OTL logfile created on: 4/15/2013 5:16:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deanna\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16384)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.89 Gb Total Physical Memory | 2.11 Gb Available Physical Memory | 54.35% Memory free
7.39 Gb Paging File | 5.71 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.04 Gb Total Space | 523.96 Gb Free Space | 89.41% Space Free | Partition Type: NTFS
Computer Name: DEANNA | User Name: Deanna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files (x86)\NortonInstaller\{CCC44C7A-717C-4ea0-A378-79ADF863BF19}\NAT\562C4DD5\1.6.0.17\InstStub.exe (Symantec Corporation)
PRC - C:\Users\Deanna\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Toshiba\System Setting\TSleepSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\wincfi39.dll ()
========== Services (SafeList) ==========
SRV:
64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\Toshiba\Teco\TecoService.exe (TOSHIBA Corporation)
SRV:
64bit: - (TPCHSrv) – C:\Program Files\Toshiba\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:
64bit: - (TMachInfo) – C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV:
64bit: - (WSService) – C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:
64bit: - (PrintNotify) – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:
64bit: - (wlidsvc) – C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:
64bit: - (WiaRpc) – C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:
64bit: - (Wcmsvc) – C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:
64bit: - (VaultSvc) – C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:
64bit: - (TimeBroker) – C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:
64bit: - (SystemEventsBroker) – C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:
64bit: - (svsvc) – C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:
64bit: - (netprofm) – C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:
64bit: - (Netlogon) – C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:
64bit: - (NcaSvc) – C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:
64bit: - (NcdAutoSetup) – C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:
64bit: - (LSM) – C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:
64bit: - (KeyIso) – C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:
64bit: - (fhsvc) – C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:
64bit: - (EFS) – C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:
64bit: - (DsmSvc) – C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:
64bit: - (DeviceAssociationService) – C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:
64bit: - (BrokerInfrastructure) – C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:
64bit: - (AudioEndpointBuilder) – C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:
64bit: - (AllUserInstallAgent) – C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:
64bit: - (vmicvss) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:
64bit: - (vmictimesync) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:
64bit: - (vmicshutdown) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:
64bit: - (vmicrdv) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:
64bit: - (vmickvpexchange) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:
64bit: - (vmicheartbeat) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:
64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:
64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV - (NAT) – C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe (Symantec Corporation)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (taisregispinger) – C:\Program Files (x86)\Toshiba\ToshibaRegistration\TaisRegistPinger.exe (Toshiba America Information Systems.)
SRV - (PrintNotify) – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) – C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (PCCUJobMgr) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (GFNEXSrv) – C:\Program Files (x86)\Toshiba\Password Utility\GFNEXSrv.exe ()
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (SynTP) – C:\Windows\SysNative\Drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (SmbDrvI) – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:
64bit: - (RTWlanE) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:
64bit: - (RTL8192Ce) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:
64bit: - (ccSet_NAT) – C:\Windows\SysNative\Drivers\NATx64\0106000.011\ccSetx64.sys (Symantec Corporation)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\Drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (Thotkey) – C:\Windows\SysNative\Drivers\Thotkey.sys (Windows ® Win 7 DDK provider)
DRV:
64bit: - (iaStorA) – C:\Windows\SysNative\Drivers\iaStorA.sys (Intel Corporation)
DRV:
64bit: - (RTL8168) – C:\Windows\SysNative\Drivers\Rt630x64.sys (Realtek )
DRV:
64bit: - (Fs_Rec) – C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (condrv) – C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:
64bit: - (USBHUB3) – C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:
64bit: - (USBXHCI) – C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:
64bit: - (VSTXRAID) – C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:
64bit: - (UCX01000) – C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:
64bit: - (VerifierExt) – C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:
64bit: - (UASPStor) – C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:
64bit: - (acpiex) – C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:
64bit: - (spaceport) – C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:
64bit: - (GPIOClx0101) – C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:
64bit: - (storahci) – C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:
64bit: - (mvumis) – C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:
64bit: - (msgpiowin32) – C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:
64bit: - (sdstor) – C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (LSI_SSS) – C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (EhStorTcgDrv) – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:
64bit: - (EhStorClass) – C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (3ware) – C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (sdbus) – C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:
64bit: - (TPM) – C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:
64bit: - (dam) – C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:
64bit: - (pdc) – C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:
64bit: - (CLFS) – C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:
64bit: - (WFPLWFS) – C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:
64bit: - (vpci) – C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:
64bit: - (WdFilter) – C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:
64bit: - (WdBoot) – C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:
64bit: - (terminpt) – C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:
64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:
64bit: - (mshidumdf) – C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:
64bit: - (BasicDisplay) – C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:
64bit: - (HyperVideo) – C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:
64bit: - (BasicRender) – C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:
64bit: - (BthAvrcpTg) – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:
64bit: - (FxPPM) – C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:
64bit: - (gencounter) – C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:
64bit: - (kdnic) – C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:
64bit: - (acpitime) – C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:
64bit: - (npsvctrig) – C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:
64bit: - (bthhfhid) – C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:
64bit: - (WpdUpFltr) – C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:
64bit: - (acpipagr) – C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:
64bit: - (hyperkbd) – C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:
64bit: - (SerCx) – C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:
64bit: - (SpbCx) – C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:
64bit: - (TsUsbGD) – C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:
64bit: - (BthHFEnum) – C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:
64bit: - (dmvsc) – C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:
64bit: - (TsUsbFlt) – C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (hidi2c) – C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:
64bit: - (wpcfltr) – C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:
64bit: - (NdisImPlatform) – C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:
64bit: - (MsLldp) – C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:
64bit: - (Ndu) – C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:
64bit: - (TVALZ) – C:\Windows\SysNative\Drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:
64bit: - (amdkmdag) – C:\Windows\SysNative\Drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (tdcmdpst) – C:\Windows\SysNative\Drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:
64bit: - (TVALZFL) – C:\Windows\SysNative\Drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:
64bit: - (MEIx64) – C:\Windows\SysNative\Drivers\HECIx64.sys (Intel Corporation)
DRV:
64bit: - (amdkmdap) – C:\Windows\SysNative\Drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (SymELAM) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\SymELAM.sys (Symantec Corporation)
DRV:
64bit: - (IntcDAud) – C:\Windows\SysNative\Drivers\IntcDAud.sys (Intel® Corporation)
DRV:
64bit: - (tos_sps64) – C:\Windows\SysNative\Drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:
64bit: - (RSUSBSTOR) – C:\Windows\SysNative\Drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (ccSet_NARA) – C:\Windows\SysNative\Drivers\NARAx64\0401000.00B\ccSetx64.sys (Symantec Corporation)
DRV:
64bit: - (ccSet_NIS) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\ccSetx64.sys (Symantec Corporation)
DRV:
64bit: - (SymDS) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\SymDS64.sys (Symantec Corporation)
DRV:
64bit: - (SymIRON) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\Ironx64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (SymEFA) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\SymEFA64.sys (Symantec Corporation)
DRV:
64bit: - (SymNetS) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\symnets.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPX) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\srtspx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130415.003\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130415.003\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20120611.002\IDSVia64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20120615.003\BHDrvx64.sys (Symantec Corporation)
DRV - (PEGAGFN) – C:\Program Files (x86)\Toshiba\Password Utility\PEGAGFN.sys (PEGATRON)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://mystart.toshiba.com [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://mystart.toshiba.com [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {7FC83991-43C2-44C5-9B60-3A06ADC52B7A}
IE:
64bit: - HKLM\..\SearchScopes\{7FC83991-43C2-44C5-9B60-3A06ADC52B7A}: "URL" =
http://www.bing.com/search?q={searchTerms}…R&pc=MATBJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://mystart.toshiba.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://mystart.toshiba.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {7FC83991-43C2-44C5-9B60-3A06ADC52B7A}
IE - HKLM\..\SearchScopes\{7FC83991-43C2-44C5-9B60-3A06ADC52B7A}: "URL" =
http://www.bing.com/search?q={searchTerms}…R&pc=MATBJS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://mystart.toshiba.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://mystart.toshiba.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {7FC83991-43C2-44C5-9B60-3A06ADC52B7A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\ [2013/04/12 21:43:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ [2013/04/12 21:43:15 | 000,000,000 | —D | M]
O1 HOSTS File: ([2012/07/26 01:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\IPS\IPSBHO.dll (Symantec Corporation)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [] File not found
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [SRS Premium Sound HD] C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (SRS Labs, Inc.)
O4:
64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TecoResident] C:\Program Files\Toshiba\Teco\TecoResident.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TODDMain] C:\Program Files (x86)\Toshiba\System Setting\TODDMain.exe ()
O4:
64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TSleepSrv] C:\Program Files (x86)\Toshiba\System Setting\TSleepSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe (Toshiba)
O4 - HKLM..\Run: [TPUReg] C:\Program Files (x86)\TOSHIBA\Password Utility\Reg.exe (TODO: <公司名稱>)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DFB04FD-8F27-47E8-B38B-C2F6762CE8DA}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs:
64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:
64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:
64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:
64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/09/14 06:00:46 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2013/04/15 17:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2013/04/15 17:09:43 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\Macromedia
[2013/04/15 17:07:26 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\TOSHIBA
[2013/04/15 17:07:24 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\SRS Labs
[2013/04/15 17:06:49 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/04/15 17:06:49 | 000,000,000 | R–D | C] – C:\Users\Deanna\Searches
[2013/04/15 17:06:49 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/04/15 17:06:49 | 000,000,000 | -H-D | C] – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/04/15 17:06:44 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\Adobe
[2013/04/15 17:06:38 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\WinBatch
[2013/04/15 17:05:30 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\VirtualStore
[2013/04/15 17:04:41 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Uninstall Information
[2013/04/13 01:38:59 | 000,000,000 | —D | C] – C:\Windows.old
[2013/04/12 22:07:36 | 000,000,000 | —D | C] – C:\windows\SoftwareDistribution
[2013/04/12 21:40:51 | 000,000,000 | –SD | C] – C:\Users\Deanna\AppData\Roaming\Microsoft
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\Favorites
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\Desktop
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\AppData\Local\Temporary Internet Files
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Templates
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Start Menu
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\SendTo
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Recent
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\PrintHood
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\NetHood
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Documents\My Videos
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Documents\My Pictures
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Documents\My Music
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\My Documents
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Local Settings
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\AppData\Local\History
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Cookies
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Application Data
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\AppData\Local\Application Data
[2013/04/12 21:40:51 | 000,000,000 | -H-D | C] – C:\Users\Deanna\AppData
[2013/04/12 21:40:51 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\Temp
[2013/04/12 21:40:51 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\Microsoft
[2013/04/12 21:40:51 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/04/12 21:10:48 | 000,000,000 | -H-D | C] – C:\$SysReset
========== Files - Modified Within 30 Days ==========
[2013/04/15 17:09:12 | 000,001,439 | —- | M] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/04/15 17:07:09 | 000,010,256 | —- | M] () – C:\Users\Deanna\Desktop\Removed Apps.html
[2013/04/15 17:03:11 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/04/12 22:12:40 | 000,000,013 | RHS- | M] () – C:\windows\SysNative\drivers\fbd.sys
[2013/04/12 21:46:08 | 000,848,230 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2013/04/12 21:46:08 | 000,719,418 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2013/04/12 21:46:08 | 000,132,748 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2013/04/12 21:41:08 | 000,017,148 | —- | M] () – C:\windows\diagwrn.xml
[2013/04/12 21:41:08 | 000,017,148 | —- | M] () – C:\windows\diagerr.xml
[2013/04/12 21:39:34 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/04/12 21:39:32 | 3338,006,528 | -HS- | M] () – C:\hiberfil.sys
[2013/04/12 17:18:40 | 000,000,600 | —- | M] () – C:\Users\Deanna\PUTTY.RND
========== Files Created - No Company Name ==========
[2013/04/15 17:09:11 | 000,001,439 | —- | C] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/04/15 17:07:09 | 000,010,256 | —- | C] () – C:\Users\Deanna\Desktop\Removed Apps.html
[2013/04/15 17:06:44 | 000,001,445 | —- | C] () – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/04/12 22:12:40 | 000,000,013 | RHS- | C] () – C:\windows\SysNative\drivers\fbd.sys
[2013/04/12 21:40:51 | 000,002,107 | —- | C] () – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
[2013/04/12 21:40:51 | 000,000,352 | —- | C] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/04/12 21:40:51 | 000,000,334 | —- | C] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/04/12 21:40:49 | 000,017,148 | —- | C] () – C:\windows\diagwrn.xml
[2013/04/12 21:40:49 | 000,017,148 | —- | C] () – C:\windows\diagerr.xml
[2013/04/12 17:12:36 | 000,000,600 | —- | C] () – C:\Users\Deanna\PUTTY.RND
[2012/09/16 12:41:16 | 000,451,072 | —- | C] () – C:\windows\SysWow64\ISSRemoveSP.exe
[2012/08/06 09:36:22 | 000,598,780 | —- | C] () – C:\windows\SysWow64\igvpkrng700.bin
[2012/08/06 09:36:08 | 000,064,512 | —- | C] () – C:\windows\SysWow64\igdde32.dll
[2012/08/06 09:36:06 | 000,755,048 | —- | C] () – C:\windows\SysWow64\igcodeckrng700.bin
[2012/07/26 04:13:10 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2012/07/25 20:48:53 | 000,083,968 | —- | C] () – C:\windows\SysWow64\OEMLicense.dll
[2012/07/25 16:37:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2012/06/02 10:31:19 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2012/04/20 16:59:44 | 000,001,536 | —- | C] () – C:\windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/07/25 23:07:16 | 019,779,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/07/25 23:19:59 | 017,559,552 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 23:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 23:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 23:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/04/15 17:06:38 | 000,000,000 | —D | M] – C:\Users\Deanna\AppData\Roaming\WinBatch
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/07/25 23:44:30 | 000,398,156 | RHS- | M] () – C:\bootmgr
[2012/06/02 10:30:55 | 000,000,001 | -HS- | M] () – C:\BOOTNXT
[2012/08/16 21:01:54 | 000,030,821 | —- | M] () – C:\DiagsCFG.dat
[2013/04/12 21:39:32 | 3338,006,528 | -HS- | M] () – C:\hiberfil.sys
[2013/04/12 21:39:34 | 3758,096,384 | -HS- | M] () – C:\pagefile.sys
[2013/04/12 21:39:34 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
< %systemroot%\Fonts\*.com >
[2012/08/01 06:06:37 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2012/08/01 06:06:37 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2012/08/01 06:06:37 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2012/08/01 06:06:37 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012/07/26 04:11:41 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/07/28 05:54:00 | 000,321,472 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2012/07/26 04:11:35 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.0.LOCALSETTINGUNIT >
[2013/04/15 17:08:45 | 000,000,359 | -HS- | M] () MD5=1135FB5CFFDCA1707FEB5E3EC4D904B2 – C:\Users\Deanna\AppData\Local\Microsoft\Windows\Live\Roaming\LocalCache\windows-explorer\Explorer.0.localsettingunit
[2012/11/03 11:00:45 | 000,000,359 | -HS- | M] () MD5=1135FB5CFFDCA1707FEB5E3EC4D904B2 – C:\Windows.old\Users\Deanna\AppData\Local\Microsoft\Windows\Live\Roaming\LocalCache\windows-explorer\Explorer.0.localsettingunit
< MD5 for: EXPLORER.ADML >
[2012/07/26 03:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16384_en-us_7bca26f6f419a854\Explorer.adml
[2012/07/26 03:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16433_en-us_7bff382ef3f2006f\Explorer.adml
[2012/07/26 03:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.20534_en-us_7c89d5440d0eb990\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16384_none_6e8451187a9a1607\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16420_none_6ec1315e7a6d062c\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16433_none_6eb962507a726e22\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20521_none_6f4bce739389bf4d\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20534_none_6f43ff65938f2743\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2012/10/11 01:53:24 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
[2012/10/11 04:09:58 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
[2012/07/25 23:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\SysWOW64\explorer.exe
[2012/07/25 23:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2012/07/26 00:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\explorer.exe
[2012/07/26 00:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
[2012/10/11 01:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows.old\windows\SysWOW64\explorer.exe
[2012/10/11 01:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
[2012/10/11 03:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows.old\windows\explorer.exe
[2012/10/11 03:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe
< MD5 for: EXPLORER.EXE.1760.DMP >
[2012/11/16 11:01:22 | 003,987,801 | —- | M] () MD5=20862EE58AF50DE86CBC19C1EBAC6691 – C:\Windows.old\Users\Deanna\AppData\Local\CrashDumps\explorer.exe.1760.dmp
< MD5 for: EXPLORER.EXE.2224.DMP >
[2012/12/14 13:58:51 | 003,753,558 | —- | M] () MD5=0197D93682B7CE0779A559D1A947E765 – C:\Windows.old\Users\Deanna\AppData\Local\CrashDumps\explorer.exe.2224.dmp
< MD5 for: EXPLORER.EXE.MUI >
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows.old\windows\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows.old\windows\SysWOW64\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_5ebc2e81fd6600eb\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_6910d8d431c6c2e6\explorer.exe.mui
< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/04/15 17:06:46 | 000,016,902 | —- | M] () MD5=91905F9B30E41B85E7CC475EF8D0E9F5 – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
[2013/04/11 22:11:13 | 000,419,326 | —- | M] () MD5=D783CDCFB1625E1832FD2BCEAE423664 – C:\Windows.old\windows\Prefetch\EXPLORER.EXE-03C49D11.pf
< MD5 for: EXPLORER.ZIP >
[2006/03/06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Windows.old\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2012/10/11 02:34:54 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=06E77B5F6BB60E11A377B68BA4AA1DA7 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_2b74d7cd3a353a33\iexplore.exe
[2013/02/21 07:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_2b6b082b3a3c6f7b\iexplore.exe
[2012/10/11 03:33:47 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=0A5074651C95792D32BCF536D64D0463 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_21202d7b05d47838\iexplore.exe
[2012/07/25 23:36:56 | 000,770,504 | —- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/07/25 23:36:56 | 000,770,504 | —- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_425d1fb32079214f\iexplore.exe
[2012/10/11 03:24:22 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=13F97D5006C3E37D0A4AABC767C0E553 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_37f8bacaec24e2f1\iexplore.exe
[2012/07/26 00:58:31 | 000,775,112 | —- | M] (Microsoft Corporation) MD5=29CD24D8CA72FDB986B39277E70A48B6 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/07/26 00:58:31 | 000,775,112 | —- | M] (Microsoft Corporation) MD5=29CD24D8CA72FDB986B39277E70A48B6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_38087560ec185f54\iexplore.exe
[2012/11/08 02:58:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=2F92EE7EE7E189EBDDADD5BEEB7E9DE0 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_37fabb5eec23159f\iexplore.exe
[2012/12/19 20:51:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=328569E3CA8BDB3FF74A3DBB8A1FE827 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2b7967573a31390b\iexplore.exe
[2012/10/23 23:14:41 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=39F90724C1A98648CCCDDF13631F2D4A – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_424e7c2f2084a4a2\iexplore.exe
[2013/02/05 01:23:09 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=4B20825770C794AF430529FCD962FDF5 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_2b6907973a3e3ccd\iexplore.exe
[2012/11/08 02:48:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=4B33704E4B071EC44806846CBE50EB2A – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2121e9b705d2f7c9\iexplore.exe
[2013/02/04 18:49:56 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=50BB41EF1CBC08E10CAB2993EEA15586 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_37eb619aec2f65fa\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows.old\Program Files\Internet Explorer\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_37ef2f80ec2bcb56\iexplore.exe
[2012/10/23 23:20:45 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=79FF6755B94FF918441D8F8162E5AC9C – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_2b75d8173a34538a\iexplore.exe
[2012/12/19 22:27:37 | 000,775,128 | —- | M] (Microsoft Corporation) MD5=7C4D4537048B255A851F19EA2C656BCB – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_37fda574ec207b45\iexplore.exe
[2012/11/08 00:52:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=7EBFC838C815C3DACA135837D8F7906E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2b7694093a33b9c4\iexplore.exe
[2012/10/24 00:43:41 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=8E1B68702CDB0DDC6597357766E941D9 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_37f9d1dcec23e2a7\iexplore.exe
[2013/02/05 02:45:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=97808A1A701DC42B07725F8C3D3BDF8D – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_21145d4505dd7ad2\iexplore.exe
[2012/12/19 21:00:31 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=B8B50206CEA0791C26B63B753BCFB1D4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_42524fc720813d40\iexplore.exe
[2012/10/11 01:41:41 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=BCF25D644DF1288CD9A6524FF7AB23C8 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_424d651d2085a4ec\iexplore.exe
[2012/11/08 00:45:20 | 000,770,520 | —- | M] (Microsoft Corporation) MD5=D05965C02FD5781503968225B22189F4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_424f65b12083d79a\iexplore.exe
[2012/12/19 22:55:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=D865B906C71BD10633BA0E9627050943 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2124bd0505d07710\iexplore.exe
[2013/02/05 01:23:07 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=DEAE808A574CF9FC667D6939387FC1CE – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_42400bed209027f5\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows.old\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_4243d9d3208c8d51\iexplore.exe
[2013/02/21 09:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_21165dd905dbad80\iexplore.exe
[2012/10/24 02:08:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=F78F14096EB41341C4D880CEA6D681A2 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_21212dc505d3918f\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows.old\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows.old\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\WinSxS\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_31b50ad823c5a03b\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\WinSxS\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_3c09b52a58266236\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-6C28DB75.PF >
[2012/11/18 19:30:13 | 000,073,556 | —- | M] () MD5=F083377854D99A96444F3057F2815753 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-6C28DB75.pf
< MD5 for: IEXPLORE.EXE-6C28DB76.PF >
[2012/11/18 19:30:13 | 000,131,702 | —- | M] () MD5=9F8ADD236CDF8A9D488168CC75839823 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-6C28DB76.pf
< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/04/15 17:09:42 | 000,094,082 | —- | M] () MD5=CAAB89892A490ACC3A0F39B53450F232 – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
[2013/04/12 17:57:18 | 000,136,230 | —- | M] () MD5=EAE12BB7B3DEF0549719CD702BF9FD96 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
< MD5 for: IEXPLORE.EXE-F4FB5D2F.PF >
[2013/04/15 17:14:21 | 000,217,758 | —- | M] () MD5=30E17B09895CF3032062765343BF4BC4 – C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
[2013/04/12 17:57:18 | 000,131,032 | —- | M] () MD5=5AF8A34E22F450A1F7D161EE1BFF8512 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
< MD5 for: SERVICES >
[2012/07/26 01:26:49 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows.old\windows\System32\Drivers\etc\services
[2012/07/26 01:26:47 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.2.9200.16384_none_8e0944daeed62829\services
< MD5 for: SERVICES.CFG >
[2012/04/04 01:53:54 | 000,585,987 | —- | M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2012/12/18 10:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Windows.old\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 15:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows.old\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
[2011/06/06 15:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2012/09/20 02:33:11 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=581190907DA1CF8CB7B87B35FFE64A07 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
[2012/07/26 01:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\windows\SysNative\services.exe
[2012/07/26 01:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
[2012/09/20 02:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows.old\windows\System32\services.exe
[2012/09/20 02:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2012/07/26 03:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows.old\windows\System32\en-US\services.exe.mui
[2012/07/26 03:48:33 | 000,018,944 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\windows\SysNative\en-US\services.exe.mui
[2012/07/26 03:48:33 | 000,018,944 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.2.9200.16384_en-us_c2c6ee7bafb963b8\services.exe.mui
< MD5 for: SERVICES.HEARSTMAGS[1].XML >
[2012/12/05 20:38:39 | 000,000,113 | —- | M] () MD5=105BFB16CCB1387DC66D35D18C69FE86 – C:\Windows.old\Users\Deanna\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\WF086D9A\services.hearstmags[1].xml
< MD5 for: SERVICES.JS >
[2012/07/26 03:54:02 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:53:53 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:53:50 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:54:33 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:53:57 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/12/30 15:34:40 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2012/12/30 15:34:14 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/22 20:45:52 | 000,069,359 | —- | M] () MD5=80CE8A6918A7BDB5328F93F4A3BB26B0 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.8.0.51_x64__8wekyb3d8bbwe\common\js\services.js
< MD5 for: SERVICES.LNK >
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows.old\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.lnk
< MD5 for: SERVICES.MOF >
[2012/06/02 10:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows.old\windows\System32\wbem\services.mof
[2012/06/02 10:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\windows\SysNative\wbem\services.mof
[2012/06/02 10:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\services.mof
< MD5 for: SERVICES.MSC >
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\System32\en-US\services.msc
[2012/06/02 10:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\System32\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\SysWOW64\en-US\services.msc
[2012/06/02 10:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\SysWOW64\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\windows\SysNative\en-US\services.msc
[2012/06/02 10:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\windows\SysNative\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\en-US\services.msc
[2012/06/02 10:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_fd08be678622fdab\services.msc
[2012/06/02 10:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.msc
[2012/06/02 10:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_3282345b03dfdcd5\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_a0ea22e3cdc58c75\services.msc
< MD5 for: SERVICES.PTXML >
[2012/07/25 16:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows.old\windows\System32\wdi\perftrack\Services.ptxml
[2012/07/25 16:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2012/07/25 16:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2012/07/26 03:49:05 | 000,008,017 | —- | M] () MD5=C270056255498A723E7331EFF1AA162F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.2.9200.16384_en-us_edcdb8ec66a62fc0\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2012/06/02 10:34:22 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.2.9200.16384_none_d3d704270306719d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2012/09/20 02:33:55 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
[2012/09/20 02:33:17 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
[2012/07/25 23:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\windows\SysNative\winlogon.exe
[2012/07/25 23:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2012/10/11 01:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows.old\windows\System32\winlogon.exe
[2012/10/11 01:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
[2012/10/11 01:45:27 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2012/07/26 03:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows.old\windows\System32\en-US\winlogon.exe.mui
[2012/07/26 03:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\windows\SysNative\en-US\winlogon.exe.mui
[2012/07/26 03:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.2.9200.16384_en-us_23c238ef8ddaa831\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2012/07/26 03:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows.old\windows\System32\wbem\en-US\winlogon.mfl
[2012/07/26 03:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2012/07/26 03:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.2.9200.16384_en-us_81848abaa91301c6\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2012/07/25 16:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows.old\windows\System32\wbem\winlogon.mof
[2012/07/25 16:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\windows\SysNative\wbem\winlogon.mof
[2012/07/25 16:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.2.9200.16384_none_d9027134ffac135f\winlogon.mof
< End of report >