD - [2010/11/20 07:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll
MOD - [2010/11/20 07:19:45 | 000,481,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscms.dll
MOD - [2010/11/20 07:19:45 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll
MOD - [2010/11/20 07:19:39 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll
MOD - [2010/11/20 07:19:23 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL
MOD - [2010/11/20 07:19:03 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FWPUCLNT.DLL
MOD - [2010/11/20 07:19:01 | 001,493,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ExplorerFrame.dll
MOD - [2010/11/20 07:18:36 | 000,508,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxgi.dll
MOD - [2010/11/20 07:18:27 | 000,854,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll
MOD - [2010/11/20 07:18:25 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10_1core.dll
MOD - [2010/11/20 07:18:23 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2010/11/20 07:18:05 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\AudioSes.dll
MOD - [2010/11/20 07:18:03 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll
MOD - [2010/11/20 07:18:02 | 000,640,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll
MOD - [2010/11/20 07:16:50 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv
MOD - [2010/11/20 07:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll
MOD - [2010/11/20 07:08:57 | 000,663,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll
MOD - [2010/11/20 07:08:51 | 000,311,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll
MOD - [2010/11/20 07:08:51 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll
MOD - [2010/11/20 06:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MOD - [2009/07/13 20:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll
MOD - [2009/07/13 20:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll
MOD - [2009/07/13 20:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wship6.dll
MOD - [2009/07/13 20:16:20 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WSHTCPIP.DLL
MOD - [2009/07/13 20:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winrnr.dll
MOD - [2009/07/13 20:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll
MOD - [2009/07/13 20:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll
MOD - [2009/07/13 20:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll
MOD - [2009/07/13 20:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll
MOD - [2009/07/13 20:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll
MOD - [2009/07/13 20:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pnrpnsp.dll
MOD - [2009/07/13 20:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll
MOD - [2009/07/13 20:16:12 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasadhlp.dll
MOD - [2009/07/13 20:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll
MOD - [2009/07/13 20:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll
MOD - [2009/07/13 20:16:11 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll
MOD - [2009/07/13 20:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\NapiNSP.dll
MOD - [2009/07/13 20:15:44 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll
MOD - [2009/07/13 20:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll
MOD - [2009/07/13 20:15:20 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\feclient.dll
MOD - [2009/07/13 20:15:13 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dui70.dll
MOD - [2009/07/13 20:15:13 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\duser.dll
MOD - [2009/07/13 20:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll
MOD - [2009/07/13 20:15:07 | 001,030,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10.dll
MOD - [2009/07/13 20:15:07 | 000,190,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10core.dll
MOD - [2009/07/13 20:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll
MOD - [2009/07/13 20:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll
MOD - [2009/07/13 20:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll
MOD - [2009/07/13 20:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll
MOD - [2009/07/13 20:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 20:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll
MOD - [2009/07/13 20:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll
MOD - [2009/07/13 20:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll
MOD - [2008/10/15 05:22:52 | 000,452,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3dx10_40.dll


========== Services (All) ==========

SRV:64bit: - [2012/10/03 12:44:21 | 000,303,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:64bit: - [2012/10/03 12:42:16 | 000,569,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\iphlpsvc.dll -- (iphlpsvc)
SRV:64bit: - [2012/07/25 22:08:14 | 000,084,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\WUDFSvc.dll -- (wudfsvc)
SRV:64bit: - [2012/07/19 13:17:25 | 001,255,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV:64bit: - [2012/07/04 17:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:64bit: - [2012/06/02 17:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:64bit: - [2012/06/02 00:41:28 | 000,184,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:64bit: - [2012/05/01 00:40:20 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:64bit: - [2012/02/11 01:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (VaultSvc)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (Netlogon)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (EFS)
SRV:64bit: - [2011/05/24 06:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:64bit: - [2011/05/04 00:19:28 | 000,591,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SearchIndexer.exe -- (WSearch)
SRV:64bit: - [2011/03/28 20:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV:64bit: - [2011/03/03 01:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:64bit: - [2011/02/19 07:05:15 | 001,139,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FntCache.dll -- (FontCache)
SRV:64bit: - [2010/11/20 08:27:29 | 002,018,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WsmSvc.dll -- (WinRM)
SRV:64bit: - [2010/11/20 08:27:28 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:64bit: - [2010/11/20 08:27:28 | 000,580,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:64bit: - [2010/11/20 08:27:28 | 000,444,416 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\winhttp.dll -- (WinHttpAutoProxySvc)
SRV:64bit: - [2010/11/20 08:27:28 | 000,258,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WebClnt.dll -- (WebClient)
SRV:64bit: - [2010/11/20 08:27:28 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)
SRV:64bit: - [2010/11/20 08:27:28 | 000,117,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpdbusenum.dll -- (WPDBusEnum)
SRV:64bit: - [2010/11/20 08:27:27 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wcncsvc.dll -- (wcncsvc)
SRV:64bit: - [2010/11/20 08:27:26 | 001,743,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\sysmain.dll -- (SysMain)
SRV:64bit: - [2010/11/20 08:27:26 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\termsrv.dll -- (TermService)
SRV:64bit: - [2010/11/20 08:27:26 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV:64bit: - [2010/11/20 08:27:26 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:64bit: - [2010/11/20 08:27:26 | 000,092,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TabSvc.dll -- (TabletInputService)
SRV:64bit: - [2010/11/20 08:27:25 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:64bit: - [2010/11/20 08:27:25 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV:64bit: - [2010/11/20 08:27:25 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:64bit: - [2010/11/20 08:27:25 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SessEnv.dll -- (SessionEnv)
SRV:64bit: - [2010/11/20 08:27:25 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:64bit: - [2010/11/20 08:27:24 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:64bit: - [2010/11/20 08:27:24 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:64bit: - [2010/11/20 08:27:24 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:64bit: - [2010/11/20 08:27:23 | 001,389,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pla.dll -- (pla)
SRV:64bit: - [2010/11/20 08:27:23 | 000,849,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:64bit: - [2010/11/20 08:27:23 | 000,476,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\QAGENTRT.DLL -- (napagent)
SRV:64bit: - [2010/11/20 08:27:23 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)
SRV:64bit: - [2010/11/20 08:26:59 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:64bit: - [2010/11/20 08:26:50 | 000,084,992 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)
SRV:64bit: - [2010/11/20 08:26:46 | 000,232,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)
SRV:64bit: - [2010/11/20 08:26:42 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\KMSVC.DLL -- (hkmsvc)
SRV:64bit: - [2010/11/20 08:26:39 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
SRV:64bit: - [2010/11/20 08:26:36 | 000,853,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\IKEEXT.DLL -- (IKEEXT)
SRV:64bit: - [2010/11/20 08:26:28 | 000,777,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\gpsvc.dll -- (gpsvc)
SRV:64bit: - [2010/11/20 08:26:07 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:64bit: - [2010/11/20 08:26:07 | 000,162,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dps.dll -- (DPS)
SRV:64bit: - [2010/11/20 08:26:04 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2010/11/20 08:25:49 | 000,080,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\certprop.dll -- (SCPolicySvc)
SRV:64bit: - [2010/11/20 08:25:49 | 000,080,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\certprop.dll -- (CertPropSvc)
SRV:64bit: - [2010/11/20 08:25:45 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:64bit: - [2010/11/20 08:25:44 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)
SRV:64bit: - [2010/11/20 08:25:42 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:64bit: - [2010/11/20 08:25:42 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2010/11/20 08:25:40 | 000,070,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:64bit: - [2010/11/20 08:25:33 | 001,525,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV:64bit: - [2010/11/20 08:25:28 | 001,504,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
SRV:64bit: - [2010/11/20 08:25:27 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:64bit: - [2010/11/20 08:25:25 | 000,533,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vds.exe -- (vds)
SRV:64bit: - [2010/11/20 08:25:04 | 003,524,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)
SRV:64bit: - [2010/11/20 08:24:58 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV:64bit: - [2010/11/20 08:24:47 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/06/18 00:10:14 | 000,258,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2010/03/05 11:26:38 | 001,425,168 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2010/03/05 11:07:58 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2010/03/05 11:06:22 | 000,831,760 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2010/01/09 20:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV:64bit: - [2009/12/29 15:19:12 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009/07/22 03:17:44 | 000,061,976 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe -- (MSSQLServerADHelper100)
SRV:64bit: - [2009/07/13 20:41:59 | 000,229,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)
SRV:64bit: - [2009/07/13 20:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:64bit: - [2009/07/13 20:41:57 | 000,012,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpcsvc.dll -- (WPCSvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,381,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\w32time.dll -- (W32Time)
SRV:64bit: - [2009/07/13 20:41:56 | 000,353,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\upnphost.dll -- (upnphost)
SRV:64bit: - [2009/07/13 20:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:64bit: - [2009/07/13 20:41:56 | 000,237,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wecsvc.dll -- (Wecsvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,163,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power)
SRV:64bit: - [2009/07/13 20:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wdi.dll -- (WdiSystemHost)
SRV:64bit: - [2009/07/13 20:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiServiceHost)
SRV:64bit: - [2009/07/13 20:41:56 | 000,084,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wercplsupport.dll -- (wercplsupport)
SRV:64bit: - [2009/07/13 20:41:56 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wersvc.dll -- (WerSvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WcsPlugInService.dll -- (WcsPlugInService)
SRV:64bit: - [2009/07/13 20:41:56 | 000,038,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\uxsms.dll -- (UxSms)
SRV:64bit: - [2009/07/13 20:41:55 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\trkwks.dll -- (TrkWks)
SRV:64bit: - [2009/07/13 20:41:55 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tbssvc.dll -- (TBS)
SRV:64bit: - [2009/07/13 20:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2009/07/13 20:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:64bit: - [2009/07/13 20:41:54 | 000,193,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ssdpsrv.dll -- (SSDPSRV)
SRV:64bit: - [2009/07/13 20:41:54 | 000,075,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sstpsvc.dll -- (SstpSvc)
SRV:64bit: - [2009/07/13 20:41:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)
SRV:64bit: - [2009/07/13 20:41:54 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,438,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\p2psvc.dll -- (p2psvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qwave.dll -- (QWAVE)
SRV:64bit: - [2009/07/13 20:41:53 | 000,190,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SCardSvr.dll -- (SCardSvr)
SRV:64bit: - [2009/07/13 20:41:53 | 000,186,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\pcasvc.dll -- (PcaSvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,159,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\regsvc.dll -- (RemoteRegistry)
SRV:64bit: - [2009/07/13 20:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:64bit: - [2009/07/13 20:41:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)
SRV:64bit: - [2009/07/13 20:41:53 | 000,064,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\Sens.dll -- (SENS)
SRV:64bit: - [2009/07/13 20:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:64bit: - [2009/07/13 20:41:53 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)
SRV:64bit: - [2009/07/13 20:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV:64bit: - [2009/07/13 20:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:64bit: - [2009/07/13 20:41:28 | 000,368,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtckrm.dll -- (KtmRm)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 20:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)
SRV:64bit: - [2009/07/13 20:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (THREADORDER)
SRV:64bit: - [2009/07/13 20:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:64bit: - [2009/07/13 20:41:18 | 000,300,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lltdsvc.dll -- (lltdsvc)
SRV:64bit: - [2009/07/13 20:41:18 | 000,023,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lmhsvc.dll -- (lmhosts)
SRV:64bit: - [2009/07/13 20:41:11 | 000,156,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\iscsiexe.dll -- (MSiSCSI)
SRV:64bit: - [2009/07/13 20:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:64bit: - [2009/07/13 20:41:09 | 000,101,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPBusEnum.dll -- (IPBusEnum)
SRV:64bit: - [2009/07/13 20:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV:64bit: - [2009/07/13 20:40:52 | 000,034,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FDResPub.dll -- (FDResPub)
SRV:64bit: - [2009/07/13 20:40:52 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fdPHost.dll -- (fdPHost)
SRV:64bit: - [2009/07/13 20:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV:64bit: - [2009/07/13 20:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:64bit: - [2009/07/13 20:40:28 | 000,291,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)
SRV:64bit: - [2009/07/13 20:40:13 | 000,083,968 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\bthserv.dll -- (bthserv)
SRV:64bit: - [2009/07/13 20:40:10 | 000,100,864 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)
SRV:64bit: - [2009/07/13 20:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:64bit: - [2009/07/13 20:40:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)
SRV:64bit: - [2009/07/13 20:39:55 | 000,203,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbem\WmiApSrv.exe -- (wmiApSrv)
SRV:64bit: - [2009/07/13 20:39:48 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\UI0Detect.exe -- (UI0Detect)
SRV:64bit: - [2009/07/13 20:39:41 | 000,014,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\snmptrap.exe -- (SNMPTRAP)
SRV:64bit: - [2009/07/13 20:39:21 | 000,141,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtc.exe -- (MSDTC)
SRV:64bit: - [2009/07/13 20:39:15 | 000,010,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Locator.exe -- (RpcLocator)
SRV:64bit: - [2009/07/13 20:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dllhost.exe -- (COMSysApp)
SRV:64bit: - [2009/07/13 20:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:64bit: - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV:64bit: - [2009/03/30 03:02:56 | 057,617,752 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS)
SRV:64bit: - [2009/03/30 03:01:06 | 000,427,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE -- (SQLAgent$SQLEXPRESS)
SRV:64bit: - [2009/03/03 05:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Disabled | Stopped] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV:64bit: - [2008/07/10 04:31:10 | 000,157,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2012/11/11 14:22:32 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/10/26 16:25:03 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/06/01 23:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV - [2012/05/13 19:39:06 | 000,022,016 | ---- | M] (Apache Software Foundation) [On_Demand | Stopped] -- c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe -- (wampapache)
SRV - [2012/04/19 15:45:02 | 009,693,696 | ---- | M] () [On_Demand | Stopped] -- c:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe -- (wampmysqld)
SRV - [2012/02/25 10:09:25 | 000,136,176 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdatem)
SRV - [2012/02/25 10:09:25 | 000,136,176 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdate)
SRV - [2012/01/04 13:22:40 | 000,822,624 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE -- (cvhsvc)
SRV - [2011/10/01 07:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 07:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/07/09 12:26:25 | 000,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2011/05/03 23:28:31 | 000,427,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWow64\SearchIndexer.exe -- (WSearch)
SRV - [2011/03/05 13:06:35 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2010/11/20 08:25:23 | 000,194,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller)
SRV - [2010/11/20 08:24:42 | 000,696,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr)
SRV - [2010/11/20 07:21:39 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WsmSvc.dll -- (WinRM)
SRV - [2010/11/20 07:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWow64\winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010/11/20 07:21:35 | 000,276,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wcncsvc.dll -- (wcncsvc)
SRV - [2010/11/20 07:21:35 | 000,204,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WebClnt.dll -- (WebClient)
SRV - [2010/11/20 07:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/20 07:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/20 07:21:08 | 000,113,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\SessEnv.dll -- (SessionEnv)
SRV - [2010/11/20 07:20:57 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)
SRV - [2010/11/20 07:20:54 | 001,508,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\pla.dll -- (pla)
SRV - [2010/11/20 07:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/20 07:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV - [2010/11/04 20:53:03 | 000,042,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
SRV - [2010/11/04 20:52:14 | 000,856,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2010/06/08 11:49:30 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010/03/18 16:23:04 | 000,044,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010/03/18 13:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/03/03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/01/09 20:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009/07/13 20:39:09 | 000,127,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehsched.exe -- (ehSched)
SRV - [2009/07/13 20:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wpcsvc.dll -- (WPCSvc)
SRV - [2009/07/13 20:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wdi.dll -- (WdiSystemHost)
SRV - [2009/07/13 20:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiServiceHost)
SRV - [2009/07/13 20:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WcsPlugInService.dll -- (WcsPlugInService)
SRV - [2009/07/13 20:16:17 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\upnphost.dll -- (upnphost)
SRV - [2009/07/13 20:16:13 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\Sens.dll -- (SENS)
SRV - [2009/07/13 20:16:12 | 000,210,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\qwave.dll -- (QWAVE)
SRV - [2009/07/13 20:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV - [2009/07/13 20:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)
SRV - [2009/07/13 20:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV - [2009/07/13 20:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV - [2009/07/13 20:14:28 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost)
SRV - [2009/07/13 20:14:18 | 000,007,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\dllhost.exe -- (COMSysApp)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/10 15:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2009/06/05 19:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/03/30 02:23:32 | 000,254,808 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)


========== Driver Services (All) ==========

DRV:64bit: - [2012/10/03 12:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tcpip.sys -- (TCPIP6)
DRV:64bit: - [2012/10/03 12:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tcpip.sys -- (Tcpip)
DRV:64bit: - [2012/10/03 11:07:26 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tcpipreg.sys -- (tcpipreg)
DRV:64bit: - [2012/08/31 13:19:35 | 001,659,760 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\ntfs.sys -- (Ntfs)
DRV:64bit: - [2012/08/22 13:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ndis.sys -- (NDIS)
DRV:64bit: - [2012/07/25 23:55:47 | 000,785,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Wdf01000.sys -- (Wdf01000)
DRV:64bit: - [2012/07/25 21:26:45 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFPf.sys -- (WudfPf)
DRV:64bit: - [2012/07/25 21:26:06 | 000,198,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WUDFRd.sys -- (WUDFRd)
DRV:64bit: - [2012/07/06 15:07:42 | 000,552,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthport.sys -- (BTHPORT)
DRV:64bit: - [2012/06/02 00:50:10 | 000,458,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cng.sys -- (CNG)
DRV:64bit: - [2012/06/02 00:48:16 | 000,151,920 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg)
DRV:64bit: - [2012/06/02 00:48:16 | 000,095,600 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecdd.sys -- (KSecDD)
DRV:64bit: - [2012/04/27 22:55:21 | 000,210,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpwd.sys -- (RDPWD)
DRV:64bit: - [2012/03/17 02:58:57 | 000,075,120 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\partmgr.sys -- (partmgr)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/16 23:57:32 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tdtcp.sys -- (TDTCP)
DRV:64bit: - [2011/12/27 22:59:24 | 000,498,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\afd.sys -- (AFD)
DRV:64bit: - [2011/10/01 07:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011/10/01 07:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011/10/01 07:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011/10/01 07:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011/08/31 12:53:22 | 012,306,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/07/08 21:46:28 | 000,288,768 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb10.sys -- (mrxsmb10)
DRV:64bit: - [2011/04/28 22:06:10 | 000,467,456 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv.sys -- (srv)
DRV:64bit: - [2011/04/28 22:05:49 | 000,410,112 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv2.sys -- (srv2)
DRV:64bit: - [2011/04/28 22:05:37 | 000,168,448 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srvnet.sys -- (srvnet)
DRV:64bit: - [2011/04/27 22:54:56 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BTHUSB.SYS -- (BTHUSB)
DRV:64bit: - [2011/04/26 21:40:40 | 000,158,208 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb.sys -- (mrxsmb)
DRV:64bit: - [2011/04/26 21:39:37 | 000,128,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb20.sys -- (mrxsmb20)
DRV:64bit: - [2011/03/24 22:29:26 | 000,343,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbhub.sys -- (usbhub)
DRV:64bit: - [2011/03/24 22:29:14 | 000,098,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbccgp.sys -- (usbccgp)
DRV:64bit: - [2011/03/24 22:29:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbehci.sys -- (usbehci)
DRV:64bit: - [2011/03/24 22:29:04 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbohci.sys -- (usbohci)
DRV:64bit: - [2011/03/24 22:29:03 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbuhci.sys -- (usbuhci)
DRV:64bit: - [2011/03/11 01:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstor.sys -- (nvstor)
DRV:64bit: - [2011/03/11 01:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvraid.sys -- (nvraid)
DRV:64bit: - [2011/03/11 01:41:26 | 000,410,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaStorV.sys -- (iaStorV)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/10 23:37:16 | 000,091,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBSTOR.SYS -- (USBSTOR)
DRV:64bit: - [2011/02/22 23:55:04 | 000,090,624 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\bowser.sys -- (bowser)
DRV:64bit: - [2011/01/15 11:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010/12/16 17:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010/12/01 19:12:06 | 000,250,984 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/11/20 08:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volsnap.sys -- (volsnap)
DRV:64bit: - [2010/11/20 08:34:01 | 000,363,392 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgrx.sys -- (volmgrx)
DRV:64bit: - [2010/11/20 08:34:01 | 000,071,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgr.sys -- (volmgr)
DRV:64bit: - [2010/11/20 08:34:00 | 000,215,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp)
DRV:64bit: - [2010/11/20 08:33:57 | 000,063,360 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\termdd.sys -- (TermDD)
DRV:64bit: - [2010/11/20 08:33:54 | 000,103,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sbp2port.sys -- (sbp2port)
DRV:64bit: - [2010/11/20 08:33:53 | 000,213,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost)
DRV:64bit: - [2010/11/20 08:33:48 | 000,184,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pci.sys -- (pci)
DRV:64bit: - [2010/11/20 08:33:45 | 000,366,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msrpc.sys -- (MsRPC)
DRV:64bit: - [2010/11/20 08:33:45 | 000,273,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msiscsi.sys -- (iScsiPrt)
DRV:64bit: - [2010/11/20 08:33:44 | 000,155,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mpio.sys -- (mpio)
DRV:64bit: - [2010/11/20 08:33:44 | 000,140,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msdsm.sys -- (msdsm)
DRV:64bit: - [2010/11/20 08:33:44 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msahci.sys -- (msahci)
DRV:64bit: - [2010/11/20 08:33:43 | 000,094,592 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mountmgr.sys -- (mountmgr)
DRV:64bit: - [2010/11/20 08:33:36 | 000,014,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 08:33:34 | 000,289,664 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fltMgr.sys -- (FltMgr)
DRV:64bit: - [2010/11/20 08:33:25 | 000,982,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dxgkrnl.sys -- (DXGKrnl)
DRV:64bit: - [2010/11/20 08:32:46 | 000,334,208 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpi.sys -- (ACPI)
DRV:64bit: - [2010/11/20 08:28:59 | 000,223,248 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 06:04:09 | 000,039,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tssecsrv.sys -- (tssecsrv)
DRV:64bit: - [2010/11/20 05:52:37 | 000,088,576 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\wanarp.sys -- (Wanarpv6)
DRV:64bit: - [2010/11/20 05:52:37 | 000,088,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wanarp.sys -- (WANARP)
DRV:64bit: - [2010/11/20 05:52:35 | 000,129,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rasl2tp.sys -- (Rasl2tp)
DRV:64bit: - [2010/11/20 05:52:34 | 000,164,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndiswan.sys -- (NdisWan)
DRV:64bit: - [2010/11/20 05:52:32 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\raspptp.sys -- (PptpMiniport)
DRV:64bit: - [2010/11/20 05:52:20 | 000,131,584 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pacer.sys -- (Psched)
DRV:64bit: - [2010/11/20 05:52:20 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndproxy.sys -- (NDProxy)
DRV:64bit: - [2010/11/20 05:52:19 | 000,082,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipfltdrv.sys -- (IpFilterDriver)
DRV:64bit: - [2010/11/20 05:51:50 | 000,125,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tunnel.sys -- (tunnel)
DRV:64bit: - [2010/11/20 05:50:08 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndisuio.sys -- (Ndisuio)
DRV:64bit: - [2010/11/20 05:44:56 | 000,229,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\1394ohci.sys -- (1394ohci)
DRV:64bit: - [2010/11/20 05:44:37 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\umbus.sys -- (umbus)
DRV:64bit: - [2010/11/20 05:44:34 | 000,184,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbvideo.sys -- (usbvideo)
DRV:64bit: - [2010/11/20 05:44:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)
DRV:64bit: - [2010/11/20 05:43:52 | 000,109,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBAUDIO.sys -- (usbaudio)
DRV:64bit: - [2010/11/20 05:43:49 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidusb.sys -- (HidUsb)
DRV:64bit: - [2010/11/20 05:43:43 | 000,122,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hdaudbus.sys -- (HDAudBus)
DRV:64bit: - [2010/11/20 05:34:00 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sffp_sd.sys -- (sffp_sd)
DRV:64bit: - [2010/11/20 05:33:25 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdhid.sys -- (kbdhid)
DRV:64bit: - [2010/11/20 05:33:17 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CompositeBus.sys -- (CompositeBus)
DRV:64bit: - [2010/11/20 05:14:37 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\appid.sys -- (AppID)
DRV:64bit: - [2010/11/20 05:09:59 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\scfilter.sys -- (scfilter)
DRV:64bit: - [2010/11/20 05:04:53 | 000,078,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IPMIDrv.sys -- (IPMIDRV)
DRV:64bit: - [2010/11/20 04:30:42 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipmi.sys -- (AcpiPmi)
DRV:64bit: - [2010/11/20 04:27:54 | 000,309,248 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\rdbss.sys -- (rdbss)
DRV:64bit: - [2010/11/20 04:26:42 | 000,140,800 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mrxdav.sys -- (MRxDAV)
DRV:64bit: - [2010/11/20 04:26:32 | 000,102,400 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\dfsc.sys -- (DfsC)
DRV:64bit: - [2010/11/20 04:26:11 | 000,328,192 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\udfs.sys -- (udfs)
DRV:64bit: - [2010/11/20 04:25:14 | 000,753,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\http.sys -- (HTTP)
DRV:64bit: - [2010/11/20 04:23:20 | 000,261,632 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\netbt.sys -- (NetBT)
DRV:64bit: - [2010/11/20 04:21:56 | 000,119,296 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tdx.sys -- (tdx)
DRV:64bit: - [2010/11/20 04:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cdrom.sys -- (cdrom)
DRV:64bit: - [2010/11/03 17:39:48 | 000,105,592 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Tpkd.sys -- (Tpkd)
DRV:64bit: - [2010/10/15 01:28:18 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010/06/18 00:10:14 | 000,515,584 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2010/06/08 11:33:14 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/03/30 14:58:06 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010/03/30 14:58:06 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010/03/30 14:58:06 | 000,053,800 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2010/03/30 14:58:06 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010/03/30 14:58:06 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/03/17 23:21:58 | 007,680,512 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
DRV:64bit: - [2010/03/17 16:44:44 | 000,301,104 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/03/17 16:41:48 | 000,325,152 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/02/26 19:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009/09/17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/07/13 20:52:31 | 000,367,696 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\clfs.sys -- (CLFS)
DRV:64bit: - [2009/07/13 20:52:31 | 000,021,584 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\compbatt.sys -- (Compbatt)
DRV:64bit: - [2009/07/13 20:52:31 | 000,017,488 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmdide.sys -- (cmdide)
DRV:64bit: - [2009/07/13 20:52:21 | 000,491,088 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\adp94xx.sys -- (adp94xx)
DRV:64bit: - [2009/07/13 20:52:21 | 000,339,536 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\adpahci.sys -- (adpahci)
DRV:64bit: - [2009/07/13 20:52:21 | 000,182,864 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\adpu320.sys -- (adpu320)
DRV:64bit: - [2009/07/13 20:52:21 | 000,097,856 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\arcsas.sys -- (arcsas)
DRV:64bit: - [2009/07/13 20:52:21 | 000,087,632 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\arc.sys -- (arc)
DRV:64bit: - [2009/07/13 20:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AGP440.sys -- (agp440)
DRV:64bit: - [2009/07/13 20:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\atapi.sys -- (atapi)
DRV:64bit: - [2009/07/13 20:52:21 | 000,015,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdide.sys -- (amdide)
DRV:64bit: - [2009/07/13 20:52:21 | 000,015,440 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aliide.sys -- (aliide)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:27 | 000,060,496 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\mup.sys -- (Mup)
DRV:64bit: - [2009/07/13 20:48:27 | 000,049,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouclass.sys -- (mouclass)
DRV:64bit: - [2009/07/13 20:48:27 | 000,032,320 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mssmbios.sys -- (mssmbios)
DRV:64bit: - [2009/07/13 20:48:27 | 000,015,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msisadrv.sys -- (msisadrv)
DRV:64bit: - [2009/07/13 20:48:26 | 000,122,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NV_AGP.SYS -- (nv_agp)
DRV:64bit: - [2009/07/13 20:48:26 | 000,051,264 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nfrd960.sys -- (nfrd960)
DRV:64bit: - [2009/07/13 20:48:04 | 000,284,736 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MegaSR.sys -- (MegaSR)
DRV:64bit: - [2009/07/13 20:48:04 | 000,115,776 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV:64bit: - [2009/07/13 20:48:04 | 000,114,752 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_fc.sys -- (LSI_FC)
DRV:64bit: - [2009/07/13 20:48:04 | 000,106,560 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas.sys -- (LSI_SAS)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:48:04 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdclass.sys -- (kbdclass)
DRV:64bit: - [2009/07/13 20:48:04 | 000,044,112 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iirsp.sys -- (iirsp)
DRV:64bit: - [2009/07/13 20:48:04 | 000,035,392 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\megasas.sys -- (megasas)
DRV:64bit: - [2009/07/13 20:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\isapnp.sys -- (isapnp)
DRV:64bit: - [2009/07/13 20:48:04 | 000,016,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelide.sys -- (intelide)
DRV:64bit: - [2009/07/13 20:47:49 | 000,055,376 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends)
DRV:64bit: - [2009/07/13 20:47:48 | 000,530,496 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\elxstor.sys -- (elxstor)
DRV:64bit: - [2009/07/13 20:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\disk.sys -- (Disk)
DRV:64bit: - [2009/07/13 20:47:48 | 000,070,224 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fileinfo.sys -- (FileInfo)
DRV:64bit: - [2009/07/13 20:47:48 | 000,065,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GAGP30KX.SYS -- (gagp30kx)
DRV:64bit: - [2009/07/13 20:47:48 | 000,024,144 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\crcdisk.sys -- (crcdisk)
DRV:64bit: - [2009/07/13 20:45:56 | 000,022,096 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount)
DRV:64bit: - [2009/07/13 20:45:55 | 000,161,872 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vsmraid.sys -- (vsmraid)
DRV:64bit: - [2009/07/13 20:45:55 | 000,064,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ULIAGPKX.SYS -- (uliagpkx)
DRV:64bit: - [2009/07/13 20:45:55 | 000,064,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UAGP35.SYS -- (uagp35)
DRV:64bit: - [2009/07/13 20:45:55 | 000,036,432 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:45:55 | 000,021,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wd.sys -- (Wd)
DRV:64bit: - [2009/07/13 20:45:55 | 000,019,008 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spldr.sys -- (spldr)
DRV:64bit: - [2009/07/13 20:45:55 | 000,017,488 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viaide.sys -- (viaide)
DRV:64bit: - [2009/07/13 20:45:55 | 000,012,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\swenum.sys -- (swenum)
DRV:64bit: - [2009/07/13 20:45:46 | 001,524,816 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ql2300.sys -- (ql2300)
DRV:64bit: - [2009/07/13 20:45:46 | 000,080,464 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sisraid4.sys -- (SiSRaid4)
DRV:64bit: - [2009/07/13 20:45:45 | 000,220,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcmcia.sys -- (pcmcia)
DRV:64bit: - [2009/07/13 20:45:45 | 000,128,592 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ql40xx.sys -- (ql40xx)
DRV:64bit: - [2009/07/13 20:45:45 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw)
DRV:64bit: - [2009/07/13 20:45:45 | 000,043,584 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sisraid2.sys -- (SiSRaid2)
DRV:64bit: - [2009/07/13 20:45:45 | 000,012,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pciide.sys -- (pciide)
DRV:64bit: - [2009/07/13 20:19:07 | 000,286,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrSerId.sys -- (Brserid)
DRV:64bit: - [2009/07/13 20:01:19 | 000,651,264 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\PEAuth.sys -- (PEAUTH)
DRV:64bit: - [2009/07/13 19:38:18 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbprint.sys -- (usbprint)
DRV:64bit: - [2009/07/13 19:17:46 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus)
DRV:64bit: - [2009/07/13 19:16:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV:64bit: - [2009/07/13 19:16:34 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPENCDD.sys -- (RDPENCDD)
DRV:64bit: - [2009/07/13 19:16:34 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPCDD.sys -- (RDPCDD)
DRV:64bit: - [2009/07/13 19:16:32 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tdpipe.sys -- (TDPIPE)
DRV:64bit: - [2009/07/13 19:10:48 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\modem.sys -- (Modem)
DRV:64bit: - [2009/07/13 19:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ws2ifsl.sys -- (ws2ifsl)
DRV:64bit: - [2009/07/13 19:10:25 | 000,083,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rassstp.sys -- (RasSstp)
DRV:64bit: - [2009/07/13 19:10:24 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agilevpn.sys -- (RasAgileVpn)
DRV:64bit: - [2009/07/13 19:10:17 | 000,092,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\raspppoe.sys -- (RasPppoe)
DRV:64bit: - [2009/07/13 19:10:13 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\asyncmac.sys -- (AsyncMac)
DRV:64bit: - [2009/07/13 19:10:09 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rasacd.sys -- (RasAcd)
DRV:64bit: - [2009/07/13 19:10:03 | 000,116,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipnat.sys -- (IPNAT)
DRV:64bit: - [2009/07/13 19:10:00 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndistapi.sys -- (NdisTapi)
DRV:64bit: - [2009/07/13 19:09:48 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qwavedrv.sys -- (QWAVEdrv)
DRV:64bit: - [2009/07/13 19:09:26 | 000,044,544 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\netbios.sys -- (NetBIOS)
DRV:64bit: - [2009/07/13 19:09:26 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\wfplwf.sys -- (WfpLwf)
DRV:64bit: - [2009/07/13 19:09:09 | 000,093,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smb.sys -- (Smb)
DRV:64bit: - [2009/07/13 19:08:59 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\irenum.sys -- (IRENUM)
DRV:64bit: - [2009/07/13 19:08:51 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rspndr.sys -- (rspndr)
DRV:64bit: - [2009/07/13 19:08:51 | 000,060,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lltdio.sys -- (lltdio)
DRV:64bit: - [2009/07/13 19:08:25 | 000,077,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mpsdrv.sys -- (mpsdrv)
DRV:64bit: - [2009/07/13 19:08:13 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiscap.sys -- (NdisCap)
DRV:64bit: - [2009/07/13 19:07:28 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vwifimp.sys -- (vwifimp)
DRV:64bit: - [2009/07/13 19:07:23 | 000,318,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nwifi.sys -- (NativeWifiP)
DRV:64bit: - [2009/07/13 19:07:22 | 000,059,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vwififlt.sys -- (vwififlt)
DRV:64bit: - [2009/07/13 19:07:21 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vwifibus.sys -- (vwifibus)
DRV:64bit: - [2009/07/13 19:07:00 | 000,118,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bthpan.sys -- (BthPan)
DRV:64bit: - [2009/07/13 19:06:56 | 000,158,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rfcomm.sys -- (RFCOMM)
DRV:64bit: - [2009/07/13 19:06:53 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bthenum.sys -- (BthEnum)
DRV:64bit: - [2009/07/13 19:06:52 | 000,100,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbth.sys -- (HidBth)
DRV:64bit: - [2009/07/13 19:06:52 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthmodem.sys -- (BTHMODEM)
DRV:64bit: - [2009/07/13 19:06:52 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\umpass.sys -- (UmPass)
DRV:64bit: - [2009/07/13 19:06:45 | 000,072,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ohci1394.sys -- (ohci1394)
DRV:64bit: - [2009/07/13 19:06:37 | 000,100,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbcir.sys -- (usbcir)
DRV:64bit: - [2009/07/13 19:06:34 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\circlass.sys -- (circlass)
DRV:64bit: - [2009/07/13 19:06:24 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV:64bit: - [2009/07/13 19:06:23 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidir.sys -- (HidIr)
DRV:64bit: - [2009/07/13 19:06:16 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\drmkaud.sys -- (drmkaud)
DRV:64bit: - [2009/07/13 19:02:08 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MTConfig.sys -- (MTConfig)
DRV:64bit: - [2009/07/13 19:02:07 | 000,027,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacompen.sys -- (WacomPen)
DRV:64bit: - [2009/07/13 19:01:03 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sffp_mmc.sys -- (sffp_mmc)
DRV:64bit: - [2009/07/13 19:01:02 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sfloppy.sys -- (sfloppy)
DRV:64bit: - [2009/07/13 19:01:01 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sffdisk.sys -- (sffdisk)
DRV:64bit: - [2009/07/13 19:00:54 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fdc.sys -- (fdc)
DRV:64bit: - [2009/07/13 19:00:54 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\flpydisk.sys -- (flpydisk)
DRV:64bit: - [2009/07/13 19:00:41 | 000,097,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\parport.sys -- (Parport)
DRV:64bit: - [2009/07/13 19:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serial.sys -- (Serial)
DRV:64bit: - [2009/07/13 19:00:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serenum.sys -- (Serenum)
DRV:64bit: - [2009/07/13 19:00:20 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouhid.sys -- (mouhid)
DRV:64bit: - [2009/07/13 19:00:20 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sermouse.sys -- (sermouse)
DRV:64bit: - [2009/07/13 19:00:19 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ksthunk.sys -- (ksthunk)
DRV:64bit: - [2009/07/13 19:00:18 | 000,011,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mskssrv.sys -- (MSKSSRV)
DRV:64bit: - [2009/07/13 19:00:17 | 000,008,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mstee.sys -- (MSTEE)
DRV:64bit: - [2009/07/13 19:00:17 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mspclock.sys -- (MSPCLOCK)
DRV:64bit: - [2009/07/13 19:00:17 | 000,006,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mspqm.sys -- (MSPQM)
DRV:64bit: - [2009/07/13 19:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\beep.sys -- (Beep)
DRV:64bit: - [2009/07/13 18:38:52 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\monitor.sys -- (monitor)
DRV:64bit: - [2009/07/13 18:38:47 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vga.sys -- (VgaSave)
DRV:64bit: - [2009/07/13 18:38:47 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vgapnp.sys -- (vga)
DRV:64bit: - [2009/07/13 18:37:18 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\discache.sys -- (discache)
DRV:64bit: - [2009/07/13 18:35:59 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\blbdrive.sys -- (blbdrive)
DRV:64bit: - [2009/07/13 18:31:06 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbatt.sys -- (HidBatt)
DRV:64bit: - [2009/07/13 18:31:04 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\errdev.sys -- (ErrDev)
DRV:64bit: - [2009/07/13 18:31:03 | 000,017,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CmBatt.sys -- (CmBatt)
DRV:64bit: - [2009/07/13 18:31:02 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wmiacpi.sys -- (WmiAcpi)
DRV:64bit: - [2009/07/13 18:26:13 | 000,113,152 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\luafv.sys -- (luafv)
DRV:64bit: - [2009/07/13 18:25:40 | 000,034,304 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\filetrace.sys -- (Filetrace)
DRV:64bit: - [2009/07/13 18:23:29 | 000,204,800 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\fastfat.sys -- (fastfat)
DRV:64bit: - [2009/07/13 18:23:29 | 000,195,072 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\exfat.sys -- (exfat)
DRV:64bit: - [2009/07/13 18:21:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\nsiproxy.sys -- (nsiproxy)
DRV:64bit: - [2009/07/13 18:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\i8042prt.sys -- (i8042prt)
DRV:64bit: - [2009/07/13 18:19:48 | 000,044,032 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\npfs.sys -- (Npfs)
DRV:64bit: - [2009/07/13 18:19:47 | 000,092,160 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cdfs.sys -- (cdfs)
DRV:64bit: - [2009/07/13 18:19:47 | 000,026,112 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\msfs.sys -- (Msfs)
DRV:64bit: - [2009/07/13 18:19:38 | 000,006,144 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\null.sys -- (Null)
DRV:64bit: - [2009/07/13 18:19:25 | 000,064,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdk8.sys -- (AmdK8)
DRV:64bit: - [2009/07/13 18:19:25 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\intelppm.sys -- (intelppm)
DRV:64bit: - [2009/07/13 18:19:25 | 000,060,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdppm.sys -- (AmdPPM)
DRV:64bit: - [2009/07/13 18:19:25 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\processr.sys -- (Processor)
DRV:64bit: - [2009/07/09 04:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/15 14:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2009/06/10 15:41:10 | 000,047,104 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrSerWdm.sys -- (BrSerWdm)
DRV:64bit: - [2009/06/10 15:41:10 | 000,014,976 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV:64bit: - [2009/06/10 15:41:10 | 000,014,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrUsbSer.sys -- (BrUsbSer)
DRV:64bit: - [2009/06/10 15:41:06 | 000,018,432 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrFiltLo.sys -- (BrFiltLo)
DRV:64bit: - [2009/06/10 15:41:06 | 000,008,704 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrFiltUp.sys -- (BrFiltUp)
DRV:64bit: - [2009/06/10 15:37:19 | 000,023,040 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\secdrv.sys -- (secdrv)
DRV:64bit: - [2009/06/10 15:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/03/30 02:53:56 | 000,311,656 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0103.sys -- (RsFx0103)
DRV:64bit: - [2009/02/24 17:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/12/29 17:35:40 | 000,146,928 | ---- | M] (CyberLink Corp.) [2011/03/05 12:09:18] [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl -- ({1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7})
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://safesearchr.l...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledAddons: {972ce4c6-7e08-4474-a285-3208198ce6fd}:16.0.2
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/18 12:10:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/18 12:10:56 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/04/21 16:48:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\RICK\AppData\Roaming\Mozilla\Extensions
[2012/11/18 12:10:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions
[2012/10/24 19:21:58 | 000,000,000 | ---D | M] (Green Fox) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\{d122ad80-ff45-11dd-87af-0800200c9a66}
[2012/11/18 11:47:52 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\[email protected]
[2012/07/27 16:49:38 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\[email protected]
[2012/10/17 18:03:56 | 000,221,098 | ---- | M] () (No name found) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\[email protected]
[2012/08/30 05:56:40 | 000,199,396 | ---- | M] () (No name found) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012/01/06 13:03:55 | 000,634,964 | ---- | M] () (No name found) -- C:\Users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/10/26 16:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/10/26 16:25:03 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/10/26 16:25:03 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/11/18 11:47:52 | 000,000,616 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012/09/26 04:50:56 | 000,001,607 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2012/09/26 04:50:56 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/26 04:50:56 | 000,001,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2012/09/26 04:50:56 | 000,003,581 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2012/10/19 16:43:32 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
[2012/09/26 04:50:56 | 000,001,391 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2012/09/26 04:50:56 | 000,001,309 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\RICK\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: YouTube = C:\Users\RICK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\RICK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\RICK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/11/16 18:54:56 | 000,001,392 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 50.31.74.129 www.google-analytics.com.
O1 - Hosts: 50.31.74.129 ad-emea.doubleclick.net.
O1 - Hosts: 50.31.74.129 www.statcounter.com.
O1 - Hosts: 217.23.13.202 www.google-analytics.com.
O1 - Hosts: 217.23.13.202 ad-emea.doubleclick.net.
O1 - Hosts: 217.23.13.202 www.statcounter.com.
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [NCsoft] File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - Startup: C:\Users\RICK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.2.1)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_02)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E83B156F-2215-4566-98B5-7002DCF2F838}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{3c14c227-d7e7-11e1-be70-889ffab8db24}\Shell - "" = AutoRun
O33 - MountPoints2\{3c14c227-d7e7-11e1-be70-889ffab8db24}\Shell\AutoRun\command - "" = E:\Keeper\WinSetup\setup.exe
O33 - MountPoints2\{3c14c237-d7e7-11e1-be70-889ffab8db24}\Shell - "" = AutoRun
O33 - MountPoints2\{3c14c237-d7e7-11e1-be70-889ffab8db24}\Shell\AutoRun\command - "" = E:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


========== Files/Folders - Created Within 60 Days ==========

[2012/11/18 14:19:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/11/18 14:18:48 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/18 14:18:48 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll
[2012/11/18 14:14:02 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/11/18 14:14:02 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/11/18 14:14:01 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/11/18 14:14:01 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/11/18 14:14:01 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/11/18 14:14:01 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/11/18 14:14:01 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/11/18 14:14:01 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/11/18 14:14:01 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/11/18 14:14:00 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/11/18 14:14:00 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/11/18 14:14:00 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/11/18 14:13:59 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/11/18 14:13:59 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/11/18 14:13:59 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/11/18 14:11:19 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll
[2012/11/18 14:11:19 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe
[2012/11/18 14:11:19 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/18 14:11:19 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/18 14:10:12 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2012/11/18 14:10:12 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2012/11/18 14:10:12 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2012/11/18 14:10:12 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2012/11/18 14:10:11 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2012/11/18 14:10:10 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2012/11/18 14:10:10 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2012/11/18 14:10:10 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2012/11/18 14:10:10 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2012/11/18 14:10:10 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2012/11/18 14:10:10 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2012/11/18 14:10:10 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/11/18 14:10:10 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/11/18 14:10:10 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/11/18 14:10:10 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2012/11/18 14:10:10 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/11/18 14:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/11/18 14:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/11/18 14:10:09 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/11/18 14:10:09 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/11/18 14:10:09 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/11/18 14:10:09 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/11/18 14:10:09 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/11/18 14:10:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/11/18 14:10:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/11/18 14:10:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/11/18 14:10:07 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2012/11/18 14:10:01 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/11/18 14:10:00 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/11/18 14:09:57 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
[2012/11/18 14:09:57 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
[2012/11/18 14:09:57 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2012/11/18 14:09:56 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
[2012/11/18 14:09:56 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2012/11/18 14:09:56 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2012/11/18 14:09:52 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
[2012/11/18 14:09:52 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/18 14:09:52 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/18 14:09:47 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/11/18 14:09:46 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/11/18 14:09:46 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/11/18 14:09:43 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2012/11/18 14:09:43 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
[2012/11/18 14:09:43 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
[2012/11/18 12:13:58 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Roaming\Malwarebytes
[2012/11/18 12:13:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/18 12:13:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/11/18 12:13:46 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/11/18 12:13:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/11/18 11:52:12 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Roaming\LavasoftStatistics
[2012/11/18 11:48:30 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\Downloaded Installations
[2012/11/17 13:54:12 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012/11/17 13:53:48 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012/11/17 13:53:48 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/11/16 21:14:53 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Roaming\AVG2013
[2012/11/16 21:14:14 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Roaming\TuneUp Software
[2012/11/16 21:14:03 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/11/16 21:14:03 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2012/11/16 21:10:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/11/16 21:10:58 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\MFAData
[2012/11/16 21:10:58 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012/11/16 21:10:58 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\Avg2013
[2012/11/14 21:08:59 | 000,000,000 | ---D | C] -- C:\Users\RICK\.WebIde50
[2012/11/14 21:08:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JetBrains
[2012/11/14 19:48:10 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\Apps
[2012/11/14 17:32:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WampServer
[2012/11/14 17:31:42 | 000,000,000 | ---D | C] -- C:\wamp
[2012/10/29 22:03:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
[2012/10/29 22:03:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guild Wars 2
[2012/10/29 22:02:47 | 000,000,000 | ---D | C] -- C:\Users\RICK\Documents\Guild Wars 2
[2012/10/26 16:25:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/10/13 17:48:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enlight
[2012/10/13 17:47:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Enlight
[2012/10/11 18:45:20 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\{E67D8700-2502-44F8-B8F4-205C4A031823}
[2012/10/02 18:59:57 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2012/10/02 18:44:01 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OxpsConverter.exe
[2012/10/02 18:43:59 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys
[2012/10/02 18:43:57 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2012/10/02 18:43:57 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/10/02 18:10:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2012/10/02 18:10:16 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2012/10/02 18:06:44 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
[2012/10/02 18:06:44 | 000,048,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll
[2012/10/02 18:06:38 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2012/10/02 18:06:35 | 003,715,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2012/10/02 18:06:35 | 001,838,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2012/10/02 18:06:35 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/10/02 18:06:35 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/10/02 18:06:33 | 003,215,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2012/10/02 18:06:30 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40.dll
[2012/10/02 18:06:30 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40u.dll
[2012/10/02 18:06:28 | 014,633,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2012/10/02 18:06:27 | 003,205,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmcndmgr.dll
[2012/10/02 18:06:26 | 004,120,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2012/10/02 18:06:26 | 003,008,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xpsservices.dll
[2012/10/02 18:06:26 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2012/10/02 18:06:26 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2012/10/02 18:06:26 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2012/10/02 18:06:26 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2012/10/02 18:06:26 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2012/10/02 18:06:25 | 001,219,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2012/10/02 18:06:25 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2012/10/02 18:06:25 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2012/10/02 18:06:24 | 002,086,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2012/10/02 18:06:24 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2012/10/02 18:06:23 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizui.dll
[2012/10/02 18:06:22 | 003,207,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2012/10/02 18:06:22 | 001,866,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2012/10/02 18:06:22 | 001,556,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RacEngn.dll
[2012/10/02 18:06:22 | 001,340,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagperf.dll
[2012/10/02 18:06:22 | 001,197,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskschd.dll
[2012/10/02 18:06:21 | 001,753,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vssapi.dll
[2012/10/02 18:06:21 | 001,334,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll
[2012/10/02 18:06:20 | 011,410,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2012/10/02 18:06:20 | 003,860,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIRibbon.dll
[2012/10/02 18:06:20 | 001,326,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NaturalLanguage6.dll
[2012/10/02 18:06:20 | 000,299,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcupdate_GenuineIntel.dll
[2012/10/02 18:06:18 | 003,957,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSAT.exe
[2012/10/02 18:06:18 | 003,027,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVCORE.DLL
[2012/10/02 18:06:18 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll
[2012/10/02 18:06:18 | 000,598,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spinstall.exe
[2012/10/02 18:06:18 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe
[2012/10/02 18:06:18 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spreview.exe
[2012/10/02 18:06:18 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe
[2012/10/02 18:06:18 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpdd.dll
[2012/10/02 18:06:18 | 000,109,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll
[2012/10/02 18:06:18 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll
[2012/10/02 18:06:17 | 002,067,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9.dll
[2012/10/02 18:06:17 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2012/10/02 18:06:16 | 005,066,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AuthFWSnapin.dll
[2012/10/02 18:06:16 | 005,066,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuthFWSnapin.dll
[2012/10/02 18:06:16 | 001,115,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RacEngn.dll
[2012/10/02 18:06:16 | 000,867,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFolder.dll
[2012/10/02 18:06:15 | 003,391,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbgeng.dll
[2012/10/02 18:06:15 | 001,632,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll
[2012/10/02 18:06:14 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2012/10/02 18:06:13 | 000,958,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\actxprxy.dll
[2012/10/02 18:06:13 | 000,750,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2012/10/02 18:06:12 | 001,244,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi2fs.dll
[2012/10/02 18:06:12 | 001,116,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2012/10/02 18:06:12 | 000,695,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netlogon.dll
[2012/10/02 18:06:11 | 001,212,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll
[2012/10/02 18:06:11 | 000,787,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2012/10/02 18:06:10 | 001,927,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2012/10/02 18:06:10 | 001,900,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupapi.dll
[2012/10/02 18:06:10 | 001,281,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\werconcpl.dll
[2012/10/02 18:06:10 | 000,505,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskschd.dll
[2012/10/02 18:06:10 | 000,464,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskeng.exe
[2012/10/02 18:06:09 | 001,049,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2012/10/02 18:06:09 | 001,008,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
[2012/10/02 18:06:09 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2012/10/02 18:06:08 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certmgr.dll
[2012/10/02 18:06:08 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2012/10/02 18:06:08 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2012/10/02 18:06:08 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll
[2012/10/02 18:06:07 | 001,371,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll
[2012/10/02 18:06:07 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceApi.dll
[2012/10/02 18:06:07 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2012/10/02 18:06:07 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shlwapi.dll
[2012/10/02 18:06:07 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsmf.dll
[2012/10/02 18:06:06 | 002,652,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netshell.dll
[2012/10/02 18:06:06 | 001,509,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdtctm.dll
[2012/10/02 18:06:06 | 000,800,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll
[2012/10/02 18:06:06 | 000,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2012/10/02 18:06:06 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll
[2012/10/02 18:06:06 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2012/10/02 18:06:06 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmicmiplugin.dll
[2012/10/02 18:06:06 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcfgx.dll
[2012/10/02 18:06:06 | 000,390,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2012/10/02 18:06:06 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsm.exe
[2012/10/02 18:06:06 | 000,297,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ws2_32.dll
[2012/10/02 18:06:06 | 000,295,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\framedynos.dll
[2012/10/02 18:06:06 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tcpmonui.dll
[2012/10/02 18:06:05 | 002,543,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdshext.dll
[2012/10/02 18:06:05 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Query.dll
[2012/10/02 18:06:05 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2012/10/02 18:06:05 | 000,481,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpps.dll
[2012/10/02 18:06:05 | 000,422,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvstore.dll
[2012/10/02 18:06:05 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll
[2012/10/02 18:06:05 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsmf.dll
[2012/10/02 18:06:05 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3api.dll
[2012/10/02 18:06:04 | 002,522,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbgeng.dll
[2012/10/02 18:06:04 | 001,098,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Vault.dll
[2012/10/02 18:06:04 | 000,897,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\azroles.dll
[2012/10/02 18:06:04 | 000,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll
[2012/10/02 18:06:04 | 000,653,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpksetup.exe
[2012/10/02 18:06:04 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmd.exe
[2012/10/02 18:06:04 | 000,281,600 | ---- | C] (Microsoft) -- C:\Windows\SysNative\DShowRdpFilter.dll
[2012/10/02 18:06:04 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QAGENT.DLL
[2012/10/02 18:06:03 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2012/10/02 18:06:02 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2012/10/02 18:06:02 | 001,190,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2012/10/02 18:06:02 | 000,582,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sxs.dll
[2012/10/02 18:06:02 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcfgx.dll
[2012/10/02 18:06:02 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wldap32.dll
[2012/10/02 18:06:02 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcbuilder.exe
[2012/10/02 18:06:01 | 002,151,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmcndmgr.dll
[2012/10/02 18:06:01 | 001,808,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pnidui.dll
[2012/10/02 18:06:01 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ipsmsnap.dll
[2012/10/02 18:06:01 | 000,473,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskcomp.dll
[2012/10/02 18:06:01 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll
[2012/10/02 18:06:01 | 000,252,928 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\DShowRdpFilter.dll
[2012/10/02 18:06:01 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hgprint.dll
[2012/10/02 18:06:01 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\upnp.dll
[2012/10/02 18:06:00 | 001,792,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2012/10/02 18:06:00 | 001,158,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webservices.dll
[2012/10/02 18:06:00 | 000,933,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqlsrv32.dll
[2012/10/02 18:06:00 | 000,732,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi2fs.dll
[2012/10/02 18:06:00 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fveapi.dll
[2012/10/02 18:06:00 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsta.dll
[2012/10/02 18:06:00 | 000,049,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll
[2012/10/02 18:05:59 | 001,009,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcmde.dll
[2012/10/02 18:05:59 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2012/10/02 18:05:59 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schtasks.exe
[2012/10/02 18:05:59 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mcbuilder.exe
[2012/10/02 18:05:59 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prncache.dll
[2012/10/02 18:05:59 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3api.dll
[2012/10/02 18:05:58 | 001,712,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xpsservices.dll
[2012/10/02 18:05:58 | 001,555,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certmgr.dll
[2012/10/02 18:05:58 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanpref.dll
[2012/10/02 18:05:58 | 001,243,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMNetMgr.dll
[2012/10/02 18:05:58 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2012/10/02 18:05:58 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\photowiz.dll
[2012/10/02 18:05:58 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvstore.dll
[2012/10/02 18:05:58 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vpnike.dll
[2012/10/02 18:05:58 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userenv.dll
[2012/10/02 18:05:57 | 002,262,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SyncCenter.dll
[2012/10/02 18:05:57 | 001,082,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll
[2012/10/02 18:05:57 | 001,024,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2012/10/02 18:05:57 | 000,412,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2012/10/02 18:05:57 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmd.exe
[2012/10/02 18:05:57 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2012/10/02 18:05:57 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\framedyn.dll
[2012/10/02 18:05:56 | 002,072,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPEncEn.dll
[2012/10/02 18:05:56 | 000,605,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpeffects.dll
[2012/10/02 18:05:56 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2012/10/02 18:05:56 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2012/10/02 18:05:56 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\framedynos.dll
[2012/10/02 18:05:56 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fde.dll
[2012/10/02 18:05:55 | 000,551,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localsec.dll
[2012/10/02 18:05:55 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi2.dll
[2012/10/02 18:05:55 | 000,501,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSATAPI.dll
[2012/10/02 18:05:55 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netdiagfx.dll
[2012/10/02 18:05:55 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll
[2012/10/02 18:05:55 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll
[2012/10/02 18:05:55 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2012/10/02 18:05:54 | 000,762,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\azroles.dll
[2012/10/02 18:05:54 | 000,298,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcryptprimitives.dll
[2012/10/02 18:05:54 | 000,253,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcpipcfg.dll
[2012/10/02 18:05:54 | 000,244,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spp.dll
[2012/10/02 18:05:54 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QSHVHOST.DLL
[2012/10/02 18:05:54 | 000,166,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetpp.dll
[2012/10/02 18:05:54 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netid.dll
[2012/10/02 18:05:54 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2012/10/02 18:05:54 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2012/10/02 18:05:53 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\biocpl.dll
[2012/10/02 18:05:52 | 002,755,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themeui.dll
[2012/10/02 18:05:52 | 002,746,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll
[2012/10/02 18:05:52 | 001,050,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printui.dll
[2012/10/02 18:05:52 | 000,571,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mspbda.dll
[2012/10/02 18:05:52 | 000,477,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PhotoScreensaver.scr
[2012/10/02 18:05:52 | 000,378,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msinfo32.exe
[2012/10/02 18:05:52 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scansetting.dll
[2012/10/02 18:05:51 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2012/10/02 18:05:51 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wusa.exe
[2012/10/02 18:05:51 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2012/10/02 18:05:51 | 000,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll
[2012/10/02 18:05:51 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IPHLPAPI.DLL
[2012/10/02 18:05:51 | 000,144,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\basecsp.dll
[2012/10/02 18:05:51 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitagent.exe
[2012/10/02 18:05:50 | 000,934,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FirewallControlPanel.dll
[2012/10/02 18:05:50 | 000,854,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbghelp.dll
[2012/10/02 18:05:50 | 000,625,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll
[2012/10/02 18:05:50 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2012/10/02 18:05:50 | 000,442,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winspool.drv
[2012/10/02 18:05:50 | 000,405,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wisptis.exe
[2012/10/02 18:05:50 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskcomp.dll
[2012/10/02 18:05:50 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2012/10/02 18:05:50 | 000,199,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PkgMgr.exe
[2012/10/02 18:05:50 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetup.exe
[2012/10/02 18:05:49 | 000,780,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2012/10/02 18:05:49 | 000,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\calc.exe
[2012/10/02 18:05:49 | 000,459,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXP.dll
[2012/10/02 18:05:49 | 000,418,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll
[2012/10/02 18:05:49 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapp3hst.dll
[2012/10/02 18:05:49 | 000,335,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WinSATAPI.dll
[2012/10/02 18:05:49 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetapi.dll
[2012/10/02 18:05:48 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIRibbon.dll
[2012/10/02 18:05:48 | 002,494,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netshell.dll
[2012/10/02 18:05:48 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmsys.cpl
[2012/10/02 18:05:48 | 000,778,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqlsrv32.dll
[2012/10/02 18:05:48 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapphost.dll
[2012/10/02 18:05:48 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\upnp.dll
[2012/10/02 18:05:48 | 000,263,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2012/10/02 18:05:48 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprapi.dll
[2012/10/02 18:05:48 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2012/10/02 18:05:48 | 000,128,000 | ---- | C] (Microsoft) -- C:\Windows\SysNative\Robocopy.exe
[2012/10/02 18:05:48 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2012/10/02 18:05:48 | 000,078,720 | ---- | C] (Hewlett-Packard Company) -- C:\Windows\SysNative\drivers\HpSAMD.sys
[2012/10/02 18:05:47 | 001,457,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DxpTaskSync.dll
[2012/10/02 18:05:47 | 001,160,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSMPEG2ENC.DLL
[2012/10/02 18:05:47 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PerfCenterCPL.dll
[2012/10/02 18:05:47 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scecli.dll
[2012/10/02 18:05:47 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmredir.dll
[2012/10/02 18:05:46 | 002,851,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themeui.dll
[2012/10/02 18:05:46 | 000,932,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\printui.dll
[2012/10/02 18:05:46 | 000,675,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXPTaskRingtone.dll
[2012/10/02 18:05:46 | 000,429,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\puiobj.dll
[2012/10/02 18:05:46 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpeffects.dll
[2012/10/02 18:05:46 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\onex.dll
[2012/10/02 18:05:46 | 000,179,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys
[2012/10/02 18:05:46 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll
[2012/10/02 18:05:46 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\net1.exe
[2012/10/02 18:05:46 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll
[2012/10/02 18:05:46 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prncache.dll
[2012/10/02 18:05:46 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll
[2012/10/02 18:05:45 | 001,363,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll
[2012/10/02 18:05:45 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scansetting.dll
[2012/10/02 18:05:44 | 001,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcenter.dll
[2012/10/02 18:05:44 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdengin2.dll
[2012/10/02 18:05:44 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll
[2012/10/02 18:05:44 | 000,691,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VAN.dll
[2012/10/02 18:05:44 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll
[2012/10/02 18:05:44 | 000,475,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlangpui.dll
[2012/10/02 18:05:44 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wiadefui.dll
[2012/10/02 18:05:44 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scesrv.dll
[2012/10/02 18:05:44 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVol.exe
[2012/10/02 18:05:44 | 000,239,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dskquoui.dll
[2012/10/02 18:05:44 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samcli.dll
[2012/10/02 18:05:44 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscapi.dll
[2012/10/02 18:05:43 | 001,750,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pnidui.dll
[2012/10/02 18:05:43 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlangpui.dll
[2012/10/02 18:05:43 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srchadmin.dll
[2012/10/02 18:05:43 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QSHVHOST.DLL
[2012/10/02 18:05:43 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll
[2012/10/02 18:05:43 | 000,112,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe
[2012/10/02 18:05:43 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2012/10/02 18:05:43 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QUTIL.DLL
[2012/10/02 18:05:43 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\regapi.dll
[2012/10/02 18:05:42 | 002,146,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SyncCenter.dll
[2012/10/02 18:05:42 | 000,782,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webservices.dll
[2012/10/02 18:05:42 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appwiz.cpl
[2012/10/02 18:05:42 | 000,684,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TabletPC.cpl
[2012/10/02 18:05:42 | 000,560,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2012/10/02 18:05:42 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll
[2012/10/02 18:05:42 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2012/10/02 18:05:42 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netdiagfx.dll
[2012/10/02 18:05:42 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fde.dll
[2012/10/02 18:05:42 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupcl.exe
[2012/10/02 18:05:42 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe
[2012/10/02 18:05:42 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll
[2012/10/02 18:05:41 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hgcpl.dll
[2012/10/02 18:05:41 | 000,300,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msconfig.exe
[2012/10/02 18:05:41 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netiohlp.dll
[2012/10/02 18:05:41 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mimefilt.dll
[2012/10/02 18:05:40 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2ENC.DLL
[2012/10/02 18:05:40 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayCpl.dll
[2012/10/02 18:05:40 | 000,633,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\riched20.dll
[2012/10/02 18:05:40 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi2.dll
[2012/10/02 18:05:40 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mtxclu.dll
[2012/10/02 18:05:40 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\clusapi.dll
[2012/10/02 18:05:40 | 000,166,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\basecsp.dll
[2012/10/02 18:05:40 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdeploy.dll
[2012/10/02 18:05:40 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsmproxy.dll
[2012/10/02 18:05:40 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/10/02 18:05:39 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll
[2012/10/02 18:05:39 | 001,624,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPEncEn.dll
[2012/10/02 18:05:39 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXPTaskRingtone.dll
[2012/10/02 18:05:39 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\powercpl.dll
[2012/10/02 18:05:39 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sharemediacpl.dll
[2012/10/02 18:05:39 | 000,199,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\onex.dll
[2012/10/02 18:05:39 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logoncli.dll
[2012/10/02 18:05:39 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscmmc.dll
[2012/10/02 18:05:39 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RpcRtRemote.dll
[2012/10/02 18:05:38 | 002,250,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SensorsCpl.dll
[2012/10/02 18:05:38 | 002,193,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themecpl.dll
[2012/10/02 18:05:38 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Narrator.exe
[2012/10/02 18:05:38 | 000,668,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe
[2012/10/02 18:05:38 | 000,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autofmt.exe
[2012/10/02 18:05:38 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eudcedit.exe
[2012/10/02 18:05:38 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Faultrep.dll
[2012/10/02 18:05:38 | 000,188,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netjoin.dll
[2012/10/02 18:05:38 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netiohlp.dll
[2012/10/02 18:05:38 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nci.dll
[2012/10/02 18:05:38 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hbaapi.dll
[2012/10/02 18:05:38 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vpnikeapi.dll
[2012/10/02 18:05:37 | 000,777,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe
[2012/10/02 18:05:37 | 000,763,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autofmt.exe
[2012/10/02 18:05:37 | 000,679,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autoconv.exe
[2012/10/02 18:05:37 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll
[2012/10/02 18:05:37 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ipsmsnap.dll
[2012/10/02 18:05:37 | 000,303,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msinfo32.exe
[2012/10/02 18:05:37 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppcomapi.dll
[2012/10/02 18:05:37 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msutb.dll
[2012/10/02 18:05:37 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll
[2012/10/02 18:05:37 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\regapi.dll
[2012/10/02 18:05:37 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mimefilt.dll
[2012/10/02 18:05:37 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\proquota.exe
[2012/10/02 18:05:36 | 001,264,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdclt.exe
[2012/10/02 18:05:36 | 000,905,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmsys.cpl
[2012/10/02 18:05:36 | 000,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autoconv.exe
[2012/10/02 18:05:36 | 000,665,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AuxiliaryDisplayCpl.dll
[2012/10/02 18:05:36 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpd_ci.dll
[2012/10/02 18:05:36 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshipsec.dll
[2012/10/02 18:05:36 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\powercpl.dll
[2012/10/02 18:05:36 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanui.dll
[2012/10/02 18:05:36 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msihnd.dll
[2012/10/02 18:05:36 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\srchadmin.dll
[2012/10/02 18:05:36 | 000,222,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanconn.dll
[2012/10/02 18:05:36 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapphost.dll
[2012/10/02 18:05:36 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\framedyn.dll
[2012/10/02 18:05:36 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tcpipcfg.dll
[2012/10/02 18:05:36 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schtasks.exe
[2012/10/02 18:05:36 | 000,171,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\scsiport.sys
[2012/10/02 18:05:36 | 000,168,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdsrv.dll
[2012/10/02 18:05:36 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prntvpt.dll
[2012/10/02 18:05:36 | 000,155,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll
[2012/10/02 18:05:36 | 000,154,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll
[2012/10/02 18:05:36 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shsetup.dll
[2012/10/02 18:05:36 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2012/10/02 18:05:36 | 000,116,224 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2012/10/02 18:05:35 | 001,227,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll
[2012/10/02 18:05:35 | 001,066,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Display.dll
[2012/10/02 18:05:35 | 000,933,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmiEngine.dll
[2012/10/02 18:05:35 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontext.dll
[2012/10/02 18:05:35 | 000,749,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\batmeter.dll
[2012/10/02 18:05:35 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2012/10/02 18:05:35 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprddm.dll
[2012/10/02 18:05:35 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QAGENT.DLL
[2012/10/02 18:05:35 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netid.dll
[2012/10/02 18:05:35 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
[2012/10/02 18:05:34 | 002,217,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bootres.dll
[2012/10/02 18:05:34 | 001,326,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanpref.dll
[2012/10/02 18:05:34 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DiagCpl.dll
[2012/10/02 18:05:34 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMNetMgr.dll
[2012/10/02 18:05:34 | 000,957,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mblctr.exe
[2012/10/02 18:05:34 | 000,933,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Vault.dll
[2012/10/02 18:05:34 | 000,625,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usercpl.dll
[2012/10/02 18:05:34 | 000,372,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2012/10/02 18:05:34 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll
[2012/10/02 18:05:34 | 000,307,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scesrv.dll
[2012/10/02 18:05:34 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpsrcwp.dll
[2012/10/02 18:05:34 | 000,098,816 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\Robocopy.exe
[2012/10/02 18:05:34 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nci.dll
[2012/10/02 18:05:34 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll
[2012/10/02 18:05:33 | 001,400,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DxpTaskSync.dll
[2012/10/02 18:05:33 | 000,812,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpccpl.dll
[2012/10/02 18:05:33 | 000,433,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MCEWMDRMNDBootstrap.dll
[2012/10/02 18:05:33 | 000,250,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ksproxy.ax
[2012/10/02 18:05:33 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskmgr.exe
[2012/10/02 18:05:33 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasppp.dll
[2012/10/02 18:05:33 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSTPager.ax
[2012/10/02 18:05:32 | 001,040,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Display.dll
[2012/10/02 18:05:32 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prnfldr.dll
[2012/10/02 18:05:32 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\termmgr.dll
[2012/10/02 18:05:32 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\puiobj.dll
[2012/10/02 18:05:32 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mtxclu.dll
[2012/10/02 18:05:32 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eudcedit.exe
[2012/10/02 18:05:32 | 000,279,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxdiagn.dll
[2012/10/02 18:05:32 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskmgr.exe
[2012/10/02 18:05:32 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVolSSO.dll
[2012/10/02 18:05:32 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
[2012/10/02 18:05:32 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2012/10/02 18:05:32 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hbaapi.dll
[2012/10/02 18:05:32 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3cfg.dll
[2012/10/02 18:05:32 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\userinit.exe
[2012/10/02 18:05:31 | 000,416,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wiadefui.dll
[2012/10/02 18:05:31 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll
[2012/10/02 18:05:31 | 000,300,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pdh.dll
[2012/10/02 18:05:31 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAC3ENC.DLL
[2012/10/02 18:05:31 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppcomapi.dll
[2012/10/02 18:05:31 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasppp.dll
[2012/10/02 18:05:31 | 000,155,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys
[2012/10/02 18:05:31 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll
[2012/10/02 18:05:31 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logoncli.dll
[2012/10/02 18:05:31 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDShServiceObj.dll
[2012/10/02 18:05:31 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shsetup.dll
[2012/10/02 18:05:31 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\proquota.exe
[2012/10/02 18:05:31 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userinit.exe
[2012/10/02 18:05:30 | 003,745,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\accessibilitycpl.dll
[2012/10/02 18:05:30 | 002,202,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SensorsCpl.dll
[2012/10/02 18:05:30 | 002,157,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themecpl.dll
[2012/10/02 18:05:30 | 000,856,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FirewallControlPanel.dll
[2012/10/02 18:05:30 | 000,649,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appwiz.cpl
[2012/10/02 18:05:30 | 000,366,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\zipfldr.dll
[2012/10/02 18:05:30 | 000,349,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slui.exe
[2012/10/02 18:05:30 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2012/10/02 18:05:30 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscmmc.dll
[2012/10/02 18:05:29 | 000,769,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sud.dll
[2012/10/02 18:05:29 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PhotoScreensaver.scr
[2012/10/02 18:05:29 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msieftp.dll
[2012/10/02 18:05:29 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hgcpl.dll
[2012/10/02 18:05:29 | 000,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\defaultlocationcpl.dll
[2012/10/02 18:05:29 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scecli.dll
[2012/10/02 18:05:28 | 002,146,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkmap.dll
[2012/10/02 18:05:28 | 001,065,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2012/10/02 18:05:28 | 000,828,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontext.dll
[2012/10/02 18:05:28 | 000,780,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionCenter.dll
[2012/10/02 18:05:28 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PerfCenterCPL.dll
[2012/10/02 18:05:28 | 000,600,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\usercpl.dll
[2012/10/02 18:05:28 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2012/10/02 18:05:28 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceCenter.dll
[2012/10/02 18:05:28 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\localsec.dll
[2012/10/02 18:05:28 | 000,410,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanui.dll
[2012/10/02 18:05:28 | 000,373,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\intl.cpl
[2012/10/02 18:05:28 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprddm.dll
[2012/10/02 18:05:28 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskbarcpl.dll
[2012/10/02 18:05:28 | 000,221,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OnLineIDCpl.dll
[2012/10/02 18:05:28 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVolSSO.dll
[2012/10/02 18:05:28 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twext.dll
[2012/10/02 18:05:28 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll
[2012/10/02 18:05:27 | 001,644,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcenter.dll
[2012/10/02 18:05:27 | 000,898,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OobeFldr.dll
[2012/10/02 18:05:27 | 000,740,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\batmeter.dll
[2012/10/02 18:05:27 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dsuiext.dll
[2012/10/02 18:05:27 | 000,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VAN.dll
[2012/10/02 18:05:27 | 000,472,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\azroleui.dll
[2012/10/02 18:05:27 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwizeng.dll
[2012/10/02 18:05:27 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdedit.exe
[2012/10/02 18:05:27 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MediaMetadataHandler.dll
[2012/10/02 18:05:27 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVol.exe
[2012/10/02 18:05:27 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uxlib.dll
[2012/10/02 18:05:27 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\recovery.dll
[2012/10/02 18:05:27 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prntvpt.dll
[2012/10/02 18:05:27 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cca.dll
[2012/10/02 18:05:27 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\isoburn.exe
[2012/10/02 18:05:27 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w32tm.exe
[2012/10/02 18:05:27 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sisbkup.dll
[2012/10/02 18:05:26 | 003,727,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\accessibilitycpl.dll
[2012/10/02 18:05:26 | 001,003,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2012/10/02 18:05:26 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdcpl.dll
[2012/10/02 18:05:26 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthprops.cpl
[2012/10/02 18:05:26 | 000,516,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\main.cpl
[2012/10/02 18:05:26 | 000,451,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shwebsvc.dll
[2012/10/02 18:05:26 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll
[2012/10/02 18:05:26 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\azroleui.dll
[2012/10/02 18:05:26 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\efscore.dll
[2012/10/02 18:05:26 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\recdisc.exe
[2012/10/02 18:05:26 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAC3ENC.DLL
[2012/10/02 18:05:26 | 000,200,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\syncui.dll
[2012/10/02 18:05:26 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VBICodec.ax
[2012/10/02 18:05:26 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll
[2012/10/02 18:05:26 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autoplay.dll
[2012/10/02 18:05:26 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdeploy.dll
[2012/10/02 18:05:26 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tzutil.exe
[2012/10/02 18:05:26 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\httpapi.dll
[2012/10/02 18:05:25 | 002,130,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkmap.dll
[2012/10/02 18:05:25 | 000,549,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionCenterCPL.dll
[2012/10/02 18:05:25 | 000,460,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2012/10/02 18:05:25 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll
[2012/10/02 18:05:25 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Faultrep.dll
[2012/10/02 18:05:25 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysclass.dll
[2012/10/02 18:05:25 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adsldp.dll
[2012/10/02 18:05:25 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netjoin.dll
[2012/10/02 18:05:25 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncryptui.dll
[2012/10/02 18:05:24 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sud.dll
[2012/10/02 18:05:24 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ActionCenter.dll
[2012/10/02 18:05:24 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx
[2012/10/02 18:05:24 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizeng.dll
[2012/10/02 18:05:24 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\termmgr.dll
[2012/10/02 18:05:24 | 000,395,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prnfldr.dll
[2012/10/02 18:05:24 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wusa.exe
[2012/10/02 18:05:24 | 000,312,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MCEWMDRMNDBootstrap.dll
[2012/10/02 18:05:24 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msieftp.dll
[2012/10/02 18:05:24 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\photowiz.dll
[2012/10/02 18:05:24 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MediaMetadataHandler.dll
[2012/10/02 18:05:24 | 000,240,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFPlay.dll
[2012/10/02 18:05:24 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OnLineIDCpl.dll
[2012/10/02 18:05:24 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll
[2012/10/02 18:05:24 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayServices.dll
[2012/10/02 18:05:24 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ksxbar.ax
[2012/10/02 18:05:23 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bthprops.cpl
[2012/10/02 18:05:23 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2012/10/02 18:05:23 | 000,446,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqlcese30.dll
[2012/10/02 18:05:23 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx
[2012/10/02 18:05:23 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl
[2012/10/02 18:05:23 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ReAgent.dll
[2012/10/02 18:05:23 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sethc.exe
[2012/10/02 18:05:23 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iprtrmgr.dll
[2012/10/02 18:05:23 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\defaultlocationcpl.dll
[2012/10/02 18:05:23 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2012/10/02 18:05:23 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ifsutil.dll
[2012/10/02 18:05:23 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntlanman.dll
[2012/10/02 18:05:23 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3cfg.dll
[2012/10/02 18:05:23 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2012/10/02 18:05:23 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ftp.exe
[2012/10/02 18:05:23 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sisbkup.dll
[2012/10/02 18:05:22 | 000,781,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2012/10/02 18:05:22 | 000,537,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ActionCenterCPL.dll
[2012/10/02 18:05:22 | 000,495,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2012/10/02 18:05:22 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DeviceCenter.dll
[2012/10/02 18:05:22 | 000,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shwebsvc.dll
[2012/10/02 18:05:22 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ssText3d.scr
[2012/10/02 18:05:22 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\unimdm.tsp
[2012/10/02 18:05:22 | 000,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iTVData.dll
[2012/10/02 18:05:22 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iprtrmgr.dll
[2012/10/02 18:05:22 | 000,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\efscore.dll
[2012/10/02 18:05:22 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\syncui.dll
[2012/10/02 18:05:22 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autoplay.dll
[2012/10/02 18:05:22 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srvcli.dll
[2012/10/02 18:05:22 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UserAccountControlSettings.dll
[2012/10/02 18:05:22 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpd3d.dll
[2012/10/02 18:05:22 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll
[2012/10/02 18:05:22 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll
[2012/10/02 18:05:21 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OobeFldr.dll
[2012/10/02 18:05:21 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll
[2012/10/02 18:05:21 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2012/10/02 18:05:21 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\systemcpl.dll
[2012/10/02 18:05:21 | 000,344,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntprint.dll
[2012/10/02 18:05:21 | 000,297,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntprint.dll
[2012/10/02 18:05:21 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srrstr.dll
[2012/10/02 18:05:21 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sethc.exe
[2012/10/02 18:05:21 | 000,255,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wavemsp.dll
[2012/10/02 18:05:21 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairingFolder.dll
[2012/10/02 18:05:21 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dskquoui.dll
[2012/10/02 18:05:21 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdboot.exe
[2012/10/02 18:05:21 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\powercfg.cpl
[2012/10/02 18:05:21 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2012/10/02 18:05:21 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NAPHLPR.DLL
[2012/10/02 18:05:21 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nslookup.exe
[2012/10/02 18:05:21 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSTPager.ax
[2012/10/02 18:05:21 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\acppage.dll
[2012/10/02 18:05:20 | 001,672,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkexplorer.dll
[2012/10/02 18:05:20 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2012/10/02 18:05:20 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshipsec.dll
[2012/10/02 18:05:20 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpx.dll
[2012/10/02 18:05:20 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\activeds.dll
[2012/10/02 18:05:20 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ksproxy.ax
[2012/10/02 18:05:20 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpsrcwp.dll
[2012/10/02 18:05:20 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll
[2012/10/02 18:05:20 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\remotepg.dll
[2012/10/02 18:05:20 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NAPHLPR.DLL
[2012/10/02 18:05:20 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppnp.dll
[2012/10/02 18:05:20 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\migisol.dll
[2012/10/02 18:05:20 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabinet.dll
[2012/10/02 18:05:20 | 000,093,696 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2012/10/02 18:05:20 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wkscli.dll
[2012/10/02 18:05:20 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\httpapi.dll
[2012/10/02 18:05:19 | 000,840,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2012/10/02 18:05:19 | 000,685,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsuiext.dll
[2012/10/02 18:05:19 | 000,636,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmdev.dll
[2012/10/02 18:05:19 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfrgui.exe
[2012/10/02 18:05:19 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wvc.dll
[2012/10/02 18:05:19 | 000,592,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll
[2012/10/02 18:05:19 | 000,586,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfrgui.exe
[2012/10/02 18:05:19 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanmsm.dll
[2012/10/02 18:05:19 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpdxm.dll
[2012/10/02 18:05:19 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3ui.dll
[2012/10/02 18:05:19 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsqmcons.exe
[2012/10/02 18:05:19 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReAgent.dll
[2012/10/02 18:05:19 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wavemsp.dll
[2012/10/02 18:05:19 | 000,217,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll
[2012/10/02 18:05:19 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2012/10/02 18:05:19 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\net1.exe
[2012/10/02 18:05:19 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kstvtune.ax
[2012/10/02 18:05:19 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\isoburn.exe
[2012/10/02 18:05:19 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsnmp32.dll
[2012/10/02 18:05:19 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ftp.exe
[2012/10/02 18:05:19 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tzutil.exe
[2012/10/02 18:05:18 | 001,911,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OpcServices.dll
[2012/10/02 18:05:18 | 000,899,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Bubbles.scr
[2012/10/02 18:05:18 | 000,444,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wvc.dll
[2012/10/02 18:05:18 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wimgapi.dll
[2012/10/02 18:05:18 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unimdm.tsp
[2012/10/02 18:05:18 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2012/10/02 18:05:18 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PkgMgr.exe
[2012/10/02 18:05:18 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstask.dll
[2012/10/02 18:05:18 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2012/10/02 18:05:18 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetup.exe
[2012/10/02 18:05:18 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qcap.dll
[2012/10/02 18:05:18 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twext.dll
[2012/10/02 18:05:18 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupugc.exe
[2012/10/02 18:05:18 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mapistub.dll
[2012/10/02 18:05:18 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mapi32.dll
[2012/10/02 18:05:18 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\unimdmat.dll
[2012/10/02 18:05:18 | 000,051,200 | ---- | C] (Twain Working Group) -- C:\Windows\twain_32.dll
[2012/10/02 18:05:18 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFaultSecure.exe
[2012/10/02 18:05:18 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/10/02 18:05:17 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\main.cpl
[2012/10/02 18:05:17 | 000,363,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskraid.exe
[2012/10/02 18:05:17 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ssText3d.scr
[2012/10/02 18:05:17 | 000,242,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Mystify.scr
[2012/10/02 18:05:17 | 000,241,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Ribbons.scr
[2012/10/02 18:05:17 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qasf.dll
[2012/10/02 18:05:17 | 000,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ifsutil.dll
[2012/10/02 18:05:17 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvfw32.dll
[2012/10/02 18:05:17 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\uxlib.dll
[2012/10/02 18:05:17 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsium.dll
[2012/10/02 18:05:17 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll
[2012/10/02 18:05:16 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2012/10/02 18:05:16 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2012/10/02 18:05:16 | 000,327,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wimserv.exe
[2012/10/02 18:05:16 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsAnytimeUpgradeResults.exe
[2012/10/02 18:05:16 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskraid.exe
[2012/10/02 18:05:16 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qasf.dll
[2012/10/02 18:05:16 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\clusapi.dll
[2012/10/02 18:05:16 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpencom.dll
[2012/10/02 18:05:16 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairingFolder.dll
[2012/10/02 18:05:16 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\perfmon.exe
[2012/10/02 18:05:16 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpshell.dll
[2012/10/02 18:05:16 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nslookup.exe
[2012/10/02 18:05:16 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll
[2012/10/02 18:05:16 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tlscsp.dll
[2012/10/02 18:05:16 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\umb.dll
[2012/10/02 18:05:16 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NAPCRYPT.DLL
[2012/10/02 18:05:16 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\acppage.dll
[2012/10/02 18:05:16 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AzSqlExt.dll
[2012/10/02 18:05:16 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netutils.dll
[2012/10/02 18:05:16 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\muifontsetup.dll
[2012/10/02 18:05:15 | 001,232,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMADMOD.DLL
[2012/10/02 18:05:15 | 001,087,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbghelp.dll
[2012/10/02 18:05:15 | 000,623,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSAPI.dll
[2012/10/02 18:05:15 | 000,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2012/10/02 18:05:15 | 000,337,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\raschap.dll
[2012/10/02 18:05:15 | 000,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\raschap.dll
[2012/10/02 18:05:15 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdwcn.dll
[2012/10/02 18:05:15 | 000,213,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionQueue.dll
[2012/10/02 18:05:15 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\input.dll
[2012/10/02 18:05:15 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpencom.dll
[2012/10/02 18:05:15 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perfmon.exe
[2012/10/02 18:05:15 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\remotepg.dll
[2012/10/02 18:05:15 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wiavideo.dll
[2012/10/02 18:05:15 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QUTIL.DLL
[2012/10/02 18:05:15 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\bfsvc.exe
[2012/10/02 18:05:15 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\runonce.exe
[2012/10/02 18:05:15 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NAPCRYPT.DLL
[2012/10/02 18:05:15 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\syssetup.dll
[2012/10/02 18:05:14 | 001,111,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\onexui.dll
[2012/10/02 18:05:14 | 000,666,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVSDECD.DLL
[2012/10/02 18:05:14 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nltest.exe
[2012/10/02 18:05:14 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpdxm.dll
[2012/10/02 18:05:14 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstask.dll
[2012/10/02 18:05:14 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bitsadmin.exe
[2012/10/02 18:05:14 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iTVData.dll
[2012/10/02 18:05:14 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxdiagn.dll
[2012/10/02 18:05:14 | 000,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpdwcn.dll
[2012/10/02 18:05:14 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsbas.dll
[2012/10/02 18:05:14 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetapi.dll
[2012/10/02 18:05:14 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vdsbas.dll
[2012/10/02 18:05:14 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MdSched.exe
[2012/10/02 18:05:14 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rmcast.sys
[2012/10/02 18:05:14 | 000,133,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Kswdmcap.ax
[2012/10/02 18:05:14 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logagent.exe
[2012/10/02 18:05:14 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UserAccountControlSettings.dll
[2012/10/02 18:05:14 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\runonce.exe
[2012/10/02 18:05:14 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PrintIsolationProxy.dll
[2012/10/02 18:05:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vpnikeapi.dll
[2012/10/02 18:05:13 | 000,527,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmnet.dll
[2012/10/02 18:05:13 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmdev.dll
[2012/10/02 18:05:13 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapp3hst.dll
[2012/10/02 18:05:13 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFPlay.dll
[2012/10/02 18:05:13 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shacct.dll
[2012/10/02 18:05:13 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QSVRMGMT.DLL
[2012/10/02 18:05:13 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shacct.dll
[2012/10/02 18:05:13 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tabcal.exe
[2012/10/02 18:05:13 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vss_ps.dll
[2012/10/02 18:05:13 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscapi.dll
[2012/10/02 18:05:12 | 000,978,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMSPDMOD.DLL
[2012/10/02 18:05:12 | 000,431,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDSp.dll
[2012/10/02 18:05:12 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2012/10/02 18:05:12 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bitsadmin.exe
[2012/10/02 18:05:12 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qcap.dll
[2012/10/02 18:05:12 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2012/10/02 18:05:12 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpshell.dll
[2012/10/02 18:05:12 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe
[2012/10/02 18:05:12 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2012/10/02 18:05:12 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unimdmat.dll
[2012/10/02 18:05:12 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsium.dll
[2012/10/02 18:05:12 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\lsmproxy.dll
[2012/10/02 18:05:11 | 001,160,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OpcServices.dll
[2012/10/02 18:05:11 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Bubbles.scr
[2012/10/02 18:05:11 | 000,435,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceStatus.dll
[2012/10/02 18:05:11 | 000,350,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WPDSp.dll
[2012/10/02 18:05:11 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqlcese30.dll
[2012/10/02 18:05:11 | 000,250,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdv.dll
[2012/10/02 18:05:11 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pdh.dll
[2012/10/02 18:05:11 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceSyncProvider.dll
[2012/10/02 18:05:11 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceSyncProvider.dll
[2012/10/02 18:05:11 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprapi.dll
[2012/10/02 18:05:11 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2012/10/02 18:05:11 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kstvtune.ax
[2012/10/02 18:05:11 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe
[2012/10/02 18:05:11 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spbcd.dll
[2012/10/02 18:05:11 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\olethk32.dll
[2012/10/02 18:05:11 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncryptui.dll
[2012/10/02 18:05:11 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpd3d.dll
[2012/10/02 18:05:10 | 001,148,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10.IME
[2012/10/02 18:05:10 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMADMOD.DLL
[2012/10/02 18:05:10 | 000,541,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVSDECD.DLL
[2012/10/02 18:05:10 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceStatus.dll
[2012/10/02 18:05:10 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2012/10/02 18:05:10 | 000,318,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2012/10/02 18:05:10 | 000,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3ui.dll
[2012/10/02 18:05:10 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mystify.scr
[2012/10/02 18:05:10 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Ribbons.scr
[2012/10/02 18:05:10 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VBICodec.ax
[2012/10/02 18:05:10 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EhStorAPI.dll
[2012/10/02 18:05:10 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\powercfg.cpl
[2012/10/02 18:05:10 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\desk.cpl
[2012/10/02 18:05:10 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fphc.dll
[2012/10/02 18:05:10 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3msm.dll
[2012/10/02 18:05:10 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wiavideo.dll
[2012/10/02 18:05:10 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Kswdmcap.ax
[2012/10/02 18:05:10 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QSVRMGMT.DLL
[2012/10/02 18:05:10 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fphc.dll
[2012/10/02 18:05:10 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll
[2012/10/02 18:05:10 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\amstream.dll
[2012/10/02 18:05:10 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mapistub.dll
[2012/10/02 18:05:10 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\takeown.exe
[2012/10/02 18:05:10 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PnPUnattend.exe
[2012/10/02 18:05:10 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\takeown.exe
[2012/10/02 18:05:10 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2012/10/02 18:05:10 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\utildll.dll
[2012/10/02 18:05:09 | 000,436,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmnet.dll
[2012/10/02 18:05:09 | 000,283,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdv.dll
[2012/10/02 18:05:09 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2012/10/02 18:05:09 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppinst.dll
[2012/10/02 18:05:09 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmstp.exe
[2012/10/02 18:05:09 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QCLIPROV.DLL
[2012/10/02 18:05:09 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QCLIPROV.DLL
[2012/10/02 18:05:09 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertPolEng.dll
[2012/10/02 18:05:09 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cca.dll
[2012/10/02 18:05:09 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WavDest.dll
[2012/10/02 18:05:09 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\djoin.exe
[2012/10/02 18:05:09 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shimgvw.dll
[2012/10/02 18:05:09 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\HotStartUserAgent.dll
[2012/10/02 18:05:09 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nrpsrv.dll
[2012/10/02 18:05:08 | 000,739,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMSPDMOD.DLL
[2012/10/02 18:05:08 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msorcl32.dll
[2012/10/02 18:05:08 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskpart.exe
[2012/10/02 18:05:08 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsicli.exe
[2012/10/02 18:05:08 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mydocs.dll
[2012/10/02 18:05:08 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\desk.cpl
[2012/10/02 18:05:08 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupcln.dll
[2012/10/02 18:05:08 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mobsync.exe
[2012/10/02 18:05:08 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmstp.exe
[2012/10/02 18:05:08 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdProxy.dll
[2012/10/02 18:05:08 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MuiUnattend.exe
[2012/10/02 18:05:08 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\g711codc.ax
[2012/10/02 18:05:08 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vfwwdm32.dll
[2012/10/02 18:05:08 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsnmp32.dll
[2012/10/02 18:05:08 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MultiDigiMon.exe
[2012/10/02 18:05:08 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pdhui.dll
[2012/10/02 18:05:08 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbisurf.ax
[2012/10/02 18:05:08 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\relog.exe
[2012/10/02 18:05:08 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\relog.exe
[2012/10/02 18:05:08 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AzSqlExt.dll
[2012/10/02 18:05:08 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netiougc.exe
[2012/10/02 18:05:08 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BWUnpairElevated.dll
[2012/10/02 18:05:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sscore.dll
[2012/10/02 18:05:07 | 001,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10.IME
[2012/10/02 18:05:07 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2012/10/02 18:05:07 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2012/10/02 18:05:07 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\itircl.dll
[2012/10/02 18:05:07 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\itircl.dll
[2012/10/02 18:05:07 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsicli.exe
[2012/10/02 18:05:07 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mydocs.dll
[2012/10/02 18:05:07 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskpart.exe
[2012/10/02 18:05:07 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3msm.dll
[2012/10/02 18:05:07 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2012/10/02 18:05:07 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2012/10/02 18:05:07 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\resutils.dll
[2012/10/02 18:05:07 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\amstream.dll
[2012/10/02 18:05:07 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastapi.dll
[2012/10/02 18:05:07 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertPolEng.dll
[2012/10/02 18:05:07 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spbcd.dll
[2012/10/02 18:05:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ksxbar.ax
[2012/10/02 18:05:07 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wkscli.dll
[2012/10/02 18:05:07 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdmo.dll
[2012/10/02 18:05:07 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netbtugc.exe
[2012/10/02 18:05:07 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\syssetup.dll
[2012/10/02 18:05:06 | 001,080,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\onexui.dll
[2012/10/02 18:05:06 | 000,434,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSTIFF.dll
[2012/10/02 18:05:06 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2012/10/02 18:05:06 | 000,278,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2012/10/02 18:05:06 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll
[2012/10/02 18:05:06 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpps.dll
[2012/10/02 18:05:06 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappgnui.dll
[2012/10/02 18:05:06 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappgnui.dll
[2012/10/02 18:05:06 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\findstr.exe
[2012/10/02 18:05:06 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tlscsp.dll
[2012/10/02 18:05:06 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\findstr.exe
[2012/10/02 18:05:06 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\luainstall.dll
[2012/10/02 18:05:06 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mciqtz32.dll
[2012/10/02 18:05:06 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\choice.exe
[2012/10/02 18:05:06 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciqtz32.dll
[2012/10/02 18:05:06 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2012/10/02 18:05:06 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFaultSecure.exe
[2012/10/02 18:05:06 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReAgentc.exe
[2012/10/02 18:05:05 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppc.dll
[2012/10/02 18:05:05 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mobsync.exe
[2012/10/02 18:05:05 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll
[2012/10/02 18:05:05 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\manage-bde.exe
[2012/10/02 18:05:05 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetmib1.dll
[2012/10/02 18:05:05 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\repair-bde.exe
[2012/10/02 18:05:05 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdiasqmmodule.dll
[2012/10/02 18:05:05 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schedcli.dll
[2012/10/02 18:05:05 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spopk.dll
[2012/10/02 18:05:05 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll
[2012/10/02 18:05:04 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RDPENCDD.dll
[2012/10/02 18:05:04 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbcconf.dll
[2012/10/02 18:05:04 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\luainstall.dll
[2012/10/02 18:05:04 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shimgvw.dll
[2012/10/02 18:05:04 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unlodctr.exe
[2012/10/02 18:05:04 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbisurf.ax
[2012/10/02 18:05:04 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdmo.dll
[2012/10/02 18:05:04 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spopk.dll
[2012/10/02 18:05:03 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIRibbonRes.dll
[2012/10/02 18:05:03 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIRibbonRes.dll
[2012/10/02 18:05:03 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetmib1.dll
[2012/10/02 18:05:03 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\g711codc.ax
[2012/10/02 18:05:03 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSMON.dll
[2012/10/02 18:05:03 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcconf.dll
[2012/10/02 18:05:03 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll
[2012/10/02 18:05:03 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tdi.sys
[2012/10/02 18:05:03 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elsTrans.dll
[2012/10/02 18:05:03 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TRAPI.dll
[2012/10/02 18:05:03 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdprefdrvapi.dll
[2012/10/02 18:05:03 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fixmapi.exe
[2012/10/02 18:05:02 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\napdsnap.dll
[2012/10/02 18:05:02 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\napdsnap.dll
[2012/10/02 18:05:02 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dsauth.dll
[2012/10/02 18:05:02 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbrpm.sys
[2012/10/02 18:05:02 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsauth.dll
[2012/10/02 18:05:02 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscdll.dll
[2012/10/02 18:05:02 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LogonUI.exe
[2012/10/02 18:05:02 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bitsperf.dll
[2012/10/02 18:05:02 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdprefdrvapi.dll
[2012/10/02 18:05:02 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elsTrans.dll
[2012/10/02 18:05:02 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TRAPI.dll
[2012/10/02 18:05:02 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bitsperf.dll
[2012/10/02 18:05:02 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSUNATD.exe
[2012/10/02 18:05:02 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schedcli.dll
[2012/10/02 18:05:02 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perfts.dll
[2012/10/02 18:05:01 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imkr80.ime
[2012/10/02 18:05:01 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imkr80.ime
[2012/10/02 18:05:01 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shgina.dll
[2012/10/02 18:05:01 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsdchngr.dll
[2012/10/02 18:05:01 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsdchngr.dll
[2012/10/02 18:05:01 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shgina.dll
[2012/10/02 18:05:01 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sscore.dll
[2012/10/02 18:05:01 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\riched32.dll
[2012/10/02 18:05:00 | 000,032,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBCAMD2.sys
[2012/10/02 18:05:00 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshirda.dll
[2012/10/02 18:05:00 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshirda.dll
[2012/10/02 18:05:00 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\riched32.dll
[2012/10/02 18:05:00 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcfgex.dll
[2012/10/02 18:04:59 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\C_ISCII.DLL
[2012/10/02 18:04:59 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\C_ISCII.DLL
[2012/10/02 18:04:59 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
[2012/10/02 18:04:59 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
[2012/10/02 18:04:59 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
[2012/10/02 18:04:59 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
[2012/10/02 18:04:58 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2012/10/02 18:04:58 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2012/10/02 18:04:58 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shunimpl.dll
[2012/10/02 18:04:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTUQ.DLL
[2012/10/02 18:04:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTUF.DLL
[2012/10/02 18:04:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDSG.DLL
[2012/10/02 18:04:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kbdlk41a.dll
[2012/10/02 18:04:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDGKL.DLL
[2012/10/02 18:04:58 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDCZ1.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTUQ.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTUF.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDSG.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDSF.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDPO.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDNEPR.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kbdlk41a.dll
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINTAM.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINBEN.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDGR1.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDGR1.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDGKL.DLL
[2012/10/02 18:04:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDCZ1.DLL
[2012/10/02 18:04:58 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINHIN.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDUS.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTURME.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTAJIK.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDMON.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINTEL.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDGEO.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDGEO.DLL
[2012/10/02 18:04:58 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBLR.DLL
[2012/10/02 18:04:58 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
[2012/10/02 18:04:58 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
[2012/10/02 18:04:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-ums-l1-1-0.dll
[2012/10/02 18:04:57 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nlsbres.dll
[2012/10/02 18:04:57 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nlsbres.dll
[2012/10/02 18:04:57 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BlbEvents.dll
[2012/10/02 18:04:57 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pifmgr.dll
[2012/10/02 18:04:57 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pifmgr.dll
[2012/10/02 18:04:57 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwizres.dll
[2012/10/02 18:04:57 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizres.dll
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDUS.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDUGHR1.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTURME.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTAJIK.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDSF.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDPO.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDNEPR.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDMON.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDMAORI.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDLT1.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINTEL.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINTAM.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINORI.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINORI.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINMAR.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINMAR.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINKAN.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINKAN.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINHIN.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINBEN.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBULG.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBLR.DLL
[2012/10/02 18:04:57 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBASH.DLL
[2012/10/02 18:04:57 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDUGHR1.DLL
[2012/10/02 18:04:57 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDMAORI.DLL
[2012/10/02 18:04:57 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDLT1.DLL
[2012/10/02 18:04:57 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBULG.DLL
[2012/10/02 18:04:57 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBASH.DLL
[2012/10/02 18:04:57 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpnaddr.dll
[2012/10/02 18:04:57 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpnaddr.dll
[2012/10/02 18:04:53 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpx.dll
[2012/10/02 18:04:53 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdscore.dll
[2012/10/02 18:04:49 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqmapi.dll
[2012/10/02 18:04:00 | 000,529,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wbemcomn.dll
[2012/10/02 18:03:54 | 000,244,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqmapi.dll
[2012/10/02 17:48:31 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2012/10/02 17:48:31 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2012/10/02 17:48:31 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2012/10/02 17:48:30 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fsquirt.exe
[2012/10/02 17:48:30 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2012/10/02 17:48:30 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2012/10/02 17:48:30 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2012/10/02 17:48:29 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2012/10/02 17:48:29 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2012/10/02 17:48:29 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2012/10/02 17:48:26 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
[2012/10/02 17:48:26 | 000,007,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys
[2012/10/02 17:48:19 | 002,565,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\esent.dll
[2012/10/02 17:48:19 | 001,699,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\esent.dll
[2012/10/02 17:48:19 | 000,189,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys
[2012/10/02 17:48:19 | 000,107,904 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdsata.sys
[2012/10/02 17:48:19 | 000,027,008 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdxata.sys
[2012/10/02 17:48:18 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fsutil.exe
[2012/10/02 17:48:18 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fsutil.exe
[2012/10/02 17:48:05 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2012/09/29 13:51:54 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\{AAAC16C6-4CEC-4CF1-B13B-3D7B00ED1B3E}
[2012/09/25 04:10:26 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Roaming\.techniclauncher
[2012/09/23 06:31:02 | 000,000,000 | ---D | C] -- C:\Users\RICK\AppData\Local\{D4F878CA-E7BB-4BBE-BE1E-D82545DF31C2}
[2012/09/22 04:56:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/09/22 04:56:23 | 000,095,208 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2012/11/18 16:32:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/18 14:32:21 | 000,013,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/18 14:32:21 | 000,013,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/18 14:25:41 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/18 14:24:37 | 000,318,824 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/18 14:24:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/18 14:20:46 | 000,887,666 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/18 14:20:46 | 000,726,942 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/18 14:20:46 | 000,146,670 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/17 13:54:12 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/11/17 09:49:23 | 000,000,219 | ---- | M] () -- C:\Users\RICK\Desktop\Portal 2.url
[2012/11/16 23:09:23 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/16 23:09:23 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/16 18:54:56 | 000,001,392 | RHS- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/11/16 15:35:06 | 000,000,218 | ---- | M] () -- C:\Users\RICK\AppData\Local\recently-used.xbel
[2012/11/14 17:32:20 | 000,000,591 | ---- | M] () -- C:\Users\RICK\Desktop\WampServer.lnk
[2012/10/30 18:50:30 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012/10/29 22:03:24 | 000,000,934 | ---- | M] () -- C:\Users\Public\Desktop\Guild Wars 2.lnk
[2012/10/29 17:08:07 | 531,951,660 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/10/24 11:20:47 | 007,075,014 | ---- | M] () -- C:\Users\RICK\Documents\Referance_Manual.pdf
[2012/10/13 04:57:21 | 000,007,592 | ---- | M] () -- C:\Users\RICK\AppData\Local\Resmon.ResmonCfg
[2012/10/09 13:17:13 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
[2012/10/09 13:17:13 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
[2012/10/09 12:40:31 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
[2012/10/08 06:31:03 | 002,312,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/10/08 06:22:55 | 001,494,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/10/08 06:22:17 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/10/08 06:18:22 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/10/08 06:17:35 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/10/08 06:17:26 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/10/08 06:15:59 | 000,729,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/10/08 06:13:54 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/10/08 06:09:39 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/10/08 02:47:44 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/10/08 02:46:32 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/10/08 02:44:05 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/10/08 02:43:05 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/10/08 02:41:19 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/10/08 02:37:23 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/10/03 12:44:17 | 000,246,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
[2012/10/03 12:44:17 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2012/10/03 12:44:16 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
[2012/10/03 11:42:24 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
[2012/10/03 11:42:24 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2012/10/03 11:42:23 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2012/10/02 18:24:37 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll
[2012/10/02 18:24:36 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll
[2012/09/29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/29 14:10:28 | 338,797,633 | ---- | M] () -- C:\Users\RICK\Documents\Automated_Processing_Center.wmv
[2012/09/27 11:10:01 | 003,438,017 | ---- | M] () -- C:\Users\RICK\Documents\475_Man_RevB_19Nov2009_1007.pdf
[2012/09/25 17:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
[2012/09/25 17:46:17 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
[2012/09/23 06:39:38 | 163,089,861 | ---- | M] () -- C:\Users\RICK\Documents\New_Tekkit_Base_No_EE.wmv
[2012/09/22 04:56:20 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2012/09/22 04:56:20 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2012/09/22 04:56:20 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2012/09/22 04:56:20 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2012/09/22 04:56:20 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2012/09/22 04:56:20 | 000,095,208 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/18 14:18:49 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/18 14:11:19 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/17 13:54:12 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012/11/17 09:49:23 | 000,000,219 | ---- | C] () -- C:\Users\RICK\Desktop\Portal 2.url
[2012/11/16 15:35:06 | 000,000,218 | ---- | C] () -- C:\Users\RICK\AppData\Local\recently-used.xbel
[2012/11/14 17:32:20 | 000,000,591 | ---- | C] () -- C:\Users\RICK\Desktop\WampServer.lnk
[2012/10/29 22:03:24 | 000,000,934 | ---- | C] () -- C:\Users\Public\Desktop\Guild Wars 2.lnk
[2012/10/24 11:20:47 | 007,075,014 | ---- | C] () -- C:\Users\RICK\Documents\Referance_Manual.pdf
[2012/10/13 04:57:21 | 000,007,592 | ---- | C] () -- C:\Users\RICK\AppData\Local\Resmon.ResmonCfg
[2012/10/02 18:06:19 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2012/10/02 18:05:06 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2012/10/02 18:04:56 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2012/10/02 18:04:56 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2012/10/02 18:04:49 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2012/09/29 14:05:35 | 338,797,633 | ---- | C] () -- C:\Users\RICK\Documents\Automated_Processing_Center.wmv
[2012/09/27 11:09:59 | 003,438,017 | ---- | C] () -- C:\Users\RICK\Documents\475_Man_RevB_19Nov2009_1007.pdf
[2012/09/23 06:37:28 | 163,089,861 | ---- | C] () -- C:\Users\RICK\Documents\New_Tekkit_Base_No_EE.wmv
[2012/07/08 14:48:22 | 000,000,111 | ---- | C] () -- C:\Users\RICK\.gitconfig
[2012/04/29 19:43:28 | 000,037,607 | ---- | C] () -- C:\Program Files (x86)\Common Files\license.rtf
[2012/04/29 19:43:28 | 000,008,046 | ---- | C] () -- C:\Program Files (x86)\Common Files\setupBanner.jpg
[2012/04/25 15:43:42 | 000,025,069 | ---- | C] () -- C:\Users\RICK\AppData\Local\Temp17.html
[2012/02/16 16:43:32 | 000,000,005 | ---- | C] () -- C:\Users\RICK\.jline-jython.history
[2012/01/23 21:26:17 | 000,001,955 | ---- | C] () -- C:\Users\RICK\AppData\Local\Temp1.html
[2012/01/14 07:35:45 | 000,000,830 | ---- | C] () -- C:\Windows\eReg.dat
[2012/01/09 12:52:35 | 000,000,043 | ---- | C] () -- C:\Users\RICK\jagex_cl_runescape_LIVE.dat
[2012/01/09 12:52:35 | 000,000,024 | ---- | C] () -- C:\Users\RICK\random.dat
[2011/12/23 02:28:57 | 000,061,923 | ---- | C] () -- C:\Users\RICK\Raycasting.html
[2011/11/24 03:42:59 | 000,000,087 | ---- | C] () -- C:\Users\RICK\StencylWorks.prefs
[2011/10/27 23:43:04 | 000,016,056 | ---- | C] () -- C:\Windows\ips.INI
[2011/09/05 13:42:03 | 000,003,584 | ---- | C] () -- C:\Users\RICK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/31 12:51:16 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/08/31 12:51:16 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/08/31 12:51:16 | 000,105,608 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/08/31 12:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/07/21 12:04:27 | 000,000,034 | ---- | C] () -- C:\Windows\Q3version.ini
[2011/07/21 11:59:06 | 000,000,927 | ---- | C] () -- C:\Windows\Qiii.INI
[2011/05/11 15:40:21 | 000,773,572 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/05 14:30:24 | 000,000,096 | ---- | C] () -- C:\Windows\LaunApp.ini
[2011/03/05 14:30:22 | 000,000,033 | ---- | C] () -- C:\Windows\DELL_OSTYPE.ini
[2011/03/05 14:30:22 | 000,000,023 | ---- | C] () -- C:\Windows\WisSysInfo.ini
[2011/03/05 14:30:21 | 000,000,271 | ---- | C] () -- C:\Windows\WisPriority.ini
[2011/03/05 14:30:21 | 000,000,035 | ---- | C] () -- C:\Windows\DELL_LANGCODE.ini
[2011/03/05 14:30:21 | 000,000,032 | ---- | C] () -- C:\Windows\WisHWDest.ini
[2011/03/05 14:30:21 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2011/03/05 13:09:55 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2010/12/09 19:33:11 | 000,000,325 | ---- | C] () -- C:\Windows\Prelaunch.ini

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 1250 bytes -> C:\Users\RICK\AppData\Local\Temp:rxbYQz7J1qY972ExytS

< End of report >

[b]===============Extras===============[/b]

OTL Extras logfile created on: 11/18/2012 5:21:46 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\RICK\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 48.89% Memory free
7.61 Gb Paging File | 5.60 Gb Available in Paging File | 73.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.42 Gb Total Space | 459.26 Gb Free Space | 78.99% Space Free | Partition Type: NTFS

Computer Name: COMPUTER | User Name: RICK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = bfjsfile] -- C:\Program Files (x86)\Bluefish\bluefish.exe (The Bluefish Developers)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = bfjsfile] -- C:\Program Files (x86)\Bluefish\bluefish.exe (The Bluefish Developers)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{463A9B3A-96D9-407F-A78F-559581531F1E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{649922D1-F167-4CD0-8067-60FCE98E507F}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0448C0B9-E4AF-441E-A4BD-EEE068E680BD}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{09DC2FD6-E920-4FB9-BD69-40CE881CB6B5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\quake 2\quake2.exe |
"{0B9AE704-7DFC-4598-9538-F9FEC3C60353}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{0BC61CB6-8E47-4509-BFCC-B3C27F15281B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto vice city\gta-vc.exe |
"{165B227D-90CD-4173-9806-4782B835ACB2}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{22D81B55-2C32-4E9F-BAE3-4C859F18A7E9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5\bina1\testapp.exe |
"{22EC8AA5-5F0B-41FB-B477-3C96B420BCA5}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |
"{3B1E3B79-64E3-4341-8CF1-53FB528C6DE7}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{3B9C73FF-7BFD-4CA5-9FB6-52092A737749}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{3D7890A1-277F-4D75-9EFB-9F5D633CF054}" = protocol=6 | dir=in | app=c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe |
"{3E780A73-AFA4-4F1A-A5F9-88ED365D752B}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{401D1A4E-9AD6-47AE-B60A-079261A977B2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{4BD57CAE-012B-4B81-BCBF-E03279EFDF4B}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{5F788848-CD49-4688-9BC3-9D321283AD13}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5\bin\h5_game.exe |
"{629F0D7B-B14F-4692-91EB-33548141B9B5}" = protocol=17 | dir=in | app=c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe |
"{6433D8C3-D0A9-4182-A429-B94A8859F8D1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto vice city\gta-vc.exe |
"{6ACEDDAE-786D-479C-B708-58EB4541039D}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{70F8BF2C-3D89-400E-BC74-2314CFD9AA98}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |
"{7381F2E9-14C9-4FCB-9B15-3783AF60237F}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{738C4B51-AB09-4B19-9DD0-D995AF7F9C58}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{76F701BB-2011-4E76-8C4B-338E5E4F9983}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5\bin\h5_game.exe |
"{7CB8BC23-A67F-45F2-8525-4C74C61E1072}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{7FD98707-D0F9-446B-9CDC-A2FB8FA2C44B}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{8BF25353-405A-410C-A600-F1E4F6C8A232}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe |
"{8D687095-A0E6-4E20-880F-4399EBA504FE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_game.exe |
"{8E09037F-8126-4BCD-954B-5FEE7024D8B7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{A52D65BB-31C0-490C-B858-5D5E510E7B80}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{A8677778-7117-4CB6-B551-087629EE825E}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{B2178D8A-FCAB-44CE-8276-5CB195C44A1A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5\bina1\testapp.exe |
"{B4C2D5C8-9941-4F6B-87B1-2A12B738E214}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{B68A0D97-3610-4878-B027-127202DA00AB}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{B8DF3D28-59F3-48C1-B273-EF5374E50364}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\quake 2\quake2.exe |
"{BE98B51A-F1BD-4FB9-A549-01898E32D09B}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{DC86D24D-9713-41A5-A959-56BD1F8ADCE0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{DD3D8932-1305-4E4A-A758-018200FA4E8C}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{E472BF1F-587D-4E6D-928A-4D10A88102C4}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{F5BF8EAC-A200-41CD-943C-9506769998FB}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{F735FEAC-38EE-44FC-B428-A582813B8942}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5 tribes of the east\bin\h5_game.exe |
"TCP Query User{02EE7614-81EF-4EFC-BA9C-B9BAD77A1C27}C:\python32\pythonw.exe" = protocol=6 | dir=in | app=c:\python32\pythonw.exe |
"TCP Query User{17F8A488-3FEB-4FB5-8A2D-8C24E4DDDF08}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{20F04AAD-ACD2-4116-9656-02B92CD8E90C}C:\program files\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\java.exe |
"TCP Query User{216DFCB0-EFDA-43EE-8D01-D2EAAF6FB9CC}C:\wamp\www\python\python.exe" = protocol=6 | dir=in | app=c:\wamp\www\python\python.exe |
"TCP Query User{286FD92D-5333-4830-A57D-B93AE1736874}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{29EF5E05-9ED4-48FD-9235-87B32FD3F578}C:\program files (x86)\quake iii arena\quake3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\quake iii arena\quake3.exe |
"TCP Query User{33E4CA3C-A8BB-4193-8EBF-6A705B5B9558}C:\users\rick\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\rick\appdata\local\temp\gw2.exe |
"TCP Query User{46E5B832-23E4-4E78-ADFE-724E44F2F297}C:\python32\python.exe" = protocol=6 | dir=in | app=c:\python32\python.exe |
"TCP Query User{687A4242-B6D2-43F5-8467-894A12839834}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{81B2EA72-5C11-4BEA-B9C3-CBF2C80BA18E}C:\wamp\bin\apache\apache2.2.22\bin\httpd.exe" = protocol=6 | dir=in | app=c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe |
"TCP Query User{959B798E-03E3-4FCA-8720-A555307F4554}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe |
"TCP Query User{9F9BDB1E-A0C8-41A0-9F08-2A0A618A2CB5}C:\python27\python.exe" = protocol=6 | dir=in | app=c:\python27\python.exe |
"TCP Query User{A2EB0038-2BFF-403B-AD21-3343E79AEBBF}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"TCP Query User{B66E04C0-FF18-47F3-B458-21700ED5525D}C:\program files (x86)\jetbrains\phpstorm 5.0.3\bin\phpstorm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jetbrains\phpstorm 5.0.3\bin\phpstorm.exe |
"TCP Query User{BC50595E-8D98-46A2-94FE-557367B2FA51}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe |
"TCP Query User{D80AC6D5-A067-4734-8A74-16EF0DC90CD0}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"TCP Query User{F6D618E6-193C-4046-AE09-B6350BCE9B93}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe |
"UDP Query User{072F3E1D-3224-46CA-99BB-8AFB52C3F6C0}C:\wamp\bin\apache\apache2.2.22\bin\httpd.exe" = protocol=17 | dir=in | app=c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe |
"UDP Query User{1412B99A-189D-427E-ADAE-5FE33AFB7B0E}C:\wamp\www\python\python.exe" = protocol=17 | dir=in | app=c:\wamp\www\python\python.exe |
"UDP Query User{2876924A-75B7-4BD6-B581-F2DAE63F1457}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe |
"UDP Query User{391FAC3B-9D74-4293-A133-F56B824BFE82}C:\program files (x86)\jetbrains\phpstorm 5.0.3\bin\phpstorm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jetbrains\phpstorm 5.0.3\bin\phpstorm.exe |
"UDP Query User{43244307-E6F5-4DD0-B7AC-1FD104863BCA}C:\python27\python.exe" = protocol=17 | dir=in | app=c:\python27\python.exe |
"UDP Query User{533CEA4F-36CE-4D0A-BAC6-AC1F4BB69E68}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe |
"UDP Query User{5CDC366E-2DAF-4A10-A16A-8BBE417CFE36}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{637C28E5-5B55-4BE6-9A56-880D7410BCC9}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe |
"UDP Query User{6BC64F5B-1E38-419D-A8DE-693134EE34D5}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{7A08ABC2-65EB-46B6-8872-B4CEF1A61AD6}C:\program files\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\java.exe |
"UDP Query User{973145A5-3190-47BA-848D-65DA5272B9FF}C:\python32\pythonw.exe" = protocol=17 | dir=in | app=c:\python32\pythonw.exe |
"UDP Query User{A0493F01-E5E4-4C06-9E64-4EECB76A7636}C:\users\rick\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\rick\appdata\local\temp\gw2.exe |
"UDP Query User{A2915190-9F58-4A90-9BE6-74335C2C03FD}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{A5ECF0E1-37C5-4938-8CAC-C59A426BCEC7}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"UDP Query User{B7920FBD-F8AF-4743-B6D3-DF39B8275D68}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"UDP Query User{D01FD899-66A7-40ED-BC78-BC905ACA2AEC}C:\python32\python.exe" = protocol=17 | dir=in | app=c:\python32\python.exe |
"UDP Query User{D181DC84-1916-48BF-8024-A235F6BE1AFD}C:\program files (x86)\quake iii arena\quake3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\quake iii arena\quake3.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{1111706F-666A-4037-7777-202648764D10}" = JavaFX 2.0.2 (64-bit)
"{183C740A-0406-380F-A235-2EC2F8A28D13}" = Microsoft Windows SDK MSHelp (30514)
"{1A8BA6CE-822D-4888-89E2-ACBF4308F271}" = Intel® PROSet/Wireless WiFi Software
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{2222706F-666A-4037-7777-202648764D10}" = JavaFX 2.0.2 SDK (64-bit)
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java™ 6 Update 23 (64-bit)
"{26A24AE4-039D-4CA4-87B4-2F86417002FF}" = Java™ 7 Update 2 (64-bit)
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{3156336D-8E44-3671-A6FE-AE51D3D6564E}" = Microsoft Windows SDK for Windows 7 (7.1)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5B0E60DB-7741-412F-88B3-E6975D30D019}" = Visual C++ 64-bit Redistributables
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64A3A4F4-B792-11D6-A78A-00B0D0170020}" = Java™ SE Development Kit 7 Update 2 (64-bit)
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{68570626-1BF6-310B-AF69-6CD686C04AEA}" = Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514)
"{6C8D7973-31F9-32E1-A820-8DD857910323}" = Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514)
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{84452C2C-BDCC-36F3-A189-CE15F02A47FB}" = Microsoft Windows SDK for Windows 7 Headers and Libraries (30514)
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{84E30D73-E30F-3A02-BAA0-5353C04DD18A}" = Microsoft Windows SDK Intellisense and Reference Assemblies (30514)
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{88387B3B-B110-392F-B919-1A15B48F21D4}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x64
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89026002-A893-42D9-9E20-6829B844735E}" = Application Verifier (x64)
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{94D70749-4281-39AC-AD90-B56A0E0A402E}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{951E6223-AC28-345E-BCF4-B55C1267E321}" = Microsoft Windows SDK for Windows 7 Samples (30514)
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A0B0F02C-410B-3DE3-9740-EC4C3D902532}" = Microsoft Windows SDK for Windows 7 Common Utilities (30514)
"{A2C55034-8DAF-3755-BA85-CC321707FE99}" = Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files
"{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}" = Microsoft SQL Server 2008 Native Client
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DBFC6AAE-DCCB-4C23-B01C-3EDDDC03298B}" = Debugging Tools for Windows (x64)
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E7F9E526-2324-437B-A609-E8C5309465CB}" = Microsoft Windows Performance Toolkit
"{F1C4B89A-8BF0-3D7C-8095-BAE412FBEA3F}" = Microsoft Windows SDK .NET Framework Tools (30514)
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"AF09E130E2FD4D1BEFD1B9132AE624BAE0364719" = Windows Driver Package - Broadcom Corporation (BTHUSB) Bluetooth (03/24/2010 6.3.0.2501)
"camcodec" = CamStudio Lossless Codec
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"nbi-nb-base-7.0.1.0.0" = NetBeans IDE 7.0.1
"ProInst" = Intel PROSet Wireless
"Recuva" = Recuva
"SDKSetup_7.1.7600.0.30514" = Microsoft Windows SDK for Windows 7 (7.1)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WhoCrashed_is1" = WhoCrashed 3.03

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{0728A653-2517-4562-BB30-D8D8E74C9D4B}" = Python 2.7 pygame-1.9.2a0
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{181E1175-1FF8-4EA5-BC08-A7CA39B85502}_is1" = Free MIDI to MP3 Converter 1.0
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E523987-412E-496E-8310-0A7A7E971E5E}" = Python 2.7 cx_Freeze-4.3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A0F2CC5-3065-492C-8380-B03AA7106B1A}" = Dell Product Registration
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2DA5F129-11AC-4F11-8188-B2F07EAAC20A}" = Cozi
"{2E295B5B-1AD4-4d36-97C2-A316084722CF}" = Python 2.7.2
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3544DED1-07DB-40C0-98F3-435A6DA195C7}" = Google SketchUp 8
"{370187B9-6964-38D0-851F-6C4898B0C2B1}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59F24743-2EA1-3A45-B8C2-6E0E1E078FA8}" = Microsoft Visual C# 2010 Express - ENU
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65AA5B18-A330-4F35-BCDF-EA85EC888906}" = AVOX Evo VST
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{67903736-E9BB-4664-B148-F62BCAB4FA42}_is1" = OpenMPT 1.19
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7D66971C-652B-4065-A6B1-B3EE313C254B}" = BlueJ
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7E64B067-2EF5-4CC0-9CA9-06589057983D}" = Capitalism II
"{7EAEB757-4D63-481C-9765-F2F55D76A869}" = Anvil Studio 2012
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C4504A1-9280-11D5-9F7E-00902712427E}" = Sid Meier's SimGolf
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA31EA7B-7917-4000-949B-38E91F848A25}" = Internet Explorer
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}" = Dell Home Systems Service Agreement
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C2AF7B2D-7018-414B-9B8B-D3C9F3BED04F}" = Visual C++ Redistributables
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{CCF89E7D-8BFC-4B3C-8C9C-8C4E9EF8BA45}" = Auto-Tune EFX VST
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E4197D6B-F046-33E7-ABDE-51FF373FDC76}" = Windows SDK IntellisenseNFX
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EFE3D683-903C-4B58-AB8F-C68C69F33758}" = System Requirements Lab for Intel
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FFF74EC9-1FF4-4456-99E3-4F05129F4FAB}" = Antares Auto-Tune Evo VST
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Audacity_is1" = Audacity 2.0
"BitTorrent" = BitTorrent
"Bluefish" = Bluefish 2.2.1
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"Dell Dock" = Dell Dock
"Dell Webcam Central" = Dell Webcam Central
"Dungeon Keeper II" = Dungeon Keeper 2
"FBReader for Windows" = FBReader for Windows
"FLV Player2.0.25" = FLV Player
"Fotosizer" = Fotosizer 1.34
"Fraps" = Fraps (remove only)
"GenTex" = GenTex
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"Guild Wars 2" = Guild Wars 2
"Imagelys Picture Styles 7.4.5" = Imagelys Picture Styles 7.4.5
"Install Creator" = Install Creator
"InstallShield_{5B0E60DB-7741-412F-88B3-E6975D30D019}" = Visual C++ 64-bit Redistributables
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft Visual C# 2010 Express - ENU" = Microsoft Visual C# 2010 Express - ENU
"Motocross Madness 2" = Microsoft Motocross Madness 2
"Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MS Access 97 SP2" = MS Access 97 SP2
"Notepad++" = Notepad++
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PandoraRecovery" = PandoraRecovery (Remove Only)
"PyScripter_is1" = PyScripter 2.5.3
"Quake III Arena" = Quake III Arena
"RollerCoaster Tycoon Deluxe_is1" = RollerCoaster Tycoon Deluxe
"SONARX1LE_is1" = SONAR X1 LE
"Steam App 105600" = Terraria
"Steam App 12110" = Grand Theft Auto: Vice City
"Steam App 15170" = Heroes of Might and Magic V
"Steam App 15370" = Heroes of Might and Magic V: Tribes of the East
"Steam App 15380" = Heroes of Might and Magic V: Hammers of Fate
"Steam App 2100" = Dark Messiah Might and Magic Single Player
"Steam App 211" = Source SDK
"Steam App 220" = Half-Life 2
"Steam App 2320" = Quake II
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 620" = Portal 2
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 2.0.3
"WampServer 2_is1" = WampServer 2.2
"WebRipper" = WebRipper 1.31
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"py2exe-py2.7" = Python 2.7 py2exe-0.6.9
"Qt SDK" = Qt SDK

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/13/2012 2:13:08 AM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 11/13/2012 6:58:59 PM | Computer Name = Computer | Source = Application Error | ID = 1000
Description = Faulting application name: hl2.exe, version: 0.0.0.0, time stamp:
0x4c525184 Faulting module name: vstdlib.dll, version: 0.0.0.0, time stamp: 0x4c6ca968
Exception
code: 0xc0000005 Fault offset: 0x0000204e Faulting process id: 0x12c Faulting application
start time: 0x01cdc1e0127aabe1 Faulting application path: c:\program files (x86)\steam\steamapps\rls0812\half-life
2 episode two\hl2.exe Faulting module path: c:\program files (x86)\steam\steamapps\rls0812\half-life
2 episode two\bin\vstdlib.dll Report Id: b507aaa1-2de5-11e2-aa02-889ffab8db24

Error - 11/13/2012 11:04:57 PM | Computer Name = Computer | Source = Application Hang | ID = 1002
Description = The program steam.exe version 1.0.1446.623 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 105c Start
Time: 01cdc1f29b28a04c Termination Time: 115 Application Path: C:\Program Files (x86)\Steam\steam.exe

Report
Id: 0f9f84de-2e08-11e2-aa02-889ffab8db24

Error - 11/14/2012 3:28:07 AM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 11/15/2012 1:48:36 AM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 11/17/2012 1:54:23 AM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 11/17/2012 11:12:35 AM | Computer Name = Computer | Source = Application Hang | ID = 1002
Description = The program hl2.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 4d8 Start Time:
01cdc4d5e8ff60e7 Termination Time: 15 Application Path: c:\program files (x86)\steam\steamapps\rls0812\portal\hl2.exe

Report
Id: 3047fe07-30c9-11e2-aab6-889ffab8db24

Error - 11/17/2012 7:18:43 PM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 11/17/2012 7:18:43 PM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 11/18/2012 1:32:15 AM | Computer Name = Computer | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
Express\CoziExpress.exe".Error in manifest or policy file "" on line . A component
version required by the application conflicts with another component version already
active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ Media Center Events ]
Error - 9/29/2012 8:18:50 AM | Computer Name = Computer | Source = MCUpdate | ID = 0
Description = 8:18:50 AM - Error connecting to the internet. 8:18:50 AM - Unable
to contact server..

Error - 11/8/2012 10:09:26 AM | Computer Name = Computer | Source = MCUpdate | ID = 0
Description = 9:09:26 AM - Error connecting to the internet. 9:09:26 AM - Unable
to contact server..

Error - 11/8/2012 11:09:31 AM | Computer Name = Computer | Source = MCUpdate | ID = 0
Description = 10:09:31 AM - Error connecting to the internet. 10:09:31 AM - Unable
to contact server..

Error - 11/8/2012 12:09:36 PM | Computer Name = Computer | Source = MCUpdate | ID = 0
Description = 11:09:36 AM - Error connecting to the internet. 11:09:36 AM - Unable
to contact server..

Error - 11/8/2012 1:09:41 PM | Computer Name = Computer | Source = MCUpdate | ID = 0
Description = 12:09:41 PM - Error connecting to the internet. 12:09:41 PM - Unable
to contact server..

[ System Events ]
Error - 11/11/2012 3:22:41 PM | Computer Name = Computer | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 11/11/2012 3:22:41 PM | Computer Name = Computer | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 11/17/2012 12:04:56 AM | Computer Name = Computer | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 11/17/2012 12:06:06 AM | Computer Name = Computer | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 11/17/2012 12:06:17 AM | Computer Name = Computer | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 11/17/2012 12:06:36 AM | Computer Name = Computer | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the SQL
Server (SQLEXPRESS) service to connect.

Error - 11/17/2012 12:06:36 AM | Computer Name = Computer | Source = Service Control Manager | ID = 7000
Description = The SQL Server (SQLEXPRESS) service failed to start due to the following
error: %%1053

Error - 11/17/2012 12:10:52 AM | Computer Name = Computer | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10003
Description = WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\IWMSSvc.dll


Error - 11/18/2012 2:47:45 PM | Computer Name = Computer | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SBRE

Error - 11/18/2012 3:25:04 PM | Computer Name = Computer | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SBRE


< End of report >

[b]==========aswMBR==========[/b]

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-11-18 17:31:48
-----------------------------
17:31:48.369 OS Version: Windows x64 6.1.7601 Service Pack 1
17:31:48.369 Number of processors: 4 586 0x2505
17:31:48.369 ComputerName: COMPUTER UserName: RICK
17:31:49.118 Initialize success
17:32:00.170 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
17:32:00.170 Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 610480MB BusType: 3
17:32:00.185 Disk 0 MBR read successfully
17:32:00.185 Disk 0 MBR scan
17:32:00.201 Disk 0 Windows 7 default MBR code
17:32:00.201 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
17:32:00.248 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
17:32:00.248 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 595378 MB offset 30926848
17:32:00.263 Disk 0 scanning C:\Windows\system32\drivers
17:32:07.954 Service scanning
17:32:25.239 Modules scanning
17:32:25.239 Disk 0 trace - called modules:
17:32:25.270 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
17:32:25.270 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bb7060]
17:32:25.286 3 CLASSPNP.SYS[fffff88001b7143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004946050]
17:32:25.286 Scan finished successfully
17:32:33.117 Disk 0 MBR has been saved successfully to "C:\Users\RICK\Downloads\MBR.dat"
17:32:33.117 The log file has been saved successfully to "C:\Users\RICK\Downloads\aswMBR.txt"
  • 0

#4
RPMcMurphy

RPMcMurphy

    Trusted Helper

  • Malware Removal
  • 930 posts
Please do this next:

Posted Image Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    @Alternate Data Stream - 1250 bytes -> C:\Users\RICK\AppData\Local\Temp:rxbYQz7J1qY972ExytS
    :Commands
    [EmptyTemp]
    [ResetHosts]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Posted Image Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
--------------------------------------------------------------------

Double click on ComboFix.exe & follow the prompts.
  • If you have trouble, stop and post back. Do not try to repeatedly run comboFix!
  • When finished, it will produce a report for you.
.
Note: If after running ComboFix you receive a message stating, "Illegal Operation Attempted on a registry key that has been marked for deletion" rebooting your computer will resolve the problem.

Please include the following in your next post:
  • OTL Fix log
  • ComboFix log

  • 1

#5
RLS0812

RLS0812

    Banned

  • Topic Starter
  • Banned
  • PipPip
  • 12 posts
Here are some more logs -

========== OTL ==========

All processes killed
========== OTL ==========
ADS C:\Users\RICK\AppData\Local\Temp:rxbYQz7J1qY972ExytS deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: RICK
->Temp folder emptied: 135289213 bytes
->Temporary Internet Files folder emptied: 6744954 bytes
->Java cache emptied: 8079351 bytes
->FireFox cache emptied: 97967605 bytes
->Google Chrome cache emptied: 8630072 bytes
->Flash cache emptied: 975 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 398516000 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46427121 bytes
RecycleBin emptied: 218184 bytes

Total Files Cleaned = 669.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 11182012_222033

Files\Folders moved on Reboot...
C:\Users\RICK\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

==========ComboFix==========

ComboFix 12-11-16.02 - RICK 11/18/2012 22:28:37.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3895.2306 [GMT -5:00]
Running from: c:\users\RICK\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\a
c:\a\AUTORUN.bak
c:\a\Autorun.inf
c:\a\DK-D3D\_INST32I.EX_
c:\a\DK-D3D\_ISDEL.EXE
c:\a\DK-D3D\_sys1.cab
c:\a\DK-D3D\_user1.cab
c:\a\DK-D3D\DATA.TAG
c:\a\DK-D3D\data1.cab
c:\a\DK-D3D\deepd3d.exe
c:\a\DK-D3D\DisableNonLocalVideoMem.reg
c:\a\DK-D3D\Drivers\3Dfx Voodoo\d3rtvg.exe
c:\a\DK-D3D\Drivers\ATI Rage Pro\w95-2278.exe
c:\a\DK-D3D\Drivers\Diamond Viper330\viper0023p.exe
c:\a\DK-D3D\Drivers\Matrox M3D\dplay.dll
c:\a\DK-D3D\Drivers\Matrox M3D\inst_eng.dll
c:\a\DK-D3D\Drivers\Matrox M3D\inst_fre.dll
c:\a\DK-D3D\Drivers\Matrox M3D\inst_ger.dll
c:\a\DK-D3D\Drivers\Matrox M3D\inst_ita.dll
c:\a\DK-D3D\Drivers\Matrox M3D\inst_spa.dll
c:\a\DK-D3D\Drivers\Matrox M3D\m3d.inf
c:\a\DK-D3D\Drivers\Matrox M3D\m3d_fre.mva
c:\a\DK-D3D\Drivers\Matrox M3D\m3d_ger.mva
c:\a\DK-D3D\Drivers\Matrox M3D\m3d_ita.mva
c:\a\DK-D3D\Drivers\Matrox M3D\m3d_spa.mva
c:\a\DK-D3D\Drivers\Matrox M3D\m3dpci.exe
c:\a\DK-D3D\Drivers\Matrox M3D\m3dsheet.dll
c:\a\DK-D3D\Drivers\Matrox M3D\mga.ini
c:\a\DK-D3D\Drivers\Matrox M3D\pvrhal32.dll
c:\a\DK-D3D\Drivers\Matrox M3D\pvrinit.exe
c:\a\DK-D3D\Drivers\Matrox M3D\pvrmid5.dll
c:\a\DK-D3D\Drivers\Matrox M3D\pvros.dll
c:\a\DK-D3D\Drivers\Matrox M3D\pvrsm3d.dll
c:\a\DK-D3D\Drivers\Matrox M3D\pvrsmx.dll
c:\a\DK-D3D\Drivers\Matrox M3D\setup.exe
c:\a\DK-D3D\Drivers\Matrox M3D\setup.ini
c:\a\DK-D3D\Drivers\Matrox M3D\setup.vxd
c:\a\DK-D3D\Drivers\Matrox M3D\setup16.exe
c:\a\DK-D3D\Drivers\Matrox M3D\sgl.dll
c:\a\DK-D3D\Drivers\Matrox M3D\sglmid5.dll
c:\a\DK-D3D\Drivers\Matrox M3D\vsgl.vxd
c:\a\DK-D3D\Drivers\PowerVR-PCX2\Build Info.wri
c:\a\DK-D3D\Drivers\PowerVR-PCX2\PowerVR.inf
c:\a\DK-D3D\Drivers\PowerVR-PCX2\PVRdev.bmp
c:\a\DK-D3D\Drivers\PowerVR-PCX2\pvrhal32.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\Pvrinit.exe
c:\a\DK-D3D\Drivers\PowerVR-PCX2\PVRMID4.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\PVRMID5.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\PVROS.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\pvrsm3d.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\pvrsmx.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\sgl.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\sgl.h
c:\a\DK-D3D\Drivers\PowerVR-PCX2\sgl.lib
c:\a\DK-D3D\Drivers\PowerVR-PCX2\SGLMID4.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\SGLMID5.dll
c:\a\DK-D3D\Drivers\PowerVR-PCX2\vsgl.vxd
c:\a\DK-D3D\dx5_2Setup.exe
c:\a\DK-D3D\EnableNonLocalVideoMem.reg
c:\a\DK-D3D\Install Keeper Direct3D.bat
c:\a\DK-D3D\keepd3d.exe
c:\a\DK-D3D\lang.dat
c:\a\DK-D3D\layout.bin
c:\a\DK-D3D\os.dat
c:\a\DK-D3D\ReadmeD3D.txt
c:\a\DK-D3D\Select Default Direct3D Device.reg
c:\a\DK-D3D\Select Primary Direct3D Device.reg
c:\a\DK-D3D\Select Secondary Direct3D Device.reg
c:\a\DK-D3D\SETUP.EXE
c:\a\DK-D3D\SETUP.INI
c:\a\DK-D3D\setup.ins
c:\a\DK-D3D\setup.lid
c:\a\DK-D3D\setupdir\0009\_SETUP.DLL
c:\a\DK-D3D\setupdir\000a\_setup.dll
c:\a\DK-D3D\setupdir\0010\_SETUP.DLL
c:\a\DK-D3D\setupdir\001d\_setup.dll
c:\a\DK-D3D\setupdir\040c\_setup.dll
c:\a\DOS4GW.EXE
c:\a\Eaukhelp.hlp
c:\a\Editor\Data\edittext.dat
c:\a\Editor\Data\GUIEDIT.DAT
c:\a\Editor\Data\GUIEDIT.TAB
c:\a\Editor\DKEditorManual.doc
c:\a\Editor\DKEditorManual.txt
c:\a\Editor\DKEditorQuickCard.doc
c:\a\Editor\Editor.exe
c:\a\Editor\Levels\ddiskmp.lof
c:\a\Editor\Levels\dklevels.lof
c:\a\Editor\Levels\MAP00200.apt
c:\a\Editor\Levels\MAP00200.clm
c:\a\Editor\Levels\MAP00200.dat
c:\a\Editor\Levels\MAP00200.inf
c:\a\Editor\Levels\MAP00200.lgt
c:\a\Editor\Levels\MAP00200.lif
c:\a\Editor\Levels\MAP00200.own
c:\a\Editor\Levels\map00200.slb
c:\a\Editor\Levels\MAP00200.tng
c:\a\Editor\Levels\map00200.txt
c:\a\Editor\Levels\MAP00200.wib
c:\a\Editor\Levels\map00200.wlb
c:\a\Editor\Levels\MAP00201.apt
c:\a\Editor\Levels\MAP00201.clm
c:\a\Editor\Levels\MAP00201.dat
c:\a\Editor\Levels\MAP00201.inf
c:\a\Editor\Levels\MAP00201.lgt
c:\a\Editor\Levels\MAP00201.lif
c:\a\Editor\Levels\MAP00201.own
c:\a\Editor\Levels\map00201.slb
c:\a\Editor\Levels\MAP00201.tng
c:\a\Editor\Levels\MAP00201.txt
c:\a\Editor\Levels\MAP00201.wib
c:\a\Editor\Levels\map00201.wlb
c:\a\Editor\readme.txt
c:\a\frhelp.hlp
c:\a\Install Keeper Direct3D.bat
c:\a\ip.cfg
c:\a\Ip.exe
c:\a\Keeper\aweman32.dll
c:\a\Keeper\Bullweb.url
c:\a\Keeper\data\ALPHA.COL
c:\a\Keeper\data\ALPHA.DAT
c:\a\Keeper\data\alpha.tab
c:\a\Keeper\data\BLOCK.TAB
c:\a\Keeper\data\BLUEPAL.DAT
c:\a\Keeper\data\BLUEPALL.DAT
c:\a\Keeper\data\BORD0-0.DAT
c:\a\Keeper\data\BORD0-0.TAB
c:\a\Keeper\data\BORD0-1.DAT
c:\a\Keeper\data\BORD0-1.TAB
c:\a\Keeper\data\CEILING.TXT
c:\a\Keeper\data\COLOURS.COL
c:\a\Keeper\data\CREAT1.TAB
c:\a\Keeper\data\CREATURE.JTY
c:\a\Keeper\data\CREATURE.TAB
c:\a\Keeper\data\creature.txt
c:\a\Keeper\data\CRET0000.DAT
c:\a\Keeper\data\CUBE.DAT
c:\a\Keeper\data\CUBEGRP.DAT
c:\a\Keeper\data\DD1CREAT.TXT
c:\a\Keeper\data\DOGPAL.PAL
c:\a\Keeper\data\DP_PREFS
c:\a\Keeper\data\dutch\dd1text.dat
c:\a\Keeper\data\dutch\TEXT.DAT
c:\a\Keeper\data\EDITICN1.DAT
c:\a\Keeper\data\EDITICN1.TAB
c:\a\Keeper\data\EDITICN2.DAT
c:\a\Keeper\data\EDITICN2.TAB
c:\a\Keeper\data\english\DD1TEXT.DAT
c:\a\Keeper\data\english\TEXT.DAT
c:\a\Keeper\data\FONT0-0.DAT
c:\a\Keeper\data\FONT0-0.TAB
c:\a\Keeper\data\FONT0-1.DAT
c:\a\Keeper\data\FONT0-1.TAB
c:\a\Keeper\data\FONT2-0.DAT
c:\a\Keeper\data\FONT2-0.TAB
c:\a\Keeper\data\font2-1.dat
c:\a\Keeper\data\font2-1.tab
c:\a\Keeper\data\FRAC00.DAT
c:\a\Keeper\data\FRAC01.DAT
c:\a\Keeper\data\FRAC02.DAT
c:\a\Keeper\data\FRAC03.DAT
c:\a\Keeper\data\FRAC04.DAT
c:\a\Keeper\data\FRAC05.DAT
c:\a\Keeper\data\FRAC06.DAT
c:\a\Keeper\data\FRAC07.DAT
c:\a\Keeper\data\frac08.dat
c:\a\Keeper\data\FRAME0-0.DAT
c:\a\Keeper\data\FRAME0-0.TAB
c:\a\Keeper\data\FRAME0-1.DAT
c:\a\Keeper\data\FRAME0-1.TAB
c:\a\Keeper\data\french\dd1Text.dat
c:\a\Keeper\data\french\TEXT.DAT
c:\a\Keeper\data\FRONTEND.PAL
c:\a\Keeper\data\FRONTEND.RAW
c:\a\Keeper\data\german\dd1Text.dat
c:\a\Keeper\data\GMAP.RAW
c:\a\Keeper\data\GMAPBUG.DAT
c:\a\Keeper\data\GMAPBUG.TAB
c:\a\Keeper\data\GMAPHI.RAW
c:\a\Keeper\data\GUI.DAT
c:\a\Keeper\data\GUI.TAB
c:\a\Keeper\data\GUI2-0-0.DAT
c:\a\Keeper\data\GUI2-0-0.TAB
c:\a\Keeper\data\GUI2-0-1.DAT
c:\a\Keeper\data\GUI2-0-1.TAB
c:\a\Keeper\data\GUIHI.DAT
c:\a\Keeper\data\GUIHI.TAB
c:\a\Keeper\data\HBUY0-0.DAT
c:\a\Keeper\data\HBUY0-0.TAB
c:\a\Keeper\data\HBUYSCRN.DAT
c:\a\Keeper\data\HIFONT.DAT
c:\a\Keeper\data\HIFONT.TAB
c:\a\Keeper\data\HITPALL.DAT
c:\a\Keeper\data\HPOINTER.DAT
c:\a\Keeper\data\HPOINTER.TAB
c:\a\Keeper\data\HPOINTS.DAT
c:\a\Keeper\data\HPOINTS.TAB
c:\a\Keeper\data\HUESHADE.TAB
c:\a\Keeper\data\ICONS0-0.DAT
c:\a\Keeper\data\ICONS0-0.TAB
c:\a\Keeper\data\ICONS0-1.DAT
c:\a\Keeper\data\ICONS0-1.TAB
c:\a\Keeper\data\italian\dd1Text.dat
c:\a\Keeper\data\KSEFFECT.JTY
c:\a\Keeper\data\LEGAL.PAL
c:\a\Keeper\data\LEGAL.RAW
c:\a\Keeper\data\LIGHTNG.PAL
c:\a\Keeper\data\LOADING.PAL
c:\a\Keeper\data\LOADING.RAW
c:\a\Keeper\data\LOFONT.DAT
c:\a\Keeper\data\LOFONT.TAB
c:\a\Keeper\data\LPOINTER.DAT
c:\a\Keeper\data\LPOINTER.TAB
c:\a\Keeper\data\LPOINTS.DAT
c:\a\Keeper\data\LPOINTS.TAB
c:\a\Keeper\data\MAIN.PAL
c:\a\Keeper\data\MAP00000.ANM
c:\a\Keeper\data\MAP00000.CUB
c:\a\Keeper\data\MAPFADEG.DAT
c:\a\Keeper\data\MENUBLK1.DAT
c:\a\Keeper\data\MENUBLK1.TAB
c:\a\Keeper\data\NOCD.PAL
c:\a\Keeper\data\NOCD.RAW
c:\a\Keeper\data\PAL00000.DAT
c:\a\Keeper\data\PAL00001.DAT
c:\a\Keeper\data\PAL00002.DAT
c:\a\Keeper\data\PAL00003.DAT
c:\a\Keeper\data\PAL00004.DAT
c:\a\Keeper\data\PALETTE.DAT
c:\a\Keeper\data\POINTERS.DAT
c:\a\Keeper\data\POINTERS.TAB
c:\a\Keeper\data\polish\DD1TEXT.DAT
c:\a\Keeper\data\polish\TEXT.DAT
c:\a\Keeper\data\PORT0-0.DAT
c:\a\Keeper\data\PORT0-0.TAB
c:\a\Keeper\data\PORT0-1.DAT
c:\a\Keeper\data\PORT0-1.TAB
c:\a\Keeper\data\REDPAL.COL
c:\a\Keeper\data\REDPALL.DAT
c:\a\Keeper\data\ROOM0-0.DAT
c:\a\Keeper\data\ROOM0-0.TAB
c:\a\Keeper\data\ROOM0-1.DAT
c:\a\Keeper\data\ROOM0-1.TAB
c:\a\Keeper\data\SAVE.CAT
c:\a\Keeper\data\SETTINGS.DAT
c:\a\Keeper\data\SHADE.TAB
c:\a\Keeper\data\SLAB.DAT
c:\a\Keeper\data\SLAB0-0.DAT
c:\a\Keeper\data\SLAB0-1.DAT
c:\a\Keeper\data\SLABS.CLM
c:\a\Keeper\data\SLABS.DAT
c:\a\Keeper\data\SLABS.OBJ
c:\a\Keeper\data\slabs.tng
c:\a\Keeper\data\spanish\dd1Text.dat
c:\a\Keeper\data\spanish\TEXT.DAT
c:\a\Keeper\data\STAT0-0.DAT
c:\a\Keeper\data\STAT0-0.TAB
c:\a\Keeper\data\STATE.RST
c:\a\Keeper\data\swedish\DD1TEXT.DAT
c:\a\Keeper\data\swedish\TEXT.DAT
c:\a\Keeper\data\SWIPE1.DAT
c:\a\Keeper\data\SWIPE1.TAB
c:\a\Keeper\data\SWPE00.DAT
c:\a\Keeper\data\SWPE00.TAB
c:\a\Keeper\data\SWPE01.DAT
c:\a\Keeper\data\SWPE01.TAB
c:\a\Keeper\data\SWPE02.DAT
c:\a\Keeper\data\SWPE02.TAB
c:\a\Keeper\data\SWPE03.DAT
c:\a\Keeper\data\SWPE03.TAB
c:\a\Keeper\data\SWPE04.DAT
c:\a\Keeper\data\SWPE04.TAB
c:\a\Keeper\data\SWPE05.DAT
c:\a\Keeper\data\SWPE05.TAB
c:\a\Keeper\data\SWPE06.DAT
c:\a\Keeper\data\SWPE06.TAB
c:\a\Keeper\data\SWPE07.DAT
c:\a\Keeper\data\SWPE07.TAB
c:\a\Keeper\data\SWPE08.DAT
c:\a\Keeper\data\SWPE08.TAB
c:\a\Keeper\data\SWPE09.DAT
c:\a\Keeper\data\SWPE09.TAB
c:\a\Keeper\data\SWPE10.DAT
c:\a\Keeper\data\SWPE10.TAB
c:\a\Keeper\data\SWPE11.DAT
c:\a\Keeper\data\SWPE11.TAB
c:\a\Keeper\data\SWPE12.DAT
c:\a\Keeper\data\SWPE12.TAB
c:\a\Keeper\data\SWPE13.DAT
c:\a\Keeper\data\SWPE13.TAB
c:\a\Keeper\data\SWPE14.DAT
c:\a\Keeper\data\SWPE14.TAB
c:\a\Keeper\data\SWPE15.DAT
c:\a\Keeper\data\SWPE15.TAB
c:\a\Keeper\data\SWPE16.DAT
c:\a\Keeper\data\SWPE16.TAB
c:\a\Keeper\data\SWPE17.DAT
c:\a\Keeper\data\SWPE17.TAB
c:\a\Keeper\data\SWPE18.DAT
c:\a\Keeper\data\SWPE18.TAB
c:\a\Keeper\data\SWPE19.DAT
c:\a\Keeper\data\SWPE19.TAB
c:\a\Keeper\data\SWPE20.DAT
c:\a\Keeper\data\SWPE20.TAB
c:\a\Keeper\data\SWPE21.DAT
c:\a\Keeper\data\SWPE21.TAB
c:\a\Keeper\data\SWPE22.DAT
c:\a\Keeper\data\SWPE22.TAB
c:\a\Keeper\data\SWPE23.DAT
c:\a\Keeper\data\SWPE23.TAB
c:\a\Keeper\data\SWPE24.DAT
c:\a\Keeper\data\SWPE24.TAB
c:\a\Keeper\data\SWPE25.DAT
c:\a\Keeper\data\SWPE25.TAB
c:\a\Keeper\data\SWPE26.DAT
c:\a\Keeper\data\SWPE26.TAB
c:\a\Keeper\data\SWPE27.DAT
c:\a\Keeper\data\SWPE27.TAB
c:\a\Keeper\data\SWPE28.DAT
c:\a\Keeper\data\SWPE28.TAB
c:\a\Keeper\data\SWPE29.DAT
c:\a\Keeper\data\SWPE29.TAB
c:\a\Keeper\data\tables.dat
c:\a\Keeper\data\TICON0-0.DAT
c:\a\Keeper\data\TICON0-0.TAB
c:\a\Keeper\data\TMAPA000.DAT
c:\a\Keeper\data\TMAPA001.DAT
c:\a\Keeper\data\TMAPA002.DAT
c:\a\Keeper\data\TMAPA003.DAT
c:\a\Keeper\data\TMAPA004.DAT
c:\a\Keeper\data\TMAPA005.DAT
c:\a\Keeper\data\TMAPA006.DAT
c:\a\Keeper\data\TMAPA007.DAT
c:\a\Keeper\data\TMAPANIM.DAT
c:\a\Keeper\data\VAMPAL.PAL
c:\a\Keeper\data\WHITEPAL.COL
c:\a\Keeper\deeper.exe
c:\a\Keeper\Deeper95.exe
c:\a\Keeper\DOS4GW.EXE
c:\a\Keeper\DOSSETUP\ART\_BACKUP_.LBM
c:\a\Keeper\DOSSETUP\ART\BACK.BMP
c:\a\Keeper\DOSSETUP\ART\BACK.LBM
c:\a\Keeper\DOSSETUP\ART\CRUD.LBM
c:\a\Keeper\DOSSETUP\ART\DKINS1.LBM
c:\a\Keeper\DOSSETUP\ART\DKINS2.LBM
c:\a\Keeper\DOSSETUP\ART\DKINS3.LBM
c:\a\Keeper\DOSSETUP\ART\DKINS4.LBM
c:\a\Keeper\DOSSETUP\ART\DOCBACK.BMP
c:\a\Keeper\DOSSETUP\ART\DUTCH.BMP
c:\a\Keeper\DOSSETUP\ART\ENGLISH.BMP
c:\a\Keeper\DOSSETUP\ART\ENMONO.BMP
c:\a\Keeper\DOSSETUP\ART\FLAG5.FLC
c:\a\Keeper\DOSSETUP\ART\FLAG5.GIF
c:\a\Keeper\DOSSETUP\ART\FLAG5.LBM
c:\a\Keeper\DOSSETUP\ART\FLAGS.BMP
c:\a\Keeper\DOSSETUP\ART\FLAGSMON.BMP
c:\a\Keeper\DOSSETUP\ART\FONT00V.LBM
c:\a\Keeper\DOSSETUP\ART\FONTPLN.LBM
c:\a\Keeper\DOSSETUP\ART\FONTRED.LBM
c:\a\Keeper\DOSSETUP\ART\FONTRSML.LBM
c:\a\Keeper\DOSSETUP\ART\FONTTINY.LBM
c:\a\Keeper\DOSSETUP\ART\FONTYELL.LBM
c:\a\Keeper\DOSSETUP\ART\FONTYSML.LBM
c:\a\Keeper\DOSSETUP\ART\FRENCH.BMP
c:\a\Keeper\DOSSETUP\ART\FRMONO.BMP
c:\a\Keeper\DOSSETUP\ART\FRONT.BMP
c:\a\Keeper\DOSSETUP\ART\GEMONO.BMP
c:\a\Keeper\DOSSETUP\ART\GERMAN.BMP
c:\a\Keeper\DOSSETUP\ART\GILO.FLC
c:\a\Keeper\DOSSETUP\ART\HSPR0-0.LBM
c:\a\Keeper\DOSSETUP\ART\INSTLOGO.BMP
c:\a\Keeper\DOSSETUP\ART\ITALIAN.BMP
c:\a\Keeper\DOSSETUP\ART\ITMONO.BMP
c:\a\Keeper\DOSSETUP\ART\JLANG.LBM
c:\a\Keeper\DOSSETUP\ART\JMAIN.LBM
c:\a\Keeper\DOSSETUP\ART\JPATH.LBM
c:\a\Keeper\DOSSETUP\ART\JSOUND.LBM
c:\a\Keeper\DOSSETUP\ART\KBOXBACK.BMP
c:\a\Keeper\DOSSETUP\ART\KBOXERR2.BMP
c:\a\Keeper\DOSSETUP\ART\KBOXINPT.BMP
c:\a\Keeper\DOSSETUP\ART\LOGO.BMP
c:\a\Keeper\DOSSETUP\ART\NBOXBACK.BMP
c:\a\Keeper\DOSSETUP\ART\NBOXBAK2.BMP
c:\a\Keeper\DOSSETUP\ART\NBOXERR2.BMP
c:\a\Keeper\DOSSETUP\ART\NBOXINPT.BMP
c:\a\Keeper\DOSSETUP\ART\PALET0-0.LBM
c:\a\Keeper\DOSSETUP\ART\POINTER.LBM
c:\a\Keeper\DOSSETUP\ART\POLISH.BMP
c:\a\Keeper\DOSSETUP\ART\SPANISH.BMP
c:\a\Keeper\DOSSETUP\ART\SPMONO.BMP
c:\a\Keeper\DOSSETUP\ART\SWEDISH.BMP
c:\a\Keeper\DOSSETUP\ART\SWMONO.BMP
c:\a\Keeper\DOSSETUP\ART\UNTITLED.LBM
c:\a\Keeper\DOSSETUP\ART\ZLANG.BMP
c:\a\Keeper\DOSSETUP\DATA\FONT0-0.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT0-0.TAB
c:\a\Keeper\DOSSETUP\DATA\FONT0-1.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT0-1.TAB
c:\a\Keeper\DOSSETUP\DATA\FONT0-2.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT0-2.TAB
c:\a\Keeper\DOSSETUP\DATA\FONT0-3.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT0-3.TAB
c:\a\Keeper\DOSSETUP\DATA\FONT0-4.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT0-4.TAB
c:\a\Keeper\DOSSETUP\DATA\FONT1-0.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT1-0.TAB
c:\a\Keeper\DOSSETUP\DATA\FONT1-1.DAT
c:\a\Keeper\DOSSETUP\DATA\FONT1-1.TAB
c:\a\Keeper\DOSSETUP\DATA\GHOST.DAT
c:\a\Keeper\DOSSETUP\DATA\HSPR0-0.DAT
c:\a\Keeper\DOSSETUP\DATA\HSPR0-0.TAB
c:\a\Keeper\DOSSETUP\DATA\MSPR0-0.DAT
c:\a\Keeper\DOSSETUP\DATA\MSPR0-0.TAB
c:\a\Keeper\DOSSETUP\DATA\PALET0-0.DAT
c:\a\Keeper\DOSSETUP\DATA\POINTER.DAT
c:\a\Keeper\DOSSETUP\DATA\POINTER.TAB
c:\a\Keeper\DOSSETUP\DDINST.exe
c:\a\Keeper\DOSSETUP\DOS4GW.EXE
c:\a\Keeper\DOSSETUP\SETUP.EXE
c:\a\Keeper\DOSSETUP\SOUND\AILDU.LST
c:\a\Keeper\DOSSETUP\SOUND\AILEN.LST
c:\a\Keeper\DOSSETUP\SOUND\AILFR.LST
c:\a\Keeper\DOSSETUP\SOUND\AILGE.LST
c:\a\Keeper\DOSSETUP\SOUND\AILIT.LST
c:\a\Keeper\DOSSETUP\SOUND\AILPO.LST
c:\a\Keeper\DOSSETUP\SOUND\AILSP.LST
c:\a\Keeper\DOSSETUP\SOUND\AILSW.LST
c:\a\Keeper\DOSSETUP\SOUND\AUDIODRV.DIG
c:\a\Keeper\DOSSETUP\SOUND\DSPWDIE2.WAV
c:\a\Keeper\DOSSETUP\SOUND\IWAV.DIG
c:\a\Keeper\DOSSETUP\SOUND\JAMMER.DIG
c:\a\Keeper\DOSSETUP\SOUND\KEEP.XMI
c:\a\Keeper\DOSSETUP\SOUND\NVDIG.DIG
c:\a\Keeper\DOSSETUP\SOUND\PROAUDIO.DIG
c:\a\Keeper\DOSSETUP\SOUND\RAP10.DIG
c:\a\Keeper\DOSSETUP\SOUND\SB16.DIG
c:\a\Keeper\DOSSETUP\SOUND\SBAWE32.MDI
c:\a\Keeper\DOSSETUP\SOUND\SBLASTER.DIG
c:\a\Keeper\DOSSETUP\SOUND\SBPRO.DIG
c:\a\Keeper\DOSSETUP\SOUND\SETSOUND.EXE
c:\a\Keeper\DOSSETUP\SOUND\SNDSCAPE.DIG
c:\a\Keeper\DOSSETUP\SOUND\SNDSYS.DIG
c:\a\Keeper\DOSSETUP\SOUND\ULTRA.DIG
c:\a\Keeper\DSETUP.DLL
c:\a\Keeper\DSETUP16.DLL
c:\a\Keeper\Goodies\Alex.TIF
c:\a\Keeper\Goodies\Amsterdm.TIF
c:\a\Keeper\Goodies\Barrie.TIF
c:\a\Keeper\Goodies\Dene.TIF
c:\a\Keeper\Goodies\DKMAP00.LBM
c:\a\Keeper\Goodies\Horny.tif
c:\a\Keeper\Goodies\Horny2.TIF
c:\a\Keeper\Goodies\Jonty.TIF
c:\a\Keeper\Goodies\Kinkyfat.TIF
c:\a\Keeper\Goodies\Mark.TIF
c:\a\Keeper\Goodies\Peter.TIF
c:\a\Keeper\Goodies\Peter2.TIF
c:\a\Keeper\Goodies\pspbrwse.jbf
c:\a\Keeper\Goodies\Russ.TIF
c:\a\Keeper\Goodies\Shin.TIF
c:\a\Keeper\Goodies\Simon.TIF
c:\a\Keeper\Goodies\Sk1.TIF
c:\a\Keeper\Goodies\Sk2.TIF
c:\a\Keeper\Goodies\Sk3.TIF
c:\a\Keeper\Goodies\Sk4.TIF
c:\a\Keeper\Goodies\Sk5.TIF
c:\a\Keeper\Goodies\Steve.TIF
c:\a\Keeper\keeper.exe
c:\a\Keeper\keeper95.exe
c:\a\Keeper\ldata\DKFLAG00.DAT
c:\a\Keeper\ldata\DKFLAG00.TAB
c:\a\Keeper\ldata\DKMAP00.PAL
c:\a\Keeper\ldata\DKMAP00.RAW
c:\a\Keeper\ldata\DKMAP01.PAL
c:\a\Keeper\ldata\DKMAP01.RAW
c:\a\Keeper\ldata\DKMAP02.PAL
c:\a\Keeper\ldata\DKMAP02.RAW
c:\a\Keeper\ldata\DKMAP03.PAL
c:\a\Keeper\ldata\DKMAP03.RAW
c:\a\Keeper\ldata\DKMAP04.PAL
c:\a\Keeper\ldata\DKMAP04.RAW
c:\a\Keeper\ldata\DKMAP05.PAL
c:\a\Keeper\ldata\DKMAP05.RAW
c:\a\Keeper\ldata\DKMAP06.PAL
c:\a\Keeper\ldata\DKMAP06.RAW
c:\a\Keeper\ldata\DKMAP07.PAL
c:\a\Keeper\ldata\DKMAP07.RAW
c:\a\Keeper\ldata\DKMAP08.PAL
c:\a\Keeper\ldata\DKMAP08.RAW
c:\a\Keeper\ldata\DKMAP09.PAL
c:\a\Keeper\ldata\DKMAP09.RAW
c:\a\Keeper\ldata\DKMAP10.PAL
c:\a\Keeper\ldata\DKMAP10.RAW
c:\a\Keeper\ldata\DKMAP11.PAL
c:\a\Keeper\ldata\DKMAP11.RAW
c:\a\Keeper\ldata\DKMAP12.PAL
c:\a\Keeper\ldata\DKMAP12.RAW
c:\a\Keeper\ldata\DKMAP13.PAL
c:\a\Keeper\ldata\DKMAP13.RAW
c:\a\Keeper\ldata\DKMAP14.PAL
c:\a\Keeper\ldata\DKMAP14.RAW
c:\a\Keeper\ldata\DKMAP15.PAL
c:\a\Keeper\ldata\DKMAP15.RAW
c:\a\Keeper\ldata\DKMAP16.PAL
c:\a\Keeper\ldata\DKMAP16.RAW
c:\a\Keeper\ldata\DKMAP17.PAL
c:\a\Keeper\ldata\DKMAP17.RAW
c:\a\Keeper\ldata\DKMAP18.PAL
c:\a\Keeper\ldata\DKMAP18.RAW
c:\a\Keeper\ldata\DKMAP19.PAL
c:\a\Keeper\ldata\DKMAP19.RAW
c:\a\Keeper\ldata\DKMAP20.PAL
c:\a\Keeper\ldata\DKMAP20.RAW
c:\a\Keeper\ldata\DKMAP21.PAL
c:\a\Keeper\ldata\DKMAP21.RAW
c:\a\Keeper\ldata\DKWIND00.DAT
c:\a\Keeper\ldata\DKWIND00.LBM
c:\a\Keeper\ldata\DKWIND01.DAT
c:\a\Keeper\ldata\DKWIND02.DAT
c:\a\Keeper\ldata\DKWIND03.DAT
c:\a\Keeper\ldata\DKWIND04.DAT
c:\a\Keeper\ldata\DKWIND05.DAT
c:\a\Keeper\ldata\DKWIND06.DAT
c:\a\Keeper\ldata\DKWIND07.DAT
c:\a\Keeper\ldata\DKWIND08.DAT
c:\a\Keeper\ldata\DKWIND09.DAT
c:\a\Keeper\ldata\DKWIND10.DAT
c:\a\Keeper\ldata\DKWIND11.DAT
c:\a\Keeper\ldata\DKWIND12.DAT
c:\a\Keeper\ldata\DKWIND13.DAT
c:\a\Keeper\ldata\DKWIND14.DAT
c:\a\Keeper\ldata\DKWIND15.DAT
c:\a\Keeper\ldata\DKWIND16.DAT
c:\a\Keeper\ldata\dkwind17.dat
c:\a\Keeper\ldata\DKWIND17.RAW
c:\a\Keeper\ldata\DKWIND18.DAT
c:\a\Keeper\ldata\DKWIND19.DAT
c:\a\Keeper\ldata\DKWIND20.DAT
c:\a\Keeper\ldata\DKWIND21.DAT
c:\a\Keeper\ldata\DOOR01.DAT
c:\a\Keeper\ldata\DOOR01.TAB
c:\a\Keeper\ldata\DOOR02.DAT
c:\a\Keeper\ldata\DOOR02.TAB
c:\a\Keeper\ldata\DOOR03.DAT
c:\a\Keeper\ldata\DOOR03.TAB
c:\a\Keeper\ldata\DOOR04.DAT
c:\a\Keeper\ldata\DOOR04.TAB
c:\a\Keeper\ldata\DOOR05.DAT
c:\a\Keeper\ldata\DOOR05.TAB
c:\a\Keeper\ldata\DOOR06.DAT
c:\a\Keeper\ldata\DOOR06.TAB
c:\a\Keeper\ldata\DOOR07.DAT
c:\a\Keeper\ldata\DOOR07.TAB
c:\a\Keeper\ldata\DOOR08.DAT
c:\a\Keeper\ldata\DOOR08.TAB
c:\a\Keeper\ldata\DOOR09.DAT
c:\a\Keeper\ldata\DOOR09.TAB
c:\a\Keeper\ldata\Drag.smk
c:\a\Keeper\ldata\DTORTURE.FLC
c:\a\Keeper\ldata\empty
c:\a\Keeper\ldata\FRONT.PAL
c:\a\Keeper\ldata\FRONT.RAW
c:\a\Keeper\ldata\FRONTBIT.DAT
c:\a\Keeper\ldata\FRONTBIT.TAB
c:\a\Keeper\ldata\FRONTFT1.DAT
c:\a\Keeper\ldata\FRONTFT1.TAB
c:\a\Keeper\ldata\FRONTFT2.DAT
c:\a\Keeper\ldata\FRONTFT2.TAB
c:\a\Keeper\ldata\FRONTFT3.DAT
c:\a\Keeper\ldata\FRONTFT3.TAB
c:\a\Keeper\ldata\FRONTFT4.DAT
c:\a\Keeper\ldata\FRONTFT4.TAB
c:\a\Keeper\ldata\FRONTTOR.DAT
c:\a\Keeper\ldata\FRONTTOR.TAB
c:\a\Keeper\ldata\HISCORES.DAT
c:\a\Keeper\ldata\intromix.smk
c:\a\Keeper\ldata\levels.txt
c:\a\Keeper\ldata\LOADING.PAL
c:\a\Keeper\ldata\LOADING.RAW
c:\a\Keeper\ldata\MAPHAND.DAT
c:\a\Keeper\ldata\MAPHAND.TAB
c:\a\Keeper\ldata\NETFLAG.DAT
c:\a\Keeper\ldata\NETFLAG.TAB
c:\a\Keeper\ldata\NETFONT.DAT
c:\a\Keeper\ldata\NETFONT.TAB
c:\a\Keeper\ldata\outromix.smk
c:\a\Keeper\ldata\TORTURE.DAT
c:\a\Keeper\ldata\TORTURE.FLC
c:\a\Keeper\ldata\TORTURE.PAL
c:\a\Keeper\ldata\TORTURE.RAW
c:\a\Keeper\levels\DD1Lev.txt
c:\a\Keeper\levels\DDISK1.LIF
c:\a\Keeper\levels\LEVELS.TXT
c:\a\Keeper\levels\MAP00001.APT
c:\a\Keeper\levels\MAP00001.CLM
c:\a\Keeper\levels\MAP00001.DAT
c:\a\Keeper\levels\MAP00001.DOC
c:\a\Keeper\levels\MAP00001.EFF
c:\a\Keeper\levels\MAP00001.FLG
c:\a\Keeper\levels\MAP00001.INF
c:\a\Keeper\levels\MAP00001.LGT
c:\a\Keeper\levels\MAP00001.OLD
c:\a\Keeper\levels\MAP00001.ORI
c:\a\Keeper\levels\MAP00001.OWN
c:\a\Keeper\levels\MAP00001.SLB
c:\a\Keeper\levels\MAP00001.TMN
c:\a\Keeper\levels\MAP00001.TNG
c:\a\Keeper\levels\MAP00001.TXT
c:\a\Keeper\levels\MAP00001.VSN
c:\a\Keeper\levels\MAP00001.WIB
c:\a\Keeper\levels\MAP00002.APT
c:\a\Keeper\levels\MAP00002.CLM
c:\a\Keeper\levels\MAP00002.DAT
c:\a\Keeper\levels\MAP00002.DOC
c:\a\Keeper\levels\MAP00002.EFF
c:\a\Keeper\levels\MAP00002.FLG
c:\a\Keeper\levels\MAP00002.INF
c:\a\Keeper\levels\MAP00002.LGT
c:\a\Keeper\levels\MAP00002.ORI
c:\a\Keeper\levels\MAP00002.OWN
c:\a\Keeper\levels\MAP00002.SLB
c:\a\Keeper\levels\MAP00002.TMN
c:\a\Keeper\levels\MAP00002.TNG
c:\a\Keeper\levels\MAP00002.TXT
c:\a\Keeper\levels\MAP00002.VSN
c:\a\Keeper\levels\MAP00002.WIB
c:\a\Keeper\levels\MAP00003.APT
c:\a\Keeper\levels\MAP00003.CLM
c:\a\Keeper\levels\MAP00003.DAT
c:\a\Keeper\levels\MAP00003.EFF
c:\a\Keeper\levels\MAP00003.FLG
c:\a\Keeper\levels\MAP00003.INF
c:\a\Keeper\levels\MAP00003.LGT
c:\a\Keeper\levels\MAP00003.ORI
c:\a\Keeper\levels\MAP00003.OWN
c:\a\Keeper\levels\MAP00003.SLB
c:\a\Keeper\levels\MAP00003.TMN
c:\a\Keeper\levels\MAP00003.TNG
c:\a\Keeper\levels\MAP00003.TXT
c:\a\Keeper\levels\MAP00003.VSN
c:\a\Keeper\levels\MAP00003.WIB
c:\a\Keeper\levels\MAP00004.APT
c:\a\Keeper\levels\MAP00004.CLM
c:\a\Keeper\levels\MAP00004.DAT
c:\a\Keeper\levels\MAP00004.EFF
c:\a\Keeper\levels\MAP00004.FLG
c:\a\Keeper\levels\MAP00004.INF
c:\a\Keeper\levels\MAP00004.LGT
c:\a\Keeper\levels\MAP00004.ORI
c:\a\Keeper\levels\MAP00004.OWN
c:\a\Keeper\levels\MAP00004.SLB
c:\a\Keeper\levels\MAP00004.TMN
c:\a\Keeper\levels\MAP00004.TNG
c:\a\Keeper\levels\MAP00004.TXT
c:\a\Keeper\levels\MAP00004.VSN
c:\a\Keeper\levels\MAP00004.WIB
c:\a\Keeper\levels\MAP00005.APT
c:\a\Keeper\levels\MAP00005.CLM
c:\a\Keeper\levels\MAP00005.DAT
c:\a\Keeper\levels\MAP00005.EFF
c:\a\Keeper\levels\MAP00005.FLG
c:\a\Keeper\levels\MAP00005.INF
c:\a\Keeper\levels\MAP00005.LGT
c:\a\Keeper\levels\MAP00005.ORI
c:\a\Keeper\levels\MAP00005.OWN
c:\a\Keeper\levels\MAP00005.SLB
c:\a\Keeper\levels\MAP00005.TMN
c:\a\Keeper\levels\MAP00005.TNG
c:\a\Keeper\levels\MAP00005.TXT
c:\a\Keeper\levels\MAP00005.VSN
c:\a\Keeper\levels\MAP00005.WIB
c:\a\Keeper\levels\MAP00006.APT
c:\a\Keeper\levels\MAP00006.CLM
c:\a\Keeper\levels\MAP00006.DAT
c:\a\Keeper\levels\MAP00006.EFF
c:\a\Keeper\levels\MAP00006.FLG
c:\a\Keeper\levels\MAP00006.INF
c:\a\Keeper\levels\MAP00006.LGT
c:\a\Keeper\levels\MAP00006.ORI
c:\a\Keeper\levels\MAP00006.OWN
c:\a\Keeper\levels\MAP00006.SLB
c:\a\Keeper\levels\MAP00006.TMN
c:\a\Keeper\levels\MAP00006.TNG
c:\a\Keeper\levels\MAP00006.TXT
c:\a\Keeper\levels\MAP00006.VSN
c:\a\Keeper\levels\MAP00006.WIB
c:\a\Keeper\levels\MAP00007.APT
c:\a\Keeper\levels\MAP00007.CLM
c:\a\Keeper\levels\MAP00007.DAT
c:\a\Keeper\levels\MAP00007.EFF
c:\a\Keeper\levels\MAP00007.FLG
c:\a\Keeper\levels\MAP00007.INF
c:\a\Keeper\levels\MAP00007.LGT
c:\a\Keeper\levels\MAP00007.ORI
c:\a\Keeper\levels\MAP00007.OWN
c:\a\Keeper\levels\MAP00007.SLB
c:\a\Keeper\levels\MAP00007.TMN
c:\a\Keeper\levels\MAP00007.TNG
c:\a\Keeper\levels\MAP00007.TXT
c:\a\Keeper\levels\MAP00007.VSN
c:\a\Keeper\levels\MAP00007.WIB
c:\a\Keeper\levels\MAP00008.APT
c:\a\Keeper\levels\MAP00008.CLM
c:\a\Keeper\levels\MAP00008.DAT
c:\a\Keeper\levels\MAP00008.DOC
c:\a\Keeper\levels\MAP00008.EFF
c:\a\Keeper\levels\MAP00008.FLG
c:\a\Keeper\levels\MAP00008.INF
c:\a\Keeper\levels\MAP00008.LGT
c:\a\Keeper\levels\MAP00008.ORI
c:\a\Keeper\levels\MAP00008.OWN
c:\a\Keeper\levels\MAP00008.SLB
c:\a\Keeper\levels\MAP00008.TMN
c:\a\Keeper\levels\MAP00008.TNG
c:\a\Keeper\levels\MAP00008.TXT
c:\a\Keeper\levels\MAP00008.VSN
c:\a\Keeper\levels\MAP00008.WIB
c:\a\Keeper\levels\MAP00009.APT
c:\a\Keeper\levels\MAP00009.CLM
c:\a\Keeper\levels\MAP00009.DAT
c:\a\Keeper\levels\MAP00009.DOC
c:\a\Keeper\levels\MAP00009.EFF
c:\a\Keeper\levels\MAP00009.FLG
c:\a\Keeper\levels\MAP00009.INF
c:\a\Keeper\levels\MAP00009.LGT
c:\a\Keeper\levels\MAP00009.ORI
c:\a\Keeper\levels\MAP00009.OWN
c:\a\Keeper\levels\MAP00009.SLB
c:\a\Keeper\levels\MAP00009.TMN
c:\a\Keeper\levels\MAP00009.TNG
c:\a\Keeper\levels\MAP00009.TXT
c:\a\Keeper\levels\MAP00009.VSN
c:\a\Keeper\levels\MAP00009.WIB
c:\a\Keeper\levels\MAP00010.APT
c:\a\Keeper\levels\MAP00010.CLM
c:\a\Keeper\levels\MAP00010.DAT
c:\a\Keeper\levels\MAP00010.DOC
c:\a\Keeper\levels\MAP00010.EFF
c:\a\Keeper\levels\MAP00010.FLG
c:\a\Keeper\levels\MAP00010.INF
c:\a\Keeper\levels\MAP00010.LGT
c:\a\Keeper\levels\MAP00010.ORI
c:\a\Keeper\levels\MAP00010.OWN
c:\a\Keeper\levels\MAP00010.SLB
c:\a\Keeper\levels\MAP00010.TMN
c:\a\Keeper\levels\MAP00010.TNG
c:\a\Keeper\levels\MAP00010.TXT
c:\a\Keeper\levels\MAP00010.VSN
c:\a\Keeper\levels\MAP00010.WIB
c:\a\Keeper\levels\MAP00011.APT
c:\a\Keeper\levels\MAP00011.CLM
c:\a\Keeper\levels\MAP00011.DAT
c:\a\Keeper\levels\MAP00011.DOC
c:\a\Keeper\levels\MAP00011.EFF
c:\a\Keeper\levels\MAP00011.FLG
c:\a\Keeper\levels\MAP00011.INF
c:\a\Keeper\levels\MAP00011.LGT
c:\a\Keeper\levels\MAP00011.ORI
c:\a\Keeper\levels\MAP00011.OWN
c:\a\Keeper\levels\MAP00011.SLB
c:\a\Keeper\levels\MAP00011.TMN
c:\a\Keeper\levels\MAP00011.TNG
c:\a\Keeper\levels\MAP00011.TXT
c:\a\Keeper\levels\MAP00011.VSN
c:\a\Keeper\levels\MAP00011.WIB
c:\a\Keeper\levels\MAP00012.APT
c:\a\Keeper\levels\MAP00012.CLM
c:\a\Keeper\levels\MAP00012.DAT
c:\a\Keeper\levels\MAP00012.DOC
c:\a\Keeper\levels\MAP00012.EFF
c:\a\Keeper\levels\MAP00012.FLG
c:\a\Keeper\levels\MAP00012.INF
c:\a\Keeper\levels\MAP00012.LGT
c:\a\Keeper\levels\MAP00012.ORI
c:\a\Keeper\levels\MAP00012.OWN
c:\a\Keeper\levels\MAP00012.SLB
c:\a\Keeper\levels\MAP00012.TMN
c:\a\Keeper\levels\MAP00012.TNG
c:\a\Keeper\levels\MAP00012.TXT
c:\a\Keeper\levels\MAP00012.VSN
c:\a\Keeper\levels\MAP00012.WIB
c:\a\Keeper\levels\MAP00013.APT
c:\a\Keeper\levels\MAP00013.CLM
c:\a\Keeper\levels\MAP00013.DAT
c:\a\Keeper\levels\MAP00013.DOC
c:\a\Keeper\levels\MAP00013.EFF
c:\a\Keeper\levels\MAP00013.FLG
c:\a\Keeper\levels\MAP00013.INF
c:\a\Keeper\levels\MAP00013.LGT
c:\a\Keeper\levels\MAP00013.ORI
c:\a\Keeper\levels\MAP00013.OWN
c:\a\Keeper\levels\MAP00013.SLB
c:\a\Keeper\levels\MAP00013.TMN
c:\a\Keeper\levels\MAP00013.TNG
c:\a\Keeper\levels\MAP00013.TXT
c:\a\Keeper\levels\MAP00013.VSN
c:\a\Keeper\levels\MAP00013.WIB
c:\a\Keeper\levels\MAP00014.APT
c:\a\Keeper\levels\MAP00014.CLM
c:\a\Keeper\levels\MAP00014.DAT
c:\a\Keeper\levels\MAP00014.FLG
c:\a\Keeper\levels\MAP00014.INF
c:\a\Keeper\levels\MAP00014.LGT
c:\a\Keeper\levels\MAP00014.ORI
c:\a\Keeper\levels\MAP00014.OWN
c:\a\Keeper\levels\MAP00014.SLB
c:\a\Keeper\levels\MAP00014.TMN
c:\a\Keeper\levels\MAP00014.TNG
c:\a\Keeper\levels\MAP00014.TXT
c:\a\Keeper\levels\MAP00014.WIB
c:\a\Keeper\levels\MAP00015.APT
c:\a\Keeper\levels\MAP00015.CLM
c:\a\Keeper\levels\MAP00015.DAT
c:\a\Keeper\levels\MAP00015.DOC
c:\a\Keeper\levels\MAP00015.EFF
c:\a\Keeper\levels\MAP00015.FLG
c:\a\Keeper\levels\MAP00015.INF
c:\a\Keeper\levels\MAP00015.LGT
c:\a\Keeper\levels\MAP00015.ORI
c:\a\Keeper\levels\MAP00015.OWN
c:\a\Keeper\levels\MAP00015.SLB
c:\a\Keeper\levels\MAP00015.TMN
c:\a\Keeper\levels\MAP00015.TNG
c:\a\Keeper\levels\MAP00015.TXT
c:\a\Keeper\levels\MAP00015.VSN
c:\a\Keeper\levels\MAP00015.WIB
c:\a\Keeper\levels\MAP00016.APT
c:\a\Keeper\levels\MAP00016.CLM
c:\a\Keeper\levels\MAP00016.DAT
c:\a\Keeper\levels\MAP00016.DOC
c:\a\Keeper\levels\MAP00016.EFF
c:\a\Keeper\levels\MAP00016.FLG
c:\a\Keeper\levels\MAP00016.INF
c:\a\Keeper\levels\MAP00016.LGT
c:\a\Keeper\levels\MAP00016.ORI
c:\a\Keeper\levels\MAP00016.OWN
c:\a\Keeper\levels\MAP00016.SLB
c:\a\Keeper\levels\MAP00016.TMN
c:\a\Keeper\levels\MAP00016.TNG
c:\a\Keeper\levels\MAP00016.TXT
c:\a\Keeper\levels\MAP00016.VSN
c:\a\Keeper\levels\MAP00016.WIB
c:\a\Keeper\levels\MAP00017.APT
c:\a\Keeper\levels\MAP00017.CLM
c:\a\Keeper\levels\MAP00017.DAT
c:\a\Keeper\levels\MAP00017.FLG
c:\a\Keeper\levels\MAP00017.INF
c:\a\Keeper\levels\MAP00017.LGT
c:\a\Keeper\levels\MAP00017.ORI
c:\a\Keeper\levels\MAP00017.OWN
c:\a\Keeper\levels\MAP00017.SLB
c:\a\Keeper\levels\MAP00017.TMN
c:\a\Keeper\levels\MAP00017.TNG
c:\a\Keeper\levels\MAP00017.TXT
c:\a\Keeper\levels\MAP00017.WIB
c:\a\Keeper\levels\MAP00018.APT
c:\a\Keeper\levels\MAP00018.CLM
c:\a\Keeper\levels\MAP00018.DAT
c:\a\Keeper\levels\MAP00018.FLG
c:\a\Keeper\levels\MAP00018.INF
c:\a\Keeper\levels\MAP00018.LGT
c:\a\Keeper\levels\MAP00018.ORI
c:\a\Keeper\levels\MAP00018.OWN
c:\a\Keeper\levels\MAP00018.SLB
c:\a\Keeper\levels\MAP00018.TMN
c:\a\Keeper\levels\MAP00018.TNG
c:\a\Keeper\levels\MAP00018.TXT
c:\a\Keeper\levels\MAP00018.WIB
c:\a\Keeper\levels\MAP00019.APT
c:\a\Keeper\levels\MAP00019.CLM
c:\a\Keeper\levels\MAP00019.DAT
c:\a\Keeper\levels\MAP00019.DOC
c:\a\Keeper\levels\MAP00019.EFF
c:\a\Keeper\levels\MAP00019.FLG
c:\a\Keeper\levels\MAP00019.INF
c:\a\Keeper\levels\MAP00019.LGT
c:\a\Keeper\levels\MAP00019.ORI
c:\a\Keeper\levels\MAP00019.OWN
c:\a\Keeper\levels\MAP00019.SLB
c:\a\Keeper\levels\MAP00019.TMN
c:\a\Keeper\levels\MAP00019.TNG
c:\a\Keeper\levels\MAP00019.TXT
c:\a\Keeper\levels\MAP00019.VSN
c:\a\Keeper\levels\MAP00019.WIB
c:\a\Keeper\levels\MAP00020.APT
c:\a\Keeper\levels\MAP00020.CLM
c:\a\Keeper\levels\MAP00020.DAT
c:\a\Keeper\levels\MAP00020.DOC
c:\a\Keeper\levels\MAP00020.EFF
c:\a\Keeper\levels\MAP00020.FLG
c:\a\Keeper\levels\MAP00020.INF
c:\a\Keeper\levels\MAP00020.LGT
c:\a\Keeper\levels\MAP00020.ORI
c:\a\Keeper\levels\MAP00020.OWN
c:\a\Keeper\levels\MAP00020.SLB
c:\a\Keeper\levels\MAP00020.TMN
c:\a\Keeper\levels\MAP00020.TNG
c:\a\Keeper\levels\MAP00020.TXT
c:\a\Keeper\levels\MAP00020.VSN
c:\a\Keeper\levels\MAP00020.WIB
c:\a\Keeper\levels\MAP00050.APT
c:\a\Keeper\levels\MAP00050.CLM
c:\a\Keeper\levels\MAP00050.DAT
c:\a\Keeper\levels\MAP00050.DOC
c:\a\Keeper\levels\MAP00050.EFF
c:\a\Keeper\levels\MAP00050.FLG
c:\a\Keeper\levels\MAP00050.INF
c:\a\Keeper\levels\MAP00050.LGT
c:\a\Keeper\levels\MAP00050.ORI
c:\a\Keeper\levels\MAP00050.OWN
c:\a\Keeper\levels\MAP00050.SLB
c:\a\Keeper\levels\MAP00050.TMN
c:\a\Keeper\levels\MAP00050.TNG
c:\a\Keeper\levels\MAP00050.TXT
c:\a\Keeper\levels\MAP00050.VSN
c:\a\Keeper\levels\MAP00050.WIB
c:\a\Keeper\levels\MAP00051.APT
c:\a\Keeper\levels\MAP00051.CLM
c:\a\Keeper\levels\MAP00051.DAT
c:\a\Keeper\levels\MAP00051.FLG
c:\a\Keeper\levels\MAP00051.INF
c:\a\Keeper\levels\MAP00051.LGT
c:\a\Keeper\levels\MAP00051.ORI
c:\a\Keeper\levels\MAP00051.OWN
c:\a\Keeper\levels\MAP00051.SLB
c:\a\Keeper\levels\MAP00051.TMN
c:\a\Keeper\levels\MAP00051.TNG
c:\a\Keeper\levels\MAP00051.TXT
c:\a\Keeper\levels\MAP00051.WIB
c:\a\Keeper\levels\MAP00052.APT
c:\a\Keeper\levels\MAP00052.CLM
c:\a\Keeper\levels\MAP00052.DAT
c:\a\Keeper\levels\MAP00052.FLG
c:\a\Keeper\levels\MAP00052.INF
c:\a\Keeper\levels\MAP00052.LGT
c:\a\Keeper\levels\MAP00052.ORI
c:\a\Keeper\levels\MAP00052.OWN
c:\a\Keeper\levels\MAP00052.SLB
c:\a\Keeper\levels\MAP00052.TMN
c:\a\Keeper\levels\MAP00052.TNG
c:\a\Keeper\levels\MAP00052.TXT
c:\a\Keeper\levels\MAP00052.WIB
c:\a\Keeper\levels\MAP00053.APT
c:\a\Keeper\levels\MAP00053.CLM
c:\a\Keeper\levels\MAP00053.DAT
c:\a\Keeper\levels\MAP00053.FLG
c:\a\Keeper\levels\MAP00053.INF
c:\a\Keeper\levels\MAP00053.LGT
c:\a\Keeper\levels\MAP00053.ORI
c:\a\Keeper\levels\MAP00053.OWN
c:\a\Keeper\levels\MAP00053.SLB
c:\a\Keeper\levels\MAP00053.TMN
c:\a\Keeper\levels\MAP00053.TNG
c:\a\Keeper\levels\MAP00053.TXT
c:\a\Keeper\levels\MAP00053.WIB
c:\a\Keeper\levels\MAP00054.APT
c:\a\Keeper\levels\MAP00054.CLM
c:\a\Keeper\levels\MAP00054.DAT
c:\a\Keeper\levels\MAP00054.DOC
c:\a\Keeper\levels\MAP00054.EFF
c:\a\Keeper\levels\MAP00054.FLG
c:\a\Keeper\levels\MAP00054.INF
c:\a\Keeper\levels\MAP00054.LGT
c:\a\Keeper\levels\MAP00054.ORI
c:\a\Keeper\levels\MAP00054.OWN
c:\a\Keeper\levels\MAP00054.SLB
c:\a\Keeper\levels\MAP00054.TMN
c:\a\Keeper\levels\MAP00054.TNG
c:\a\Keeper\levels\MAP00054.TXT
c:\a\Keeper\levels\MAP00054.VSN
c:\a\Keeper\levels\MAP00054.WIB
c:\a\Keeper\levels\MAP00055.APT
c:\a\Keeper\levels\MAP00055.CLM
c:\a\Keeper\levels\MAP00055.DAT
c:\a\Keeper\levels\MAP00055.FLG
c:\a\Keeper\levels\MAP00055.INF
c:\a\Keeper\levels\MAP00055.LGT
c:\a\Keeper\levels\MAP00055.ORI
c:\a\Keeper\levels\MAP00055.OWN
c:\a\Keeper\levels\MAP00055.SLB
c:\a\Keeper\levels\MAP00055.TMN
c:\a\Keeper\levels\MAP00055.TNG
c:\a\Keeper\levels\MAP00055.TXT
c:\a\Keeper\levels\MAP00055.WIB
c:\a\Keeper\levels\MAP00056.APT
c:\a\Keeper\levels\MAP00056.CLM
c:\a\Keeper\levels\MAP00056.DAT
c:\a\Keeper\levels\MAP00056.FLG
c:\a\Keeper\levels\MAP00056.INF
c:\a\Keeper\levels\MAP00056.LGT
c:\a\Keeper\levels\MAP00056.ORI
c:\a\Keeper\levels\MAP00056.OWN
c:\a\Keeper\levels\MAP00056.SLB
c:\a\Keeper\levels\MAP00056.TMN
c:\a\Keeper\levels\MAP00056.TNG
c:\a\Keeper\levels\MAP00056.TXT
c:\a\Keeper\levels\MAP00056.WIB
c:\a\Keeper\levels\MAP00057.APT
c:\a\Keeper\levels\MAP00057.CLM
c:\a\Keeper\levels\MAP00057.DAT
c:\a\Keeper\levels\MAP00057.FLG
c:\a\Keeper\levels\MAP00057.INF
c:\a\Keeper\levels\MAP00057.LGT
c:\a\Keeper\levels\MAP00057.ORI
c:\a\Keeper\levels\MAP00057.OWN
c:\a\Keeper\levels\MAP00057.SLB
c:\a\Keeper\levels\MAP00057.TMN
c:\a\Keeper\levels\MAP00057.TNG
c:\a\Keeper\levels\MAP00057.TXT
c:\a\Keeper\levels\MAP00057.WIB
c:\a\Keeper\levels\MAP00058.APT
c:\a\Keeper\levels\MAP00058.CLM
c:\a\Keeper\levels\MAP00058.DAT
c:\a\Keeper\levels\MAP00058.DOC
c:\a\Keeper\levels\MAP00058.EFF
c:\a\Keeper\levels\MAP00058.FLG
c:\a\Keeper\levels\MAP00058.INF
c:\a\Keeper\levels\MAP00058.LGT
c:\a\Keeper\levels\MAP00058.ORI
c:\a\Keeper\levels\MAP00058.OWN
c:\a\Keeper\levels\MAP00058.SLB
c:\a\Keeper\levels\MAP00058.TMN
c:\a\Keeper\levels\MAP00058.TNG
c:\a\Keeper\levels\MAP00058.TXT
c:\a\Keeper\levels\MAP00058.VSN
c:\a\Keeper\levels\MAP00058.WIB
c:\a\Keeper\levels\MAP00059.APT
c:\a\Keeper\levels\MAP00059.CLM
c:\a\Keeper\levels\MAP00059.DAT
c:\a\Keeper\levels\MAP00059.FLG
c:\a\Keeper\levels\MAP00059.INF
c:\a\Keeper\levels\MAP00059.LGT
c:\a\Keeper\levels\MAP00059.ORI
c:\a\Keeper\levels\MAP00059.OWN
c:\a\Keeper\levels\MAP00059.SLB
c:\a\Keeper\levels\MAP00059.TMN
c:\a\Keeper\levels\MAP00059.TNG
c:\a\Keeper\levels\MAP00059.TXT
c:\a\Keeper\levels\MAP00059.WIB
c:\a\Keeper\levels\MAP00060.APT
c:\a\Keeper\levels\MAP00060.CLM
c:\a\Keeper\levels\MAP00060.DAT
c:\a\Keeper\levels\MAP00060.FLG
c:\a\Keeper\levels\MAP00060.INF
c:\a\Keeper\levels\MAP00060.LGT
c:\a\Keeper\levels\MAP00060.ORI
c:\a\Keeper\levels\MAP00060.OWN
c:\a\Keeper\levels\MAP00060.SLB
c:\a\Keeper\levels\MAP00060.TMN
c:\a\Keeper\levels\MAP00060.TNG
c:\a\Keeper\levels\MAP00060.TXT
c:\a\Keeper\levels\MAP00060.WIB
c:\a\Keeper\levels\MAP00061.APT
c:\a\Keeper\levels\MAP00061.CLM
c:\a\Keeper\levels\MAP00061.DAT
c:\a\Keeper\levels\MAP00061.FLG
c:\a\Keeper\levels\MAP00061.INF
c:\a\Keeper\levels\MAP00061.LGT
c:\a\Keeper\levels\MAP00061.ORI
c:\a\Keeper\levels\MAP00061.OWN
c:\a\Keeper\levels\MAP00061.SLB
c:\a\Keeper\levels\MAP00061.TMN
c:\a\Keeper\levels\MAP00061.TNG
c:\a\Keeper\levels\MAP00061.TXT
c:\a\Keeper\levels\MAP00061.WIB
c:\a\Keeper\levels\MAP00062.APT
c:\a\Keeper\levels\MAP00062.CLM
c:\a\Keeper\levels\MAP00062.DAT
c:\a\Keeper\levels\MAP00062.FLG
c:\a\Keeper\levels\MAP00062.INF
c:\a\Keeper\levels\MAP00062.LGT
c:\a\Keeper\levels\MAP00062.ORI
c:\a\Keeper\levels\MAP00062.OWN
c:\a\Keeper\levels\MAP00062.SLB
c:\a\Keeper\levels\MAP00062.TMN
c:\a\Keeper\levels\MAP00062.TNG
c:\a\Keeper\levels\MAP00062.TXT
c:\a\Keeper\levels\MAP00062.WIB
c:\a\Keeper\levels\MAP00063.APT
c:\a\Keeper\levels\MAP00063.CLM
c:\a\Keeper\levels\MAP00063.DAT
c:\a\Keeper\levels\MAP00063.FLG
c:\a\Keeper\levels\MAP00063.INF
c:\a\Keeper\levels\MAP00063.LGT
c:\a\Keeper\levels\MAP00063.ORI
c:\a\Keeper\levels\MAP00063.OWN
c:\a\Keeper\levels\MAP00063.SLB
c:\a\Keeper\levels\MAP00063.TMN
c:\a\Keeper\levels\MAP00063.TNG
c:\a\Keeper\levels\MAP00063.TXT
c:\a\Keeper\levels\MAP00063.WIB
c:\a\Keeper\levels\MAP00064.APT
c:\a\Keeper\levels\MAP00064.CLM
c:\a\Keeper\levels\MAP00064.DAT
c:\a\Keeper\levels\MAP00064.FLG
c:\a\Keeper\levels\MAP00064.INF
c:\a\Keeper\levels\MAP00064.LGT
c:\a\Keeper\levels\MAP00064.ORI
c:\a\Keeper\levels\MAP00064.OWN
c:\a\Keeper\levels\MAP00064.SLB
c:\a\Keeper\levels\MAP00064.TMN
c:\a\Keeper\levels\MAP00064.TNG
c:\a\Keeper\levels\MAP00064.TXT
c:\a\Keeper\levels\MAP00064.WIB
c:\a\Keeper\levels\MAP00065.APT
c:\a\Keeper\levels\MAP00065.CLM
c:\a\Keeper\levels\MAP00065.DAT
c:\a\Keeper\levels\MAP00065.FLG
c:\a\Keeper\levels\MAP00065.INF
c:\a\Keeper\levels\MAP00065.LGT
c:\a\Keeper\levels\MAP00065.ORI
c:\a\Keeper\levels\MAP00065.OWN
c:\a\Keeper\levels\MAP00065.SLB
c:\a\Keeper\levels\MAP00065.TMN
c:\a\Keeper\levels\MAP00065.TNG
c:\a\Keeper\levels\MAP00065.TXT
c:\a\Keeper\levels\MAP00065.WIB
c:\a\Keeper\levels\MAP00066.APT
c:\a\Keeper\levels\MAP00066.CLM
c:\a\Keeper\levels\MAP00066.DAT
c:\a\Keeper\levels\MAP00066.FLG
c:\a\Keeper\levels\MAP00066.INF
c:\a\Keeper\levels\MAP00066.LGT
c:\a\Keeper\levels\MAP00066.ORI
c:\a\Keeper\levels\MAP00066.OWN
c:\a\Keeper\levels\MAP00066.SLB
c:\a\Keeper\levels\MAP00066.TMN
c:\a\Keeper\levels\MAP00066.TNG
c:\a\Keeper\levels\MAP00066.TXT
c:\a\Keeper\levels\MAP00066.WIB
c:\a\Keeper\levels\MAP00067.APT
c:\a\Keeper\levels\MAP00067.CLM
c:\a\Keeper\levels\MAP00067.DAT
c:\a\Keeper\levels\MAP00067.FLG
c:\a\Keeper\levels\MAP00067.INF
c:\a\Keeper\levels\MAP00067.LGT
c:\a\Keeper\levels\MAP00067.ORI
c:\a\Keeper\levels\MAP00067.OWN
c:\a\Keeper\levels\MAP00067.SLB
c:\a\Keeper\levels\MAP00067.TMN
c:\a\Keeper\levels\MAP00067.TNG
c:\a\Keeper\levels\MAP00067.TXT
c:\a\Keeper\levels\MAP00067.WIB
c:\a\Keeper\levels\MAP00068.APT
c:\a\Keeper\levels\MAP00068.CLM
c:\a\Keeper\levels\MAP00068.DAT
c:\a\Keeper\levels\MAP00068.FLG
c:\a\Keeper\levels\MAP00068.INF
c:\a\Keeper\levels\MAP00068.LGT
c:\a\Keeper\levels\MAP00068.ORI
c:\a\Keeper\levels\MAP00068.OWN
c:\a\Keeper\levels\MAP00068.SLB
c:\a\Keeper\levels\MAP00068.TMN
c:\a\Keeper\levels\MAP00068.TNG
c:\a\Keeper\levels\MAP00068.TXT
c:\a\Keeper\levels\MAP00068.WIB
c:\a\Keeper\levels\MAP00069.APT
c:\a\Keeper\levels\MAP00069.CLM
c:\a\Keeper\levels\MAP00069.DAT
c:\a\Keeper\levels\MAP00069.FLG
c:\a\Keeper\levels\MAP00069.INF
c:\a\Keeper\levels\MAP00069.LGT
c:\a\Keeper\levels\MAP00069.ORI
c:\a\Keeper\levels\MAP00069.OWN
c:\a\Keeper\levels\MAP00069.SLB
c:\a\Keeper\levels\MAP00069.TMN
c:\a\Keeper\levels\MAP00069.TNG
c:\a\Keeper\levels\MAP00069.TXT
c:\a\Keeper\levels\MAP00069.WIB
c:\a\Keeper\levels\MAP00070.APT
c:\a\Keeper\levels\MAP00070.CLM
c:\a\Keeper\levels\MAP00070.DAT
c:\a\Keeper\levels\MAP00070.FLG
c:\a\Keeper\levels\MAP00070.INF
c:\a\Keeper\levels\MAP00070.LGT
c:\a\Keeper\levels\MAP00070.ORI
c:\a\Keeper\levels\MAP00070.OWN
c:\a\Keeper\levels\MAP00070.SLB
c:\a\Keeper\levels\MAP00070.TMN
c:\a\Keeper\levels\MAP00070.TNG
c:\a\Keeper\levels\MAP00070.TXT
c:\a\Keeper\levels\MAP00070.WIB
c:\a\Keeper\levels\MAP00071.APT
c:\a\Keeper\levels\MAP00071.CLM
c:\a\Keeper\levels\MAP00071.DAT
c:\a\Keeper\levels\MAP00071.FLG
c:\a\Keeper\levels\MAP00071.INF
c:\a\Keeper\levels\MAP00071.LGT
c:\a\Keeper\levels\MAP00071.ORI
c:\a\Keeper\levels\MAP00071.OWN
c:\a\Keeper\levels\MAP00071.SLB
c:\a\Keeper\levels\MAP00071.TMN
c:\a\Keeper\levels\MAP00071.TNG
c:\a\Keeper\levels\MAP00071.TXT
c:\a\Keeper\levels\MAP00071.WIB
c:\a\Keeper\levels\MAP00072.APT
c:\a\Keeper\levels\MAP00072.CLM
c:\a\Keeper\levels\MAP00072.DAT
c:\a\Keeper\levels\MAP00072.FLG
c:\a\Keeper\levels\MAP00072.INF
c:\a\Keeper\levels\MAP00072.LGT
c:\a\Keeper\levels\MAP00072.ORI
c:\a\Keeper\levels\MAP00072.OWN
c:\a\Keeper\levels\MAP00072.SLB
c:\a\Keeper\levels\MAP00072.TMN
c:\a\Keeper\levels\MAP00072.TNG
c:\a\Keeper\levels\MAP00072.TXT
c:\a\Keeper\levels\MAP00072.WIB
c:\a\Keeper\levels\MAP00073.APT
c:\a\Keeper\levels\MAP00073.CLM
c:\a\Keeper\levels\MAP00073.DAT
c:\a\Keeper\levels\MAP00073.FLG
c:\a\Keeper\levels\MAP00073.INF
c:\a\Keeper\levels\MAP00073.LGT
c:\a\Keeper\levels\MAP00073.ORI
c:\a\Keeper\levels\MAP00073.OWN
c:\a\Keeper\levels\MAP00073.SLB
c:\a\Keeper\levels\MAP00073.TMN
c:\a\Keeper\levels\MAP00073.TNG
c:\a\Keeper\levels\MAP00073.TXT
c:\a\Keeper\levels\MAP00073.WIB
c:\a\Keeper\levels\MAP00074.APT
c:\a\Keeper\levels\MAP00074.CLM
c:\a\Keeper\levels\MAP00074.DAT
c:\a\Keeper\levels\MAP00074.FLG
c:\a\Keeper\levels\MAP00074.INF
c:\a\Keeper\levels\MAP00074.LGT
c:\a\Keeper\levels\MAP00074.ORI
c:\a\Keeper\levels\MAP00074.OWN
c:\a\Keeper\levels\MAP00074.SLB
c:\a\Keeper\levels\MAP00074.TMN
c:\a\Keeper\levels\MAP00074.TNG
c:\a\Keeper\levels\MAP00074.TXT
c:\a\Keeper\levels\MAP00074.WIB
c:\a\Keeper\levels\MAP00075.APT
c:\a\Keeper\levels\MAP00075.CLM
c:\a\Keeper\levels\MAP00075.DAT
c:\a\Keeper\levels\MAP00075.FLG
c:\a\Keeper\levels\MAP00075.INF
c:\a\Keeper\levels\MAP00075.LGT
c:\a\Keeper\levels\MAP00075.ORI
c:\a\Keeper\levels\MAP00075.OWN
c:\a\Keeper\levels\MAP00075.SLB
c:\a\Keeper\levels\MAP00075.TMN
c:\a\Keeper\levels\MAP00075.TNG
c:\a\Keeper\levels\MAP00075.TXT
c:\a\Keeper\levels\MAP00075.WIB
c:\a\Keeper\levels\MAP00076.APT
c:\a\Keeper\levels\MAP00076.CLM
c:\a\Keeper\levels\MAP00076.DAT
c:\a\Keeper\levels\MAP00076.FLG
c:\a\Keeper\levels\MAP00076.INF
c:\a\Keeper\levels\MAP00076.LGT
c:\a\Keeper\levels\MAP00076.ORI
c:\a\Keeper\levels\MAP00076.OWN
c:\a\Keeper\levels\MAP00076.SLB
c:\a\Keeper\levels\MAP00076.TMN
c:\a\Keeper\levels\MAP00076.TNG
c:\a\Keeper\levels\MAP00076.TXT
c:\a\Keeper\levels\MAP00076.WIB
c:\a\Keeper\levels\MAP00077.APT
c:\a\Keeper\levels\MAP00077.CLM
c:\a\Keeper\levels\MAP00077.DAT
c:\a\Keeper\levels\MAP00077.DOC
c:\a\Keeper\levels\MAP00077.EFF
c:\a\Keeper\levels\MAP00077.FLG
c:\a\Keeper\levels\MAP00077.INF
c:\a\Keeper\levels\MAP00077.LGT
c:\a\Keeper\levels\MAP00077.ORI
c:\a\Keeper\levels\MAP00077.OWN
c:\a\Keeper\levels\MAP00077.SLB
c:\a\Keeper\levels\MAP00077.TMN
c:\a\Keeper\levels\MAP00077.TNG
c:\a\Keeper\levels\MAP00077.TXT
c:\a\Keeper\levels\MAP00077.VSN
c:\a\Keeper\levels\MAP00077.WIB
c:\a\Keeper\levels\MAP00078.APT
c:\a\Keeper\levels\MAP00078.CLM
c:\a\Keeper\levels\MAP00078.DAT
c:\a\Keeper\levels\MAP00078.FLG
c:\a\Keeper\levels\MAP00078.INF
c:\a\Keeper\levels\MAP00078.LGT
c:\a\Keeper\levels\MAP00078.ORI
c:\a\Keeper\levels\MAP00078.OWN
c:\a\Keeper\levels\MAP00078.SLB
c:\a\Keeper\levels\MAP00078.TMN
c:\a\Keeper\levels\MAP00078.TNG
c:\a\Keeper\levels\MAP00078.TXT
c:\a\Keeper\levels\MAP00078.WIB
c:\a\Keeper\levels\MAP00079.APT
c:\a\Keeper\levels\MAP00079.CLM
c:\a\Keeper\levels\MAP00079.DAT
c:\a\Keeper\levels\MAP00079.FLG
c:\a\Keeper\levels\MAP00079.INF
c:\a\Keeper\levels\MAP00079.LGT
c:\a\Keeper\levels\MAP00079.ORI
c:\a\Keeper\levels\MAP00079.OWN
c:\a\Keeper\levels\MAP00079.SLB
c:\a\Keeper\levels\MAP00079.TMN
c:\a\Keeper\levels\MAP00079.TNG
c:\a\Keeper\levels\MAP00079.TXT
c:\a\Keeper\levels\MAP00079.WIB
c:\a\Keeper\levels\MAP00080.APT
c:\a\Keeper\levels\MAP00080.BAK
c:\a\Keeper\levels\MAP00080.CEI
c:\a\Keeper\levels\MAP00080.CLM
c:\a\Keeper\levels\MAP00080.DAT
c:\a\Keeper\levels\MAP00080.ERR
c:\a\Keeper\levels\MAP00080.FLG
c:\a\Keeper\levels\MAP00080.INF
c:\a\Keeper\levels\MAP00080.LGT
c:\a\Keeper\levels\MAP00080.ORI
c:\a\Keeper\levels\MAP00080.OWN
c:\a\Keeper\levels\MAP00080.SLB
c:\a\Keeper\levels\MAP00080.TMN
c:\a\Keeper\levels\MAP00080.TNG
c:\a\Keeper\levels\MAP00080.TXT
c:\a\Keeper\levels\MAP00080.WIB
c:\a\Keeper\levels\MAP00080.WLB
c:\a\Keeper\levels\MAP00081.APT
c:\a\Keeper\levels\MAP00081.BAK
c:\a\Keeper\levels\MAP00081.CLM
c:\a\Keeper\levels\MAP00081.DAT
c:\a\Keeper\levels\MAP00081.INF
c:\a\Keeper\levels\MAP00081.LGT
c:\a\Keeper\levels\MAP00081.OWN
c:\a\Keeper\levels\MAP00081.SLB
c:\a\Keeper\levels\MAP00081.TNG
c:\a\Keeper\levels\MAP00081.TXT
c:\a\Keeper\levels\MAP00081.WIB
c:\a\Keeper\levels\MAP00081.WLB
c:\a\Keeper\levels\MAP00082.APT
c:\a\Keeper\levels\MAP00082.BAK
c:\a\Keeper\levels\MAP00082.CLM
c:\a\Keeper\levels\MAP00082.DAT
c:\a\Keeper\levels\MAP00082.INF
c:\a\Keeper\levels\MAP00082.LGT
c:\a\Keeper\levels\MAP00082.OWN
c:\a\Keeper\levels\MAP00082.SLB
c:\a\Keeper\levels\MAP00082.TNG
c:\a\Keeper\levels\MAP00082.TXT
c:\a\Keeper\levels\MAP00082.WIB
c:\a\Keeper\levels\MAP00082.WLB
c:\a\Keeper\levels\MAP00083.APT
c:\a\Keeper\levels\MAP00083.BAK
c:\a\Keeper\levels\MAP00083.CLM
c:\a\Keeper\levels\MAP00083.DAT
c:\a\Keeper\levels\MAP00083.INF
c:\a\Keeper\levels\MAP00083.LGT
c:\a\Keeper\levels\MAP00083.OWN
c:\a\Keeper\levels\MAP00083.SLB
c:\a\Keeper\levels\MAP00083.TNG
c:\a\Keeper\levels\MAP00083.TXT
c:\a\Keeper\levels\MAP00083.WIB
c:\a\Keeper\levels\MAP00083.WLB
c:\a\Keeper\levels\MAP00084.APT
c:\a\Keeper\levels\MAP00084.BAK
c:\a\Keeper\levels\MAP00084.CLM
c:\a\Keeper\levels\MAP00084.DAT
c:\a\Keeper\levels\MAP00084.INF
c:\a\Keeper\levels\MAP00084.LGT
c:\a\Keeper\levels\MAP00084.OWN
c:\a\Keeper\levels\MAP00084.SLB
c:\a\Keeper\levels\MAP00084.TNG
c:\a\Keeper\levels\MAP00084.TXT
c:\a\Keeper\levels\MAP00084.WIB
c:\a\Keeper\levels\MAP00084.WLB
c:\a\Keeper\levels\MAP00085.APT
c:\a\Keeper\levels\MAP00085.BAK
c:\a\Keeper\levels\MAP00085.CLM
c:\a\Keeper\levels\MAP00085.DAT
c:\a\Keeper\levels\MAP00085.INF
c:\a\Keeper\levels\MAP00085.LGT
c:\a\Keeper\levels\MAP00085.OWN
c:\a\Keeper\levels\MAP00085.SLB
c:\a\Keeper\levels\MAP00085.TNG
c:\a\Keeper\levels\MAP00085.TXT
c:\a\Keeper\levels\MAP00085.WIB
c:\a\Keeper\levels\MAP00085.WLB
c:\a\Keeper\levels\MAP00086.APT
c:\a\Keeper\levels\MAP00086.BAK
c:\a\Keeper\levels\MAP00086.CLM
c:\a\Keeper\levels\MAP00086.DAT
c:\a\Keeper\levels\MAP00086.INF
c:\a\Keeper\levels\MAP00086.LGT
c:\a\Keeper\levels\MAP00086.OWN
c:\a\Keeper\levels\MAP00086.SLB
c:\a\Keeper\levels\MAP00086.TNG
c:\a\Keeper\levels\MAP00086.TXT
c:\a\Keeper\levels\MAP00086.WIB
c:\a\Keeper\levels\MAP00086.WLB
c:\a\Keeper\levels\MAP00087.APT
c:\a\Keeper\levels\MAP00087.BAK
c:\a\Keeper\levels\MAP00087.CLM
c:\a\Keeper\levels\MAP00087.DAT
c:\a\Keeper\levels\MAP00087.INF
c:\a\Keeper\levels\MAP00087.LGT
c:\a\Keeper\levels\MAP00087.OWN
c:\a\Keeper\levels\MAP00087.SLB
c:\a\Keeper\levels\MAP00087.TNG
c:\a\Keeper\levels\MAP00087.TXT
c:\a\Keeper\levels\MAP00087.WIB
c:\a\Keeper\levels\MAP00087.WLB
c:\a\Keeper\levels\MAP00088.APT
c:\a\Keeper\levels\MAP00088.BAK
c:\a\Keeper\levels\MAP00088.CLM
c:\a\Keeper\levels\MAP00088.DAT
c:\a\Keeper\levels\MAP00088.INF
c:\a\Keeper\levels\MAP00088.LGT
c:\a\Keeper\levels\MAP00088.OWN
c:\a\Keeper\levels\MAP00088.SLB
c:\a\Keeper\levels\MAP00088.TNG
c:\a\Keeper\levels\MAP00088.TXT
c:\a\Keeper\levels\MAP00088.WIB
c:\a\Keeper\levels\MAP00088.WLB
c:\a\Keeper\levels\MAP00091.APT
c:\a\Keeper\levels\MAP00091.BAK
c:\a\Keeper\levels\MAP00091.CLM
c:\a\Keeper\levels\MAP00091.DAT
c:\a\Keeper\levels\MAP00091.INF
c:\a\Keeper\levels\MAP00091.LGT
c:\a\Keeper\levels\MAP00091.OWN
c:\a\Keeper\levels\MAP00091.SLB
c:\a\Keeper\levels\MAP00091.TMN
c:\a\Keeper\levels\MAP00091.TNG
c:\a\Keeper\levels\MAP00091.TXT
c:\a\Keeper\levels\MAP00091.WIB
c:\a\Keeper\levels\MAP00091.WLB
c:\a\Keeper\levels\MAP00092.APT
c:\a\Keeper\levels\MAP00092.BAK
c:\a\Keeper\levels\MAP00092.CLM
c:\a\Keeper\levels\MAP00092.DAT
c:\a\Keeper\levels\MAP00092.FLG
c:\a\Keeper\levels\MAP00092.INF
c:\a\Keeper\levels\MAP00092.LGT
c:\a\Keeper\levels\MAP00092.ORI
c:\a\Keeper\levels\MAP00092.OWN
c:\a\Keeper\levels\MAP00092.SLB
c:\a\Keeper\levels\MAP00092.TMN
c:\a\Keeper\levels\MAP00092.TNG
c:\a\Keeper\levels\MAP00092.TXT
c:\a\Keeper\levels\MAP00092.WIB
c:\a\Keeper\levels\MAP00092.WLB
c:\a\Keeper\levels\MAP00093.APT
c:\a\Keeper\levels\MAP00093.BAK
c:\a\Keeper\levels\MAP00093.CLM
c:\a\Keeper\levels\MAP00093.DAT
c:\a\Keeper\levels\MAP00093.FLG
c:\a\Keeper\levels\MAP00093.INF
c:\a\Keeper\levels\MAP00093.LGT
c:\a\Keeper\levels\MAP00093.ORI
c:\a\Keeper\levels\MAP00093.OWN
c:\a\Keeper\levels\MAP00093.SLB
c:\a\Keeper\levels\MAP00093.TMN
c:\a\Keeper\levels\MAP00093.TNG
c:\a\Keeper\levels\MAP00093.TXT
c:\a\Keeper\levels\MAP00093.WIB
c:\a\Keeper\levels\MAP00093.WLB
c:\a\Keeper\levels\MAP00094.APT
c:\a\Keeper\levels\MAP00094.BAK
c:\a\Keeper\levels\MAP00094.CLM
c:\a\Keeper\levels\MAP00094.DAT
c:\a\Keeper\levels\MAP00094.FLG
c:\a\Keeper\levels\MAP00094.INF
c:\a\Keeper\levels\MAP00094.LGT
c:\a\Keeper\levels\MAP00094.ORI
c:\a\Keeper\levels\MAP00094.OWN
c:\a\Keeper\levels\MAP00094.SLB
c:\a\Keeper\levels\MAP00094.TMN
c:\a\Keeper\levels\MAP00094.TNG
c:\a\Keeper\levels\MAP00094.TXT
c:\a\Keeper\levels\MAP00094.WIB
c:\a\Keeper\levels\MAP00094.WLB
c:\a\Keeper\levels\MAP00095.APT
c:\a\Keeper\levels\MAP00095.BAK
c:\a\Keeper\levels\MAP00095.CLM
c:\a\Keeper\levels\MAP00095.DAT
c:\a\Keeper\levels\MAP00095.FLG
c:\a\Keeper\levels\MAP00095.INF
c:\a\Keeper\levels\MAP00095.LGT
c:\a\Keeper\levels\MAP00095.ORI
c:\a\Keeper\levels\MAP00095.OWN
c:\a\Keeper\levels\MAP00095.SLB
c:\a\Keeper\levels\MAP00095.TMN
c:\a\Keeper\levels\MAP00095.TNG
c:\a\Keeper\levels\MAP00095.TXT
c:\a\Keeper\levels\MAP00095.WIB
c:\a\Keeper\levels\MAP00095.WLB
c:\a\Keeper\levels\MAP00097.APT
c:\a\Keeper\levels\MAP00097.BAK
c:\a\Keeper\levels\MAP00097.CLM
c:\a\Keeper\levels\MAP00097.DAT
c:\a\Keeper\levels\MAP00097.INF
c:\a\Keeper\levels\MAP00097.LGT
c:\a\Keeper\levels\MAP00097.OWN
c:\a\Keeper\levels\MAP00097.SLB
c:\a\Keeper\levels\MAP00097.TNG
c:\a\Keeper\levels\MAP00097.TXT
c:\a\Keeper\levels\MAP00097.WIB
c:\a\Keeper\levels\MAP00097.WLB
c:\a\Keeper\levels\MAP00100.APT
c:\a\Keeper\levels\MAP00100.CLM
c:\a\Keeper\levels\MAP00100.DAT
c:\a\Keeper\levels\MAP00100.FLG
c:\a\Keeper\levels\MAP00100.INF
c:\a\Keeper\levels\MAP00100.LGT
c:\a\Keeper\levels\MAP00100.ORI
c:\a\Keeper\levels\MAP00100.OWN
c:\a\Keeper\levels\MAP00100.SLB
c:\a\Keeper\levels\MAP00100.TMN
c:\a\Keeper\levels\MAP00100.TNG
c:\a\Keeper\levels\MAP00100.TXT
c:\a\Keeper\levels\MAP00100.WIB
c:\a\Keeper\levels\MAP00101.APT
c:\a\Keeper\levels\MAP00101.CLM
c:\a\Keeper\levels\MAP00101.DAT
c:\a\Keeper\levels\MAP00101.FLG
c:\a\Keeper\levels\MAP00101.INF
c:\a\Keeper\levels\MAP00101.LGT
c:\a\Keeper\levels\MAP00101.ORI
c:\a\Keeper\levels\MAP00101.OWN
c:\a\Keeper\levels\MAP00101.SLB
c:\a\Keeper\levels\MAP00101.TMN
c:\a\Keeper\levels\MAP00101.TNG
c:\a\Keeper\levels\MAP00101.TXT
c:\a\Keeper\levels\MAP00101.WIB
c:\a\Keeper\levels\MAP00102.APT
c:\a\Keeper\levels\MAP00102.CLM
c:\a\Keeper\levels\MAP00102.DAT
c:\a\Keeper\levels\MAP00102.FLG
c:\a\Keeper\levels\MAP00102.INF
c:\a\Keeper\levels\MAP00102.LGT
c:\a\Keeper\levels\MAP00102.ORI
c:\a\Keeper\levels\MAP00102.OWN
c:\a\Keeper\levels\MAP00102.SLB
c:\a\Keeper\levels\MAP00102.TMN
c:\a\Keeper\levels\MAP00102.TNG
c:\a\Keeper\levels\MAP00102.TXT
c:\a\Keeper\levels\MAP00102.WIB
c:\a\Keeper\levels\MAP00103.APT
c:\a\Keeper\levels\MAP00103.CLM
c:\a\Keeper\levels\MAP00103.DAT
c:\a\Keeper\levels\MAP00103.FLG
c:\a\Keeper\levels\MAP00103.INF
c:\a\Keeper\levels\MAP00103.LGT
c:\a\Keeper\levels\MAP00103.ORI
c:\a\Keeper\levels\MAP00103.OWN
c:\a\Keeper\levels\MAP00103.SLB
c:\a\Keeper\levels\MAP00103.TMN
c:\a\Keeper\levels\MAP00103.TNG
c:\a\Keeper\levels\MAP00103.TXT
c:\a\Keeper\levels\MAP00103.WIB
c:\a\Keeper\levels\MAP00104.APT
c:\a\Keeper\levels\MAP00104.CLM
c:\a\Keeper\levels\MAP00104.DAT
c:\a\Keeper\levels\MAP00104.FLG
c:\a\Keeper\levels\MAP00104.INF
c:\a\Keeper\levels\MAP00104.LGT
c:\a\Keeper\levels\MAP00104.ORI
c:\a\Keeper\levels\MAP00104.OWN
c:\a\Keeper\levels\MAP00104.SLB
c:\a\Keeper\levels\MAP00104.TMN
c:\a\Keeper\levels\MAP00104.TNG
c:\a\Keeper\levels\MAP00104.TXT
c:\a\Keeper\levels\MAP00104.WIB
c:\a\Keeper\levels\MAP00105.APT
c:\a\Keeper\levels\MAP00105.CLM
c:\a\Keeper\levels\MAP00105.DAT
c:\a\Keeper\levels\MAP00105.FLG
c:\a\Keeper\levels\MAP00105.INF
c:\a\Keeper\levels\MAP00105.LGT
c:\a\Keeper\levels\MAP00105.ORI
c:\a\Keeper\levels\MAP00105.OWN
c:\a\Keeper\levels\MAP00105.SLB
c:\a\Keeper\levels\MAP00105.TMN
c:\a\Keeper\levels\MAP00105.TNG
c:\a\Keeper\levels\MAP00105.TXT
c:\a\Keeper\levels\MAP00105.WIB
c:\a\Keeper\levels\MAP00122.APT
c:\a\Keeper\levels\MAP00122.CLM
c:\a\Keeper\levels\MAP00122.DAT
c:\a\Keeper\levels\MAP00122.INF
c:\a\Keeper\levels\MAP00122.LGT
c:\a\Keeper\levels\MAP00122.OWN
c:\a\Keeper\levels\MAP00122.SLB
c:\a\Keeper\levels\MAP00122.TNG
c:\a\Keeper\levels\MAP00122.TXT
c:\a\Keeper\levels\MAP00122.WIB
c:\a\Keeper\levels\MAP00122.WLB
c:\a\Keeper\levels\MAP00123.APT
c:\a\Keeper\levels\MAP00123.CLM
c:\a\Keeper\levels\MAP00123.DAT
c:\a\Keeper\levels\MAP00123.INF
c:\a\Keeper\levels\MAP00123.LGT
c:\a\Keeper\levels\MAP00123.OWN
c:\a\Keeper\levels\MAP00123.SLB
c:\a\Keeper\levels\MAP00123.TNG
c:\a\Keeper\levels\MAP00123.TXT
c:\a\Keeper\levels\MAP00123.WIB
c:\a\Keeper\levels\MAP00123.WLB
c:\a\Keeper\levels\MAP00124.APT
c:\a\Keeper\levels\MAP00124.BAK
c:\a\Keeper\levels\MAP00124.CLM
c:\a\Keeper\levels\MAP00124.DAT
c:\a\Keeper\levels\MAP00124.INF
c:\a\Keeper\levels\MAP00124.LGT
c:\a\Keeper\levels\MAP00124.OWN
c:\a\Keeper\levels\MAP00124.SLB
c:\a\Keeper\levels\MAP00124.TNG
c:\a\Keeper\levels\MAP00124.TXT
c:\a\Keeper\levels\MAP00124.WIB
c:\a\Keeper\levels\MAP00124.WLB
c:\a\Keeper\levels\MAP00126.APT
c:\a\Keeper\levels\MAP00126.BAK
c:\a\Keeper\levels\MAP00126.CLM
c:\a\Keeper\levels\MAP00126.DAT
c:\a\Keeper\levels\MAP00126.INF
c:\a\Keeper\levels\MAP00126.LGT
c:\a\Keeper\levels\MAP00126.OWN
c:\a\Keeper\levels\MAP00126.SLB
c:\a\Keeper\levels\MAP00126.TNG
c:\a\Keeper\levels\MAP00126.TXT
c:\a\Keeper\levels\MAP00126.WIB
c:\a\Keeper\levels\MAP00126.WLB
c:\a\Keeper\levels\MAP00127.APT
c:\a\Keeper\levels\MAP00127.CLM
c:\a\Keeper\levels\MAP00127.DAT
c:\a\Keeper\levels\MAP00127.INF
c:\a\Keeper\levels\MAP00127.LGT
c:\a\Keeper\levels\MAP00127.OWN
c:\a\Keeper\levels\MAP00127.SLB
c:\a\Keeper\levels\MAP00127.TNG
c:\a\Keeper\levels\MAP00127.TXT
c:\a\Keeper\levels\MAP00127.WIB
c:\a\Keeper\levels\MAP00127.WLB
c:\a\Keeper\levels\MAP00130.APT
c:\a\Keeper\levels\MAP00130.CLM
c:\a\Keeper\levels\MAP00130.DAT
c:\a\Keeper\levels\MAP00130.INF
c:\a\Keeper\levels\MAP00130.LGT
c:\a\Keeper\levels\MAP00130.OWN
c:\a\Keeper\levels\MAP00130.SLB
c:\a\Keeper\levels\MAP00130.TNG
c:\a\Keeper\levels\MAP00130.TXT
c:\a\Keeper\levels\MAP00130.WIB
c:\a\Keeper\levels\MAP00130.WLB
c:\a\Keeper\levels\MAP00131.APT
c:\a\Keeper\levels\MAP00131.BAK
c:\a\Keeper\levels\MAP00131.CLM
c:\a\Keeper\levels\MAP00131.DAT
c:\a\Keeper\levels\MAP00131.INF
c:\a\Keeper\levels\MAP00131.LGT
c:\a\Keeper\levels\MAP00131.OWN
c:\a\Keeper\levels\MAP00131.SLB
c:\a\Keeper\levels\MAP00131.TNG
c:\a\Keeper\levels\MAP00131.TXT
c:\a\Keeper\levels\MAP00131.WIB
c:\a\Keeper\levels\MAP00131.WLB
c:\a\Keeper\levels\MAP00132.APT
c:\a\Keeper\levels\MAP00132.CLM
c:\a\Keeper\levels\MAP00132.DAT
c:\a\Keeper\levels\MAP00132.INF
c:\a\Keeper\levels\MAP00132.LGT
c:\a\Keeper\levels\MAP00132.OWN
c:\a\Keeper\levels\MAP00132.SLB
c:\a\Keeper\levels\MAP00132.TNG
c:\a\Keeper\levels\MAP00132.TXT
c:\a\Keeper\levels\MAP00132.WIB
c:\a\Keeper\levels\MAP00132.WLB
c:\a\Keeper\levels\MAP00133.APT
c:\a\Keeper\levels\MAP00133.BAK
c:\a\Keeper\levels\MAP00133.CLM
c:\a\Keeper\levels\MAP00133.DAT
c:\a\Keeper\levels\MAP00133.INF
c:\a\Keeper\levels\MAP00133.LGT
c:\a\Keeper\levels\MAP00133.OWN
c:\a\Keeper\levels\MAP00133.SLB
c:\a\Keeper\levels\MAP00133.TNG
c:\a\Keeper\levels\MAP00133.TXT
c:\a\Keeper\levels\MAP00133.WIB
c:\a\Keeper\levels\MAP00133.WLB
c:\a\Keeper\levels\MAP00135.APT
c:\a\Keeper\levels\MAP00135.CLM
c:\a\Keeper\levels\MAP00135.DAT
c:\a\Keeper\levels\MAP00135.INF
c:\a\Keeper\levels\MAP00135.LGT
c:\a\Keeper\levels\MAP00135.OWN
c:\a\Keeper\levels\MAP00135.SLB
c:\a\Keeper\levels\MAP00135.TNG
c:\a\Keeper\levels\MAP00135.TXT
c:\a\Keeper\levels\MAP00135.WIB
c:\a\Keeper\levels\MAP00135.WLB
c:\a\Keeper\levels\MAP00145.APT
c:\a\Keeper\levels\MAP00145.CLM
c:\a\Keeper\levels\MAP00145.DAT
c:\a\Keeper\levels\MAP00145.INF
c:\a\Keeper\levels\MAP00145.LGT
c:\a\Keeper\levels\MAP00145.OWN
c:\a\Keeper\levels\MAP00145.SLB
c:\a\Keeper\levels\MAP00145.TNG
c:\a\Keeper\levels\MAP00145.TXT
c:\a\Keeper\levels\MAP00145.WIB
c:\a\Keeper\levels\MAP00145.WLB
c:\a\Keeper\levels\MAP00146.APT
c:\a\Keeper\levels\MAP00146.CLM
c:\a\Keeper\levels\MAP00146.DAT
c:\a\Keeper\levels\MAP00146.INF
c:\a\Keeper\levels\MAP00146.LGT
c:\a\Keeper\levels\MAP00146.OWN
c:\a\Keeper\levels\MAP00146.SLB
c:\a\Keeper\levels\MAP00146.TNG
c:\a\Keeper\levels\MAP00146.TXT
c:\a\Keeper\levels\MAP00146.WIB
c:\a\Keeper\levels\MAP00146.WLB
c:\a\Keeper\levels\MAP00147.APT
c:\a\Keeper\levels\MAP00147.CLM
c:\a\Keeper\levels\MAP00147.DAT
c:\a\Keeper\levels\MAP00147.INF
c:\a\Keeper\levels\MAP00147.LGT
c:\a\Keeper\levels\MAP00147.OWN
c:\a\Keeper\levels\MAP00147.SLB
c:\a\Keeper\levels\MAP00147.TNG
c:\a\Keeper\levels\MAP00147.TXT
c:\a\Keeper\levels\MAP00147.WIB
c:\a\Keeper\levels\MAP00147.WLB
c:\a\Keeper\levels\MAP00149.APT
c:\a\Keeper\levels\MAP00149.CLM
c:\a\Keeper\levels\MAP00149.DAT
c:\a\Keeper\levels\MAP00149.INF
c:\a\Keeper\levels\MAP00149.LGT
c:\a\Keeper\levels\MAP00149.OWN
c:\a\Keeper\levels\MAP00149.SLB
c:\a\Keeper\levels\MAP00149.TNG
c:\a\Keeper\levels\MAP00149.TXT
c:\a\Keeper\levels\MAP00149.WIB
c:\a\Keeper\levels\MAP00149.WLB
c:\a\Keeper\levels\MAP00150.APT
c:\a\Keeper\levels\MAP00150.CLM
c:\a\Keeper\levels\MAP00150.DAT
c:\a\Keeper\levels\MAP00150.INF
c:\a\Keeper\levels\MAP00150.LGT
c:\a\Keeper\levels\MAP00150.OWN
c:\a\Keeper\levels\MAP00150.SLB
c:\a\Keeper\levels\MAP00150.TNG
c:\a\Keeper\levels\MAP00150.TXT
c:\a\Keeper\levels\MAP00150.WIB
c:\a\Keeper\levels\MAP00150.WLB
c:\a\Keeper\levels\MAP01000.APT
c:\a\Keeper\levels\MAP01000.CLM
c:\a\Keeper\levels\MAP01000.DAT
c:\a\Keeper\levels\MAP01000.FLG
c:\a\Keeper\levels\MAP01000.INF
c:\a\Keeper\levels\MAP01000.LGT
c:\a\Keeper\levels\MAP01000.ORI
c:\a\Keeper\levels\MAP01000.OWN
c:\a\Keeper\levels\MAP01000.SLB
c:\a\Keeper\levels\MAP01000.TMN
c:\a\Keeper\levels\MAP01000.TNG
c:\a\Keeper\levels\MAP01000.VSN
c:\a\Keeper\levels\MAP01000.WIB
c:\a\Keeper\Mss32.dll
c:\a\Keeper\MSVCRTD.DLL
c:\a\Keeper\SMACKW32.DLL
c:\a\Keeper\sound\ADRV688.DIG
c:\a\Keeper\sound\AILDRVR.LST
c:\a\Keeper\sound\AILDRVRG.LST
c:\a\Keeper\sound\AILDRVRI.LST
c:\a\Keeper\sound\atlas\dutch\BAD01.WAV
c:\a\Keeper\sound\atlas\dutch\BAD02.WAV
c:\a\Keeper\sound\atlas\dutch\BAD03.WAV
c:\a\Keeper\sound\atlas\dutch\BAD04.WAV
c:\a\Keeper\sound\atlas\dutch\BAD05.WAV
c:\a\Keeper\sound\atlas\dutch\BAD06.WAV
c:\a\Keeper\sound\atlas\dutch\BAD07.WAV
c:\a\Keeper\sound\atlas\dutch\BAD08.WAV
c:\a\Keeper\sound\atlas\dutch\BAD09.WAV
c:\a\Keeper\sound\atlas\dutch\BAD10.WAV
c:\a\Keeper\sound\atlas\dutch\BAD11.WAV
c:\a\Keeper\sound\atlas\dutch\BAD12.WAV
c:\a\Keeper\sound\atlas\dutch\BAD13.WAV
c:\a\Keeper\sound\atlas\dutch\BAD14.WAV
c:\a\Keeper\sound\atlas\dutch\BAD15.WAV
c:\a\Keeper\sound\atlas\dutch\BAD16.WAV
c:\a\Keeper\sound\atlas\dutch\BAD17.WAV
c:\a\Keeper\sound\atlas\dutch\BAD18.WAV
c:\a\Keeper\sound\atlas\dutch\BAD19.WAV
c:\a\Keeper\sound\atlas\dutch\BAD20.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD01.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD02.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD03.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD04.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD05.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD06.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD07.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD08.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD09.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD10.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD11.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD12.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD13.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD14.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD15.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD16.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD17.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD18.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD19.WAV
c:\a\Keeper\sound\atlas\dutch\GOOD20.WAV
c:\a\Keeper\sound\atlas\english\BAD01.WAV
c:\a\Keeper\sound\atlas\english\BAD02.WAV
c:\a\Keeper\sound\atlas\english\BAD03.WAV
c:\a\Keeper\sound\atlas\english\BAD04.WAV
c:\a\Keeper\sound\atlas\english\BAD05.WAV
c:\a\Keeper\sound\atlas\english\BAD06.WAV
c:\a\Keeper\sound\atlas\english\BAD07.WAV
c:\a\Keeper\sound\atlas\english\BAD08.WAV
c:\a\Keeper\sound\atlas\english\BAD09.WAV
c:\a\Keeper\sound\atlas\english\BAD10.WAV
c:\a\Keeper\sound\atlas\english\BAD11.WAV
c:\a\Keeper\sound\atlas\english\BAD12.WAV
c:\a\Keeper\sound\atlas\english\BAD13.WAV
c:\a\Keeper\sound\atlas\english\BAD14.WAV
c:\a\Keeper\sound\atlas\english\BAD15.WAV
c:\a\Keeper\sound\atlas\english\BAD16.WAV
c:\a\Keeper\sound\atlas\english\BAD17.WAV
c:\a\Keeper\sound\atlas\english\BAD18.WAV
c:\a\Keeper\sound\atlas\english\BAD19.WAV
c:\a\Keeper\sound\atlas\english\BAD20.WAV
c:\a\Keeper\sound\atlas\english\GOOD01.WAV
c:\a\Keeper\sound\atlas\english\GOOD02.WAV
c:\a\Keeper\sound\atlas\english\GOOD03.WAV
c:\a\Keeper\sound\atlas\english\GOOD04.WAV
c:\a\Keeper\sound\atlas\english\GOOD05.WAV
c:\a\Keeper\sound\atlas\english\GOOD06.WAV
c:\a\Keeper\sound\atlas\english\GOOD07.WAV
c:\a\Keeper\sound\atlas\english\GOOD08.WAV
c:\a\Keeper\sound\atlas\english\GOOD09.WAV
c:\a\Keeper\sound\atlas\english\GOOD10.WAV
c:\a\Keeper\sound\atlas\english\GOOD11.WAV
c:\a\Keeper\sound\atlas\english\GOOD12.WAV
c:\a\Keeper\sound\atlas\english\GOOD13.WAV
c:\a\Keeper\sound\atlas\english\GOOD14.WAV
c:\a\Keeper\sound\atlas\english\GOOD15.WAV
c:\a\Keeper\sound\atlas\english\GOOD16.WAV
c:\a\Keeper\sound\atlas\english\GOOD17.WAV
c:\a\Keeper\sound\atlas\english\GOOD18.WAV
c:\a\Keeper\sound\atlas\english\GOOD19.WAV
c:\a\Keeper\sound\atlas\english\GOOD20.WAV
c:\a\Keeper\sound\atlas\french\BAD01.WAV
c:\a\Keeper\sound\atlas\french\BAD02.WAV
c:\a\Keeper\sound\atlas\french\BAD03.WAV
c:\a\Keeper\sound\atlas\french\BAD04.WAV
c:\a\Keeper\sound\atlas\french\BAD05.WAV
c:\a\Keeper\sound\atlas\french\BAD06.WAV
c:\a\Keeper\sound\atlas\french\BAD07.WAV
c:\a\Keeper\sound\atlas\french\BAD08.WAV
c:\a\Keeper\sound\atlas\french\BAD09.WAV
c:\a\Keeper\sound\atlas\french\BAD10.WAV
c:\a\Keeper\sound\atlas\french\BAD11.WAV
c:\a\Keeper\sound\atlas\french\BAD12.WAV
c:\a\Keeper\sound\atlas\french\BAD13.WAV
c:\a\Keeper\sound\atlas\french\BAD14.WAV
c:\a\Keeper\sound\atlas\french\BAD15.WAV
c:\a\Keeper\sound\atlas\french\BAD16.WAV
c:\a\Keeper\sound\atlas\french\BAD17.WAV
c:\a\Keeper\sound\atlas\french\BAD18.WAV
c:\a\Keeper\sound\atlas\french\BAD19.WAV
c:\a\Keeper\sound\atlas\french\BAD20.WAV
c:\a\Keeper\sound\atlas\french\GOOD01.WAV
c:\a\Keeper\sound\atlas\french\GOOD02.WAV
c:\a\Keeper\sound\atlas\french\GOOD03.WAV
c:\a\Keeper\sound\atlas\french\GOOD04.WAV
c:\a\Keeper\sound\atlas\french\GOOD05.WAV
c:\a\Keeper\sound\atlas\french\GOOD06.WAV
c:\a\Keeper\sound\atlas\french\GOOD07.WAV
c:\a\Keeper\sound\atlas\french\GOOD08.WAV
c:\a\Keeper\sound\atlas\french\GOOD09.WAV
c:\a\Keeper\sound\atlas\french\GOOD10.WAV
c:\a\Keeper\sound\atlas\french\GOOD11.WAV
c:\a\Keeper\sound\atlas\french\GOOD12.WAV
c:\a\Keeper\sound\atlas\french\GOOD13.WAV
c:\a\Keeper\sound\atlas\french\GOOD14.WAV
c:\a\Keeper\sound\atlas\french\GOOD15.WAV
c:\a\Keeper\sound\atlas\french\GOOD16.WAV
c:\a\Keeper\sound\atlas\french\GOOD17.WAV
c:\a\Keeper\sound\atlas\french\GOOD18.WAV
c:\a\Keeper\sound\atlas\french\GOOD19.WAV
c:\a\Keeper\sound\atlas\french\GOOD20.WAV
c:\a\Keeper\sound\atlas\polish\BAD01.WAV
c:\a\Keeper\sound\atlas\polish\BAD02.WAV
c:\a\Keeper\sound\atlas\polish\BAD03.WAV
c:\a\Keeper\sound\atlas\polish\BAD04.WAV
c:\a\Keeper\sound\atlas\polish\BAD05.WAV
c:\a\Keeper\sound\atlas\polish\BAD06.WAV
c:\a\Keeper\sound\atlas\polish\BAD07.WAV
c:\a\Keeper\sound\atlas\polish\BAD08.WAV
c:\a\Keeper\sound\atlas\polish\BAD09.WAV
c:\a\Keeper\sound\atlas\polish\BAD10.WAV
c:\a\Keeper\sound\atlas\polish\BAD11.WAV
c:\a\Keeper\sound\atlas\polish\BAD12.WAV
c:\a\Keeper\sound\atlas\polish\BAD13.WAV
c:\a\Keeper\sound\atlas\polish\BAD14.WAV
c:\a\Keeper\sound\atlas\polish\BAD15.WAV
c:\a\Keeper\sound\atlas\polish\BAD16.WAV
c:\a\Keeper\sound\atlas\polish\BAD17.WAV
c:\a\Keeper\sound\atlas\polish\BAD18.WAV
c:\a\Keeper\sound\atlas\polish\BAD19.WAV
c:\a\Keeper\sound\atlas\polish\BAD20.WAV
c:\a\Keeper\sound\atlas\polish\GOOD01.WAV
c:\a\Keeper\sound\atlas\polish\GOOD02.WAV
c:\a\Keeper\sound\atlas\polish\GOOD03.WAV
c:\a\Keeper\sound\atlas\polish\GOOD04.WAV
c:\a\Keeper\sound\atlas\polish\GOOD05.WAV
c:\a\Keeper\sound\atlas\polish\GOOD06.WAV
c:\a\Keeper\sound\atlas\polish\GOOD07.WAV
c:\a\Keeper\sound\atlas\polish\GOOD08.WAV
c:\a\Keeper\sound\atlas\polish\GOOD09.WAV
c:\a\Keeper\sound\atlas\polish\GOOD10.WAV
c:\a\Keeper\sound\atlas\polish\GOOD11.WAV
c:\a\Keeper\sound\atlas\polish\GOOD12.WAV
c:\a\Keeper\sound\atlas\polish\GOOD13.WAV
c:\a\Keeper\sound\atlas\polish\GOOD14.WAV
c:\a\Keeper\sound\atlas\polish\GOOD15.WAV
c:\a\Keeper\sound\atlas\polish\GOOD16.WAV
c:\a\Keeper\sound\atlas\polish\GOOD17.WAV
c:\a\Keeper\sound\atlas\polish\GOOD18.WAV
c:\a\Keeper\sound\atlas\polish\GOOD19.WAV
c:\a\Keeper\sound\atlas\polish\GOOD20.WAV
c:\a\Keeper\sound\atlas\spanish\BAD01.WAV
c:\a\Keeper\sound\atlas\spanish\BAD02.WAV
c:\a\Keeper\sound\atlas\spanish\BAD03.WAV
c:\a\Keeper\sound\atlas\spanish\BAD04.WAV
c:\a\Keeper\sound\atlas\spanish\BAD05.WAV
c:\a\Keeper\sound\atlas\spanish\BAD06.WAV
c:\a\Keeper\sound\atlas\spanish\BAD07.WAV
c:\a\Keeper\sound\atlas\spanish\BAD08.WAV
c:\a\Keeper\sound\atlas\spanish\BAD09.WAV
c:\a\Keeper\sound\atlas\spanish\BAD10.WAV
c:\a\Keeper\sound\atlas\spanish\BAD11.WAV
c:\a\Keeper\sound\atlas\spanish\BAD12.WAV
c:\a\Keeper\sound\atlas\spanish\BAD13.WAV
c:\a\Keeper\sound\atlas\spanish\BAD14.WAV
c:\a\Keeper\sound\atlas\spanish\BAD15.WAV
c:\a\Keeper\sound\atlas\spanish\BAD16.WAV
c:\a\Keeper\sound\atlas\spanish\BAD17.WAV
c:\a\Keeper\sound\atlas\spanish\BAD18.WAV
c:\a\Keeper\sound\atlas\spanish\BAD19.WAV
c:\a\Keeper\sound\atlas\spanish\BAD20.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD01.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD02.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD03.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD04.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD05.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD06.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD07.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD08.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD09.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD10.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD11.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD12.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD13.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD14.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD15.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD16.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD17.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD18.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD19.WAV
c:\a\Keeper\sound\atlas\spanish\GOOD20.WAV
c:\a\Keeper\sound\atlas\swedish\BAD01.WAV
c:\a\Keeper\sound\atlas\swedish\BAD02.WAV
c:\a\Keeper\sound\atlas\swedish\BAD03.WAV
c:\a\Keeper\sound\atlas\swedish\BAD04.WAV
c:\a\Keeper\sound\atlas\swedish\BAD05.WAV
c:\a\Keeper\sound\atlas\swedish\BAD06.WAV
c:\a\Keeper\sound\atlas\swedish\BAD07.WAV
c:\a\Keeper\sound\atlas\swedish\BAD08.WAV
c:\a\Keeper\sound\atlas\swedish\BAD09.WAV
c:\a\Keeper\sound\atlas\swedish\BAD10.WAV
c:\a\Keeper\sound\atlas\swedish\BAD11.WAV
c:\a\Keeper\sound\atlas\swedish\BAD12.WAV
c:\a\Keeper\sound\atlas\swedish\BAD13.WAV
c:\a\Keeper\sound\atlas\swedish\BAD14.WAV
c:\a\Keeper\sound\atlas\swedish\BAD15.WAV
c:\a\Keeper\sound\atlas\swedish\BAD16.WAV
c:\a\Keeper\sound\atlas\swedish\BAD17.WAV
c:\a\Keeper\sound\atlas\swedish\BAD18.WAV
c:\a\Keeper\sound\atlas\swedish\BAD19.WAV
c:\a\Keeper\sound\atlas\swedish\BAD20.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD01.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD02.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD03.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD04.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD05.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD06.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD07.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD08.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD09.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD10.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD11.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD12.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD13.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD14.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD15.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD16.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD17.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD18.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD19.WAV
c:\a\Keeper\sound\atlas\swedish\GOOD20.WAV
c:\a\Keeper\sound\ATMOS1.SBK
c:\a\Keeper\sound\ATMOS2.SBK
c:\a\Keeper\sound\AUDIODRV.DIG
c:\a\Keeper\sound\bullfrog.sbk
c:\a\Keeper\sound\DIG.INI
c:\a\Keeper\sound\IWAV.DIG
c:\a\Keeper\sound\JAMMER.DIG
c:\a\Keeper\sound\MSSDRVR.LST
c:\a\Keeper\sound\MSSW95.EXE
c:\a\Keeper\sound\MUSIC.DAT
c:\a\Keeper\sound\NVDIG.DIG
c:\a\Keeper\sound\PROAUDIO.DIG
c:\a\Keeper\sound\RAP10.DIG
c:\a\Keeper\sound\SB16.DIG
c:\a\Keeper\sound\SBAWE32.MDI
c:\a\Keeper\sound\SBLASTER.DIG
c:\a\Keeper\sound\SBPRO.DIG
c:\a\Keeper\sound\SETSOUND.EXE
c:\a\Keeper\sound\SNDSCAPE.DIG
c:\a\Keeper\sound\SNDSYS.DIG
c:\a\Keeper\sound\sound.dat
c:\a\Keeper\sound\speech\Dutch\SPEECH.DAT
c:\a\Keeper\sound\speech\english\SPEECH.DAT
c:\a\Keeper\sound\speech\French\SPEECH.DAT
c:\a\Keeper\sound\speech\Polish\SPEECH.DAT
c:\a\Keeper\sound\speech\Spanish\SPEECH.DAT
c:\a\Keeper\sound\speech\Swedish\SPEECH.DAT
c:\a\Keeper\sound\ULTRA.DIG
c:\a\Keeper\WinSetup\_INST32I.EX_
c:\a\Keeper\WinSetup\_ISDEL.EXE
c:\a\Keeper\WinSetup\_SETUP.DLL
c:\a\Keeper\WinSetup\_SETUP.LIB
c:\a\Keeper\WinSetup\art\BACK.BMP
c:\a\Keeper\WinSetup\Dutch\_INST32I.EX_
c:\a\Keeper\WinSetup\Dutch\_ISDEL.EXE
c:\a\Keeper\WinSetup\Dutch\_ISRES.DLL
c:\a\Keeper\WinSetup\Dutch\_SETUP.DLL
c:\a\Keeper\WinSetup\Dutch\_SETUP.LIB
c:\a\Keeper\WinSetup\Dutch\DATALIST.BAK
c:\a\Keeper\WinSetup\Dutch\DISK1.ID
c:\a\Keeper\WinSetup\Dutch\DXLICENS.TXT
c:\a\Keeper\WinSetup\Dutch\ITEXT.TXT
c:\a\Keeper\WinSetup\Dutch\LISTATLA.TXT
c:\a\Keeper\WinSetup\Dutch\LISTDAT.TXT
c:\a\Keeper\WinSetup\Dutch\LISTSND.TXT
c:\a\Keeper\WinSetup\Dutch\PACKLIST.BAK
c:\a\Keeper\WinSetup\Dutch\PACKLIST.TXT
c:\a\Keeper\WinSetup\Dutch\SETUP.BAK
c:\a\Keeper\WinSetup\Dutch\SETUP.DBG
c:\a\Keeper\WinSetup\Dutch\SETUP.EXE
c:\a\Keeper\WinSetup\Dutch\SETUP.INI
c:\a\Keeper\WinSetup\Dutch\SETUP.INS
c:\a\Keeper\WinSetup\Dutch\setup.pkg
c:\a\Keeper\WinSetup\Dutch\setup.rul
c:\a\Keeper\WinSetup\Dutch\SETUPE.BAK
c:\a\Keeper\WinSetup\Dutch\UNINST.EXE
c:\a\Keeper\WinSetup\English\_INST32I.EX_
c:\a\Keeper\WinSetup\English\_ISDEL.EXE
c:\a\Keeper\WinSetup\English\_SETUP.DLL
c:\a\Keeper\WinSetup\English\_SETUP.LIB
c:\a\Keeper\WinSetup\English\DISK1.ID
c:\a\Keeper\WinSetup\English\DXLICENS.TXT
c:\a\Keeper\WinSetup\English\ITEXT.TXT
c:\a\Keeper\WinSetup\English\LISTATLA.TXT
c:\a\Keeper\WinSetup\English\listdat.txt
c:\a\Keeper\WinSetup\English\LISTSND.TXT
c:\a\Keeper\WinSetup\English\PACKLIST.BAK
c:\a\Keeper\WinSetup\English\PACKLIST.TXT
c:\a\Keeper\WinSetup\English\SETUP.DBG
c:\a\Keeper\WinSetup\English\SETUP.EXE
c:\a\Keeper\WinSetup\English\SETUP.INI
c:\a\Keeper\WinSetup\English\SETUP.INS
c:\a\Keeper\WinSetup\English\setup.pkg
c:\a\Keeper\WinSetup\English\SETUP.RUL
c:\a\Keeper\WinSetup\English\STATE.RST
c:\a\Keeper\WinSetup\English\UNINST.EXE
c:\a\Keeper\WinSetup\FRENCH\_INST32I.EX_
c:\a\Keeper\WinSetup\FRENCH\_ISDEL.EXE
c:\a\Keeper\WinSetup\FRENCH\_ISRES.DLL
c:\a\Keeper\WinSetup\FRENCH\_SETUP.DLL
c:\a\Keeper\WinSetup\FRENCH\_SETUP.LIB
c:\a\Keeper\WinSetup\FRENCH\DATALIST.BAK
c:\a\Keeper\WinSetup\FRENCH\DISK1.ID
c:\a\Keeper\WinSetup\FRENCH\DXLICENS.TXT
c:\a\Keeper\WinSetup\FRENCH\ITEXT.TXT
c:\a\Keeper\WinSetup\FRENCH\LISTATLA.TXT
c:\a\Keeper\WinSetup\FRENCH\LISTDAT.TXT
c:\a\Keeper\WinSetup\FRENCH\LISTSND.TXT
c:\a\Keeper\WinSetup\FRENCH\PACKLIST.BAK
c:\a\Keeper\WinSetup\FRENCH\PACKLIST.TXT
c:\a\Keeper\WinSetup\FRENCH\SETUP.BAK
c:\a\Keeper\WinSetup\FRENCH\SETUP.DBG
c:\a\Keeper\WinSetup\FRENCH\SETUP.EXE
c:\a\Keeper\WinSetup\FRENCH\SETUP.INI
c:\a\Keeper\WinSetup\FRENCH\SETUP.INS
c:\a\Keeper\WinSetup\FRENCH\setup.pkg
c:\a\Keeper\WinSetup\FRENCH\SETUP.RUL
c:\a\Keeper\WinSetup\FRENCH\SETUPE.BAK
c:\a\Keeper\WinSetup\FRENCH\UNINST.EXE
c:\a\Keeper\WinSetup\ISDBGN.DLL
c:\a\Keeper\WinSetup\Makedat.bat
c:\a\Keeper\WinSetup\PACKALL.BAK
c:\a\Keeper\WinSetup\PACKALL.BAT
c:\a\Keeper\WinSetup\Polish\_INST32I.EX_
c:\a\Keeper\WinSetup\Polish\_ISDEL.EXE
c:\a\Keeper\WinSetup\Polish\_ISRES.DLL
c:\a\Keeper\WinSetup\Polish\_SETUP.DLL
c:\a\Keeper\WinSetup\Polish\_SETUP.LIB
c:\a\Keeper\WinSetup\Polish\DISK1.ID
c:\a\Keeper\WinSetup\Polish\DP_BPAL.$$$
c:\a\Keeper\WinSetup\Polish\DP_CPAL.$$$
c:\a\Keeper\WinSetup\Polish\DP_OPAL.$$$
c:\a\Keeper\WinSetup\Polish\DP_PREFS
c:\a\Keeper\WinSetup\Polish\DP_SPAL.$$$
c:\a\Keeper\WinSetup\Polish\DXLICENS.TXT
c:\a\Keeper\WinSetup\Polish\ITEXT.TXT
c:\a\Keeper\WinSetup\Polish\LISTATLA.TXT
c:\a\Keeper\WinSetup\Polish\LISTDAT.TXT
c:\a\Keeper\WinSetup\Polish\LISTSND.TXT
c:\a\Keeper\WinSetup\Polish\PACKLIST.BAK
c:\a\Keeper\WinSetup\Polish\PACKLIST.TXT
c:\a\Keeper\WinSetup\Polish\SETUP.DBG
c:\a\Keeper\WinSetup\Polish\SETUP.EXE
c:\a\Keeper\WinSetup\Polish\SETUP.INI
c:\a\Keeper\WinSetup\Polish\SETUP.INS
c:\a\Keeper\WinSetup\Polish\setup.pkg
c:\a\Keeper\WinSetup\Polish\setup.rul
c:\a\Keeper\WinSetup\Polish\SETUPE.BAK
c:\a\Keeper\WinSetup\Polish\UNINST.EXE
c:\a\Keeper\WinSetup\REDIST\CREATIVE\AWEMAN.DLL
c:\a\Keeper\WinSetup\REDIST\CREATIVE\AWEMAN32.DLL
c:\a\Keeper\WinSetup\REDIST\CREATIVE\CIFMAN.CRL
c:\a\Keeper\WinSetup\REDIST\CREATIVE\CIFMAN.DLL
c:\a\Keeper\WinSetup\REDIST\CREATIVE\CSPMAN.DLL
c:\a\Keeper\WinSetup\REDIST\CREATIVE\CT3DSE.VXD
c:\a\Keeper\WinSetup\REDIST\CREATIVE\ctdetect.exe
c:\a\Keeper\WinSetup\REDIST\CREATIVE\CTRESV.INF
c:\a\Keeper\WinSetup\REDIST\CREATIVE\CTRESV.VXD
c:\a\Keeper\WinSetup\REDIST\CREATIVE\DISK.ID
c:\a\Keeper\WinSetup\REDIST\CREATIVE\FILE_ID.DIZ
c:\a\Keeper\WinSetup\REDIST\CREATIVE\HISTORY.TXT
c:\a\Keeper\WinSetup\REDIST\CREATIVE\LICENSE.TXT
c:\a\Keeper\WinSetup\REDIST\CREATIVE\README.TXT
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SB16.VXD
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SB16AWE.INF
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SB16SND.DRV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SBAWE.VXD
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SBAWE32.DRV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SBFM.DRV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\sbw95up.exe
c:\a\Keeper\WinSetup\REDIST\CREATIVE\SYNTHGM.SBK
c:\a\Keeper\WinSetup\REDIST\CREATIVE\UPDDRV95.EXE
c:\a\Keeper\WinSetup\REDIST\CREATIVE\UPDDRV95.INF
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0200.ACV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0200A.CSP
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0201.ACV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0201A.CSP
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0202.ACV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0202A.CSP
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0203.ACV
c:\a\Keeper\WinSetup\REDIST\CREATIVE\WFM0203A.CSP
c:\a\Keeper\WinSetup\SETALL.BAT
c:\a\Keeper\WinSetup\SETUP.DBG
c:\a\Keeper\WinSetup\setup.exe
c:\a\Keeper\WinSetup\SETUP.INI
c:\a\Keeper\WinSetup\SETUP.INS
c:\a\Keeper\WinSetup\SETUP.RUL
c:\a\Keeper\WinSetup\SPANISH\_INST32I.EX_
c:\a\Keeper\WinSetup\SPANISH\_ISDEL.EXE
c:\a\Keeper\WinSetup\SPANISH\_ISRES.DLL
c:\a\Keeper\WinSetup\SPANISH\_SETUP.DLL
c:\a\Keeper\WinSetup\SPANISH\_SETUP.LIB
c:\a\Keeper\WinSetup\SPANISH\DATALIST.BAK
c:\a\Keeper\WinSetup\SPANISH\DISK1.ID
c:\a\Keeper\WinSetup\SPANISH\DXLICENS.TXT
c:\a\Keeper\WinSetup\SPANISH\ITEXT.TXT
c:\a\Keeper\WinSetup\SPANISH\LISTATLA.TXT
c:\a\Keeper\WinSetup\SPANISH\LISTDAT.TXT
c:\a\Keeper\WinSetup\SPANISH\LISTSND.TXT
c:\a\Keeper\WinSetup\SPANISH\PACKLIST.BAK
c:\a\Keeper\WinSetup\SPANISH\PACKLIST.TX
c:\a\Keeper\WinSetup\SPANISH\PACKLIST.TXT
c:\a\Keeper\WinSetup\SPANISH\SETUP.BAK
c:\a\Keeper\WinSetup\SPANISH\SETUP.DBG
c:\a\Keeper\WinSetup\SPANISH\SETUP.EXE
c:\a\Keeper\WinSetup\SPANISH\SETUP.INI
c:\a\Keeper\WinSetup\SPANISH\SETUP.INS
c:\a\Keeper\WinSetup\SPANISH\setup.pkg
c:\a\Keeper\WinSetup\SPANISH\setup.rul
c:\a\Keeper\WinSetup\SPANISH\SETUPE.BAK
c:\a\Keeper\WinSetup\SPANISH\UNINST.EXE
c:\a\Keeper\WinSetup\STATE.RST
c:\a\Keeper\WinSetup\SWEDISH\_INST32I.EX_
c:\a\Keeper\WinSetup\SWEDISH\_ISDEL.EXE
c:\a\Keeper\WinSetup\SWEDISH\_ISRES.DLL
c:\a\Keeper\WinSetup\SWEDISH\_SETUP.DLL
c:\a\Keeper\WinSetup\SWEDISH\_SETUP.LIB
c:\a\Keeper\WinSetup\SWEDISH\DATALIST.BAK
c:\a\Keeper\WinSetup\SWEDISH\DISK1.ID
c:\a\Keeper\WinSetup\SWEDISH\DXLICENS.TXT
c:\a\Keeper\WinSetup\SWEDISH\ITEXT.TXT
c:\a\Keeper\WinSetup\SWEDISH\LISTATLA.TXT
c:\a\Keeper\WinSetup\SWEDISH\LISTDAT.TXT
c:\a\Keeper\WinSetup\SWEDISH\LISTSND.TXT
c:\a\Keeper\WinSetup\SWEDISH\PACKLIST.BAK
c:\a\Keeper\WinSetup\SWEDISH\PACKLIST.TXT
c:\a\Keeper\WinSetup\SWEDISH\SETUP.BAK
c:\a\Keeper\WinSetup\SWEDISH\SETUP.DBG
c:\a\Keeper\WinSetup\SWEDISH\SETUP.EXE
c:\a\Keeper\WinSetup\SWEDISH\SETUP.INI
c:\a\Keeper\WinSetup\SWEDISH\SETUP.INS
c:\a\Keeper\WinSetup\SWEDISH\setup.pkg
c:\a\Keeper\WinSetup\SWEDISH\Setup.rul
c:\a\Keeper\WinSetup\SWEDISH\UNINST.EXE
c:\a\Keeper\WinSetup\UNINST.EXE
c:\a\Keeper\WSnd7R.dll
c:\a\KEEPERQQ\DATA\ALPHA.COL
c:\a\Setup.exe
c:\a\Theme\Keeper Theme.exe
c:\a\Theme\readme.txt
c:\a\Trailer\trailer.exe
c:\a\Trailer\Trailer.tgq
c:\users\RICK\AppData\Local\assembly\tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-10-19 to 2012-11-19 )))))))))))))))))))))))))))))))
.
.
2012-11-19 03:38 . 2012-11-19 03:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-19 03:20 . 2012-11-19 03:20 -------- d-----w- C:\_OTL
2012-11-18 19:30 . 2012-11-18 19:30 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28648740-EB86-4DD2-ACD9-A4DAED751A82}\offreg.dll
2012-11-18 19:18 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-18 19:18 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-18 19:18 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-18 19:18 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-18 19:13 . 2012-10-08 11:17 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-11-18 19:11 . 2012-10-12 07:19 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28648740-EB86-4DD2-ACD9-A4DAED751A82}\mpengine.dll
2012-11-18 19:11 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-18 19:11 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-18 19:11 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-18 19:11 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-18 19:11 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-18 19:11 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-18 19:11 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-18 19:09 . 2012-08-31 18:19 1659760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-11-18 17:13 . 2012-11-18 17:13 -------- d-----w- c:\users\RICK\AppData\Roaming\Malwarebytes
2012-11-18 17:13 . 2012-11-18 17:13 -------- d-----w- c:\programdata\Malwarebytes
2012-11-18 17:13 . 2012-11-18 17:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-11-18 17:13 . 2012-09-30 00:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-18 16:52 . 2012-11-18 16:52 -------- d-----w- c:\users\RICK\AppData\Roaming\LavasoftStatistics
2012-11-18 16:48 . 2012-11-18 16:48 -------- d-----w- c:\users\RICK\AppData\Local\Downloaded Installations
2012-11-17 18:54 . 2012-10-30 23:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-11-17 18:53 . 2012-11-18 18:47 -------- d-----w- c:\programdata\AVAST Software
2012-11-17 18:53 . 2012-11-17 18:53 -------- d-----w- c:\program files\AVAST Software
2012-11-17 02:14 . 2012-11-17 02:14 -------- d-----w- c:\users\RICK\AppData\Roaming\AVG2013
2012-11-17 02:14 . 2012-11-17 02:14 -------- d-----w- c:\users\RICK\AppData\Roaming\TuneUp Software
2012-11-17 02:14 . 2012-11-17 04:10 -------- d-----w- c:\programdata\AVG2013
2012-11-17 02:14 . 2012-11-17 04:10 -------- d-----w- C:\$AVG
2012-11-17 02:10 . 2012-11-17 04:10 -------- d-----w- c:\programdata\MFAData
2012-11-17 02:10 . 2012-11-17 02:20 -------- d-----w- c:\users\RICK\AppData\Local\Avg2013
2012-11-17 02:10 . 2012-11-17 02:10 -------- d--h--w- c:\programdata\Common Files
2012-11-17 02:10 . 2012-11-17 02:10 -------- d-----w- c:\users\RICK\AppData\Local\MFAData
2012-11-15 02:08 . 2012-11-16 19:58 -------- d-----w- c:\users\RICK\.WebIde50
2012-11-15 02:08 . 2012-11-15 02:08 -------- d-----w- c:\program files (x86)\JetBrains
2012-11-15 00:48 . 2012-11-15 00:48 -------- d-----w- c:\users\RICK\AppData\Local\Apps
2012-11-14 22:31 . 2012-11-14 22:32 -------- d-----w- C:\wamp
2012-10-30 03:03 . 2012-10-30 09:52 -------- d-----w- c:\program files (x86)\Guild Wars 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-17 04:09 . 2012-04-14 18:29 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-17 04:09 . 2011-06-18 17:53 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-30 02:04 . 2012-10-02 23:08 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-10-02 23:24 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-02 23:24 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-02 23:13 . 2012-07-20 12:50 190656 ----a-w- c:\programdata\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2012-09-22 09:56 . 2012-09-22 09:56 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-22 09:56 . 2012-06-26 22:48 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-09-22 09:56 . 2011-05-08 16:29 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-08-22 18:12 . 2012-10-02 23:44 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-10-02 23:43 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-10-02 23:43 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-10-02 23:44 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2010-11-10 4144448]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\RICK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-03-05 340240]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-02 250984]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-03-17 325152]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-19 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
R4 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S2 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7};Power Control [2011/03/05 12:09];c:\program files (x86)\CyberLink\PowerDVD DX\000.fcl [2009-12-29 22:35 146928]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-06-08 13336]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-03-30 53800]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-30 35104]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]
S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2010-03-18 7680512]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-25 15:09]
.
2012-11-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-25 15:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-06-18 487424]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - ExtSQL: 2012-11-18 11:47; [email protected]; c:\users\RICK\AppData\Roaming\Mozilla\Firefox\Profiles\ynj3dtjx.default\extensions\[email protected]
FF - user.js: extentions.y2layers.installId - 2e520094-4e30-46e2-aca3-2352d40692ad
FF - user.js: extentions.y2layers.defaultEnableAppsList - bestvideodownloader
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-NCsoft - (no file)
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD DX\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-138261994-4095444355-3702608340-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96E68DC0-92CD-3322-209D-87BEF68686BD}*]
"iakeeaoaihkpjbcknb"=hex:63,61,70,70,69,62,00,01
"haodajglnkaaigjp"=hex:67,61,64,61,68,67,70,6c,61,66,61,69,70,65,00,77
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-18 22:40:25
ComboFix-quarantined-files.txt 2012-11-19 03:40
.
Pre-Run: 492,997,935,104 bytes free
Post-Run: 492,846,690,304 bytes free
.
- - End Of File - - F128C6CEB67D6F0717934034C35C2061
  • 0

#6
RLS0812

RLS0812

    Banned

  • Topic Starter
  • Banned
  • PipPip
  • 12 posts
I have not seen any ads since running the fix - Thanks A Lot !

Do you know what bug that was, or more importantly, were it came from ?
  • 0

#7
RPMcMurphy

RPMcMurphy

    Trusted Helper

  • Malware Removal
  • 930 posts
Glad to hear it - we still have work to do though. Please do this next:

Posted Image You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Uncheck any entries from C:\System Volume Information, C:\_OTL\MovedFiles or C:\Qoobox
  • Make sure that everything else is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Posted Image Go to thisLINK to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • If you are using Internet Explorer, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic.
Please include the following in your next post:
  • MBAM log
  • ESET log

  • 1

#8
RLS0812

RLS0812

    Banned

  • Topic Starter
  • Banned
  • PipPip
  • 12 posts
After the update, it was not surprising that Malwarebytes still found nothing.
Note: ESET failed to install ( I have no control over my firewall ).

Here is the log

========== MWB ==========

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.20.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
RICK :: COMPUTER [administrator]

11/20/2012 4:21:41 PM
mbam-log-2012-11-20 (16-21-41).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 580114
Time elapsed: 1 hour(s), 20 minute(s), 19 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
  • 0

#9
RPMcMurphy

RPMcMurphy

    Trusted Helper

  • Malware Removal
  • 930 posts
Your logs look good, so we can skip that ESET scan if you can't get it to run. All I have left for are two software updates and some very important cleanup:

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please go to www.java.com and press the "Free Java Download" button near the center of the page. Follow the prompts to install the latest version.

Posted Image Your Adobe reader needs to be updated. Please visit Adobe's site and grab the newest version. Be sure to watch for and uncheck any boxes offering to install other software.

Posted Image Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall
Posted Image

Posted Image Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
Posted Image Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application and MBAM current and updated. Scan with them at least weekly.
  • Please read this post for some helpful information.
Please post once more so I know you are all set and I can mark this thread resolved. Good luck and stay safe!
  • 1

#10
RPMcMurphy

RPMcMurphy

    Trusted Helper

  • Malware Removal
  • 930 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP