Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91681 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Closed] svchost.exe host error plzzzz help


  • This topic is locked This topic is locked
5 replies to this topic

#1 disturbedguy92

disturbedguy92

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 22 September 2009 - 03:37 PM

ok everytime i start up my laptop i get an error saying svchost.exe has stopped working then either my windows will freeze and then restart or it will say checking for solutions then say windows will try and find a solution to ypur problem and i have to hit cancel its very annoying can anyone help me fix this problem? this is my hijack file...............Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:48:25 PM, on 9/22/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Users\kevin\Desktop\Cracked exe\SRSSSC.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre6\bin\java.exe
C:\Users\kevin\Desktop\hijack\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...a...n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Users\kevin\Desktop\Cracked exe\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [Cerberus] C:\Users\kevin\AppData\Roaming\Cerberus\svhost.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.ad...Plus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=100
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

--
End of file - 9422 bytes
.......................................thank you to anyone who can help

    Advertisements

Register to Remove


#2 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 23 September 2009 - 07:15 PM

Please do the following:

Download OTSto your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Check the box that says 64 bit
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#3 disturbedguy92

disturbedguy92

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 23 September 2009 - 08:04 PM

here you go hope you can help me, thank you...........................................OTS logfile created on: 9/23/2009 9:53:53 PM - Run 1
OTS by OldTimer - Version 3.0.12.1 Folder = C:\Users\kevin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 0.88 Gb Available Physical Memory | 45.32% Memory free
4.00 Gb Paging File | 2.64 Gb Available in Paging File | 65.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 109.09 Gb Free Space | 38.26% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 1.94 Gb Free Space | 15.00% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEVIN-PC
Current User Name: kevin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days

[Processes - Safe List]
aluschedulersvc.exe -> c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe -> [2007/08/23 15:35:00 | 00,243,064 | ---- | M] (Symantec Corporation)
hpqsrmon.exe -> C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe -> [2007/08/22 20:31:16 | 00,080,896 | ---- | M] (Hewlett-Packard)
hpqwmiex.exe -> C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -> [2006/05/02 15:41:28 | 00,135,168 | ---- | M] (Hewlett-Packard Development Company, L.P.)
hpwuschd2.exe -> C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe -> [2007/05/08 20:24:20 | 00,054,840 | ---- | M] (Hewlett-Packard)
iexplore.exe -> C:\Program Files (x86)\Internet Explorer\iexplore.exe -> [2009/07/18 17:39:09 | 00,634,648 | ---- | M] (Microsoft Corporation)
jusched.exe -> C:\Program Files (x86)\Java\jre6\bin\jusched.exe -> [2009/08/31 00:34:49 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
lssrvc.exe -> C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -> [2007/08/23 17:40:48 | 00,079,136 | ---- | M] (Hewlett-Packard Company)
mbamgui.exe -> C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe -> [2009/09/10 14:54:00 | 00,420,176 | ---- | M] (Malwarebytes Corporation)
mbamservice.exe -> C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -> [2009/09/10 14:54:02 | 00,269,648 | ---- | M] (Malwarebytes Corporation)
ots.exe -> C:\Users\kevin\Desktop\OTS.exe -> [2009/09/23 21:51:40 | 00,514,560 | ---- | M] (OldTimer Tools)
qlbctrl.exe -> C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe -> [2007/09/19 17:31:34 | 00,202,032 | ---- | M] ( Hewlett-Packard Development Company, L.P.)
qpcapsvc.exe -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe -> [2007/12/19 22:28:34 | 00,271,760 | ---- | M] ()
qpsched.exe -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe -> [2007/12/19 22:28:34 | 00,112,016 | ---- | M] ()
qpservice.exe -> C:\Program Files (x86)\HP\QuickPlay\QPService.exe -> [2007/12/19 22:27:50 | 00,468,264 | ---- | M] (CyberLink Corp.)
richvideo.exe -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2007/01/09 06:25:30 | 00,272,024 | ---- | M] ()
srsssc.exe -> C:\Users\kevin\Desktop\Cracked exe\SRSSSC.exe -> [2009/09/07 09:30:44 | 04,354,048 | ---- | M] (SRS Labs, Inc.)
utorrent.exe -> C:\Program Files (x86)\uTorrent\uTorrent.exe -> [2009/08/15 19:20:05 | 00,288,048 | ---- | M] (BitTorrent, Inc.)
vlc.exe -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -> [2009/07/26 17:17:46 | 00,135,416 | ---- | M] ()
yahoomessenger.exe -> C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe -> [2009/05/26 21:06:32 | 04,351,216 | ---- | M] (Yahoo! Inc.)

[Win32 Services - Safe List]
64bit-(WinDefend) Windows Defender [Win32_Shared | Auto | Running] -> C:\Program Files\Windows Defender\mpsvc.dll -> [2008/01/20 22:47:32 | 00,383,544 | ---- | M] (Microsoft Corporation)
64bit-(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\wmpnetwk.exe -> [2008/01/20 22:52:15 | 01,216,000 | ---- | M] (Microsoft Corporation)
64bit-(XAudioService) XAudioService [Win32_Own | Auto | Running] -> C:\Windows\SysNative\DRIVERS\xaudio64.exe -> [2007/10/18 06:37:22 | 00,412,672 | ---- | M] ()
(AntiVirMailService) Avira AntiVir MailGuard [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe -> [2009/09/15 06:44:26 | 00,194,817 | ---- | M] (Avira GmbH)
(AntiVirSchedulerService) Avira AntiVir Scheduler [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -> [2009/09/15 06:44:43 | 00,108,289 | ---- | M] (Avira GmbH)
(AntiVirService) Avira AntiVir Guard [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -> [2009/09/15 06:44:26 | 00,185,089 | ---- | M] (Avira GmbH)
(AntiVirWebService) Avira AntiVir WebGuard [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE -> [2009/09/15 06:44:28 | 00,434,945 | ---- | M] (Avira GmbH)
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe -> [2007/08/23 15:35:00 | 00,243,064 | ---- | M] (Symantec Corporation)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/27 14:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_64) Microsoft .NET Framework NGEN v2.0.50727_X64 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -> [2008/07/27 14:01:49 | 00,093,184 | ---- | M] (Microsoft Corporation)
(Com4Qlb) Com4Qlb [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -> [2007/03/05 13:30:06 | 00,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.)
(ehRecvr) Windows Media Center Receiver Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehRecvr.exe -> [2008/01/20 22:51:36 | 00,344,064 | ---- | M] (Microsoft Corporation)
(ehSched) Windows Media Center Scheduler Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehsched.exe -> [2008/01/20 22:51:36 | 00,153,600 | ---- | M] (Microsoft Corporation)
(ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> C:\Windows\ehome\ehstart.dll -> [2006/11/02 11:03:48 | 00,015,360 | ---- | M] (Microsoft Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe -> [2008/06/19 21:17:12 | 00,046,104 | ---- | M] (Microsoft Corporation)
(GameConsoleService) GameConsoleService [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe -> [2007/07/23 19:33:06 | 00,181,800 | ---- | M] (WildTangent, Inc.)
(HP Health Check Service) HP Health Check Service [Win32_Own | Auto | Running] -> c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe -> [2007/09/19 17:30:52 | 00,065,536 | ---- | M] (Hewlett-Packard)
(hpqwmiex) hpqwmiex [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -> [2006/05/02 15:41:28 | 00,135,168 | ---- | M] (Hewlett-Packard Development Company, L.P.)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -> [2008/06/19 21:16:53 | 00,859,648 | ---- | M] (Microsoft Corporation)
(KeyIso) CNG Key Isolation [Win32_Shared | On_Demand | Running] -> C:\Windows\SysWow64\keyiso.dll -> [2006/11/02 05:46:05 | 00,018,944 | ---- | M] (Microsoft Corporation)
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -> [2007/08/23 17:40:48 | 00,079,136 | ---- | M] (Hewlett-Packard Company)
(LiveUpdate) LiveUpdate [Win32_Shared | On_Demand | Stopped] -> c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE -> [2007/08/23 15:35:00 | 03,192,184 | ---- | M] (Symantec Corporation)
(MBAMService) MBAMService [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -> [2009/09/10 14:54:02 | 00,269,648 | ---- | M] (Malwarebytes Corporation)
(MSDTC) Distributed Transaction Coordinator [Win32_Own | Unknown | Stopped] -> C:\Windows\SysWow64\Msdtc -> [2006/11/02 09:34:14 | 00,000,000 | ---D | M]
(Netlogon) Netlogon [Win32_Shared | On_Demand | Stopped] -> C:\Windows\SysWow64\netlogon.dll -> [2008/01/20 22:48:28 | 00,592,384 | ---- | M] (Microsoft Corporation)
(QPCapSvc) QuickPlay Background Capture Service (QBCS) [Win32_Own | Auto | Running] -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe -> [2007/12/19 22:28:34 | 00,271,760 | ---- | M] ()
(QPSched) QuickPlay Task Scheduler (QTS) [Win32_Own | Auto | Running] -> C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe -> [2007/12/19 22:28:34 | 00,112,016 | ---- | M] ()
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2007/01/09 06:25:30 | 00,272,024 | ---- | M] ()
(vds) Virtual Disk [Win32_Own | On_Demand | Stopped] -> C:\Windows\SysWow64\Wbem\vds.mof -> [2006/11/02 02:35:15 | 00,060,994 | ---- | M] ()
(VSS) Volume Shadow Copy [Win32_Own | On_Demand | Stopped] -> C:\Windows\SysWow64\Wbem\vss.mof -> [2006/11/02 02:35:15 | 00,055,846 | ---- | M] ()

[Driver Services - Safe List]
64bit-(ApfiltrService) Alps Pointing-device Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\Apfiltr.sys -> [2007/07/07 02:19:50 | 00,190,000 | ---- | M] ()
64bit-(avgntflt) avgntflt [File_System | Auto | Running] -> C:\Windows\SysNative\DRIVERS\avgntflt.sys -> [2009/09/15 06:45:05 | 00,073,048 | ---- | M] ()
64bit-(BCM43XV) Broadcom Extensible 802.11 Network Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\bcmwl664.sys -> [2008/10/23 02:16:34 | 01,526,776 | ---- | M] ()
64bit-(BCM43XX) Broadcom 802.11 Network Adapter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\bcmwl664.sys -> [2008/10/23 02:16:34 | 01,526,776 | ---- | M] ()
64bit-(CAXHWAZL) CAXHWAZL [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys -> [2007/11/01 09:19:46 | 00,293,376 | ---- | M] ()
64bit-(CmBatt) Microsoft ACPI Control Method Battery Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\CmBatt.sys -> [2008/01/20 22:46:51 | 00,017,792 | ---- | M] ()
64bit-(CnxtHdAudService) Conexant UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\CHDRT64.sys -> [2008/03/04 02:32:46 | 00,222,720 | ---- | M] ()
64bit-(HdAudAddService) Microsoft UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\CHDART64.sys -> [2007/10/01 07:26:06 | 00,207,872 | ---- | M] ()
64bit-(HpqKbFiltr) HpqKbFilter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys -> [2007/06/18 20:13:12 | 00,018,432 | ---- | M] ()
64bit-(HpqRemHid) HP Remote Control HID Device [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\HpqRemHid.sys -> [2007/07/11 13:30:34 | 00,009,088 | ---- | M] ()
64bit-(HSFHWAZL) HSFHWAZL [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS -> [2008/01/20 22:46:57 | 00,286,720 | ---- | M] ()
64bit-(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\CAX_DPV.sys -> [2007/11/01 09:22:50 | 01,481,216 | ---- | M] ()
64bit-(lmimirr) lmimirr [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\lmimirr.sys -> [2008/08/11 12:40:32 | 00,011,552 | ---- | M] ()
64bit-(LMIRfsClientNP) LMIRfsClientNP [File_System | Disabled | Stopped] -> C:\Windows\SysNative\LMIRfsClientNP.dll -> [2009/09/05 11:24:04 | 00,087,384 | ---- | M] ()
64bit-(LMIRfsDriver) LogMeIn Remote File System Driver [File_System | Auto | Running] -> C:\Windows\SysNative\drivers\LMIRfsDriver.sys -> [2008/08/11 12:40:58 | 00,072,216 | ---- | M] ()
64bit-(MBAMProtector) MBAMProtector [File_System | On_Demand | Running] -> C:\Windows\SysNative\drivers\mbam.sys -> [2009/09/10 14:53:52 | 00,022,104 | ---- | M] ()
64bit-(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\mdmxsdk.sys -> [2006/06/18 04:27:24 | 00,017,024 | ---- | M] ()
64bit-(pcouffin) VSO Software pcouffin [Kernel | On_Demand | Running] -> C:\Windows\SysNative\Drivers\pcouffin.sys -> [2009/09/15 13:20:14 | 00,082,816 | ---- | M] ()
64bit-(regi) regi [Kernel | Auto | Running] -> C:\Windows\SysNative\drivers\regi.sys -> [2007/01/15 14:36:18 | 00,014,112 | ---- | M] ()
64bit-(rimmptsk) rimmptsk [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\rimmpx64.sys -> [2007/08/08 20:39:46 | 00,060,928 | ---- | M] ()
64bit-(rimsptsk) rimsptsk [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\rimspx64.sys -> [2007/07/26 23:33:54 | 00,055,296 | ---- | M] ()
64bit-(rismxdp) Ricoh xD-Picture Card Driver [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\rixdpx64.sys -> [2007/07/27 22:45:52 | 00,057,856 | ---- | M] ()
64bit-(sdbus) sdbus [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\sdbus.sys -> [2008/01/20 22:46:55 | 00,111,104 | ---- | M] ()
64bit-(SRS_SSCFilter) SRS Labs Audio Sandbox (WDM) [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\srs_sscfilter_amd64.sys -> [2007/07/26 09:28:54 | 00,055,040 | ---- | M] ()
64bit-(usbvideo) USB Video Device (WDM) [Kernel | On_Demand | Running] -> C:\Windows\SysNative\Drivers\usbvideo.sys -> [2008/01/20 22:47:27 | 00,168,704 | ---- | M] ()
64bit-(winachsf) winachsf [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys -> [2007/11/01 09:18:32 | 00,740,864 | ---- | M] ()
64bit-(XAudio) XAudio [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\xaudio64.sys -> [2007/10/18 06:37:10 | 00,010,240 | ---- | M] ()
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> C:\Windows\SysWow64\mdmxsdk.dll -> [2006/06/18 04:26:50 | 00,094,208 | ---- | M] (Conexant)
(mpsdrv) Windows Firewall Authorization Driver [Kernel | On_Demand | Running] -> C:\Windows\SysWow64\Wbem\mpsdrv.mof -> [2006/09/18 17:35:23 | 00,001,088 | ---- | M] ()
(Tcpip) TCP/IP Protocol Driver [Kernel | Boot | Running] -> C:\Windows\SysWow64\Wbem\tcpip.mof -> [2006/09/18 17:36:40 | 00,003,066 | ---- | M] ()
(WinFLdrv) WinFLdrv [File_System | Auto | Running] -> C:\Windows\SysWow64\WinFLdrv.sys -> [2009/09/22 17:11:57 | 00,021,888 | ---- | M] ()
(WinVd32) WinVd32 [Kernel | Auto | Running] -> C:\Windows\WinVd32.sys -> [2009/09/22 17:11:59 | 00,197,728 | ---- | M] ()

[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://ie.redirect.h...a...n&pf=laptop ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft....k/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft....k/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://ie.redirect.h...a...n&pf=laptop ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://ie.redirect.h...a...n&pf=laptop ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft....k/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft....k/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://ie.redirect.h...a...n&pf=laptop ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\] > -> ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\: Main\\"Default_Page_URL" -> http://ie.redirect.h...a...n&pf=laptop ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\: Main\\"Local Page" -> C:\Windows\system32\blank.htm ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\: Main\\"Search Page" -> http://go.microsoft....k/?LinkId=54896 ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\: Main\\"Start Page" -> http://www.google.com/ ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\: Main\\"StartPageCache" -> 1 ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\: "ProxyEnable" -> 0 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/08/20 17:38:15 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
< HOSTS File > (761 bytes and 20 lines) -> C:\Windows\SysNative\Drivers\etc\hosts ->
Reset Hosts
127.0.0.1 localhost
::1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [Java™ Plug-In 2 SSV Helper] -> [2009/08/31 00:34:49 | 00,041,760 | ---- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Apoint" -> C:\Program Files\Apoint2K\Apoint.exe [C:\Program Files\Apoint2K\Apoint.exe] -> [2007/07/08 13:46:20 | 00,218,112 | ---- | M] (Alps Electric Co., Ltd.)
"HP Health Check Scheduler" -> [[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe] -> File not found
"LogMeIn GUI" -> C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe ["C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"] -> File not found
"NvCplDaemon" -> C:\Windows\SysNative\NvCpl.DLL [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2009/06/24 11:38:00 | 15,952,416 | ---- | M] ()
"NvMediaCenter" -> C:\Windows\SysNative\NvMcTray.DLL [RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit] -> [2009/06/24 11:38:00 | 00,082,464 | ---- | M] ()
"OnScreenDisplay" -> C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe] -> [2007/09/04 16:49:10 | 00,701,440 | ---- | M] ( Hewlett-Packard Development Company, L.P.)
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008/01/20 22:47:32 | 01,584,184 | ---- | M] (Microsoft Corporation)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Adobe Reader Speed Launcher" -> C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated)
"avgnt" -> C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe ["C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min] -> [2009/09/15 06:44:26 | 00,209,153 | ---- | M] (Avira GmbH)
"HP Software Update" -> C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe] -> [2007/05/08 20:24:20 | 00,054,840 | ---- | M] (Hewlett-Packard)
"hpqSRMon" -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe] -> [2007/08/22 20:31:16 | 00,080,896 | ---- | M] (Hewlett-Packard)
"Malwarebytes' Anti-Malware" -> C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe ["C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray] -> [2009/09/10 14:54:00 | 00,420,176 | ---- | M] (Malwarebytes Corporation)
"Malwarebytes Anti-Malware (reboot)" -> C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe ["C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript] -> [2009/09/10 14:53:56 | 01,312,080 | ---- | M] (Malwarebytes Corporation)
"NeroCheck" -> C:\Windows\SysWow64\NeroCheck.exe [C:\Windows\system32\NeroCheck.exe] -> [2001/07/09 11:50:42 | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"QlbCtrl" -> C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [%ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start] -> [2007/09/19 17:31:34 | 00,202,032 | ---- | M] ( Hewlett-Packard Development Company, L.P.)
"QPService" -> C:\Program Files (x86)\HP\QuickPlay\QPService.exe ["C:\Program Files (x86)\HP\QuickPlay\QPService.exe"] -> [2007/12/19 22:27:50 | 00,468,264 | ---- | M] (CyberLink Corp.)
"SunJavaUpdateSched" -> C:\Program Files (x86)\Java\jre6\bin\jusched.exe ["C:\Program Files (x86)\Java\jre6\bin\jusched.exe"] -> [2009/08/31 00:34:49 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
"UCam_Menu" -> C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe ["C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"] -> [2007/08/17 02:13:28 | 00,218,408 | ---- | M] (CyberLink Corp.)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2008/01/20 22:47:33 | 01,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 22:47:52 | 02,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2008/01/20 22:47:33 | 01,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 22:47:52 | 02,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\] > -> HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Cerberus" -> C:\Users\kevin\AppData\Roaming\Cerberus\svhost.exe [C:\Users\kevin\AppData\Roaming\Cerberus\svhost.exe] -> [2009/09/12 07:18:22 | 36,388,864 | RHS- | M] ()
"ehTray.exe" -> C:\Windows\ehome\ehTray.exe [C:\Windows\ehome\ehTray.exe] -> [2008/01/20 22:51:33 | 00,138,240 | ---- | M] (Microsoft Corporation)
"LightScribe Control Panel" -> C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden] -> [2007/08/23 17:36:30 | 00,455,968 | ---- | M] (Hewlett-Packard Company)
"Messenger (Yahoo!)" -> C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe ["C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet] -> [2009/05/26 21:06:32 | 04,351,216 | ---- | M] (Yahoo! Inc.)
"SRS Audio Sandbox" -> C:\Users\kevin\Desktop\Cracked exe\SRSSSC.exe ["C:\Users\kevin\Desktop\Cracked exe\SRSSSC.exe" /hideme] -> [2009/09/07 09:30:44 | 04,354,048 | ---- | M] (SRS Labs, Inc.)
"uTorrent" -> C:\Program Files (x86)\uTorrent\uTorrent.exe ["C:\Program Files (x86)\uTorrent\uTorrent.exe"] -> [2009/08/15 19:20:05 | 00,288,048 | ---- | M] (BitTorrent, Inc.)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" -> [1] -> File not found
\\"ForceActiveDesktopOn" -> [0] -> File not found
\\"NoActiveDesktopChanges" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" -> [2] -> File not found
\\"ConsentPromptBehaviorUser" -> [1] -> File not found
\\"EnableInstallerDetection" -> [1] -> File not found
\\"EnableLUA" -> [0] -> File not found
\\"EnableSecureUIAPaths" -> [1] -> File not found
\\"EnableVirtualization" -> [1] -> File not found
\\"PromptOnSecureDesktop" -> [1] -> File not found
\\"ValidateAdminCodeSignatures" -> [0] -> File not found
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"scforceoption" -> [0] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"FilterAdministratorToken" -> [0] -> File not found
\\"EnableUIADesktopToggle" -> [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
\UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" -> [1] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" -> [2] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" -> [7] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIB" -> [8] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" -> [9] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" -> [13] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" -> [17] -> File not found
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.micro...d...=%s&mime=%s ->
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.micro...d...=%s&mime=%s ->
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\] > -> HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\] > -> HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-2822036804-3982795513-2901414936-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macr...director/sw.cab [Shockwave ActiveX Control] ->
{233C1507-6A77-46A4-9443-F871F945D258} [HKLM] -> http://download.macr...director/sw.cab [Shockwave ActiveX Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_15] ->
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_15] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_15] ->
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] -> http://platformdl.ad...Plus/1.6/gp.cab [Reg Error: Key error.] ->
{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} [HKLM] -> https://secure.logme...trl.cab?lmi=100 [Performance Viewer Activex Control] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.2.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{5DD99BC7-999F-455D-8A33-F9B5BCB78020}\\DhcpNameServer -> 192.168.1.1 192.168.1.1 (NVIDIA nForce 10/100/1000 Mbps Ethernet ) ->
{FD48FF2B-0768-4E2D-9D2A-92F23FC9C864}\\DhcpNameServer -> 192.168.2.1 (Broadcom 802.11b/g WLAN) ->
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\explorer.exe -> [2008/10/29 02:49:22 | 03,080,704 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2008/10/29 02:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Vista Public Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications ->
< Vista Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications ->
64bit-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
\List\\"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" -> C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe [C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink] -> [2006/08/30 16:35:12 | 00,952,088 | ---- | M] (EarthLink, Inc.)
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{0F3E39C4-54E9-43D4-9D63-B98D74648904} -> profile=public | protocol=17 | dir=in | action=allow | name=bittorrent | app=c:\program files (x86)\bittorrent\bittorrent.exe |
{109647F6-8FDA-479B-B52D-DE2AC5911B61} -> profile=public | protocol=6 | dir=in | action=allow | name=aol loader | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
{3B200488-35D3-42A9-A6B5-1ED8EEA8D39A} -> dir=in | action=allow | name=quick play | app=c:\program files (x86)\hp\quickplay\qp.exe |
{61F7AD8E-139E-42B7-9C5C-A7BD525CFFBC} -> profile=public | protocol=17 | dir=in | action=allow | name=aol loader | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
{7FECF811-9325-4DEA-87AA-506D9ED00DDD} -> profile=public | protocol=6 | dir=in | action=allow | name=μtorrent (tcp-in) | app=c:\program files (x86)\utorrent\utorrent.exe |
{9480CE52-8E38-4CE8-8C2C-C8DCB9E8039D} -> dir=in | action=allow | name=cyberlink powerdirector | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
{A38878B3-5DC0-4F65-B3C7-A6F686F95ED7} -> dir=in | action=allow | name=quick play resident program | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
{C2E14683-2898-4EE9-8A02-9B6671FBC904} -> profile=public | protocol=6 | dir=in | action=allow | name=yahoo! messenger | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
{CBBC4037-FB1A-4349-8ED8-7B92F25890B3} -> profile=public | protocol=6 | dir=in | action=allow | name=bittorrent | app=c:\program files (x86)\bittorrent\bittorrent.exe |
{D617FB9C-4960-46E7-B015-F2D4011468DD} -> profile=public | protocol=17 | dir=in | action=allow | name=μtorrent (udp-in) | app=c:\program files (x86)\utorrent\utorrent.exe |
{EBA4A833-4780-4B2F-BCB4-E28A37BFB01A} -> profile=public | protocol=17 | dir=in | action=allow | name=yahoo! messenger | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
TCP Query User{5E0B427F-0D42-4A68-A3C9-AACE722787F2}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe -> profile=private | protocol=6 | dir=in | action=block | name=yahoo! messenger | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
TCP Query User{AF997A29-303B-46DD-9830-BFABEA95F443}C:\program files (x86)\java\jre6\bin\java.exe -> profile=public | protocol=6 | dir=in | action=allow | name=java™ platform se binary | app=c:\program files (x86)\java\jre6\bin\java.exe |
TCP Query User{CB611147-5009-473B-A8B6-E8E961B2299F}C:\program files (x86)\utorrent\utorrent.exe -> profile=private | protocol=6 | dir=in | action=block | name=μtorrent | app=c:\program files (x86)\utorrent\utorrent.exe |
UDP Query User{1CD41727-244E-4249-8179-9A4AE6558B58}C:\program files (x86)\java\jre6\bin\java.exe -> profile=public | protocol=17 | dir=in | action=allow | name=java™ platform se binary | app=c:\program files (x86)\java\jre6\bin\java.exe |
UDP Query User{456FCF5D-B2C4-4D37-84C0-2B6B2FD3512C}C:\program files (x86)\utorrent\utorrent.exe -> profile=private | protocol=17 | dir=in | action=block | name=μtorrent | app=c:\program files (x86)\utorrent\utorrent.exe |
UDP Query User{A648464F-3FF0-4B8B-BC34-49009D75EACE}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe -> profile=private | protocol=17 | dir=in | action=block | name=yahoo! messenger | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" -> C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe [C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink] -> [2006/08/30 16:35:12 | 00,952,088 | ---- | M] (EarthLink, Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> C:\Windows\SysNative\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/01/20 22:46:54 | 00,079,872 | ---- | M] ()
< Drives with AutoRun files > -> ->
D:\AUTOMODE [@echo off | IF EXIST C:\ST_RP\MANUALMODE ECHO MANUAL BATCH MODE ALREADY SET ! | IF NOT EXIST C:\ST_RP\MANUALMODE ECHO SET TO MANUAL BATCH EXECUTION ! | IF NOT EXIST C:\ST_RP\MANUALMODE IF EXIST C:\ST_RP\AUTOMODE DEL C:\ST_RP\AUTOMODE /F > NUL | IF NOT EXIST C:\ST_RP\MANUALMODE COPY C:\ST_RP\SET_AUTO_MODE.CMD C:\ST_RP\MANUALMODE > NUL | ECHO. | ] -> D:\AUTOMODE [ NTFS ] -> [2005/09/11 11:18:54 | 00,000,340 | -HS- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->

[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 9/22/2009 3:38:44 PM Computer Name = kevin-PC | Source = Application Error | ID = 1000 -> Description = Faulting application svhost.exe, version 0.0.0.0, time stamp 0x4aa0b87c, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00297640, process id 0x880, application start time 0x01ca3bbc4af65ec4.
Application [ Error ] 9/22/2009 3:38:45 PM Computer Name = kevin-PC | Source = Application Error | ID = 1000 -> Description = Faulting application HPWAMain.exe, version 3.0.8.2, time stamp 0x46e93ef4, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x005db048, process id 0xa1c, application start time 0x01ca3bbc4b6fc4e4.
Application [ Error ] 9/22/2009 3:38:47 PM Computer Name = kevin-PC | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 9/22/2009 3:47:55 PM Computer Name = kevin-PC | Source = Avira AntiVir | ID = 4122 -> Description = Unable to load file AVPREF.DLL. Returned error code: 0x45a
Application [ Error ] 9/22/2009 3:48:24 PM Computer Name = kevin-PC | Source = Application Error | ID = 1000 -> Description = Faulting application svhost.exe, version 0.0.0.0, time stamp 0x4aa0b87c, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x02817640, process id 0x300, application start time 0x01ca3bbda4fde557.
Application [ Error ] 9/22/2009 3:48:25 PM Computer Name = kevin-PC | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 9/22/2009 3:48:26 PM Computer Name = kevin-PC | Source = Application Error | ID = 1000 -> Description = Faulting application HPWAMain.exe, version 3.0.8.2, time stamp 0x46e93ef4, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x005e8fc0, process id 0xb6c, application start time 0x01ca3bbda5782e07.
Application [ Error ] 9/22/2009 4:00:50 PM Computer Name = kevin-PC | Source = Avira AntiVir | ID = 4122 -> Description = Unable to load file AVPREF.DLL. Returned error code: 0x45a
Application [ Error ] 9/22/2009 4:01:18 PM Computer Name = kevin-PC | Source = Application Error | ID = 1000 -> Description = Faulting application svhost.exe, version 0.0.0.0, time stamp 0x4aa0b87c, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00237640, process id 0x774, application start time 0x01ca3bbf72477ed4.
Application [ Error ] 9/22/2009 4:01:22 PM Computer Name = kevin-PC | Source = WinMgmt | ID = 10 -> Description =
System [ Error ] 9/23/2009 5:57:07 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 6:01:58 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 6:12:08 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 6:23:20 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 7:58:00 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 7:58:40 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 8:12:43 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 8:28:55 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 8:58:58 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.
System [ Error ] 9/23/2009 9:26:11 PM Computer Name = kevin-PC | Source = atapi | ID = 262155 -> Description = The driver detected a controller error on \Device\Ide\IdePort2.

[Files/Folders - Created Within 30 Days]
1 C:\Users\kevin\Documents\*.tmp files -> C:\Users\kevin\Documents\*.tmp ->
OTS.exe -> C:\Users\kevin\Desktop\OTS.exe -> [2009/09/23 21:51:34 | 00,514,560 | ---- | C] (OldTimer Tools)
WinVd32.sys -> C:\Windows\WinVd32.sys -> [2009/09/22 17:11:59 | 00,197,728 | ---- | C] ()
WinFLsrv.exe -> C:\Windows\SysWow64\WinFLsrv.exe -> [2009/09/22 17:11:57 | 00,007,680 | ---- | C] ()
.# -> C:\Users\kevin\AppData\Roaming\.# -> [2009/09/22 17:11:56 | 00,000,000 | -HSD | C]
flk-icon.ico -> C:\Windows\SysWow64\flk-icon.ico -> [2009/09/22 17:11:51 | 00,033,982 | ---- | C] ()
Uniblue -> C:\Users\kevin\AppData\Roaming\Uniblue -> [2009/09/22 15:27:31 | 00,000,000 | ---D | C]
ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/22 03:14:53 | 00,524,288 | -HS- | C] ()
ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/22 03:14:53 | 00,524,288 | -HS- | C] ()
ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TM.blf -> [2009/09/22 03:14:53 | 00,065,536 | -HS- | C] ()
ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/22 02:48:23 | 00,524,288 | -HS- | C] ()
ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/22 02:48:23 | 00,524,288 | -HS- | C] ()
ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TM.blf -> [2009/09/22 02:48:23 | 00,065,536 | -HS- | C] ()
WindowsSearch -> C:\ProgramData\WindowsSearch -> [2009/09/22 00:31:38 | 00,000,000 | ---D | C]
Manhunt User Files -> C:\Users\kevin\Documents\Manhunt User Files -> [2009/09/20 16:01:14 | 00,000,000 | ---D | C]
Games -> C:\Games -> [2009/09/20 14:09:33 | 00,000,000 | ---D | C]
gg.rtf -> C:\Users\kevin\Documents\gg.rtf -> [2009/09/16 14:07:02 | 00,000,167 | ---- | C] ()
vsosdk -> C:\ProgramData\vsosdk -> [2009/09/15 14:07:08 | 00,000,000 | ---D | C]
ConvertXtoDVD -> C:\Users\kevin\Documents\ConvertXtoDVD -> [2009/09/15 13:24:52 | 00,000,000 | ---D | C]
vso_ts_preview.xml -> C:\Users\kevin\AppData\Roaming\vso_ts_preview.xml -> [2009/09/15 13:22:30 | 00,001,044 | ---- | C] ()
inst.exe -> C:\Users\kevin\AppData\Roaming\inst.exe -> [2009/09/15 13:20:14 | 00,099,384 | ---- | C] ()
pcouffin.sys -> C:\Users\kevin\AppData\Roaming\pcouffin.sys -> [2009/09/15 13:20:14 | 00,082,816 | ---- | C] (VSO Software)
pcouffin.sys -> C:\Windows\SysNative\drivers\pcouffin.sys -> [2009/09/15 13:20:14 | 00,082,816 | ---- | C] ()
pcouffin.cat -> C:\Users\kevin\AppData\Roaming\pcouffin.cat -> [2009/09/15 13:20:14 | 00,007,859 | ---- | C] ()
pcouffin.inf -> C:\Users\kevin\AppData\Roaming\pcouffin.inf -> [2009/09/15 13:20:14 | 00,001,167 | ---- | C] ()
Vso -> C:\Users\kevin\AppData\Roaming\Vso -> [2009/09/15 13:20:13 | 00,000,000 | ---D | C]
ConvertXtoDvd 3.lnk -> C:\Users\kevin\Desktop\ConvertXtoDvd 3.lnk -> [2009/09/15 13:20:12 | 00,001,027 | ---- | C] ()
wvc1dmod.dll -> C:\Windows\SysWow64\wvc1dmod.dll -> [2009/09/15 13:20:06 | 01,184,984 | ---- | C] (Microsoft Corporation)
vp7vfw.dll -> C:\Windows\SysWow64\vp7vfw.dll -> [2009/09/15 13:20:06 | 00,626,688 | ---- | C] (On2.com)
VSO -> C:\Program Files (x86)\VSO -> [2009/09/15 13:20:04 | 00,000,000 | ---D | C]
jscript.dll -> C:\Windows\SysNative\jscript.dll -> [2009/09/15 12:45:29 | 00,753,152 | ---- | C] ()
jscript.dll -> C:\Windows\SysWow64\jscript.dll -> [2009/09/15 12:45:28 | 00,512,000 | ---- | C] (Microsoft Corporation)
WMVCORE.DLL -> C:\Windows\SysNative\WMVCORE.DLL -> [2009/09/15 12:33:31 | 02,900,480 | ---- | C] ()
mf.dll -> C:\Windows\SysNative\mf.dll -> [2009/09/15 12:33:29 | 03,547,136 | ---- | C] ()
WMVCORE.DLL -> C:\Windows\SysWow64\WMVCORE.DLL -> [2009/09/15 12:33:29 | 02,386,944 | ---- | C] (Microsoft Corporation)
mf.dll -> C:\Windows\SysWow64\mf.dll -> [2009/09/15 12:33:28 | 02,868,224 | ---- | C] (Microsoft Corporation)
tcpip.sys -> C:\Windows\SysNative\drivers\tcpip.sys -> [2009/09/15 12:33:20 | 01,418,840 | ---- | C] ()
netiohlp.dll -> C:\Windows\SysNative\netiohlp.dll -> [2009/09/15 12:33:19 | 00,141,312 | ---- | C] ()
netiohlp.dll -> C:\Windows\SysWow64\netiohlp.dll -> [2009/09/15 12:33:19 | 00,104,960 | ---- | C] (Microsoft Corporation)
NETSTAT.EXE -> C:\Windows\SysNative\NETSTAT.EXE -> [2009/09/15 12:33:19 | 00,032,256 | ---- | C] ()
NETSTAT.EXE -> C:\Windows\SysWow64\NETSTAT.EXE -> [2009/09/15 12:33:17 | 00,027,136 | ---- | C] (Microsoft Corporation)
ARP.EXE -> C:\Windows\SysNative\ARP.EXE -> [2009/09/15 12:33:17 | 00,023,040 | ---- | C] ()
ARP.EXE -> C:\Windows\SysWow64\ARP.EXE -> [2009/09/15 12:33:17 | 00,019,968 | ---- | C] (Microsoft Corporation)
MRINFO.EXE -> C:\Windows\SysNative\MRINFO.EXE -> [2009/09/15 12:33:17 | 00,012,800 | ---- | C] ()
finger.exe -> C:\Windows\SysWow64\finger.exe -> [2009/09/15 12:33:17 | 00,010,240 | ---- | C] (Microsoft Corporation)
TCPSVCS.EXE -> C:\Windows\SysWow64\TCPSVCS.EXE -> [2009/09/15 12:33:17 | 00,009,728 | ---- | C] (Microsoft Corporation)
HOSTNAME.EXE -> C:\Windows\SysWow64\HOSTNAME.EXE -> [2009/09/15 12:33:17 | 00,008,704 | ---- | C] (Microsoft Corporation)
ROUTE.EXE -> C:\Windows\SysNative\ROUTE.EXE -> [2009/09/15 12:33:16 | 00,021,504 | ---- | C] ()
ROUTE.EXE -> C:\Windows\SysWow64\ROUTE.EXE -> [2009/09/15 12:33:16 | 00,017,920 | ---- | C] (Microsoft Corporation)
netevent.dll -> C:\Windows\SysWow64\netevent.dll -> [2009/09/15 12:33:16 | 00,017,920 | ---- | C] (Microsoft Corporation)
netevent.dll -> C:\Windows\SysNative\netevent.dll -> [2009/09/15 12:33:16 | 00,017,920 | ---- | C] ()
MRINFO.EXE -> C:\Windows\SysWow64\MRINFO.EXE -> [2009/09/15 12:33:16 | 00,011,264 | ---- | C] (Microsoft Corporation)
finger.exe -> C:\Windows\SysNative\finger.exe -> [2009/09/15 12:33:16 | 00,011,264 | ---- | C] ()
TCPSVCS.EXE -> C:\Windows\SysNative\TCPSVCS.EXE -> [2009/09/15 12:33:16 | 00,010,752 | ---- | C] ()
HOSTNAME.EXE -> C:\Windows\SysNative\HOSTNAME.EXE -> [2009/09/15 12:33:16 | 00,010,240 | ---- | C] ()
Apphlpdm.dll -> C:\Windows\SysNative\Apphlpdm.dll -> [2009/09/15 12:32:08 | 00,032,256 | ---- | C] ()
Apphlpdm.dll -> C:\Windows\SysWow64\Apphlpdm.dll -> [2009/09/15 12:32:07 | 00,028,672 | ---- | C] (Microsoft Corporation)
GameUXLegacyGDFs.dll -> C:\Windows\SysWow64\GameUXLegacyGDFs.dll -> [2009/09/15 12:32:06 | 04,240,384 | ---- | C] (Microsoft)
GameUXLegacyGDFs.dll -> C:\Windows\SysNative\GameUXLegacyGDFs.dll -> [2009/09/15 12:32:05 | 04,240,384 | ---- | C] ()
wlan.tmf -> C:\Windows\SysNative\wlan.tmf -> [2009/09/15 12:32:02 | 02,608,803 | ---- | C] ()
wlansec.dll -> C:\Windows\SysNative\wlansec.dll -> [2009/09/15 12:32:01 | 00,376,832 | ---- | C] ()
wlanmsm.dll -> C:\Windows\SysNative\wlanmsm.dll -> [2009/09/15 12:32:01 | 00,353,280 | ---- | C] ()
L2SecHC.dll -> C:\Windows\SysNative\L2SecHC.dll -> [2009/09/15 12:32:01 | 00,157,184 | ---- | C] ()
wlanmsm.dll -> C:\Windows\SysWow64\wlanmsm.dll -> [2009/09/15 12:32:00 | 00,293,376 | ---- | C] (Microsoft Corporation)
L2SecHC.dll -> C:\Windows\SysWow64\L2SecHC.dll -> [2009/09/15 12:32:00 | 00,127,488 | ---- | C] (Microsoft Corporation)
wlansvc.dll -> C:\Windows\SysNative\wlansvc.dll -> [2009/09/15 12:31:59 | 00,615,936 | ---- | C] ()
wlansec.dll -> C:\Windows\SysWow64\wlansec.dll -> [2009/09/15 12:31:59 | 00,302,592 | ---- | C] (Microsoft Corporation)
wlanhlp.dll -> C:\Windows\SysNative\wlanhlp.dll -> [2009/09/15 12:31:59 | 00,097,792 | ---- | C] ()
wlanapi.dll -> C:\Windows\SysNative\wlanapi.dll -> [2009/09/15 12:31:59 | 00,086,528 | ---- | C] ()
Corel -> C:\Users\kevin\AppData\Roaming\Corel -> [2009/09/15 11:40:41 | 00,000,000 | ---D | C]
2B5DF783E1.sys -> C:\ProgramData\2B5DF783E1.sys -> [2009/09/15 11:40:40 | 00,000,088 | RHS- | C] ()
KGyGaAvL.sys -> C:\ProgramData\KGyGaAvL.sys -> [2009/09/15 11:40:39 | 00,002,828 | -HS- | C] ()
ivireg.ivr -> C:\Windows\SysNative\ivireg.ivr -> [2009/09/15 11:39:49 | 00,000,040 | -H-- | C] ()
regi.sys -> C:\Windows\SysNative\drivers\regi.sys -> [2009/09/15 11:39:48 | 00,014,112 | ---- | C] ()
IZArc -> C:\Program Files (x86)\IZArc -> [2009/09/15 10:55:05 | 00,000,000 | ---D | C]
Malwarebytes' Scheduled Scan for kevin.job -> C:\Windows\tasks\Malwarebytes' Scheduled Scan for kevin.job -> [2009/09/15 07:56:53 | 00,000,516 | ---- | C] ()
Cerberus -> C:\Users\kevin\AppData\Roaming\Cerberus -> [2009/09/15 07:55:00 | 00,000,000 | RHSD | C]
2.rtf -> C:\Users\kevin\Documents\2.rtf -> [2009/09/15 07:52:51 | 00,000,312 | ---- | C] ()
Malwarebytes' Scheduled Update for kevin.job -> C:\Windows\tasks\Malwarebytes' Scheduled Update for kevin.job -> [2009/09/15 07:48:24 | 00,000,502 | ---- | C] ()
avgntflt.sys -> C:\Windows\SysNative\drivers\avgntflt.sys -> [2009/09/15 07:08:44 | 00,073,048 | ---- | C] ()
ssmdrv.sys -> C:\Windows\SysWow64\drivers\ssmdrv.sys -> [2009/09/15 07:08:44 | 00,028,520 | ---- | C] (Avira GmbH)
Avira -> C:\ProgramData\Avira -> [2009/09/15 07:08:27 | 00,000,000 | ---D | C]
Avira -> C:\Program Files (x86)\Avira -> [2009/09/15 07:08:27 | 00,000,000 | ---D | C]
Document.rtf -> C:\Users\kevin\Documents\Document.rtf -> [2009/09/14 04:28:47 | 00,000,235 | ---- | C] ()
Conduit -> C:\Program Files (x86)\Conduit -> [2009/09/12 00:43:05 | 00,000,000 | ---D | C]
Webteh -> C:\Program Files (x86)\Webteh -> [2009/09/12 00:43:01 | 00,000,000 | ---D | C]
BSplayer Pro -> C:\Users\kevin\AppData\Roaming\BSplayer Pro -> [2009/09/12 00:43:01 | 00,000,000 | ---D | C]
BSplayer -> C:\Users\kevin\AppData\Roaming\BSplayer -> [2009/09/12 00:43:01 | 00,000,000 | ---D | C]
LMIport.dll -> C:\Windows\SysNative\LMIport.dll -> [2009/09/09 00:29:18 | 00,029,496 | ---- | C] ()
LMIRfsClientNP.dll -> C:\Windows\SysNative\LMIRfsClientNP.dll -> [2009/09/09 00:29:17 | 00,087,384 | ---- | C] ()
LMIRfsDriver.sys -> C:\Windows\SysNative\drivers\LMIRfsDriver.sys -> [2009/09/09 00:29:17 | 00,072,216 | ---- | C] ()
LMIinit.dll -> C:\Windows\SysNative\LMIinit.dll -> [2009/09/09 00:29:11 | 00,080,696 | ---- | C] ()
.rnd -> C:\.rnd -> [2009/09/09 00:29:06 | 00,001,024 | ---- | C] ()
LogMeIn -> C:\Program Files (x86)\LogMeIn -> [2009/09/09 00:28:51 | 00,000,000 | ---D | C]
Apps -> C:\Users\kevin\AppData\Local\Apps -> [2009/09/09 00:25:16 | 00,000,000 | ---D | C]
Deployment -> C:\Users\kevin\AppData\Local\Deployment -> [2009/09/09 00:25:15 | 00,000,000 | ---D | C]
Searches -> C:\Users\kevin\Searches -> [2009/09/08 02:16:50 | 00,000,000 | R--D | C]
SRS Labs -> C:\Users\kevin\AppData\Local\SRS Labs -> [2009/09/07 09:36:33 | 00,000,000 | ---D | C]
SRS Labs -> C:\ProgramData\SRS Labs -> [2009/09/07 09:36:07 | 00,000,000 | ---D | C]
Surroundhp_kern_amd64.sys -> C:\Windows\SysNative\drivers\Surroundhp_kern_amd64.sys -> [2009/09/07 09:35:11 | 00,064,768 | ---- | C] ()
csiidecoder_kern_amd64.sys -> C:\Windows\SysNative\drivers\csiidecoder_kern_amd64.sys -> [2009/09/07 09:35:11 | 00,064,384 | ---- | C] ()
tshd4_kern_amd64.sys -> C:\Windows\SysNative\drivers\tshd4_kern_amd64.sys -> [2009/09/07 09:35:11 | 00,059,904 | ---- | C] ()
SRS_SSCFilter_amd64.sys -> C:\Windows\SysNative\drivers\SRS_SSCFilter_amd64.sys -> [2009/09/07 09:35:11 | 00,055,040 | ---- | C] ()
wowhd_kern_amd64.sys -> C:\Windows\SysNative\drivers\wowhd_kern_amd64.sys -> [2009/09/07 09:35:11 | 00,042,880 | ---- | C] ()
SRS Labs -> C:\Program Files\SRS Labs -> [2009/09/07 09:35:04 | 00,000,000 | ---D | C]
Cracked exe -> C:\Users\kevin\Desktop\Cracked exe -> [2009/09/07 09:30:01 | 00,000,000 | ---D | C]
Favorites -> C:\Users\kevin\Favorites -> [2009/09/07 02:43:35 | 00,000,000 | R--D | C]
ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/07 02:33:24 | 00,524,288 | -HS- | C] ()
ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/07 02:33:24 | 00,524,288 | -HS- | C] ()
ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TM.blf -> [2009/09/07 02:33:24 | 00,065,536 | -HS- | C] ()
Pictures -> C:\Users\kevin\Documents\Pictures -> [2009/09/07 02:20:21 | 00,000,000 | ---D | C]
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009/09/06 23:17:12 | 00,031,871 | ---- | C] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009/09/06 23:17:12 | 00,031,871 | ---- | C] ()
Adobe -> C:\Program Files (x86)\Common Files\Adobe -> [2009/09/06 22:47:04 | 00,000,000 | ---D | C]
Adobe -> C:\Program Files (x86)\Adobe -> [2009/09/06 22:47:04 | 00,000,000 | ---D | C]
jagex_runescape_preferences2.dat -> C:\Users\kevin\jagex_runescape_preferences2.dat -> [2009/09/05 18:44:07 | 00,000,045 | ---- | C] ()
jagex_runescape_preferences.dat -> C:\Users\kevin\jagex_runescape_preferences.dat -> [2009/09/05 18:44:01 | 00,000,037 | ---- | C] ()
ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\ProgramData\ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/05 04:30:38 | 00,524,288 | -HS- | C] ()
ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\ProgramData\ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/05 04:30:38 | 00,524,288 | -HS- | C] ()
ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TM.blf -> C:\ProgramData\ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TM.blf -> [2009/09/05 04:30:38 | 00,065,536 | -HS- | C] ()
ntuser.dat -> C:\ProgramData\ntuser.dat -> [2009/09/05 04:30:37 | 00,262,144 | ---- | C] ()
SwiftKit.lnk -> C:\Users\kevin\Desktop\SwiftKit.lnk -> [2009/09/02 10:38:24 | 00,000,846 | ---- | C] ()
SwiftKit -> C:\ProgramData\SwiftKit -> [2009/09/02 10:38:14 | 00,000,000 | ---D | C]
SwiftKit -> C:\Program Files (x86)\SwiftKit -> [2009/09/02 10:37:52 | 00,000,000 | ---D | C]
Adobe -> C:\Windows\SysWow64\Adobe -> [2009/08/31 00:54:16 | 00,000,000 | ---D | C]
Java -> C:\Program Files (x86)\Java -> [2009/08/31 00:34:45 | 00,000,000 | ---D | C]
ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/08/29 04:37:30 | 00,524,288 | -HS- | C] ()
ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/08/29 04:37:30 | 00,524,288 | -HS- | C] ()
ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TM.blf -> [2009/08/29 04:37:30 | 00,065,536 | -HS- | C] ()
.jagex_cache_32 -> C:\.jagex_cache_32 -> [2009/08/28 16:00:11 | 00,000,000 | ---D | C]
tzres.dll -> C:\Windows\SysWow64\tzres.dll -> [2009/08/26 03:16:35 | 00,002,048 | ---- | C] (Microsoft Corporation)
tzres.dll -> C:\Windows\SysNative\tzres.dll -> [2009/08/26 03:16:35 | 00,002,048 | ---- | C] ()
ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/08/26 03:12:05 | 00,524,288 | -HS- | C] ()
ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/08/26 03:12:05 | 00,524,288 | -HS- | C] ()
ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TM.blf -> [2009/08/26 03:12:05 | 00,065,536 | -HS- | C] ()
Combined Community Codec Pack -> C:\Program Files (x86)\Combined Community Codec Pack -> [2009/08/26 02:00:36 | 00,000,000 | ---D | C]
MCE Logs -> C:\Users\Public\Documents\MCE Logs -> [2009/08/26 01:16:49 | 00,000,000 | -HSD | C]
vlc -> C:\Users\kevin\AppData\Roaming\vlc -> [2009/08/25 01:20:08 | 00,000,000 | ---D | C]
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2009/08/25 01:19:46 | 00,000,901 | ---- | C] ()
VideoLAN -> C:\Program Files (x86)\VideoLAN -> [2009/08/25 01:19:33 | 00,000,000 | ---D | C]
ractrlkeyhook.dll -> C:\Windows\SysWow64\ractrlkeyhook.dll -> [2009/05/14 14:29:30 | 00,008,520 | ---- | C] ()
tcpmon.ini -> C:\Windows\SysWow64\tcpmon.ini -> [2008/01/20 22:50:05 | 00,060,124 | ---- | C] ()
msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2008/01/20 22:49:49 | 00,368,640 | ---- | C] ()
system.ini -> C:\Windows\system.ini -> [2006/11/02 08:34:27 | 00,000,219 | ---- | C] ()
win.ini -> C:\Windows\win.ini -> [2006/11/02 08:34:27 | 00,000,144 | ---- | C] ()

[Files/Folders - Modified Within 30 Days]
2 C:\Windows\*.tmp files -> C:\Windows\*.tmp ->
128 C:\Users\kevin\AppData\Local\Temp\*.tmp files -> C:\Users\kevin\AppData\Local\Temp\*.tmp ->
9 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp ->
ntuser.dat -> C:\Users\kevin\ntuser.dat -> [2009/09/23 21:51:47 | 01,835,008 | -HS- | M] ()
OTS.exe -> C:\Users\kevin\Desktop\OTS.exe -> [2009/09/23 21:51:40 | 00,514,560 | ---- | M] (OldTimer Tools)
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009/09/23 21:20:25 | 00,003,216 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009/09/23 21:20:25 | 00,003,216 | -H-- | M] ()
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009/09/23 20:57:26 | 00,031,871 | ---- | M] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009/09/23 20:57:26 | 00,031,871 | ---- | M] ()
qmgr1.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat -> [2009/09/23 16:43:46 | 04,194,304 | ---- | M] ()
qmgr0.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat -> [2009/09/23 16:43:46 | 04,194,304 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\kevin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/09/23 12:21:56 | 00,156,160 | ---- | M] ()
Malwarebytes' Scheduled Scan for kevin.job -> C:\Windows\tasks\Malwarebytes' Scheduled Scan for kevin.job -> [2009/09/23 05:03:40 | 00,000,516 | ---- | M] ()
Malwarebytes' Scheduled Update for kevin.job -> C:\Windows\tasks\Malwarebytes' Scheduled Update for kevin.job -> [2009/09/23 04:00:06 | 00,000,502 | ---- | M] ()
hpqp.ini -> C:\Users\Public\Documents\hpqp.ini -> [2009/09/23 03:36:20 | 00,000,258 | ---- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2009/09/23 03:20:19 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009/09/23 03:20:18 | 00,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/09/23 03:20:13 | 20,792,48384 | -HS- | M] ()
ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/23 03:18:49 | 00,524,288 | -HS- | M] ()
ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TM.blf -> [2009/09/23 03:18:49 | 00,065,536 | -HS- | M] ()
IconCache.db -> C:\Users\kevin\AppData\Local\IconCache.db -> [2009/09/23 03:18:29 | 01,985,632 | -H-- | M] ()
PublishedRacMonSWITable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonSWITable.DAT -> [2009/09/23 00:15:55 | 00,058,504 | ---- | M] ()
PublishedRacMonAFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonAFLTable.DAT -> [2009/09/23 00:15:55 | 00,024,840 | ---- | M] ()
PublishedRacMonOSFTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonOSFTable.DAT -> [2009/09/23 00:15:55 | 00,007,176 | ---- | M] ()
PublishedRacMonIndex.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonIndex.DAT -> [2009/09/23 00:15:55 | 00,000,960 | ---- | M] ()
PublishedRacMonHFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonHFLTable.DAT -> [2009/09/23 00:15:55 | 00,000,000 | ---- | M] ()
PublishedRacMonCLKTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonCLKTable.DAT -> [2009/09/23 00:15:55 | 00,000,000 | ---- | M] ()
WinVd32.sys -> C:\Windows\WinVd32.sys -> [2009/09/22 17:11:59 | 00,197,728 | ---- | M] ()
WinFLsrv.exe -> C:\Windows\SysWow64\WinFLsrv.exe -> [2009/09/22 17:11:57 | 00,007,680 | ---- | M] ()
ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{bc4fa16e-a743-11de-9cf9-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/22 04:39:14 | 00,524,288 | -HS- | M] ()
ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/22 03:02:45 | 00,524,288 | -HS- | M] ()
ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/22 03:02:45 | 00,524,288 | -HS- | M] ()
ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{4a7ede6a-a73f-11de-a5ab-001d7262a495}.TM.blf -> [2009/09/22 03:02:45 | 00,065,536 | -HS- | M] ()
ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/22 02:42:24 | 00,524,288 | -HS- | M] ()
ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TM.blf -> [2009/09/22 02:42:24 | 00,065,536 | -HS- | M] ()
jagex_runescape_preferences2.dat -> C:\Users\kevin\jagex_runescape_preferences2.dat -> [2009/09/19 11:51:44 | 00,000,045 | ---- | M] ()
jagex_runescape_preferences.dat -> C:\Users\kevin\jagex_runescape_preferences.dat -> [2009/09/19 11:50:59 | 00,000,037 | ---- | M] ()
avira_antivir_premium_en.exe -> C:\Users\kevin\AppData\Local\Temp\avira_antivir_premium_en.exe -> [2009/09/19 05:50:55 | 35,953,656 | ---- | M] ()
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2009/09/18 05:52:52 | 00,690,960 | ---- | M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2009/09/18 05:52:52 | 00,595,684 | ---- | M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2009/09/18 05:52:52 | 00,101,350 | ---- | M] ()
vso_ts_preview.xml -> C:\Users\kevin\AppData\Roaming\vso_ts_preview.xml -> [2009/09/17 13:07:29 | 00,001,044 | ---- | M] ()
MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2009/09/16 18:40:02 | 33,338,7006 | ---- | M] ()
gg.rtf -> C:\Users\kevin\Documents\gg.rtf -> [2009/09/16 14:07:02 | 00,000,167 | ---- | M] ()
d3d9caps.dat -> C:\Users\kevin\AppData\Local\d3d9caps.dat -> [2009/09/16 10:34:30 | 00,007,620 | ---- | M] ()
nvModes.001 -> C:\Users\kevin\AppData\Roaming\nvModes.001 -> [2009/09/16 02:36:20 | 00,027,335 | ---- | M] ()
inst.exe -> C:\Users\kevin\AppData\Roaming\inst.exe -> [2009/09/15 13:20:14 | 00,099,384 | ---- | M] ()
pcouffin.sys -> C:\Users\kevin\AppData\Roaming\pcouffin.sys -> [2009/09/15 13:20:14 | 00,082,816 | ---- | M] (VSO Software)
pcouffin.sys -> C:\Windows\SysNative\drivers\pcouffin.sys -> [2009/09/15 13:20:14 | 00,082,816 | ---- | M] ()
pcouffin.cat -> C:\Users\kevin\AppData\Roaming\pcouffin.cat -> [2009/09/15 13:20:14 | 00,007,859 | ---- | M] ()
pcouffin.inf -> C:\Users\kevin\AppData\Roaming\pcouffin.inf -> [2009/09/15 13:20:14 | 00,001,167 | ---- | M] ()
ConvertXtoDvd 3.lnk -> C:\Users\kevin\Desktop\ConvertXtoDvd 3.lnk -> [2009/09/15 13:20:12 | 00,001,027 | ---- | M] ()
GDIPFONTCACHEV1.DAT -> C:\Users\kevin\AppData\Local\GDIPFONTCACHEV1.DAT -> [2009/09/15 12:41:45 | 00,071,000 | ---- | M] ()
FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2009/09/15 12:40:20 | 00,301,968 | ---- | M] ()
KGyGaAvL.sys -> C:\ProgramData\KGyGaAvL.sys -> [2009/09/15 12:00:32 | 00,002,828 | -HS- | M] ()
2B5DF783E1.sys -> C:\ProgramData\2B5DF783E1.sys -> [2009/09/15 12:00:32 | 00,000,088 | RHS- | M] ()
YSPCUNLR.dll -> C:\Users\kevin\AppData\Local\Temp\YSPCUNLR.dll -> [2009/09/15 11:58:12 | 00,032,768 | ---- | M] (Corel Corporation)
ivireg.ivr -> C:\Windows\SysNative\ivireg.ivr -> [2009/09/15 11:39:54 | 00,000,040 | -H-- | M] ()
2.rtf -> C:\Users\kevin\Documents\2.rtf -> [2009/09/15 07:52:52 | 00,000,312 | ---- | M] ()
avgntflt.sys -> C:\Windows\SysNative\drivers\avgntflt.sys -> [2009/09/15 06:45:05 | 00,073,048 | ---- | M] ()
ssmdrv.sys -> C:\Windows\SysWow64\drivers\ssmdrv.sys -> [2009/09/15 06:45:05 | 00,028,520 | ---- | M] (Avira GmbH)
Document.rtf -> C:\Users\kevin\Documents\Document.rtf -> [2009/09/14 04:28:47 | 00,000,235 | ---- | M] ()
HPCeeScheduleForkevin.job -> C:\Windows\tasks\HPCeeScheduleForkevin.job -> [2009/09/12 22:43:05 | 00,000,334 | ---- | M] ()
Au_.exe -> C:\Users\kevin\AppData\Local\Temp\~nsu.tmp\Au_.exe -> [2009/09/12 00:43:02 | 00,071,785 | ---- | M] ()
nvModes.dat -> C:\Users\kevin\AppData\Roaming\nvModes.dat -> [2009/09/10 21:09:24 | 00,027,335 | ---- | M] ()
GetVersion.dll -> C:\Users\kevin\AppData\Local\Temp\nsnE4BA.tmp\GetVersion.dll -> [2009/09/10 19:49:35 | 00,005,120 | ---- | M] ()
mbamswissarmy.sys -> C:\Windows\SysWow64\drivers\mbamswissarmy.sys -> [2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\SysNative\drivers\mbam.sys -> [2009/09/10 14:53:52 | 00,022,104 | ---- | M] ()
.rnd -> C:\.rnd -> [2009/09/09 00:29:07 | 00,001,024 | ---- | M] ()
ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{231abcd0-9b5d-11de-8073-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/08 03:49:06 | 00,524,288 | -HS- | M] ()
ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/07 02:27:34 | 00,524,288 | -HS- | M] ()
ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TM.blf -> [2009/09/07 02:27:34 | 00,065,536 | -HS- | M] ()
nos_uninstall_Adobe.dll -> C:\Users\kevin\AppData\Local\Temp\nos_uninstall_Adobe.dll -> [2009/09/06 23:01:19 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.)
LMIRfsClientNP.dll -> C:\Windows\SysNative\LMIRfsClientNP.dll -> [2009/09/05 11:24:04 | 00,087,384 | ---- | M] ()
LMIport.dll -> C:\Windows\SysNative\LMIport.dll -> [2009/09/05 11:23:52 | 00,029,496 | ---- | M] ()
LMIinit.dll -> C:\Windows\SysNative\LMIinit.dll -> [2009/09/05 11:23:50 | 00,080,696 | ---- | M] ()
ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\ProgramData\ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/09/05 04:30:38 | 00,524,288 | -HS- | M] ()
ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\ProgramData\ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/05 04:30:38 | 00,524,288 | -HS- | M] ()
ntuser.dat -> C:\ProgramData\ntuser.dat -> [2009/09/05 04:30:38 | 00,262,144 | ---- | M] ()
ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TM.blf -> C:\ProgramData\ntuser.dat{7f32d1d7-997d-11de-b698-001d7262a495}.TM.blf -> [2009/09/05 04:30:38 | 00,065,536 | -HS- | M] ()
b.dat -> C:\Users\kevin\AppData\Local\Temp\b.dat -> [2009/09/04 01:11:47 | 00,086,352 | ---- | M] ()
c.exe -> C:\Users\kevin\AppData\Local\Temp\c.exe -> [2009/09/03 21:40:25 | 00,150,016 | ---- | M] ()
SwiftKit.lnk -> C:\Users\kevin\Desktop\SwiftKit.lnk -> [2009/09/02 10:38:24 | 00,000,846 | ---- | M] ()
ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{c1f23b6c-9430-11de-84b6-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/08/29 06:51:18 | 00,524,288 | -HS- | M] ()
ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/08/29 04:01:50 | 00,524,288 | -HS- | M] ()
ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TM.blf -> [2009/08/29 04:01:50 | 00,065,536 | -HS- | M] ()
mrt.exe -> C:\Windows\SysNative\mrt.exe -> [2009/08/28 18:10:41 | 26,035,144 | ---- | M] ()
setup.exe -> C:\Users\kevin\AppData\Local\Temp\pft88F3~tmp\setup.exe -> [2009/08/28 15:28:22 | 11,502,1048 | ---- | M] (Corel Inc. )
setup.exe -> C:\Users\kevin\AppData\Local\Temp\pft7E98~tmp\setup.exe -> [2009/08/28 15:28:22 | 11,502,1048 | ---- | M] (Corel Inc. )
setup.exe -> C:\Users\kevin\AppData\Local\Temp\pft48B8~tmp\setup.exe -> [2009/08/28 15:28:22 | 11,502,1048 | ---- | M] (Corel Inc. )
Apphlpdm.dll -> C:\Windows\SysNative\Apphlpdm.dll -> [2009/08/28 08:51:05 | 00,032,256 | ---- | M] ()
Apphlpdm.dll -> C:\Windows\SysWow64\Apphlpdm.dll -> [2009/08/28 08:39:07 | 00,028,672 | ---- | M] (Microsoft Corporation)
GameUXLegacyGDFs.dll -> C:\Windows\SysNative\GameUXLegacyGDFs.dll -> [2009/08/28 06:39:32 | 04,240,384 | ---- | M] ()
GameUXLegacyGDFs.dll -> C:\Windows\SysWow64\GameUXLegacyGDFs.dll -> [2009/08/28 06:15:30 | 04,240,384 | ---- | M] (Microsoft)
ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\kevin\ntuser.dat{952155e5-920f-11de-b185-001d7262a495}.TMContainer00000000000000000002.regtrans-ms -> [2009/08/26 13:24:49 | 00,524,288 | -HS- | M] ()
ntuser.dat{72f62f81-89e8-11de-b97e-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\kevin\ntuser.dat{72f62f81-89e8-11de-b97e-001d7262a495}.TMContainer00000000000000000001.regtrans-ms -> [2009/08/25 21:42:10 | 00,524,288 | -HS- | M] ()
ntuser.dat{72f62f81-89e8-11de-b97e-001d7262a495}.TM.blf -> C:\Users\kevin\ntuser.dat{72f62f81-89e8-11de-b97e-001d7262a495}.TM.blf -> [2009/08/25 21:42:10 | 00,065,536 | -HS- | M] ()
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2009/08/25 01:19:46 | 00,000,901 | ---- | M] ()
a.dat -> C:\Users\kevin\AppData\Local\Temp\a.dat -> [2009/08/16 15:29:08 | 00,084,140 | ---- | M] ()
GetVersion.dll -> C:\Users\kevin\AppData\Local\Temp\nsyD72D.tmp\GetVersion.dll -> [2009/08/15 19:12:15 | 00,005,120 | ---- | M] ()
FW_Register_Plugin_Action.dat -> C:\Users\kevin\AppData\Local\Temp\FW_Register_Plugin_Action.dat -> [2009/08/14 13:57:14 | 00,000,172 | ---- | M] ()
DefInstAction.dat -> C:\Users\kevin\AppData\Local\Temp\DefInstAction.dat -> [2009/08/14 13:53:40 | 00,000,124 | ---- | M] ()
QBackupInst.dat -> C:\Users\kevin\AppData\Local\Temp\QBackupInst.dat -> [2009/08/14 13:53:38 | 00,000,124 | ---- | M] ()
GetVersion.dll -> C:\Users\kevin\AppData\Local\Temp\nshCDA0.tmp\GetVersion.dll -> [2009/08/14 06:15:29 | 00,005,120 | ---- | M] ()
nsisFirewall.dll -> C:\Users\kevin\AppData\Local\Temp\nshCDA0.tmp\nsisFirewall.dll -> [2009/08/14 06:15:28 | 00,008,192 | ---- | M] ()
UserInfo.dll -> C:\Users\kevin\AppData\Local\Temp\nshCDA0.tmp\UserInfo.dll -> [2009/08/14 06:15:28 | 00,004,096 | ---- | M] ()
UAC.dll -> C:\Users\kevin\AppData\Local\Temp\nshCDA0.tmp\UAC.dll -> [2009/08/14 06:15:04 | 00,016,384 | ---- | M] ()
NSISdl.dll -> C:\Users\kevin\AppData\Local\Temp\nshCDA0.tmp\NSISdl.dll -> [2009/08/14 06:15:04 | 00,014,848 | ---- | M] ()
UAC.dll -> C:\Users\kevin\AppData\Local\Temp\nsmB7CF.tmp\UAC.dll -> [2009/08/14 06:14:59 | 00,016,384 | ---- | M] ()
utt2060.tmp.exe -> C:\Users\kevin\AppData\Local\Temp\utt2060.tmp.exe -> [2009/08/14 06:12:09 | 00,875,768 | ---- | M] (Ask.com )
NSISArray.dll -> C:\Users\kevin\AppData\Local\Temp\nsu4F3A.tmp\NSISArray.dll -> [2009/08/14 02:18:37 | 00,017,920 | ---- | M] ()
utility.dll -> C:\Users\kevin\AppData\Local\Temp\nszAFC1.tmp\utility.dll -> [2009/08/14 02:16:50 | 00,072,752 | ---- | M] ()
utility.dll -> C:\Users\kevin\AppData\Local\Temp\nsz7BA7.tmp\utility.dll -> [2009/08/14 02:16:36 | 00,072,752 | ---- | M] ()
kevin.dat -> C:\ProgramData\Microsoft\User Account Pictures\kevin.dat -> [2009/08/13 22:23:32 | 00,000,000 | ---- | M] ()
AskInstallChecker.exe -> C:\Users\kevin\AppData\Local\Temp\AskInstallChecker.exe -> [2009/03/25 15:20:56 | 00,054,664 | ---- | M] ()
ywiseext.dll -> C:\Users\kevin\AppData\Local\Temp\6759585\ywiseext.dll -> [2008/12/04 14:51:04 | 00,126,976 | ---- | M] (Yahoo! Inc.)
_setup.dll -> C:\Users\kevin\AppData\Local\Temp\isp8A9B.tmp\_setup.dll -> [2008/06/26 11:08:04 | 00,344,064 | ---- | M] (InstallShield Software Corporation)
A~NSISu_.exe -> C:\Users\kevin\AppData\Local\Temp\A~NSISu_.exe -> [2008/02/22 12:28:53 | 00,093,488 | ---- | M] (AOL LLC)
B~NSISu_.exe -> C:\Users\kevin\AppData\Local\Temp\B~NSISu_.exe -> [2008/02/22 12:28:40 | 00,088,495 | ---- | M] (AOL LLC)
srtspso.dat -> C:\Users\kevin\AppData\Local\Temp\srtspso.dat -> [2008/02/22 12:16:15 | 00,002,692 | ---- | M] ()
srtspsp.dat -> C:\Users\kevin\AppData\Local\Temp\srtspsp.dat -> [2008/02/22 12:15:28 | 00,000,524 | ---- | M] ()
srtspse.dat -> C:\Users\kevin\AppData\Local\Temp\srtspse.dat -> [2008/02/22 12:15:28 | 00,000,284 | ---- | M] ()
UIU32a.exe -> C:\Windows\Temp\1214492910\Hermosa\V32\UIU32a.exe -> [2007/10/01 11:35:54 | 00,825,912 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Hermosa\V32\Setup.exe -> [2007/10/01 11:35:54 | 00,825,912 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Hermosa\Setup.exe -> [2007/10/01 11:35:54 | 00,825,912 | ---- | M] (Conexant Systems, Inc.)
UCI32A22.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\UCI32A22.dll -> [2007/10/01 11:35:54 | 00,227,896 | ---- | M] (Conexant Systems, Inc.)
CnxtAP32.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\CnxtAP32.dll -> [2007/10/01 11:35:52 | 00,537,144 | ---- | M] (Conexant Systems Inc.)
DIFxAPI.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\DIFxAPI.dll -> [2007/10/01 11:35:52 | 00,319,544 | ---- | M] (Microsoft Corporation)
CnxtAP64.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\CnxtAP64.dll -> [2007/10/01 07:31:14 | 00,566,784 | ---- | M] (Conexant Systems Inc.)
setup64.exe -> C:\Windows\Temp\1214492910\Hermosa\V64\setup64.exe -> [2007/09/27 06:49:20 | 01,108,872 | ---- | M] (Conexant Systems, Inc.)
UIU64a.exe -> C:\Windows\Temp\1214492910\Hermosa\V64\UIU64a.exe -> [2007/09/27 06:28:08 | 01,103,360 | ---- | M] (Conexant Systems, Inc.)
_isB364.exe -> C:\Users\kevin\AppData\Local\Temp\_isB364.exe -> [2007/09/26 03:00:30 | 00,453,688 | ---- | M] (Macrovision Corporation)
UCI64A22.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\UCI64A22.dll -> [2007/09/24 06:39:34 | 00,314,880 | ---- | M] (Conexant Systems, Inc.)
SmAudio.exe -> C:\Windows\Temp\1214492971\SmAudio\SmAudio.exe -> [2007/09/18 10:06:20 | 03,917,128 | ---- | M] (Conexant)
SmAudio.exe -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\SmAudio.exe -> [2007/09/18 10:06:20 | 03,917,128 | ---- | M] (Conexant)
SmAudio.exe -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\SmAudio.exe -> [2007/09/18 10:06:20 | 03,917,128 | ---- | M] (Conexant)
youcam-tutorial.exe -> C:\Users\kevin\AppData\Local\Temp\YouCam\Tutorial\youcam-tutorial.exe -> [2007/09/04 22:48:46 | 02,358,636 | ---- | M] (Macromedia, Inc.)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1f\01\rcSvcHst.dll -> [2007/09/04 20:51:36 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1f\01\rcLgView.dll -> [2007/09/04 20:51:20 | 00,015,720 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1f\01\rcErrDsp.dll -> [2007/09/04 20:51:14 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1f\01\rcEmlPxy.dll -> [2007/09/04 20:51:10 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1f\01\rcApp.dll -> [2007/09/04 20:51:04 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1f\01\rcAlert.dll -> [2007/09/04 20:50:58 | 00,053,608 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\19\01\rcSvcHst.dll -> [2007/09/04 20:43:24 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\19\01\rcLgView.dll -> [2007/09/04 20:43:08 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\19\01\rcErrDsp.dll -> [2007/09/04 20:43:04 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\19\01\rcEmlPxy.dll -> [2007/09/04 20:42:58 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\19\01\rcApp.dll -> [2007/09/04 20:42:52 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\19\01\rcAlert.dll -> [2007/09/04 20:42:46 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0e\01\rcSvcHst.dll -> [2007/09/04 20:19:28 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0e\01\rcLgView.dll -> [2007/09/04 20:19:12 | 00,016,232 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0e\01\rcErrDsp.dll -> [2007/09/04 20:19:06 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0e\01\rcEmlPxy.dll -> [2007/09/04 20:19:00 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0e\01\rcApp.dll -> [2007/09/04 20:18:54 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0e\01\rcAlert.dll -> [2007/09/04 20:18:50 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\05\01\rcSvcHst.dll -> [2007/09/03 12:52:56 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\05\01\rcLgView.dll -> [2007/09/03 12:52:40 | 00,015,720 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\05\01\rcErrDsp.dll -> [2007/09/03 12:52:36 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\05\01\rcEmlPxy.dll -> [2007/09/03 12:52:30 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\05\01\rcApp.dll -> [2007/09/03 12:52:26 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\05\01\rcAlert.dll -> [2007/09/03 12:52:20 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\15\01\rcSvcHst.dll -> [2007/09/03 12:50:50 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\15\01\rcLgView.dll -> [2007/09/03 12:50:34 | 00,015,720 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\15\01\rcErrDsp.dll -> [2007/09/03 12:50:30 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\15\01\rcEmlPxy.dll -> [2007/09/03 12:50:24 | 00,013,672 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\15\01\rcApp.dll -> [2007/09/03 12:50:18 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\15\01\rcAlert.dll -> [2007/09/03 12:50:14 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0b\01\rcSvcHst.dll -> [2007/09/03 12:39:14 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0b\01\rcLgView.dll -> [2007/09/03 12:39:00 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0b\01\rcErrDsp.dll -> [2007/09/03 12:38:54 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0b\01\rcEmlPxy.dll -> [2007/09/03 12:38:48 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0b\01\rcApp.dll -> [2007/09/03 12:38:44 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0b\01\rcAlert.dll -> [2007/09/03 12:38:38 | 00,053,608 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\14\01\rcSvcHst.dll -> [2007/09/03 12:36:46 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\14\01\rcLgView.dll -> [2007/09/03 12:36:30 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\14\01\rcErrDsp.dll -> [2007/09/03 12:36:26 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\14\01\rcEmlPxy.dll -> [2007/09/03 12:36:20 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\14\01\rcApp.dll -> [2007/09/03 12:36:14 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\14\01\rcAlert.dll -> [2007/09/03 12:36:10 | 00,053,608 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1d\01\rcSvcHst.dll -> [2007/08/28 12:30:24 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1d\01\rcLgView.dll -> [2007/08/28 12:30:08 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1d\01\rcErrDsp.dll -> [2007/08/28 12:30:04 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1d\01\rcEmlPxy.dll -> [2007/08/28 12:29:58 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1d\01\rcApp.dll -> [2007/08/28 12:29:52 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\1d\01\rcAlert.dll -> [2007/08/28 12:29:48 | 00,053,608 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\13\01\rcSvcHst.dll -> [2007/08/28 12:27:38 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\13\01\rcLgView.dll -> [2007/08/28 12:27:22 | 00,016,232 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\13\01\rcErrDsp.dll -> [2007/08/28 12:27:16 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\13\01\rcEmlPxy.dll -> [2007/08/28 12:27:12 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\13\01\rcApp.dll -> [2007/08/28 12:27:06 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\13\01\rcAlert.dll -> [2007/08/28 12:27:02 | 00,053,608 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\16\01\rcSvcHst.dll -> [2007/08/28 12:06:44 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\16\01\rcLgView.dll -> [2007/08/28 12:06:28 | 00,016,232 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\16\01\rcErrDsp.dll -> [2007/08/28 12:06:24 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\16\01\rcEmlPxy.dll -> [2007/08/28 12:06:18 | 00,013,672 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\16\01\rcApp.dll -> [2007/08/28 12:06:12 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\16\01\rcAlert.dll -> [2007/08/28 12:06:08 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\06\01\rcSvcHst.dll -> [2007/08/28 12:01:24 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\06\01\rcLgView.dll -> [2007/08/28 12:01:08 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\06\01\rcErrDsp.dll -> [2007/08/28 12:01:02 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\06\01\rcEmlPxy.dll -> [2007/08/28 12:00:58 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\06\01\rcApp.dll -> [2007/08/28 12:00:52 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\06\01\rcAlert.dll -> [2007/08/28 12:00:48 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\11\01\rcSvcHst.dll -> [2007/08/28 11:35:52 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\11\01\rcLgView.dll -> [2007/08/28 11:35:36 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\11\01\rcErrDsp.dll -> [2007/08/28 11:35:32 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\11\01\rcEmlPxy.dll -> [2007/08/28 11:35:26 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\11\01\rcApp.dll -> [2007/08/28 11:35:20 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\11\01\rcAlert.dll -> [2007/08/28 11:35:16 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\12\01\rcSvcHst.dll -> [2007/08/28 07:42:34 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\12\01\rcLgView.dll -> [2007/08/28 07:42:18 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\12\01\rcErrDsp.dll -> [2007/08/28 07:42:12 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\12\01\rcEmlPxy.dll -> [2007/08/28 07:42:08 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\12\01\rcApp.dll -> [2007/08/28 07:42:02 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\12\01\rcAlert.dll -> [2007/08/28 07:41:58 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\01\rcSvcHst.dll -> [2007/08/27 18:43:26 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\01\rcLgView.dll -> [2007/08/27 18:43:10 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\01\rcErrDsp.dll -> [2007/08/27 18:43:04 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\01\rcEmlPxy.dll -> [2007/08/27 18:43:00 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\01\rcApp.dll -> [2007/08/27 18:42:54 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\01\rcAlert.dll -> [2007/08/27 18:42:50 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\02\rcSvcHst.dll -> [2007/08/27 18:41:00 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\02\rcLgView.dll -> [2007/08/27 18:40:44 | 00,015,208 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\02\rcErrDsp.dll -> [2007/08/27 18:40:38 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\02\rcEmlPxy.dll -> [2007/08/27 18:40:32 | 00,013,160 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\02\rcApp.dll -> [2007/08/27 18:40:28 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\04\02\rcAlert.dll -> [2007/08/27 18:40:22 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\10\01\rcSvcHst.dll -> [2007/08/27 16:46:40 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\10\01\rcLgView.dll -> [2007/08/27 16:46:24 | 00,016,232 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\10\01\rcErrDsp.dll -> [2007/08/27 16:46:18 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\10\01\rcEmlPxy.dll -> [2007/08/27 16:46:12 | 00,013,672 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\10\01\rcApp.dll -> [2007/08/27 16:46:08 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\10\01\rcAlert.dll -> [2007/08/27 16:46:02 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\07\01\rcSvcHst.dll -> [2007/08/27 16:45:20 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\07\01\rcLgView.dll -> [2007/08/27 16:45:06 | 00,016,744 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\07\01\rcErrDsp.dll -> [2007/08/27 16:45:00 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\07\01\rcEmlPxy.dll -> [2007/08/27 16:44:54 | 00,013,672 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\07\01\rcApp.dll -> [2007/08/27 16:44:50 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\07\01\rcAlert.dll -> [2007/08/27 16:44:44 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0a\03\rcSvcHst.dll -> [2007/08/27 16:41:08 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0a\03\rcLgView.dll -> [2007/08/27 16:40:52 | 00,016,232 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0a\03\rcErrDsp.dll -> [2007/08/27 16:40:48 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0a\03\rcEmlPxy.dll -> [2007/08/27 16:40:42 | 00,013,672 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0a\03\rcApp.dll -> [2007/08/27 16:40:36 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0a\03\rcAlert.dll -> [2007/08/27 16:40:32 | 00,053,096 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0c\01\rcSvcHst.dll -> [2007/08/27 16:36:54 | 00,009,064 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0c\01\rcLgView.dll -> [2007/08/27 16:36:38 | 00,016,744 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0c\01\rcErrDsp.dll -> [2007/08/27 16:36:34 | 00,022,888 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0c\01\rcEmlPxy.dll -> [2007/08/27 16:36:28 | 00,013,672 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0c\01\rcApp.dll -> [2007/08/27 16:36:22 | 00,008,552 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\0c\01\rcAlert.dll -> [2007/08/27 16:36:18 | 00,053,096 | ---- | M] (Symantec Corporation)
ccL70U.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccL70U.dll -> [2007/08/25 00:14:00 | 00,616,808 | ---- | M] (Symantec Corporation)
ccL70.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccL70.dll -> [2007/08/25 00:14:00 | 00,498,536 | ---- | M] (Symantec Corporation)
ccSEUPDT.exe -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccSEUPDT.exe -> [2007/08/25 00:07:00 | 00,875,880 | ---- | M] (Symantec Corporation)
ccSEBind.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccSEBind.dll -> [2007/08/25 00:07:00 | 00,631,144 | ---- | M] (Symantec Corporation)
ccRkSn.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRkSn.dll -> [2007/08/25 00:07:00 | 00,414,568 | ---- | M] (Symantec Corporation)
ccScanW.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccScanW.dll -> [2007/08/25 00:07:00 | 00,369,512 | ---- | M] (Symantec Corporation)
ccSubEng.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccSubEng.dll -> [2007/08/25 00:07:00 | 00,342,376 | ---- | M] (Symantec Corporation)
ccIPC.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccIPC.dll -> [2007/08/25 00:07:00 | 00,153,960 | ---- | M] (Symantec Corporation)
ccAppPlg.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccAppPlg.dll -> [2007/08/25 00:07:00 | 00,070,504 | ---- | M] (Symantec Corporation)
rcAlert.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\09\01\rcAlert.dll -> [2007/08/25 00:07:00 | 00,053,096 | ---- | M] (Symantec Corporation)
rcErrDsp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\09\01\rcErrDsp.dll -> [2007/08/25 00:07:00 | 00,022,888 | ---- | M] (Symantec Corporation)
rcLgView.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\09\01\rcLgView.dll -> [2007/08/25 00:07:00 | 00,015,208 | ---- | M] (Symantec Corporation)
rcEmlPxy.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\09\01\rcEmlPxy.dll -> [2007/08/25 00:07:00 | 00,013,160 | ---- | M] (Symantec Corporation)
ccSEDLuM.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccSEDLuM.dll -> [2007/08/25 00:07:00 | 00,009,576 | ---- | M] (Symantec Corporation)
ccRtkLuM.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRtkLuM.dll -> [2007/08/25 00:07:00 | 00,009,576 | ---- | M] (Symantec Corporation)
ccResLuM.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccResLuM.dll -> [2007/08/25 00:07:00 | 00,009,576 | ---- | M] (Symantec Corporation)
ccMSLLuM.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccMSLLuM.dll -> [2007/08/25 00:07:00 | 00,009,576 | ---- | M] (Symantec Corporation)
ccCmnLuM.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccCmnLuM.dll -> [2007/08/25 00:07:00 | 00,009,576 | ---- | M] (Symantec Corporation)
rcSvcHst.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\09\01\rcSvcHst.dll -> [2007/08/25 00:07:00 | 00,009,064 | ---- | M] (Symantec Corporation)
rcApp.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\ccRes\09\01\rcApp.dll -> [2007/08/25 00:07:00 | 00,008,552 | ---- | M] (Symantec Corporation)
Setup.exe -> C:\Windows\Temp\1214492971\Setup.exe -> [2007/08/23 09:37:06 | 00,801,336 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\Setup.exe -> [2007/08/23 09:37:06 | 00,801,336 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\Setup.exe -> [2007/08/23 09:37:06 | 00,801,336 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Venice\V32\Setup.exe -> [2007/08/23 09:36:38 | 00,801,336 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Venice\Setup.exe -> [2007/08/23 09:36:38 | 00,801,336 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Setup.exe -> [2007/08/23 09:36:38 | 00,801,336 | ---- | M] (Conexant Systems, Inc.)
setup64.exe -> C:\Windows\Temp\1214492971\x64\setup64.exe -> [2007/08/23 09:31:12 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
setup64.exe -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\x64\setup64.exe -> [2007/08/23 09:31:12 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
setup64.exe -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\x64\setup64.exe -> [2007/08/23 09:31:12 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
KESLYN.EXE -> C:\Windows\Temp\1214492971\KESLYN.EXE -> [2007/08/23 09:31:12 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
Setup64.exe -> C:\Windows\Temp\1214492910\x64\Setup64.exe -> [2007/08/23 09:26:02 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
Setup64.exe -> C:\Windows\Temp\1214492910\Venice\V64\Setup64.exe -> [2007/08/23 09:26:02 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
KESLYN.EXE -> C:\Windows\Temp\1214492910\KESLYN.EXE -> [2007/08/23 09:26:02 | 01,075,256 | ---- | M] (Conexant Systems, Inc.)
SEVINST64x86.EXE -> C:\Users\kevin\AppData\Local\Temp\SEVINST64x86.EXE -> [2007/08/13 19:06:00 | 01,018,760 | ---- | M] (Symantec Corporation)
CnxtAP64.dll -> C:\Windows\Temp\1214492910\Venice\V64\CnxtAP64.dll -> [2007/08/01 11:45:36 | 00,561,152 | ---- | M] (Conexant Systems Inc.)
CnxtAP32.dll -> C:\Windows\Temp\1214492910\Venice\V32\CnxtAP32.dll -> [2007/08/01 11:44:00 | 00,526,336 | ---- | M] (Conexant Systems Inc.)
UIU64a.exe -> C:\Windows\Temp\1214492910\Venice\V64\UIU64a.exe -> [2007/07/26 06:05:08 | 01,068,544 | ---- | M] (Conexant Systems, Inc.)
UIU32a.exe -> C:\Windows\Temp\1214492910\Venice\V32\UIU32a.exe -> [2007/07/26 06:01:42 | 00,794,624 | ---- | M] (Conexant Systems, Inc.)
SmAudio.exe -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\SmAudio.exe -> [2007/07/23 20:37:36 | 03,495,240 | ---- | M] (Conexant)
SmAudio.exe -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\SmAudio.exe -> [2007/07/23 20:37:36 | 03,495,240 | ---- | M] (Conexant)
UCI64A21.dll -> C:\Windows\Temp\1214492910\Venice\V64\UCI64A21.dll -> [2007/07/23 20:09:08 | 00,310,272 | ---- | M] (Conexant Systems, Inc.)
UCI32A21.dll -> C:\Windows\Temp\1214492910\Venice\V32\UCI32A21.dll -> [2007/07/23 20:08:04 | 00,217,088 | ---- | M] (Conexant Systems, Inc.)
decluman.dll -> C:\Users\kevin\AppData\Local\Temp\ccInst_E8F75FE4-535E-4739-A45D-8758C698EA79\decluman.dll -> [2007/07/18 18:42:00 | 00,008,032 | ---- | M] (Symantec Corporation)
Setup.exe -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\Setup.exe -> [2007/06/25 18:36:40 | 00,796,040 | ---- | M] (Conexant Systems, Inc.)
Setup.exe -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\Setup.exe -> [2007/06/25 18:36:40 | 00,796,040 | ---- | M] (Conexant Systems, Inc.)
setup64.exe -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\x64\setup64.exe -> [2007/06/25 18:31:36 | 01,072,008 | ---- | M] (Conexant Systems, Inc.)
setup64.exe -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\x64\setup64.exe -> [2007/06/25 18:31:36 | 01,072,008 | ---- | M] (Conexant Systems, Inc.)
res0409.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0409.dll -> [2006/12/12 13:23:30 | 00,028,672 | ---- | M] (Conexant)
res0409.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0409.dll -> [2006/12/12 13:23:30 | 00,028,672 | ---- | M] (Conexant)
res0409.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0409.dll -> [2006/12/12 13:23:30 | 00,028,672 | ---- | M] (Conexant)
res0409.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0409.dll -> [2006/12/11 22:23:30 | 00,028,672 | ---- | M] (Conexant)
res0409.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0409.dll -> [2006/12/11 22:23:30 | 00,028,672 | ---- | M] (Conexant)
NPS.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Setup\NPS.dll -> [2006/11/17 21:25:18 | 03,334,144 | ---- | M] (Nero AG)
NeroDelTmp.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Setup\NeroDelTmp.exe -> [2006/11/17 21:24:28 | 00,860,160 | ---- | M] (Nero AG)
UninstallNero.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Setup\UninstallNero.exe -> [2006/11/17 21:24:10 | 00,946,176 | ---- | M] (Nero AG)
SetupX.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\SetupX.exe -> [2006/11/17 21:23:36 | 01,556,480 | ---- | M] (Nero AG)
NeroRcPluginHauppaugeD1EEA012.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeroRcPluginHauppaugeD1EEA012.dll -> [2006/11/16 18:57:32 | 00,081,920 | ---- | M] (Nero AG)
NeroRcPluginAti3935D9B2.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeroRcPluginAti3935D9B2.dll -> [2006/11/16 18:53:48 | 00,081,920 | ---- | M] (Nero AG)
SetupNeroMobileUnsignedA8C35C16.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\SetupNeroMobileUnsignedA8C35C16.exe -> [2006/11/16 15:43:54 | 03,375,705 | ---- | M] (Nero AG)
AdvrCntr2.dll -> C:\Users\kevin\AppData\Local\Temp\nro.tmp\AdvrCntr2.dll -> [2006/11/14 11:25:00 | 02,854,912 | ---- | M] (Nero AG)
AReadyLB_Nero.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\AReadyLB_Nero.dll -> [2006/11/10 13:59:00 | 00,598,016 | ---- | M] (Audible Inc.)
NeroIPP55B9FD4A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeroIPP55B9FD4A.dll -> [2006/11/09 16:04:20 | 03,371,008 | ---- | M] (Nero AG)
NeroIPP18F99FA5.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeroIPP18F99FA5.dll -> [2006/11/09 16:04:20 | 03,371,008 | ---- | M] (Nero AG)
NeroMediaConD4CB9F82.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeroMediaConD4CB9F82.dll -> [2006/11/09 16:04:20 | 01,265,664 | ---- | M] (Nero AG)
NeroMediaCon041A55CE.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeroMediaCon041A55CE.dll -> [2006/11/09 16:04:20 | 01,265,664 | ---- | M] (Nero AG)
NeVcr50E5ADBC.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeVcr50E5ADBC.dll -> [2006/11/09 16:04:20 | 00,323,584 | ---- | M] (Nero AG)
em2v6300DBD6.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\em2v6300DBD6.dll -> [2006/11/09 16:04:18 | 00,184,320 | ---- | M] (Nero AG)
em2v01DC7D73.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\em2v01DC7D73.dll -> [2006/11/09 16:04:18 | 00,184,320 | ---- | M] (Nero AG)
NeEm2a57A96039.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeEm2a57A96039.dll -> [2006/11/09 16:04:18 | 00,135,168 | ---- | M] (Nero AG)
NeEm2a529CBA7F.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeEm2a529CBA7F.dll -> [2006/11/09 16:04:18 | 00,135,168 | ---- | M] (Nero AG)
NeAcEnc9FC8C58A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeAcEnc9FC8C58A.dll -> [2006/11/09 16:04:18 | 00,126,976 | ---- | M] (Nero AG)
ndvddiscD56CC44A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\ndvddiscD56CC44A.dll -> [2006/11/09 16:04:14 | 00,045,568 | ---- | M] (Nero AG)
TMPVImporterF67588C5.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\TMPVImporterF67588C5.dll -> [2006/10/27 16:37:20 | 00,094,208 | ---- | M] (Nero AG)
UDFImporter4B649A67.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\UDFImporter4B649A67.dll -> [2006/10/27 16:37:08 | 00,425,984 | ---- | M] (Nero AG)
NeRSDB05C2D9D9.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\NeRSDB05C2D9D9.dll -> [2006/10/27 16:29:54 | 00,034,816 | ---- | M] (Nero AG)
DIFXAPI.DLL -> C:\Windows\Temp\DIFXAPI.DLL -> [2006/10/02 23:36:00 | 00,524,768 | ---- | M] (Microsoft Corporation)
DIFxAPI.dll -> C:\Windows\Temp\1214492910\Venice\V64\DIFxAPI.dll -> [2006/10/02 23:36:00 | 00,524,768 | ---- | M] (Microsoft Corporation)
DIFxAPI.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\DIFxAPI.dll -> [2006/10/02 23:36:00 | 00,524,768 | ---- | M] (Microsoft Corporation)
DIFxAPI.dll -> C:\Windows\Temp\1214492910\Venice\V32\DIFxAPI.dll -> [2006/10/02 23:35:46 | 00,319,968 | ---- | M] (Microsoft Corporation)
NiReg.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Setup\NiReg.exe -> [2006/09/22 09:05:20 | 00,823,296 | ---- | M] (Nero AG)
dsetup32.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\DirectX\dsetup32.dll -> [2006/08/14 16:08:04 | 02,248,984 | ---- | M] (Microsoft Corporation)
dxsetup.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\DirectX\dxsetup.exe -> [2006/08/14 16:08:04 | 00,484,632 | ---- | M] (Microsoft Corporation)
DSETUP.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\DirectX\DSETUP.dll -> [2006/08/14 16:08:04 | 00,074,520 | ---- | M] (Microsoft Corporation)
HPQSi.exe -> C:\Users\kevin\AppData\Local\Temp\HPQSi.exe -> [2006/08/08 13:55:48 | 00,069,632 | ---- | M] (Hewlett-Packard Company)
Drweb323680E0DF.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\Drweb323680E0DF.dll -> [2006/05/31 19:46:46 | 01,347,584 | ---- | M] (Doctor Web, Ltd.)
VMPEGEncNDX44D4A2E4.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\VMPEGEncNDX44D4A2E4.dll -> [2006/05/31 19:46:46 | 00,364,544 | ---- | M] (Nero AG)
unrar.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Setup\unrar.dll -> [2006/01/05 16:56:06 | 00,160,768 | ---- | M] ()
BCGPOleAcc9B39C142.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\BCGPOleAcc9B39C142.dll -> [2005/12/23 16:50:28 | 00,032,768 | ---- | M] ()
BCGCBPRO8002D9B60E3.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\BCGCBPRO8002D9B60E3.dll -> [2005/10/17 16:07:46 | 02,600,960 | ---- | M] (BCGSoft Ltd)
res0816.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0816.dll -> [2005/10/03 11:19:16 | 00,028,672 | ---- | M] (Conexant)
res0816.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0816.dll -> [2005/10/03 11:19:16 | 00,028,672 | ---- | M] (Conexant)
res0816.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0816.dll -> [2005/10/03 11:19:16 | 00,028,672 | ---- | M] (Conexant)
res0416.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0416.dll -> [2005/10/03 11:16:22 | 00,028,672 | ---- | M] (Conexant)
res0416.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0416.dll -> [2005/10/03 11:16:22 | 00,028,672 | ---- | M] (Conexant)
res0416.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0416.dll -> [2005/10/03 11:16:22 | 00,028,672 | ---- | M] (Conexant)
res0816.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0816.dll -> [2005/10/02 20:19:16 | 00,028,672 | ---- | M] (Conexant)
res0816.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0816.dll -> [2005/10/02 20:19:16 | 00,028,672 | ---- | M] (Conexant)
res0416.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0416.dll -> [2005/10/02 20:16:22 | 00,028,672 | ---- | M] (Conexant)
res0416.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0416.dll -> [2005/10/02 20:16:22 | 00,028,672 | ---- | M] (Conexant)
res0404.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0404.dll -> [2005/04/20 07:42:24 | 00,024,576 | ---- | M] (Conexant)
res0404.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0404.dll -> [2005/04/20 07:42:24 | 00,024,576 | ---- | M] (Conexant)
res0404.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0404.dll -> [2005/04/20 07:42:24 | 00,024,576 | ---- | M] (Conexant)
res040a.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res040a.dll -> [2005/04/20 07:40:56 | 00,028,672 | ---- | M] (Conexant)
res040a.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res040a.dll -> [2005/04/20 07:40:56 | 00,028,672 | ---- | M] (Conexant)
res040a.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res040a.dll -> [2005/04/20 07:40:56 | 00,028,672 | ---- | M] (Conexant)
res0412.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0412.dll -> [2005/04/20 07:38:40 | 00,024,576 | ---- | M] (Conexant)
res0412.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0412.dll -> [2005/04/20 07:38:40 | 00,024,576 | ---- | M] (Conexant)
res0412.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0412.dll -> [2005/04/20 07:38:40 | 00,024,576 | ---- | M] (Conexant)
res0410.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0410.dll -> [2005/04/20 07:34:56 | 00,028,672 | ---- | M] (Conexant)
res0410.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0410.dll -> [2005/04/20 07:34:56 | 00,028,672 | ---- | M] (Conexant)
res0410.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0410.dll -> [2005/04/20 07:34:56 | 00,028,672 | ---- | M] (Conexant)
res040d.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res040d.dll -> [2005/04/20 07:33:42 | 00,028,672 | ---- | M] ()
res040d.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res040d.dll -> [2005/04/20 07:33:42 | 00,028,672 | ---- | M] ()
res040d.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res040d.dll -> [2005/04/20 07:33:42 | 00,028,672 | ---- | M] ()
res0407.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0407.dll -> [2005/04/20 07:32:20 | 00,028,672 | ---- | M] (Conexant)
res0407.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0407.dll -> [2005/04/20 07:32:20 | 00,028,672 | ---- | M] (Conexant)
res0407.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0407.dll -> [2005/04/20 07:32:20 | 00,028,672 | ---- | M] (Conexant)
res040c.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res040c.dll -> [2005/04/20 07:30:20 | 00,028,672 | ---- | M] (Conexant)
res040c.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res040c.dll -> [2005/04/20 07:30:20 | 00,028,672 | ---- | M] (Conexant)
res040c.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res040c.dll -> [2005/04/20 07:30:20 | 00,028,672 | ---- | M] (Conexant)
res0404.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0404.dll -> [2005/04/19 16:42:24 | 00,024,576 | ---- | M] (Conexant)
res0404.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0404.dll -> [2005/04/19 16:42:24 | 00,024,576 | ---- | M] (Conexant)
res040a.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res040a.dll -> [2005/04/19 16:40:56 | 00,028,672 | ---- | M] (Conexant)
res040a.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res040a.dll -> [2005/04/19 16:40:56 | 00,028,672 | ---- | M] (Conexant)
res0412.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0412.dll -> [2005/04/19 16:38:40 | 00,024,576 | ---- | M] (Conexant)
res0412.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0412.dll -> [2005/04/19 16:38:40 | 00,024,576 | ---- | M] (Conexant)
res0410.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0410.dll -> [2005/04/19 16:34:56 | 00,028,672 | ---- | M] (Conexant)
res0410.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0410.dll -> [2005/04/19 16:34:56 | 00,028,672 | ---- | M] (Conexant)
res040d.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res040d.dll -> [2005/04/19 16:33:42 | 00,028,672 | ---- | M] ()
res040d.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res040d.dll -> [2005/04/19 16:33:42 | 00,028,672 | ---- | M] ()
res0407.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0407.dll -> [2005/04/19 16:32:20 | 00,028,672 | ---- | M] (Conexant)
res0407.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0407.dll -> [2005/04/19 16:32:20 | 00,028,672 | ---- | M] (Conexant)
res040c.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res040c.dll -> [2005/04/19 16:30:20 | 00,028,672 | ---- | M] (Conexant)
res040c.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res040c.dll -> [2005/04/19 16:30:20 | 00,028,672 | ---- | M] (Conexant)
res041f.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res041f.dll -> [2005/04/12 08:02:04 | 00,028,672 | ---- | M] (Conexant)
res041f.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res041f.dll -> [2005/04/12 08:02:04 | 00,028,672 | ---- | M] (Conexant)
res041f.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res041f.dll -> [2005/04/12 08:02:04 | 00,028,672 | ---- | M] (Conexant)
res041e.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res041e.dll -> [2005/04/12 08:00:42 | 00,028,672 | ---- | M] (Conexant)
res041e.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res041e.dll -> [2005/04/12 08:00:42 | 00,028,672 | ---- | M] (Conexant)
res041e.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res041e.dll -> [2005/04/12 08:00:42 | 00,028,672 | ---- | M] (Conexant)
res041d.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res041d.dll -> [2005/04/12 07:49:48 | 00,028,672 | ---- | M] (Conexant)
res041d.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res041d.dll -> [2005/04/12 07:49:48 | 00,028,672 | ---- | M] (Conexant)
res041d.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res041d.dll -> [2005/04/12 07:49:48 | 00,028,672 | ---- | M] (Conexant)
res0804.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0804.dll -> [2005/04/12 07:47:44 | 00,024,576 | ---- | M] (Conexant)
res0804.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0804.dll -> [2005/04/12 07:47:44 | 00,024,576 | ---- | M] (Conexant)
res0804.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0804.dll -> [2005/04/12 07:47:44 | 00,024,576 | ---- | M] (Conexant)
res0419.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0419.dll -> [2005/04/12 07:46:38 | 00,028,672 | ---- | M] (Conexant)
res0419.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0419.dll -> [2005/04/12 07:46:38 | 00,028,672 | ---- | M] (Conexant)
res0419.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0419.dll -> [2005/04/12 07:46:38 | 00,028,672 | ---- | M] (Conexant)
res0415.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0415.dll -> [2005/04/12 07:44:56 | 00,028,672 | ---- | M] (Conexant)
res0415.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0415.dll -> [2005/04/12 07:44:56 | 00,028,672 | ---- | M] (Conexant)
res0415.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0415.dll -> [2005/04/12 07:44:56 | 00,028,672 | ---- | M] (Conexant)
res0414.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0414.dll -> [2005/04/12 07:44:02 | 00,028,672 | ---- | M] (Conexant)
res0414.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0414.dll -> [2005/04/12 07:44:02 | 00,028,672 | ---- | M] (Conexant)
res0414.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0414.dll -> [2005/04/12 07:44:02 | 00,028,672 | ---- | M] (Conexant)
res0411.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0411.dll -> [2005/04/12 07:42:26 | 00,024,576 | ---- | M] (Conexant)
res0411.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0411.dll -> [2005/04/12 07:42:26 | 00,024,576 | ---- | M] (Conexant)
res0411.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0411.dll -> [2005/04/12 07:42:26 | 00,024,576 | ---- | M] (Conexant)
res040e.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res040e.dll -> [2005/04/12 07:40:06 | 00,028,672 | ---- | M] (Conexant)
res040e.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res040e.dll -> [2005/04/12 07:40:06 | 00,028,672 | ---- | M] (Conexant)
res040e.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res040e.dll -> [2005/04/12 07:40:06 | 00,028,672 | ---- | M] (Conexant)
res0408.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0408.dll -> [2005/04/12 07:33:58 | 00,028,672 | ---- | M] (Conexant)
res0408.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0408.dll -> [2005/04/12 07:33:58 | 00,028,672 | ---- | M] (Conexant)
res0408.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0408.dll -> [2005/04/12 07:33:58 | 00,028,672 | ---- | M] (Conexant)
res040b.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res040b.dll -> [2005/04/12 07:29:42 | 00,028,672 | ---- | M] (Conexant)
res040b.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res040b.dll -> [2005/04/12 07:29:42 | 00,028,672 | ---- | M] (Conexant)
res040b.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res040b.dll -> [2005/04/12 07:29:42 | 00,028,672 | ---- | M] (Conexant)
res0413.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0413.dll -> [2005/04/12 07:29:02 | 00,028,672 | ---- | M] (Conexant)
res0413.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0413.dll -> [2005/04/12 07:29:02 | 00,028,672 | ---- | M] (Conexant)
res0413.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0413.dll -> [2005/04/12 07:29:02 | 00,028,672 | ---- | M] (Conexant)
res0406.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0406.dll -> [2005/04/12 07:28:16 | 00,028,672 | ---- | M] (Conexant)
res0406.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0406.dll -> [2005/04/12 07:28:16 | 00,028,672 | ---- | M] (Conexant)
res0406.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0406.dll -> [2005/04/12 07:28:16 | 00,028,672 | ---- | M] (Conexant)
res0405.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0405.dll -> [2005/04/12 07:27:24 | 00,028,672 | ---- | M] (Conexant)
res0405.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0405.dll -> [2005/04/12 07:27:24 | 00,028,672 | ---- | M] (Conexant)
res0405.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0405.dll -> [2005/04/12 07:27:24 | 00,028,672 | ---- | M] (Conexant)
res0401.dll -> C:\Windows\Temp\1214492971\SmAudio\dll\res0401.dll -> [2005/04/12 07:24:48 | 00,028,672 | ---- | M] (Conexant)
res0401.dll -> C:\Windows\Temp\1214492910\Hermosa\V64\SmAudio\SmAudio\dll\res0401.dll -> [2005/04/12 07:24:48 | 00,028,672 | ---- | M] (Conexant)
res0401.dll -> C:\Windows\Temp\1214492910\Hermosa\V32\SmAudio\SmAudio\dll\res0401.dll -> [2005/04/12 07:24:48 | 00,028,672 | ---- | M] (Conexant)
res041f.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res041f.dll -> [2005/04/11 17:02:04 | 00,028,672 | ---- | M] (Conexant)
res041f.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res041f.dll -> [2005/04/11 17:02:04 | 00,028,672 | ---- | M] (Conexant)
res041e.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res041e.dll -> [2005/04/11 17:00:42 | 00,028,672 | ---- | M] (Conexant)
res041e.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res041e.dll -> [2005/04/11 17:00:42 | 00,028,672 | ---- | M] (Conexant)
res041d.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res041d.dll -> [2005/04/11 16:49:48 | 00,028,672 | ---- | M] (Conexant)
res041d.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res041d.dll -> [2005/04/11 16:49:48 | 00,028,672 | ---- | M] (Conexant)
res0804.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0804.dll -> [2005/04/11 16:47:44 | 00,024,576 | ---- | M] (Conexant)
res0804.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0804.dll -> [2005/04/11 16:47:44 | 00,024,576 | ---- | M] (Conexant)
res0419.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0419.dll -> [2005/04/11 16:46:38 | 00,028,672 | ---- | M] (Conexant)
res0419.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0419.dll -> [2005/04/11 16:46:38 | 00,028,672 | ---- | M] (Conexant)
res0415.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0415.dll -> [2005/04/11 16:44:56 | 00,028,672 | ---- | M] (Conexant)
res0415.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0415.dll -> [2005/04/11 16:44:56 | 00,028,672 | ---- | M] (Conexant)
res0414.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0414.dll -> [2005/04/11 16:44:02 | 00,028,672 | ---- | M] (Conexant)
res0414.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0414.dll -> [2005/04/11 16:44:02 | 00,028,672 | ---- | M] (Conexant)
res0411.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0411.dll -> [2005/04/11 16:42:26 | 00,024,576 | ---- | M] (Conexant)
res0411.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0411.dll -> [2005/04/11 16:42:26 | 00,024,576 | ---- | M] (Conexant)
res040e.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res040e.dll -> [2005/04/11 16:40:06 | 00,028,672 | ---- | M] (Conexant)
res040e.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res040e.dll -> [2005/04/11 16:40:06 | 00,028,672 | ---- | M] (Conexant)
res0408.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0408.dll -> [2005/04/11 16:33:58 | 00,028,672 | ---- | M] (Conexant)
res0408.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0408.dll -> [2005/04/11 16:33:58 | 00,028,672 | ---- | M] (Conexant)
res040b.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res040b.dll -> [2005/04/11 16:29:42 | 00,028,672 | ---- | M] (Conexant)
res040b.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res040b.dll -> [2005/04/11 16:29:42 | 00,028,672 | ---- | M] (Conexant)
res0413.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0413.dll -> [2005/04/11 16:29:02 | 00,028,672 | ---- | M] (Conexant)
res0413.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0413.dll -> [2005/04/11 16:29:02 | 00,028,672 | ---- | M] (Conexant)
res0406.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0406.dll -> [2005/04/11 16:28:16 | 00,028,672 | ---- | M] (Conexant)
res0406.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0406.dll -> [2005/04/11 16:28:16 | 00,028,672 | ---- | M] (Conexant)
res0405.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0405.dll -> [2005/04/11 16:27:24 | 00,028,672 | ---- | M] (Conexant)
res0405.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0405.dll -> [2005/04/11 16:27:24 | 00,028,672 | ---- | M] (Conexant)
res0401.dll -> C:\Windows\Temp\1214492910\Venice\V64\SmAudio\SmAudio\dll\res0401.dll -> [2005/04/11 16:24:48 | 00,028,672 | ---- | M] (Conexant)
res0401.dll -> C:\Windows\Temp\1214492910\Venice\V32\SmAudio\SmAudio\dll\res0401.dll -> [2005/04/11 16:24:48 | 00,028,672 | ---- | M] (Conexant)
gdiplusF33DEC0A.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusF33DEC0A.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplusE1DA3D0E.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusE1DA3D0E.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplusDC8C5D2A.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusDC8C5D2A.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplusD6EBAEF5.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusD6EBAEF5.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplusB1DBFAF0.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusB1DBFAF0.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplusAF831C96.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusAF831C96.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplusA455ADFC.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplusA455ADFC.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus985FC367.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus985FC367.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus9071448E.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus9071448E.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus78D63180.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus78D63180.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus74C97B78.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus74C97B78.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus5C39907C.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus5C39907C.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus5ABC3C3B.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus5ABC3C3B.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus55EBB4A3.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus55EBB4A3.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus5461AF19.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus5461AF19.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus536CC5AD.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus536CC5AD.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
gdiplus38B07F0B.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\gdiplus38B07F0B.DLL -> [2004/05/04 10:53:40 | 01,645,320 | ---- | M] (Microsoft Corporation)
MFC71F47B49DB.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71F47B49DB.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC71E906F697.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71E906F697.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC71CB545924.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71CB545924.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC71AE66EE48.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71AE66EE48.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC718A0B572D.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC718A0B572D.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC716251E7FF.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC716251E7FF.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC716011AF24.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC716011AF24.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC715B49AA52.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC715B49AA52.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC7149090881.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC7149090881.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC71461BF8FA.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71461BF8FA.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC713F517409.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC713F517409.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC71249A74F9.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71249A74F9.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
MFC71109CB9C7.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\MFC71109CB9C7.dll -> [2003/03/19 06:20:00 | 01,060,864 | ---- | M] (Microsoft Corporation)
msvcp71FC7343DA.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71FC7343DA.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71F525E9F7.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71F525E9F7.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71F4FBCFF4.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71F4FBCFF4.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71EF1A49EE.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71EF1A49EE.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71EB0FA0C2.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71EB0FA0C2.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71C50F23DB.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71C50F23DB.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71C138A21F.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71C138A21F.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71BBF6D7CF.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71BBF6D7CF.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71B4C16822.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71B4C16822.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7198B02AF4.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7198B02AF4.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7178516802.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7178516802.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7177B7CF3F.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7177B7CF3F.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7169869529.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7169869529.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7162535DFA.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7162535DFA.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7158986D1C.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7158986D1C.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7151207FF7.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7151207FF7.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp7150E1E867.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp7150E1E867.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp714D58BA94.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp714D58BA94.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp714536764D.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp714536764D.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71346249B2.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71346249B2.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp71318C1171.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp71318C1171.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp712CF144D3.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp712CF144D3.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
msvcp710E7F954E.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcp710E7F954E.dll -> [2003/03/19 06:14:52 | 00,499,712 | ---- | M] (Microsoft Corporation)
mfc71uF18EADFB.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\mfc71uF18EADFB.dll -> [2003/03/18 20:12:12 | 01,047,552 | ---- | M] (Microsoft Corporation)
mfc71uE8BEE4D1.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\mfc71uE8BEE4D1.dll -> [2003/03/18 20:12:12 | 01,047,552 | ---- | M] (Microsoft Corporation)
mfc71u93490C3B.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\mfc71u93490C3B.dll -> [2003/03/18 20:12:12 | 01,047,552 | ---- | M] (Microsoft Corporation)
mfc71u4D1989F2.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\mfc71u4D1989F2.dll -> [2003/03/18 20:12:12 | 01,047,552 | ---- | M] (Microsoft Corporation)
mfc71u4C5C5DD0.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\mfc71u4C5C5DD0.dll -> [2003/03/18 20:12:12 | 01,047,552 | ---- | M] (Microsoft Corporation)
mfc71u12406601.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\mfc71u12406601.dll -> [2003/03/18 20:12:12 | 01,047,552 | ---- | M] (Microsoft Corporation)
msvcr71FD47894B.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71FD47894B.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71F5084597.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71F5084597.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71F2E0F0EF.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71F2E0F0EF.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71F02E11D7.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71F02E11D7.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71EE7C0081.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71EE7C0081.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71E0BAC39B.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71E0BAC39B.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71E0570AA5.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71E0570AA5.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71D1A5E404.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71D1A5E404.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71CC2005AB.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71CC2005AB.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71BB261ECC.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71BB261ECC.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71BA5A88D0.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71BA5A88D0.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr719D484A5A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr719D484A5A.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr7193442B58.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr7193442B58.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr716A7F987A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr716A7F987A.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr7166D31FF4.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr7166D31FF4.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr7144B7F012.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr7144B7F012.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71402AC422.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71402AC422.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr713C2058C6.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr713C2058C6.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr7135AD2B54.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr7135AD2B54.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr712E243769.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr712E243769.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr71264D7D03.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr71264D7D03.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr7113A22A6A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr7113A22A6A.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
msvcr7103CBFF9A.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\msvcr7103CBFF9A.dll -> [2003/02/21 14:42:22 | 00,348,160 | ---- | M] (Microsoft Corporation)
50comupd.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\50comupd.exe -> [2002/12/18 12:43:16 | 00,509,984 | ---- | M] (Microsoft Corporation)
isrt.dll -> C:\Users\kevin\AppData\Local\Temp\{D5459BE0-50D0-437A-907C-CD497777CE73}\{59F6A514-9813-47A3-948C-8A155460CC2A}\isrt.dll -> [2002/12/02 13:33:04 | 00,372,736 | ---- | M] (InstallShield Software Corporation)
_IsRes.dll -> C:\Users\kevin\AppData\Local\Temp\{D5459BE0-50D0-437A-907C-CD497777CE73}\{59F6A514-9813-47A3-948C-8A155460CC2A}\_IsRes.dll -> [2002/12/02 13:33:02 | 00,290,816 | ---- | M] (InstallShield Software Corporation)
GLB1A2B.EXE -> C:\Users\kevin\AppData\Local\Temp\GLB1A2B.EXE -> [2002/07/26 17:02:06 | 00,153,088 | ---- | M] ()
APATCH.DLL -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Setup\APATCH.DLL -> [2002/05/27 19:50:06 | 00,263,848 | ---- | M] (Catalyst Development Corporation)
instmsia.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\instmsia.exe -> [2002/03/11 14:45:02 | 01,708,856 | ---- | M] (Microsoft Corporation)
instmsiw.exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\instmsiw.exe -> [2002/03/11 08:06:30 | 01,822,520 | ---- | M] (Microsoft Corporation)
Msvcrt11D4118E.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Cab\Tmp\Msvcrt11D4118E.dll -> [2001/05/04 11:05:02 | 00,290,869 | ---- | M] (Microsoft Corporation)
ShFolder.Exe -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\ShFolder.Exe -> [2001/01/23 11:13:28 | 00,117,288 | ---- | M] (Microsoft Corporation)
msvcp60.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\msvcp60.dll -> [2000/08/29 01:19:16 | 00,401,462 | ---- | M] (Microsoft Corporation)
oleaut32.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\oleaut32.dll -> [2000/04/12 13:00:24 | 00,598,288 | ---- | M] (Microsoft Corporation)
mfc42.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\mfc42.dll -> [2000/04/06 19:13:36 | 00,995,383 | ---- | M] (Microsoft Corporation)
msvcrt.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\msvcrt.dll -> [2000/04/06 19:10:40 | 00,278,581 | ---- | M] (Microsoft Corporation)
msvcirt.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\msvcirt.dll -> [2000/04/06 19:10:38 | 00,077,878 | ---- | M] (Microsoft Corporation)
olepro32.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\olepro32.dll -> [1999/03/08 11:50:56 | 00,164,112 | ---- | M] (Microsoft Corporation)
asycfilt.dll -> C:\Users\kevin\AppData\Local\Temp\NeroDemo11531\Redist\MS\System\asycfilt.dll -> [1999/03/08 11:50:56 | 00,147,728 | ---- | M] (Microsoft Corporation)

[File - Lop Check]
Roaming -> C:\Users\Default\AppData\Roaming -> [2006/11/02 11:07:25 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\Default\AppData\Roaming\Media Center Programs -> [2006/11/02 11:07:25 | 00,000,000 | ---D | M]
Roaming -> C:\Users\Default User\AppData\Roaming -> [2006/11/02 11:07:25 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\Default User\AppData\Roaming\Media Center Programs -> [2006/11/02 11:07:25 | 00,000,000 | ---D | M]
Roaming -> C:\Users\kevin\AppData\Roaming -> [2009/09/22 17:12:28 | 00,000,000 | ---D | M]
.# -> C:\Users\kevin\AppData\Roaming\.# -> [2009/09/22 17:12:30 | 00,000,000 | -HSD | M]
Ahead -> C:\Users\kevin\AppData\Roaming\Ahead -> [2009/08/23 00:53:46 | 00,000,000 | ---D | M]
BSplayer -> C:\Users\kevin\AppData\Roaming\BSplayer -> [2009/09/12 00:51:33 | 00,000,000 | ---D | M]
BSplayer Pro -> C:\Users\kevin\AppData\Roaming\BSplayer Pro -> [2009/09/12 00:43:01 | 00,000,000 | ---D | M]
Cerberus -> C:\Users\kevin\AppData\Roaming\Cerberus -> [2009/09/18 06:48:18 | 00,000,000 | RHSD | M]
Corel -> C:\Users\kevin\AppData\Roaming\Corel -> [2009/09/15 12:00:40 | 00,000,000 | ---D | M]
CyberLink -> C:\Users\kevin\AppData\Roaming\CyberLink -> [2009/08/23 01:34:17 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\kevin\AppData\Roaming\Media Center Programs -> [2006/11/02 11:07:25 | 00,000,000 | ---D | M]
Uniblue -> C:\Users\kevin\AppData\Roaming\Uniblue -> [2009/09/22 15:27:31 | 00,000,000 | ---D | M]
uTorrent -> C:\Users\kevin\AppData\Roaming\uTorrent -> [2009/09/23 21:50:20 | 00,000,000 | ---D | M]
Vso -> C:\Users\kevin\AppData\Roaming\Vso -> [2009/09/17 13:07:30 | 00,000,000 | ---D | M]
C:\Windows\Tasks\ -> C:\Windows\Tasks -> [2009/09/22 03:07:14 | 00,000,000 | ---D | M]
HPCeeScheduleForkevin.job -> C:\Windows\Tasks\HPCeeScheduleForkevin.job -> [2009/09/12 22:43:05 | 00,000,334 | ---- | M] ()
Malwarebytes' Scheduled Scan for kevin.job -> C:\Windows\Tasks\Malwarebytes' Scheduled Scan for kevin.job -> [2009/09/23 05:03:40 | 00,000,516 | ---- | M] ()
Malwarebytes' Scheduled Update for kevin.job -> C:\Windows\Tasks\Malwarebytes' Scheduled Update for kevin.job -> [2009/09/23 04:00:06 | 00,000,502 | ---- | M] ()
SA.DAT -> C:\Windows\Tasks\SA.DAT -> [2009/09/23 03:20:19 | 00,000,006 | -H-- | M] ()
SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2009/09/23 03:19:03 | 00,032,602 | ---- | M] ()

[File - Purity Scan]

< End of report >
[/code]
........

#4 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 23 September 2009 - 09:02 PM

Hi,

Please do the following:


Start OTS
Copy/Paste the information inside the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]
[Unregister Dlls]
[Processes - Safe List]
YN -> iexplore.exe -> C:\Program Files (x86)\Internet Explorer\iexplore.exe
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
[Files/Folders - Created Within 30 Days]
NY -> .# -> C:\Users\kevin\AppData\Roaming\.#
[Files/Folders - Modified Within 30 Days]
NY -> 2 C:\Windows\*.tmp files -> C:\Windows\*.tmp
NY -> 128 C:\Users\kevin\AppData\Local\Temp\*.tmp files -> C:\Users\kevin\AppData\Local\Temp\*.tmp
NY -> 9 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp
NY -> Au_.exe -> C:\Users\kevin\AppData\Local\Temp\~nsu.tmp\Au_.exe
NY -> b.dat -> C:\Users\kevin\AppData\Local\Temp\b.dat
NY -> c.exe -> C:\Users\kevin\AppData\Local\Temp\c.exe
NY -> a.dat -> C:\Users\kevin\AppData\Local\Temp\a.dat
NY -> UAC.dll -> C:\Users\kevin\AppData\Local\Temp\nshCDA0.tmp\UAC.dll
[File - Lop Check]
NY -> .# -> C:\Users\kevin\AppData\Roaming\.#
[Purity]
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    Posted Image
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • OTS Log
  • MBAM Log
  • Kaspersky report

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#5 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 27 September 2009 - 05:41 PM

Hi, do you still need help with your machine? If the instructions are unclear, or you are experiencing other issues, please advise

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#6 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 September 2009 - 08:07 AM

Due to inactivity this topic will be closed. If you need help please start a new thread.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users