This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware? "Pop-up" ads in corner of browsers [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a virus of some sort that causes ads to pop up on web pages- even when using Steam. Always in the bottom left or bottom right corner. Sometimes they're google adsense ads. Currently using chrome though. Also, I'm currently using Windows 7 64 bit.

Things I have attempted to solve this:

Norton 360
AdAware
Malwarebytes
CCleaner

The anti-virus software I used found infections (Except for norton since I used it after AdAware and Malwarebytes, which cleaned the files they found) but the problem I have still persists. A picture of one of these "pop-up" ads is located here:
http://www.webpagescreenshot.info/i3/52002678202a42-06928113

I realize this is a problem other people have had in the past, but I didn't want to use potentially damaging programs without being properly directed by someone who really does know what they're doing. Just to precede whatever response I get, I thank you immensely for your time and help. These ads scare me, as they make me feel like my computer is unsecure.



I used OTL and my results are below .



OTL.txt


OTL logfile created on: 8/5/2013 6:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\domportera\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.89 Gb Total Physical Memory | 4.62 Gb Available Physical Memory | 58.56% Memory free
15.78 Gb Paging File | 12.14 Gb Available in Paging File | 76.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 703.50 Gb Free Space | 75.53% Space Free | Partition Type: NTFS

Computer Name: DOMPORTERA-PC | User Name: domportera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\domportera\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Users\domportera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Hotkey\Hotkey.exe ()
PRC - C:\Program Files (x86)\Hotkey\PowerBiosServer.exe ()
PRC - C:\Program Files (x86)\Dxtory Software\Dxtory2.0\Dxtory.exe (Dxtory Software)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe (PandoraTV)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
PRC - C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe (AuthenTec Inc.)
PRC - C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._core_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\_ssl.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._windows_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._gdi_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._misc_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\_hashlib.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\pysqlite2._sqlite.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\windows._cacheinvalidation.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\pythoncom27.dll ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32com.shell.shell.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\_elementtree.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._wizard.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32file.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\PyWinTypes27.dll ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32security.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32api.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\_ctypes.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._html2.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\_socket.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32inet.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32process.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\_multiprocessing.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32pdh.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32ts.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32profile.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32crypt.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\wx._controls_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\unicodedata.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\pyexpat.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\win32event.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI32922\select.pyd ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\3f0863816ab6f5fef4e0abb442752b9f\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\e8aafadcd1fc0f8f406434176fb97477\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\51fe07d5205cd85d996af305a38b3770\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a7a3ebc76a454af37918211506e81e31\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a2920ed81e097f8551231a9350697bbd\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\f752f8cf702b7c7eff6c659b2e0c760a\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fc4a8709f71eba20cc71c7905bba3dee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\178644ab40108f3becd8b91049a254c3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bfa7a95284aec941f4b03bae0debe07c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ef17be93e209cc95b9768c7822530432\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c25666b99761bc42322bae2e59968df8\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\32066405eb9ab14056b2af3115d2a6de\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\187c13e8967097d2ed1e5f123e7d890a\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\4c152db66c5438fbf9e3975858dde0bc\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8d9db55b1eef7728c04fb1ec500089c6\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\a1c174e579c9ad4e5b6eeed8a58a721b\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\91c185bd043af039dcdc93e3fcf87f3d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\d3c944049319ebe51e939c9342f0bcc2\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\4787bb699ed4291859fb86f15d793add\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\9631f1dac820cb6987560f074492150d\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\256b7bb1216345c5a66ced50c1cf239d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\dc48e3e467309e2bbde8a876614b38e4\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\8a6d1c8abeb8eb82f06c7d075130cc67\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Hotkey\Hotkey.exe ()
MOD - C:\Program Files (x86)\Hotkey\en\HotKey.resources.dll ()
MOD - C:\Program Files (x86)\Hotkey\en-US\HotKey.resources.dll ()
MOD - C:\Users\domportera\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Users\domportera\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\wincfi39.dll ()
MOD - C:\Program Files (x86)\Hotkey\Audiodll.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NvStreamSvc) – C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AMPPALR3) – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (ZeroConfigService) – C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (VIAKaraokeService) – C:\Windows\SysNative\ViakaraokeSrv.exe (VIA Technologies, Inc.)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel® Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (BTHSSecurityMgr) – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV:64bit: - (FPLService) – C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (AuthenTec, Inc)
SRV:64bit: - (TrueService) – C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Ad-Aware Service) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (PowerBiosServer) – C:\Program Files (x86)\Hotkey\PowerBiosServer.exe ()
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (PanService) – C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
SRV - (SBAMSvc) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (gfibto) – C:\Windows\SysNative\drivers\gfibto.sys (GFI Software)
DRV:64bit: - (nvpciflt) – C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (nvvad_WaveExtensible) – C:\Windows\SysNative\drivers\nvvad64v.sys (NVIDIA Corporation)
DRV:64bit: - (ccSet_N360) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\Netwsw00.sys (Intel Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\1403000.024\symnets.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (RSBASTOR) – C:\Windows\SysNative\drivers\RtsBaStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SmbDrvI) – C:\Windows\SysNative\drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (VMfilt) – C:\Windows\SysNative\drivers\VMfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130805.005\ex64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilDrv11220) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130805.005\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130802.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nmd.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {CDEF1E49-EFBD-4A63-9F2E-F308510F2372}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{CDEF1E49-EFBD-4A63-9F2E-F308510F2372}: "URL" = http://findgala.com/?&uid=5689&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@authentec.com/ffwloplugin: C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll (AuthenTec, Inc)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\IPSFFPlgn\ [2013/08/05 12:25:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\coFFPlgn\ [2013/08/05 12:24:47 | 000,000,000 | —D | M]

[2013/08/01 02:29:47 | 000,000,000 | —D | M] (No name found) – C:\Users\domportera\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: http://blekko.com/?source=c3348dd4&tbp…A6E1512B33797C6
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: TrueSuite (Enabled) = C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Missing e = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid\2.14.3_0\
CHR - Extension: YouTube = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Webpage & WebCam Screenshot = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki\9.2_0\
CHR - Extension: Google Search = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0\
CHR - Extension: Skyrim: Book of the Dragonborn Theme = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioigkhgefneinlgdahhpddckbpofpnfi\0.2.0.23_0\
CHR - Extension: iSideWith = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\nekniaobhkcioppbllliijfaillbaiik\1.5_0\
CHR - Extension: Website Logon = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelloajafbopojkjmieelljfkcmdpdhf\6.0_0\
CHR - Extension: Gmail = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/08/04 22:31:52 | 000,001,397 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 199.193.118.246 www.google-analytics.com.
O1 - Hosts: 199.193.118.246 connect.facebook.net.
O1 - Hosts: 199.193.118.246 platform.twitter.com.
O1 - Hosts: 93.115.241.27 www.google-analytics.com.
O1 - Hosts: 93.115.241.27 connect.facebook.net.
O1 - Hosts: 93.115.241.27 platform.twitter.com.
O2:64bit: - BHO: (TrueSuite Browser Helper Object) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.dll (AuthenTec Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (TrueSuite Browser Helper Object) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [CECAPLF] C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [KeepSafe] C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (Authentec)
O4:64bit: - HKLM..\Run: [MBCfg64] C:\Windows\SysNative\MBCfg64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Sound Blaster Cinema] C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe (Dxtory Software)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\domportera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk = C:\Program Files (x86)\Dxtory Software\Dxtory2.0\Dxtory.exe (Dxtory Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Classes = C:\Users\domportera\AppData\Roaming\bauwefiv\ggeecugd.exe
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…30321/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19CD3E11-5A83-42C5-9C55-86F17F471CF0}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll) - C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.xtor - DxtoryCodec.dll (Dxtory Software)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.xtor - C:\Windows\SysWow64\DxtoryCodec.dll (Dxtory Software)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/05 18:04:31 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\ElevatedDiagnostics
[2013/08/05 13:49:52 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2013/08/05 12:40:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2013/08/05 12:36:44 | 000,433,752 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnets.sys
[2013/08/05 12:36:43 | 001,139,800 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.sys
[2013/08/05 12:36:43 | 000,796,760 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.sys
[2013/08/05 12:36:43 | 000,493,656 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.sys
[2013/08/05 12:36:43 | 000,224,416 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ironx64.sys
[2013/08/05 12:36:43 | 000,169,048 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.sys
[2013/08/05 12:36:43 | 000,036,952 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.sys
[2013/08/05 12:36:43 | 000,023,448 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symelam.sys
[2013/08/05 12:35:44 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\1404000.028
[2013/08/05 12:24:21 | 000,177,312 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/08/05 12:24:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2013/08/05 12:24:21 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2013/08/05 12:23:34 | 001,139,800 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA64.sys
[2013/08/05 12:23:34 | 000,493,656 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS64.sys
[2013/08/05 12:23:34 | 000,432,800 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\symnets.sys
[2013/08/05 12:23:34 | 000,023,448 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymELAM.sys
[2013/08/05 12:23:33 | 000,796,248 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.sys
[2013/08/05 12:23:33 | 000,224,416 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\Ironx64.sys
[2013/08/05 12:23:33 | 000,036,952 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.sys
[2013/08/05 12:23:32 | 000,168,096 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccSetx64.sys
[2013/08/05 12:21:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64
[2013/08/05 12:21:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\1403000.024
[2013/08/05 12:21:18 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/08/05 12:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360
[2013/08/05 12:21:17 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2013/08/05 12:20:03 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2013/08/05 12:20:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2013/08/05 12:15:00 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apple Computer
[2013/08/05 11:05:09 | 000,039,504 | —- | C] (ThreatTrack Security) – C:\Windows\SysNative\drivers\gfiark.sys
[2013/08/05 03:13:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\LavasoftStatistics
[2013/08/05 03:02:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/08/05 03:01:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/08/05 03:01:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/08/05 03:00:36 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2013/08/05 02:52:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2013/08/05 02:52:33 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2013/08/05 02:52:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2013/08/05 02:52:22 | 000,000,000 | —D | C] – C:\ProgramData\blekko toolbars
[2013/08/05 02:52:21 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\adawarebp
[2013/08/05 02:52:21 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2013/08/05 02:52:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2013/08/05 02:52:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2013/08/05 02:50:48 | 000,047,496 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2013/08/05 02:50:48 | 000,014,456 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/08/05 02:50:47 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Ad-Aware Antivirus
[2013/08/05 02:38:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/08/05 02:38:17 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/08/05 01:58:57 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\WinRAR
[2013/08/05 01:58:45 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/05 01:58:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/05 01:58:40 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2013/08/05 01:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Caphyon
[2013/08/04 19:49:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PANDORATV
[2013/08/04 19:49:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\PANDORA.TV
[2013/08/04 19:49:46 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2013/08/04 19:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\The KMPlayer
[2013/08/03 11:59:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
[2013/08/03 11:59:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Exact Audio Copy
[2013/08/03 11:18:04 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\EAC
[2013/08/03 11:17:58 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\AccurateRip
[2013/08/03 04:13:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
[2013/08/03 04:13:09 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Last.fm
[2013/08/03 04:13:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Last.fm
[2013/08/03 02:20:59 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Dxtory Software
[2013/08/03 02:20:58 | 008,043,008 | —- | C] (Dxtory Software) – C:\Windows\SysNative\DxtoryCodec.dll
[2013/08/03 02:20:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
[2013/08/03 02:20:57 | 008,300,544 | —- | C] (Dxtory Software) – C:\Windows\SysWow64\DxtoryCodec.dll
[2013/08/03 02:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dxtory Software
[2013/08/03 02:19:17 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\Wizards of the Coast
[2013/08/03 02:03:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft XNA
[2013/08/03 02:01:54 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\My Games
[2013/08/03 00:14:42 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/08/02 21:00:03 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Capsule Utilities
[2013/08/02 21:00:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Capsule
[2013/08/02 12:43:22 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\AuthenTec
[2013/08/02 10:52:28 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Malwarebytes
[2013/08/02 10:52:07 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/08/02 05:25:19 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Adobe
[2013/08/02 05:15:52 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/08/02 05:06:28 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2013/08/02 05:06:28 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2013/08/02 04:42:27 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/08/02 04:42:27 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/08/02 04:42:27 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/08/02 04:42:27 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/08/02 04:42:27 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2013/08/02 04:42:27 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2013/08/02 04:42:27 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/08/02 04:42:27 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/08/02 04:42:26 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2013/08/02 04:42:26 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2013/08/02 04:42:26 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2013/08/02 04:42:26 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2013/08/02 04:42:26 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/08/02 04:42:26 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/08/02 04:42:25 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2013/08/02 04:42:25 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2013/08/02 04:42:25 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_6.dll
[2013/08/02 04:42:25 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_6.dll
[2013/08/02 04:42:25 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_6.dll
[2013/08/02 04:42:25 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_6.dll
[2013/08/02 04:42:25 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_4.dll
[2013/08/02 04:42:25 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_4.dll
[2013/08/02 04:41:29 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_7.dll
[2013/08/02 04:41:29 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_7.dll
[2013/08/02 04:41:23 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_5.dll
[2013/08/02 04:41:22 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_5.dll
[2013/08/02 04:41:22 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_5.dll
[2013/08/02 04:41:21 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_42.dll
[2013/08/02 04:41:21 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2013/08/02 04:41:21 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_42.dll
[2013/08/02 04:41:21 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/08/02 04:41:20 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2013/08/02 04:41:20 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/08/02 04:41:18 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2013/08/02 04:41:18 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2013/08/02 04:41:17 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2013/08/02 04:41:17 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2013/08/02 04:41:16 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2013/08/02 04:41:16 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2013/08/02 04:41:16 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2013/08/02 04:41:16 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2013/08/02 04:41:16 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2013/08/02 04:41:15 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2013/08/02 04:41:15 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2013/08/02 04:41:15 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2013/08/02 04:41:15 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2013/08/02 04:41:14 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2013/08/02 04:41:14 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/08/02 04:41:14 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2013/08/02 04:41:14 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2013/08/02 04:41:14 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2013/08/02 04:41:14 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2013/08/02 04:41:14 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2013/08/02 04:41:14 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2013/08/02 04:41:14 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2013/08/02 04:41:14 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2013/08/02 04:41:14 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2013/08/02 04:41:14 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2013/08/02 04:41:14 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2013/08/02 04:41:14 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2013/08/02 04:41:13 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2013/08/02 04:41:13 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2013/08/02 04:41:13 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2013/08/02 04:41:13 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2013/08/02 04:41:13 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2013/08/02 04:41:13 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2013/08/02 04:41:13 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2013/08/02 04:41:13 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2013/08/02 04:41:13 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2013/08/02 04:41:13 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2013/08/02 04:41:12 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2013/08/02 04:41:12 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2013/08/02 04:41:12 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2013/08/02 04:41:12 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2013/08/02 04:41:12 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2013/08/02 04:41:12 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2013/08/02 04:41:11 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2013/08/02 04:41:11 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2013/08/02 04:41:11 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2013/08/02 04:41:11 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2013/08/02 04:41:10 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2013/08/02 04:41:10 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2013/08/02 04:41:10 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2013/08/02 04:41:10 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2013/08/02 04:41:10 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2013/08/02 04:41:10 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2013/08/02 04:41:09 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2013/08/02 04:41:09 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2013/08/02 04:41:09 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2013/08/02 04:41:09 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2013/08/02 04:41:09 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2013/08/02 04:41:09 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2013/08/02 04:41:02 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2013/08/02 04:41:02 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2013/08/02 04:41:02 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2013/08/02 04:41:02 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2013/08/02 04:41:01 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2013/08/02 04:41:01 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2013/08/02 04:40:59 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2013/08/02 04:40:59 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2013/08/02 04:40:59 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2013/08/02 04:40:59 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2013/08/02 04:40:59 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2013/08/02 04:40:59 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2013/08/02 04:40:58 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2013/08/02 04:40:58 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2013/08/02 04:40:58 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2013/08/02 04:40:58 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2013/08/02 04:40:57 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/08/02 04:40:57 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2013/08/02 04:40:57 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2013/08/02 04:40:57 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2013/08/02 04:40:57 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2013/08/02 04:40:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2013/08/02 04:40:56 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2013/08/02 04:40:56 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2013/08/02 04:40:56 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2013/08/02 04:40:56 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2013/08/02 04:40:43 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2013/08/02 04:40:43 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2013/08/02 04:40:43 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2013/08/02 04:40:43 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2013/08/02 04:40:40 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2013/08/02 04:40:40 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2013/08/02 04:40:40 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2013/08/02 04:40:40 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2013/08/02 04:40:38 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2013/08/02 04:40:38 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2013/08/02 04:40:35 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2013/08/02 04:40:35 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2013/08/02 04:40:34 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2013/08/02 04:40:34 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2013/08/02 04:40:31 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2013/08/02 04:40:31 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2013/08/02 04:40:29 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2013/08/02 04:40:29 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2013/08/02 04:40:27 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2013/08/02 04:40:27 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2013/08/02 04:40:25 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2013/08/02 04:40:25 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2013/08/02 04:40:16 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2013/08/02 04:40:16 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2013/08/02 04:40:16 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2013/08/02 04:40:16 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2013/08/02 04:40:14 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2013/08/02 04:40:14 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2013/08/02 04:40:14 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2013/08/02 04:40:14 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2013/08/02 04:40:14 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2013/08/02 04:40:14 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2013/08/02 04:40:13 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2013/08/02 04:40:13 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2013/08/02 04:40:13 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2013/08/02 04:40:13 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2013/08/02 04:40:13 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2013/08/02 04:40:13 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2013/08/02 04:40:12 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/08/02 04:40:12 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/08/02 04:40:10 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2013/08/02 04:40:10 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2013/08/02 04:40:10 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2013/08/02 04:40:10 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2013/08/02 04:40:10 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2013/08/02 04:40:10 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2013/08/02 04:40:10 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2013/08/02 04:40:10 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2013/08/02 04:40:10 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2013/08/02 04:40:10 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2013/08/02 04:40:10 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2013/08/02 04:40:10 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2013/08/02 04:40:09 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2013/08/02 04:40:09 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2013/08/02 04:40:09 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2013/08/02 04:40:09 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2013/08/02 04:31:39 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/08/02 04:05:32 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/02 04:05:32 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/02 04:05:32 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/02 04:05:32 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/08/02 04:05:32 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/08/02 04:05:32 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/08/02 04:05:32 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/02 04:05:32 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/08/02 04:05:32 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/02 04:05:32 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/08/02 04:05:32 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/02 04:05:32 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/02 04:05:32 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/02 04:05:32 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/08/02 04:05:32 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/08/02 04:05:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/02 04:05:32 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/08/02 04:05:32 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/08/02 04:05:32 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/02 04:05:32 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/02 04:05:32 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/08/02 04:05:32 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/08/02 04:05:32 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/08/02 04:05:32 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/08/02 04:05:32 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/02 04:05:32 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/08/02 04:05:32 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/08/02 04:05:32 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/08/02 04:05:32 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/08/02 04:05:32 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/08/02 04:05:32 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/08/02 04:05:32 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/02 04:05:32 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/08/02 04:05:32 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/08/02 04:05:32 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/08/02 04:05:32 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/08/02 04:05:32 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/08/02 04:05:32 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/08/02 04:05:32 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/02 04:05:32 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/08/02 04:05:32 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/08/02 04:05:32 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/02 04:05:32 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/08/02 04:05:32 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/08/02 04:05:32 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/08/02 04:05:32 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/08/02 04:05:32 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/08/02 04:05:32 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/08/02 04:05:32 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/08/02 04:05:32 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/08/02 04:05:32 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/08/02 04:05:32 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/08/02 04:05:32 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/08/02 04:05:32 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/08/02 04:05:32 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/08/02 04:05:32 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/08/02 04:05:32 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/08/02 04:05:32 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/08/02 04:00:34 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/08/02 04:00:34 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/08/02 04:00:34 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/08/02 04:00:34 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/08/02 04:00:34 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/08/02 04:00:34 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/08/02 04:00:34 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/08/02 04:00:34 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/08/02 04:00:34 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/08/02 04:00:34 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/08/02 04:00:34 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/08/02 04:00:34 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/08/02 04:00:34 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/08/02 04:00:34 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/08/02 04:00:34 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 03:36:33 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/08/02 03:36:33 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/08/02 03:36:33 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/08/02 03:36:32 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/08/02 03:35:10 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2013/08/02 03:35:10 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2013/08/02 03:35:10 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2013/08/02 03:35:10 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2013/08/02 03:10:47 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2013/08/02 03:10:46 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2013/08/01 12:02:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Sleep
[2013/08/01 12:02:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Sleep
[2013/08/01 11:37:40 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\vlc
[2013/08/01 11:29:35 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/08/01 11:29:34 | 002,079,816 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2013/08/01 10:04:06 | 000,000,000 | —D | C] – C:\NvidiaLogging
[2013/08/01 10:03:30 | 000,039,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvvad64v.sys
[2013/08/01 10:03:30 | 000,029,984 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvaudcap64v.dll
[2013/08/01 10:03:30 | 000,028,448 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvaudcap32v.dll
[2013/08/01 10:03:14 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\NVIDIA
[2013/08/01 09:41:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\AGEIA Technologies
[2013/08/01 09:40:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2013/08/01 09:40:30 | 000,000,000 | —D | C] – C:\Windows\SysWow64\NV
[2013/08/01 09:40:30 | 000,000,000 | —D | C] – C:\Windows\SysNative\NV
[2013/08/01 09:39:14 | 000,000,000 | —D | C] – C:\Users\domportera\Desktop\Game Design
[2013/08/01 09:38:04 | 000,000,000 | —D | C] – C:\Users\domportera\Desktop\Diversions Music
[2013/08/01 09:37:56 | 027,781,920 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2013/08/01 09:37:56 | 021,102,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2013/08/01 09:37:56 | 015,920,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2013/08/01 09:37:56 | 015,144,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2013/08/01 09:37:56 | 013,411,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2013/08/01 09:37:56 | 009,239,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2013/08/01 09:37:56 | 007,687,592 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2013/08/01 09:37:56 | 007,641,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2013/08/01 09:37:56 | 006,324,360 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2013/08/01 09:37:56 | 002,953,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2013/08/01 09:37:56 | 002,777,888 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2013/08/01 09:37:56 | 002,363,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2013/08/01 09:37:56 | 002,002,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2013/08/01 09:37:56 | 001,832,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco6432049.dll
[2013/08/01 09:37:56 | 001,511,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco6432049.dll
[2013/08/01 09:37:56 | 000,572,704 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvFBC64.dll
[2013/08/01 09:37:56 | 000,570,656 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvIFR64.dll
[2013/08/01 09:37:56 | 000,467,232 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NvIFR.dll
[2013/08/01 09:37:56 | 000,465,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NvFBC.dll
[2013/08/01 09:37:56 | 000,432,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvEncodeAPI64.dll
[2013/08/01 09:37:56 | 000,372,000 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvEncodeAPI.dll
[2013/08/01 09:37:56 | 000,218,592 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglshim64.dll
[2013/08/01 09:37:56 | 000,181,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglshim32.dll
[2013/08/01 09:37:56 | 000,030,496 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvpciflt.sys
[2013/08/01 09:37:55 | 025,256,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2013/08/01 09:37:55 | 017,560,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2013/08/01 09:37:55 | 002,597,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2013/08/01 09:31:17 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Tomahawk
[2013/08/01 09:31:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tomahawk
[2013/08/01 09:31:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tomahawk
[2013/08/01 09:22:17 | 000,000,000 | —D | C] – C:\NVIDIA
[2013/08/01 09:15:44 | 000,000,000 | —D | C] – C:\Windows\Sun
[2013/08/01 09:14:56 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/08/01 09:14:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/08/01 09:14:41 | 000,867,240 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/08/01 09:14:41 | 000,789,416 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/08/01 09:14:41 | 000,263,592 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/08/01 09:14:37 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/08/01 09:14:37 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/08/01 09:14:37 | 000,096,168 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/08/01 09:14:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/08/01 09:14:16 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/08/01 05:46:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2013/08/01 05:46:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2013/08/01 05:46:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/08/01 05:46:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/08/01 05:46:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/08/01 05:46:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/08/01 05:46:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/08/01 05:46:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/08/01 05:46:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/08/01 05:46:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/08/01 05:46:01 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/08/01 05:46:01 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/08/01 05:46:01 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/08/01 05:46:01 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/08/01 05:46:01 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/08/01 05:46:01 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/08/01 05:46:01 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/08/01 05:46:01 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/08/01 05:46:01 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/08/01 05:46:01 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/08/01 05:46:01 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/08/01 05:46:01 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/08/01 05:46:01 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/08/01 05:46:01 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/08/01 05:46:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/08/01 05:46:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/08/01 05:46:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/08/01 05:46:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/08/01 05:41:40 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2013/08/01 05:41:40 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2013/08/01 05:12:35 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2013/08/01 05:12:30 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/08/01 05:12:30 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/08/01 05:12:28 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2013/08/01 05:12:28 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2013/08/01 05:12:28 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2013/08/01 05:12:28 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2013/08/01 05:12:28 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2013/08/01 05:12:27 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2013/08/01 05:12:27 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2013/08/01 05:12:27 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2013/08/01 05:12:26 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2013/08/01 05:12:09 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2013/08/01 05:12:09 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2013/08/01 05:12:08 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2013/08/01 05:12:08 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2013/08/01 05:12:08 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2013/08/01 05:12:02 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/08/01 05:12:02 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/08/01 05:12:01 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/08/01 05:12:01 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/08/01 05:12:01 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/08/01 05:12:01 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/08/01 05:11:49 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/08/01 05:07:25 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2013/08/01 05:07:25 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2013/08/01 05:07:25 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/08/01 05:07:25 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/08/01 05:07:10 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2013/08/01 05:06:05 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/08/01 05:06:05 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/08/01 05:06:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/08/01 05:06:05 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/08/01 04:57:44 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/08/01 04:51:11 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2013/08/01 04:51:11 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2013/08/01 04:37:54 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2013/08/01 04:36:56 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/08/01 04:36:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2013/08/01 04:36:48 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2013/08/01 04:36:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2013/08/01 04:36:37 | 001,447,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/08/01 04:36:36 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspicli.dll
[2013/08/01 04:36:36 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspisrv.dll
[2013/08/01 04:36:36 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2013/08/01 04:36:35 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2013/08/01 04:36:35 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2013/08/01 04:36:35 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2013/08/01 04:36:35 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2013/08/01 04:36:35 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2013/08/01 04:36:34 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2013/08/01 04:36:34 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2013/08/01 04:36:10 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2013/08/01 04:36:09 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2013/08/01 04:36:07 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/08/01 04:36:07 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/08/01 04:36:05 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/08/01 04:36:00 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/01 04:35:55 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/01 04:35:55 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/01 04:35:51 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/08/01 04:35:51 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/01 04:35:51 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/01 04:35:51 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/01 04:35:51 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/01 04:35:51 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/01 04:34:33 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2013/08/01 04:28:24 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/08/01 04:28:08 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2013/08/01 04:28:08 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2013/08/01 04:28:08 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2013/08/01 04:28:08 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2013/08/01 04:27:24 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2013/08/01 04:27:20 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/08/01 04:27:20 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/08/01 04:27:20 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/08/01 04:27:20 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/08/01 04:27:18 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/01 04:27:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/08/01 04:27:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/08/01 04:27:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/08/01 04:27:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/08/01 04:27:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/08/01 04:27:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/08/01 04:20:43 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2013/08/01 04:20:43 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2013/08/01 04:20:39 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/08/01 04:20:39 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/08/01 04:19:51 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/08/01 04:16:55 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/08/01 04:16:55 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/08/01 04:12:22 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netapi32.dll
[2013/08/01 04:12:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browcli.dll
[2013/08/01 04:12:22 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\browcli.dll
[2013/08/01 04:12:18 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\srcore.dll
[2013/08/01 04:12:15 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2013/08/01 04:12:12 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/01 04:12:12 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/08/01 04:12:12 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/08/01 04:12:12 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/08/01 04:12:12 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/08/01 04:12:12 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/08/01 04:12:01 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2013/08/01 04:11:45 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2013/08/01 04:11:45 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2013/08/01 04:11:39 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2013/08/01 04:11:39 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2013/08/01 04:11:30 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/01 04:11:30 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/01 04:11:30 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/01 04:11:30 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/08/01 04:11:30 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/08/01 04:11:29 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/08/01 04:10:59 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2013/08/01 04:10:59 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2013/08/01 04:09:10 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/08/01 04:09:10 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/08/01 04:07:36 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/01 04:07:33 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\splwow64.exe
[2013/08/01 03:16:15 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2013/08/01 03:16:15 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2013/08/01 03:07:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2013/08/01 02:56:56 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Apple Computer
[2013/08/01 02:41:52 | 000,000,000 | —D | C] – C:\af24f2736e42f1c2053ea0b65e481b6e
[2013/08/01 02:41:06 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Programs
[2013/08/01 02:31:31 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2013/08/01 02:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/08/01 02:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/08/01 02:29:46 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Mozilla
[2013/08/01 01:21:10 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/08/01 01:21:10 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/01 01:19:48 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apple
[2013/08/01 01:19:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/08/01 01:18:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/08/01 01:18:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/08/01 01:18:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/08/01 01:18:21 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/08/01 01:18:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/08/01 00:51:32 | 000,000,000 | R–D | C] – C:\Users\domportera\Dropbox
[2013/08/01 00:49:39 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013/08/01 00:45:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\dumps
[2013/08/01 00:45:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2013/08/01 00:45:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/08/01 00:45:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2013/08/01 00:42:20 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Dropbox
[2013/08/01 00:42:15 | 000,000,000 | R–D | C] – C:\Users\domportera\Google Drive
[2013/08/01 00:41:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/08/01 00:38:18 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Creative
[2013/08/01 00:32:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/08/01 00:32:20 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Google
[2013/08/01 00:32:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/08/01 00:32:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Deployment
[2013/08/01 00:32:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apps
[2013/08/01 00:30:10 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2013/08/01 00:30:10 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2013/08/01 00:26:43 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\KeepSafe
[2013/08/01 00:26:27 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/08/01 00:26:27 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/08/01 00:26:27 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2013/08/01 00:26:15 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/08/01 00:26:15 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/08/01 00:26:15 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\Searches
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/08/01 00:26:14 | 000,000,000 | -H-D | C] – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/08/01 00:25:48 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/08/01 00:25:48 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/08/01 00:25:38 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Identities
[2013/08/01 00:25:35 | 000,000,000 | R–D | C] – C:\Users\domportera\Contacts
[2013/08/01 00:25:26 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Intel
[2013/08/01 00:25:24 | 000,000,000 | –SD | C] – C:\Users\domportera\AppData\Roaming\Microsoft
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Videos
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Saved Games
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Pictures
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Music
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Links
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Favorites
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Downloads
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Documents
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Desktop
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\Temporary Internet Files
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Templates
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Start Menu
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\SendTo
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Recent
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\PrintHood
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\NetHood
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Videos
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Pictures
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Music
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\My Documents
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Local Settings
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\History
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Cookies
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Application Data
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\Application Data
[2013/08/01 00:25:24 | 000,000,000 | -H-D | C] – C:\Users\domportera\AppData
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Temp
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\Roaming
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Microsoft
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Media Center Programs
[2013/08/01 00:25:10 | 000,000,000 | -HSD | C] – C:\Recovery
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\upeksce
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AuthenTec TrueSuite
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AuthenTec
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AuthenTec
[2013/07/25 14:42:15 | 000,000,000 | —D | C] – C:\Program Files\AuthenTec TrueSuite
[2013/07/25 14:42:12 | 000,000,000 | —D | C] – C:\ProgramData\Downloaded Installations
[2013/07/25 14:42:04 | 000,000,000 | —D | C] – C:\Program Files\AuthenTec
[2013/07/25 14:41:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\FingerPrinter
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/05 17:37:01 | 000,000,906 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/05 16:17:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/05 12:37:45 | 000,007,631 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/08/05 12:37:44 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/08/05 12:37:44 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/08/05 12:26:33 | 001,690,265 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\Cat.DB
[2013/08/05 12:24:01 | 000,002,402 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/08/05 11:20:33 | 000,021,888 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/05 11:20:33 | 000,021,888 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/05 11:17:42 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/05 11:17:42 | 000,660,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/05 11:17:42 | 000,121,214 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/05 11:12:51 | 000,001,875 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013/08/05 11:11:56 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/05 11:11:19 | 2060,148,735 | -HS- | M] () – C:\hiberfil.sys
[2013/08/05 03:10:00 | 000,773,050 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/08/05 02:50:48 | 000,014,456 | —- | M] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/08/05 02:42:03 | 000,001,193 | —- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk
[2013/08/05 02:38:17 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/04 22:31:52 | 000,001,397 | RHS- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/08/04 19:51:26 | 000,000,974 | —- | M] () – C:\Users\domportera\Desktop\KMPlayer.lnk
[2013/08/03 11:59:41 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\Exact Audio Copy.lnk
[2013/08/03 04:13:10 | 000,000,992 | —- | M] () – C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013/08/03 02:20:58 | 000,001,193 | —- | M] () – C:\Users\domportera\Desktop\Dxtory.lnk
[2013/08/02 21:00:03 | 000,001,092 | —- | M] () – C:\Users\domportera\Desktop\Capsule.lnk
[2013/08/02 05:10:01 | 000,275,712 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/08/02 04:05:32 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/02 04:05:32 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/02 04:05:32 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/02 04:05:32 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/08/02 04:05:32 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/08/02 04:05:32 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/08/02 04:05:32 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/02 04:05:32 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/08/02 04:05:32 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/02 04:05:32 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/08/02 04:05:32 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/02 04:05:32 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/02 04:05:32 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/02 04:05:32 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/08/02 04:05:32 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/08/02 04:05:32 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/02 04:05:32 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/08/02 04:05:32 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/08/02 04:05:32 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/02 04:05:32 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/02 04:05:32 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/08/02 04:05:32 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/08/02 04:05:32 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/08/02 04:05:32 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/08/02 04:05:32 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/02 04:05:32 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/08/02 04:05:32 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/08/02 04:05:32 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/08/02 04:05:32 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/08/02 04:05:32 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/08/02 04:05:32 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/08/02 04:05:32 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/02 04:05:32 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/08/02 04:05:32 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/08/02 04:05:32 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/08/02 04:05:32 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/08/02 04:05:32 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/08/02 04:05:32 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/08/02 04:05:32 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/02 04:05:32 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/08/02 04:05:32 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/08/02 04:05:32 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/02 04:05:32 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/08/02 04:05:32 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/08/02 04:05:32 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/08/02 04:05:32 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/08/02 04:05:32 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/08/02 04:05:32 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/08/02 04:05:32 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/08/02 04:05:32 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/08/02 04:05:32 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/08/02 04:05:32 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/08/02 04:05:32 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/08/02 04:05:32 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/08/02 04:05:32 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/08/02 04:05:32 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/08/02 04:05:32 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/08/02 04:05:32 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/08/02 04:05:32 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/08/02 04:05:32 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/08/02 04:00:34 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/08/02 04:00:34 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/08/02 04:00:34 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/08/02 04:00:34 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/08/02 04:00:34 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/08/02 04:00:34 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/08/02 04:00:34 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/08/02 04:00:34 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/08/02 04:00:34 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/08/02 04:00:34 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/08/02 04:00:34 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/08/02 04:00:34 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/08/02 04:00:34 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/08/02 04:00:34 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/08/02 04:00:34 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/01 12:22:01 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2013/08/01 12:22:01 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2013/08/01 09:31:07 | 000,001,018 | —- | M] () – C:\Users\domportera\Desktop\Tomahawk.lnk
[2013/08/01 09:14:31 | 000,867,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/08/01 09:14:31 | 000,789,416 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/08/01 09:14:31 | 000,263,592 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/08/01 09:14:31 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/08/01 09:14:31 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/08/01 09:14:31 | 000,096,168 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/08/01 00:51:32 | 000,001,057 | —- | M] () – C:\Users\domportera\Desktop\Dropbox.lnk
[2013/08/01 00:50:21 | 000,001,067 | —- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/01 00:45:24 | 000,000,924 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2013/08/01 00:42:17 | 000,002,290 | —- | M] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/01 00:42:16 | 000,001,717 | —- | M] () – C:\Users\domportera\Desktop\Google Drive.lnk
[2013/08/01 00:41:03 | 000,002,051 | —- | M] () – C:\Users\Public\Desktop\Google Slides.lnk
[2013/08/01 00:41:03 | 000,002,047 | —- | M] () – C:\Users\Public\Desktop\Google Sheets.lnk
[2013/08/01 00:41:03 | 000,002,035 | —- | M] () – C:\Users\Public\Desktop\Google Docs.lnk
[2013/08/01 00:32:51 | 000,002,266 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/01 00:31:33 | 000,001,448 | —- | M] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/07/25 14:42:09 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_tcwbf_01_09_00.Wdf
[2013/07/25 14:42:09 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/05 12:40:04 | 000,014,818 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\VT20130115.021
[2013/08/05 12:36:44 | 000,009,670 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symelam64.cat
[2013/08/05 12:36:44 | 000,008,067 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnet64.cat
[2013/08/05 12:36:44 | 000,001,440 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnet.inf
[2013/08/05 12:36:43 | 000,007,667 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.cat
[2013/08/05 12:36:43 | 000,007,593 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\iron.cat
[2013/08/05 12:36:43 | 000,007,589 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.cat
[2013/08/05 12:36:43 | 000,007,587 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.cat
[2013/08/05 12:36:43 | 000,003,434 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa.inf
[2013/08/05 12:36:43 | 000,002,852 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds.inf
[2013/08/05 12:36:43 | 000,001,437 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.inf
[2013/08/05 12:36:43 | 000,001,420 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.inf
[2013/08/05 12:36:43 | 000,000,996 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symelam.inf
[2013/08/05 12:36:43 | 000,000,853 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.inf
[2013/08/05 12:36:43 | 000,000,767 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\iron.inf
[2013/08/05 12:35:44 | 000,008,067 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.cat
[2013/08/05 12:35:44 | 000,008,063 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.cat
[2013/08/05 12:35:44 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\isolate.ini
[2013/08/05 12:24:37 | 001,690,265 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\Cat.DB
[2013/08/05 12:24:21 | 000,007,631 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/08/05 12:24:21 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/08/05 12:24:01 | 000,002,402 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/08/05 12:22:11 | 000,001,440 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymNet.inf
[2013/08/05 12:22:10 | 000,003,434 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA.inf
[2013/08/05 12:22:10 | 000,002,852 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS.inf
[2013/08/05 12:22:10 | 000,001,438 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.inf
[2013/08/05 12:22:10 | 000,001,420 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.inf
[2013/08/05 12:22:10 | 000,000,996 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\symELAM.inf
[2013/08/05 12:22:10 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccSetx64.inf
[2013/08/05 12:22:10 | 000,000,767 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\Iron.inf
[2013/08/05 12:21:22 | 000,014,818 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymVTcer.dat
[2013/08/05 12:21:22 | 000,009,670 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymELAM64.cat
[2013/08/05 12:21:22 | 000,007,611 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\ccsetx64.cat
[2013/08/05 12:21:22 | 000,007,601 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\symnet64.cat
[2013/08/05 12:21:22 | 000,007,593 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\iron.cat
[2013/08/05 12:21:22 | 000,007,589 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtspx64.cat
[2013/08/05 12:21:22 | 000,007,587 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymEFA64.cat
[2013/08/05 12:21:22 | 000,007,585 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\srtsp64.cat
[2013/08/05 12:21:22 | 000,007,581 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\SymDS64.cat
[2013/08/05 12:21:22 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1403000.024\isolate.ini
[2013/08/05 02:52:38 | 000,001,875 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013/08/05 02:42:03 | 000,001,193 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk
[2013/08/05 02:38:17 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/05 01:46:41 | 000,007,062 | —- | C] () – C:\Windows\SysWow64\audiopid.vxd
[2013/08/04 19:49:47 | 000,000,974 | —- | C] () – C:\Users\domportera\Desktop\KMPlayer.lnk
[2013/08/03 11:59:41 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\Exact Audio Copy.lnk
[2013/08/03 04:13:10 | 000,000,992 | —- | C] () – C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013/08/03 02:20:58 | 000,001,193 | —- | C] () – C:\Users\domportera\Desktop\Dxtory.lnk
[2013/08/02 21:00:03 | 000,001,200 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Capsule.lnk
[2013/08/02 21:00:03 | 000,001,092 | —- | C] () – C:\Users\domportera\Desktop\Capsule.lnk
[2013/08/02 04:05:32 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/08/02 04:05:32 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/08/02 03:35:10 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/08/01 09:31:07 | 000,001,018 | —- | C] () – C:\Users\domportera\Desktop\Tomahawk.lnk
[2013/08/01 03:15:03 | 000,773,050 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/08/01 01:19:47 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/08/01 00:51:32 | 000,001,057 | —- | C] () – C:\Users\domportera\Desktop\Dropbox.lnk
[2013/08/01 00:50:21 | 000,001,067 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/01 00:45:24 | 000,000,924 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2013/08/01 00:42:16 | 000,001,717 | —- | C] () – C:\Users\domportera\Desktop\Google Drive.lnk
[2013/08/01 00:41:03 | 000,002,051 | —- | C] () – C:\Users\Public\Desktop\Google Slides.lnk
[2013/08/01 00:41:03 | 000,002,047 | —- | C] () – C:\Users\Public\Desktop\Google Sheets.lnk
[2013/08/01 00:41:03 | 000,002,035 | —- | C] () – C:\Users\Public\Desktop\Google Docs.lnk
[2013/08/01 00:32:51 | 000,002,290 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/01 00:32:51 | 000,002,266 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/01 00:32:24 | 000,000,906 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/01 00:32:23 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/01 00:31:33 | 000,001,448 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/08/01 00:26:17 | 000,001,424 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/08/01 00:25:24 | 000,000,290 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/08/01 00:25:24 | 000,000,272 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/07/25 14:42:09 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_tcwbf_01_09_00.Wdf
[2013/07/25 14:42:09 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/06/20 19:16:35 | 000,008,570 | —- | C] () – C:\Windows\SysWow64\MBCfg32.ini
[2013/06/20 19:16:35 | 000,005,856 | —- | C] () – C:\Windows\SysWow64\MBCfgUninstall32.ini
[2013/06/20 19:16:35 | 000,002,835 | —- | C] () – C:\Windows\MBCfg_SP_APOIM.ini
[2013/06/20 19:16:35 | 000,002,783 | —- | C] () – C:\Windows\MBCfg_APOIM.ini
[2013/06/20 19:16:35 | 000,002,747 | —- | C] () – C:\Windows\MBCfg_HP_APOIM.ini
[2013/06/20 19:16:33 | 000,246,272 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2013/06/20 19:16:33 | 000,074,240 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2013/06/20 18:25:53 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2013/06/20 18:25:52 | 019,586,560 | —- | C] () – C:\Windows\SysWow64\igdfcl32.dll
[2013/06/20 18:25:52 | 000,103,936 | —- | C] () – C:\Windows\SysWow64\igdail32.dll
[2013/05/13 18:48:06 | 002,567,680 | —- | C] () – C:\Windows\SysWow64\DeviceControl.exe
[2012/12/10 17:12:50 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/08/05 18:04:38 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\Ad-Aware Antivirus
[2013/08/04 22:26:36 | 000,000,000 | -HSD | M] – C:\Users\domportera\AppData\Roaming\bauwefiv
[2013/08/05 11:12:56 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\Dropbox
[2013/08/03 11:18:05 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\EAC
[2013/08/01 00:30:11 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\KeepSafe

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 03:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/05 02:10:34 | 000,158,002 | —- | M] () MD5=E9179D763F908B4CB84EED6E809533C8 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2013/08/02 04:05:32 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/08/02 04:05:32 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_184d84e8cdd3303c\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011/11/22 12:49:55 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2013/08/02 04:05:32 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/02 04:05:32 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/05/29 02:24:18 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=AFF2C99AD2C599108B6BD9E77C24B463 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_0d0dec99809dccc9\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/05/29 01:56:53 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=C9C29508A433DAF0118D28C4F38CDDFC – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_0df8da9699726e41\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_176296ebb4fe8ec4\iexplore.exe
[2011/11/22 12:49:55 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011/11/22 12:49:55 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/11/22 12:49:55 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 03:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/08/05 11:11:19 | 2060,148,735 | -HS- | M] () – C:\hiberfil.sys
[2013/08/05 11:11:21 | 4178,522,111 | -HS- | M] () – C:\pagefile.sys
[2013/06/20 19:01:27 | 000,000,087 | —- | M] () – C:\setup.log

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 19:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Windows
Volume Serial Number is 6644-2D63
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\domportera
08/01/2013 12:25 AM Application Data [C:\Users\domportera\AppData\Roaming]
08/01/2013 12:25 AM Cookies [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Cookies]
08/01/2013 12:25 AM Local Settings [C:\Users\domportera\AppData\Local]
08/01/2013 12:25 AM My Documents [C:\Users\domportera\Documents]
08/01/2013 12:25 AM NetHood [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/01/2013 12:25 AM PrintHood [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/01/2013 12:25 AM Recent [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Recent]
08/01/2013 12:25 AM SendTo [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\SendTo]
08/01/2013 12:25 AM Start Menu [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu]
08/01/2013 12:25 AM Templates [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\domportera\AppData\Local
08/01/2013 12:25 AM Application Data [C:\Users\domportera\AppData\Local]
08/01/2013 12:25 AM History [C:\Users\domportera\AppData\Local\Microsoft\Windows\History]
08/01/2013 12:25 AM Temporary Internet Files [C:\Users\domportera\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\domportera\Documents
08/01/2013 12:25 AM My Music [C:\Users\domportera\Music]
08/01/2013 12:25 AM My Pictures [C:\Users\domportera\Pictures]
08/01/2013 12:25 AM My Videos [C:\Users\domportera\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser
06/20/2013 06:29 PM Application Data [C:\Users\UpdatusUser\AppData\Roaming]
06/20/2013 06:29 PM Cookies [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies]
06/20/2013 06:29 PM Local Settings [C:\Users\UpdatusUser\AppData\Local]
06/20/2013 06:29 PM My Documents [C:\Users\UpdatusUser\Documents]
06/20/2013 06:29 PM NetHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/20/2013 06:29 PM PrintHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/20/2013 06:29 PM Recent [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent]
06/20/2013 06:29 PM SendTo [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo]
06/20/2013 06:29 PM Start Menu [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu]
06/20/2013 06:29 PM Templates [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\AppData\Local
06/20/2013 06:29 PM Application Data [C:\Users\UpdatusUser\AppData\Local]
06/20/2013 06:29 PM History [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History]
06/20/2013 06:29 PM Temporary Internet Files [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\Documents
06/20/2013 06:29 PM My Music [C:\Users\UpdatusUser\Music]
06/20/2013 06:29 PM My Pictures [C:\Users\UpdatusUser\Pictures]
06/20/2013 06:29 PM My Videos [C:\Users\UpdatusUser\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
66 Dir(s) 755,273,949,184 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/08/01 00:31:33 | 000,000,221 | -HS- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


Extras.txt

OTL Extras logfile created on: 8/5/2013 6:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\domportera\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.89 Gb Total Physical Memory | 4.62 Gb Available Physical Memory | 58.56% Memory free
15.78 Gb Paging File | 12.14 Gb Available in Paging File | 76.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 703.50 Gb Free Space | 75.53% Space Free | Partition Type: NTFS

Computer Name: DOMPORTERA-PC | User Name: domportera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12812F08-72C5-4646-AE08-C29EAA3CF050}" = rport=139 | protocol=6 | dir=out | app=system |
"{20DF5334-7361-4CD0-99FE-200DF9B6E04F}" = lport=139 | protocol=6 | dir=in | app=system |
"{2CBE11F2-E8D6-4977-8DD9-217D4863329E}" = rport=137 | protocol=17 | dir=out | app=system |
"{30FD6225-4264-4231-868F-50FC491BB5CC}" = lport=445 | protocol=6 | dir=in | app=system |
"{59CE9ED5-E4DF-4C01-9F55-B243297E604D}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{5BCBE92F-39F1-4B81-891A-D19AC5A9B50B}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{5CDEE76D-0B80-467D-B764-841EBCBD2C1F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{66292AF4-1711-4D0F-93ED-B10966453992}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{69ACB8F1-E9E9-41E8-B406-2D8F3792F418}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{69FE08C0-3856-4856-A37A-17F5FC50A196}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{6C9B3700-1841-40E6-968D-9ADA6CBABF7B}" = lport=138 | protocol=17 | dir=in | app=system |
"{702666A9-1B09-45BB-8594-DA6C81A872AF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7A74974E-4AB3-4D21-851F-3CDD4B7C1A14}" = lport=137 | protocol=17 | dir=in | app=system |
"{7B403AB4-1A5C-4ED2-BB69-ECB8BAE4C633}" = rport=138 | protocol=17 | dir=out | app=system |
"{85D1A48A-49BC-4B0B-8D55-6F567637E654}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{86A48A4F-6224-4FCA-ADC5-4A16E780FA4B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8F648ABE-4C86-4816-8E3A-7E908B6FFDCA}" = rport=445 | protocol=6 | dir=out | app=system |
"{941D7A8E-5D2E-4F17-BDC5-885F879DC1C1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{968EF110-5DB9-42C3-8416-38E6B7EB2995}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A3942AD0-9703-40DE-8AB2-9D3B12716A9C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AD098929-6E74-4577-948F-48BCA225D331}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{B559EB82-7759-40DD-9DCC-38B883919FBF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D0BB712A-7805-458E-B273-3D443371AE3B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D54721A3-2B49-403E-9A00-E1C5246F1501}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DB063814-623A-413C-A3A5-7C56FA71B08D}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{E16096D0-9D8C-4023-BB34-23326B4E1872}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F0153CDE-3EA9-430A-BE3A-5E18C0253237}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05AD58ED-5EE9-4DA5-B299-70EE07198A12}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{087EF594-87CC-4662-9211-162526B09665}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\support\ea help\electronic_arts_technical_support.htm |
"{0B9BE629-FDE3-4606-9EC8-379A4FD24724}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{168C5B0A-B5FB-4F3D-BE4E-1F57D19188C0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe |
"{19D37191-8A0E-4317-A54B-FD53031FBE99}" = protocol=6 | dir=out | app=system |
"{1A33B5C2-E69F-4730-9C93-987C8F3FBEFC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{1AE430C0-E699-4111-8EBD-7319CAC6A5CA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{1B06815A-8917-4504-BFF7-5C1C0797EA96}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\quake 3 arena\quake3.exe |
"{1BC36235-63FD-491F-81AC-80C65C7DE3E1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1F117329-D5E0-4CF6-B2BE-8F0610E8E473}" = protocol=6 | dir=in | app=c:\users\domportera\appdata\roaming\dropbox\bin\dropbox.exe |
"{2381EFDB-AECA-4531-9A39-BD16882556F4}" = protocol=17 | dir=in | app=c:\users\domportera\appdata\roaming\dropbox\bin\dropbox.exe |
"{26802C8B-1258-4C1F-BF0E-D66C457181C9}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe |
"{26FEBAE0-346C-4DD3-89F3-E17970915612}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{2C674E77-0AD4-4C0D-BAFA-4043F097D85C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\support\ea help\electronic_arts_technical_support.htm |
"{39FCEAD8-37B4-43F5-8548-54C8BBAC4BB5}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{3CC04EB1-40AC-429B-996C-9B3B368DE407}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_gold\thief.exe |
"{3E332CF1-3DE0-45A5-BC21-89B714384CE7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{474F3568-53A2-4C04-B23F-8877DBC3799C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{4B10A19B-6409-42CE-B2B8-D88211BB29AE}" = protocol=6 | dir=in | app=c:\program files (x86)\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{4DBD7E93-8A17-4268-AA7F-E03EA5881874}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe |
"{4E2BCDD2-81F6-4E50-9C09-49D7BEB2F5AB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{538FD6F9-FBD9-4464-949B-092070D2C43E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{541059D7-D2E6-4FB8-8154-4A2EFA6A9E14}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5B692AAA-775C-4BD2-96DB-8832EB54DA78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe |
"{5BC15F99-E4A3-4DCF-9B4F-DDE464C03135}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{634208E9-FB7C-470C-9249-C22609176C36}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{650528A1-69A9-4E62-8424-4326D59F09A1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68F21F29-CCF8-4BCE-A9E9-E6EA582730F1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe |
"{75BDD8BB-8A46-431E-86DB-19BCD7997D1B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{773875E4-BAED-4119-B469-6972DE493573}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\benchmark.bat |
"{8046EDE7-8012-414F-B3D8-2CF4549CB950}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{8221559D-3178-4DD6-BDE9-02B940CFFEF1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{84BE1C5B-640F-45F5-A7E1-44AF8BE3A5FB}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{875535FB-2EE0-40EC-A62C-4A6FC7098B78}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe |
"{8B5ED10F-AD72-4989-A00D-85B55A0C526D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8C446201-A37D-4268-93CD-3FB5E3D7E75C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8D199B94-DC14-4F17-BAC1-908E513E9CB3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gamemaker_studio\gamemakerplayer.exe |
"{8F574577-14EC-45DE-9BAD-2F060AF98E1B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magic 2014\dotp_d14.exe |
"{94EABFAE-56DD-4C4D-A371-86BACE4413B3}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{97A04A6A-7C1A-4144-82E8-C04B110D9CC7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{990BB09B-BC13-4251-9003-530D6D916B94}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gamemaker_studio\gamemakerplayer.exe |
"{9984CB85-93ED-463E-A0F8-E14AF744B3D4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_gold\thief.exe |
"{9BA9D7D6-484B-45E3-B4A4-830620FD3AC8}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{A1E2BEE9-C165-4909-9C49-F5241EE42F72}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{A2CE2911-1476-4E85-B49F-C2F2919DAE8D}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{A3545850-35A2-40CD-92E6-0483F94C4F6A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{A653386C-F68F-4B7F-8A87-259BC3D232C1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A7E0378E-17B9-444B-BCCF-488334847A2F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A915AC33-2DF4-4E9D-BEA3-E69CD07E475D}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{A98D590F-4B47-482A-A2AB-C1F3AA3FED67}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe |
"{AD53BD09-DF6F-40DB-8C49-4AF9879510C4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magic 2014\dotp_d14.exe |
"{B167B413-F57F-4F1B-8E02-BEAC0CF929A3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B5CC4F37-E5C4-4035-9D4C-D8554B12DC75}" = protocol=17 | dir=in | app=c:\program files (x86)\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{B80E6733-411F-4562-8CC4-AFF80FDFAF2E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{B840F083-47A5-4FC3-9D69-FAE0135E2070}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{C0130D78-7C51-403F-8DF6-BBF97AAFABD5}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C1C73145-4E4D-4562-955A-5E6FEDF0B3E9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C305C49C-9A4C-4D5F-9ACE-5BEFFC26F579}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C337B023-0FE1-4808-B68A-01EBA5633714}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{C572745D-C2D5-4ADF-B9A9-DE2E27743D90}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D388BCF8-929B-4208-B52B-F58A72D51D0F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{DA93A261-9540-46CC-A891-D2102A9C8ED1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\quake 3 arena\quake3.exe |
"{DCD414CF-5330-4192-B9FC-6B33E38B0AB2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe |
"{E39840C6-F6F5-4A4B-B21A-6268859E0E26}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E7D11C07-976F-4A7E-A837-1B87FDE1DA54}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EC1F72ED-873B-4EDC-BA2E-C7257C8CB86C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F3BD349D-9503-44F0-828F-BB0714365AF9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe |
"{F4B86103-14B4-4AA5-AFCC-4330A293BD56}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe |
"{F56DB8BC-1C2B-4F4C-935D-7FC63E23CD80}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F574F7AB-70B4-46B9-9F1C-377395E344D3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{F774CD76-0AC3-481D-9FEF-4A387745F4C5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock infinite\binaries\win32\benchmark.bat |
"{F9F4F4A0-54A6-444E-A3D4-2AFCEFAC1E29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{9D80B6A7-F719-424B-AF03-9D8FAC0EF369}C:\windows\syswow64\svchost.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\svchost.exe |
"TCP Query User{D96B4093-3408-49BF-AD7F-81E5DFA4065D}C:\users\domportera\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\domportera\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{DBFDD82D-8D12-4491-B5D4-C2CE3138051A}C:\program files (x86)\tomahawk\tomahawk.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tomahawk\tomahawk.exe |
"UDP Query User{322F6823-6777-4539-BEE1-23DCA85DC34E}C:\windows\syswow64\svchost.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\svchost.exe |
"UDP Query User{A5335411-D6D6-49C9-91AF-651059499FCD}C:\users\domportera\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\domportera\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{B178A59A-672E-425C-A0B1-7DF5754F6D3A}C:\program files (x86)\tomahawk\tomahawk.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tomahawk\tomahawk.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7C6CD9B4-B230-4E76-80AA-FB465FF4DE29}" = Intel® PROSet/Wireless WiFi Software Driver
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A4D399F-F790-4326-A9E4-64DF25E0EBE1}" = AuthenTec TrueSuite
"{A94C50AA-21E8-4627-ADD0-E16A07030D7D}" = Intel® PROSet/Wireless for Bluetooth® + High Speed
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.6
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 7.2.17
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 7.2.17
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.1
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{CEA5CD5B-DD10-46BF-82CE-CD578E3409BA}" = AuthenTec Fingerprint Driver
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DEF50764-F1A7-4DD4-B8BA-C81A4807631A}" = Intel® PROSet/Wireless WiFi Software
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA00A3CC-7440-4938-A271-F186F50DD40D}" = Intel® Trusted Connect Service Client
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 5.00 beta 8 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}" = Realtek PCIE Card Reader
"{11BD0F20-27DC-4584-AD10-9E99F32F8501}" = PC Sleep
"{164714B6-46BC-4649-9A30-A6ED32F03B5A}" = Hotkey 7.0010
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A14D7BC-1876-4B38-830B-18856C27F550}" = WebCam Installer
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{3282FBE1-35FC-48D8-98CA-115A5EF1F9B4}" = NVIDIA PhysX
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5BBC4803-C96E-4D3E-9D1D-2E43774C4062}" = BisonCam
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{793C03D1-884D-4C11-A7F6-07F3FDF10066}" = Finger Printer
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8801CA65-921A-4CCC-9D63-879D1D0BAA97}" = Sound Blaster Cinema
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{944167EA-7F89-4705-8DCD-1D63B53141B0}" = Ad-Aware Antivirus
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2201542-DA80-457F-8BD9-6C9C90196481}" = ChiconyCam
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{C2D4CD4A-AE20-40B3-8726-8ED1C03E8C15}" = Google Drive
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{fad118b4-798f-4755-9e67-a622eec95b62}" = Intel® PROSet/Wireless Software
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® SDK for OpenCL - CPU Only Runtime Package
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"4F6D5E84-5826-4394-9F40-3A9A19165651_is1" = Pandora Service
"adawaretb" = Ad-Aware Security Add-on
"Capsule" = Capsule
"Dxtory2.0_is1" = Dxtory version 2.0.122
"Exact Audio Copy" = Exact Audio Copy 1.0beta3
"Google Chrome" = Google Chrome
"InstallShield_{164714B6-46BC-4649-9A30-A6ED32F03B5A}" = Hotkey 7.0010
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{2A14D7BC-1876-4B38-830B-18856C27F550}" = WebCam Installer
"InstallShield_{793C03D1-884D-4C11-A7F6-07F3FDF10066}" = Finger Printer
"LastFM_is1" = Last.fm Scrobbler 2.1.35
"N360" = Norton 360
"Steam App 105600" = Terraria
"Steam App 211600" = Thief Gold
"Steam App 213850" = Magic 2014
"Steam App 214850" = GameMaker: Studio
"Steam App 219640" = Chivalry: Medieval Warfare
"Steam App 2200" = Quake III Arena
"Steam App 47780" = Dead Space 2
"Steam App 550" = Left 4 Dead 2
"Steam App 55230" = Saints Row: The Third
"Steam App 6060" = Star Wars - Battlefront II
"Steam App 8870" = BioShock Infinite
"The KMPlayer" = The KMPlayer (remove only)
"Tomahawk" = Tomahawk
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/5/2013 2:02:31 AM | Computer Name = domportera-PC | Source = NvStreamSvc | ID = 131073
Description =

Error - 8/5/2013 2:02:37 AM | Computer Name = domportera-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/5/2013 5:22:58 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/5/2013 5:22:58 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 999

Error - 8/5/2013 5:22:58 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 999

Error - 8/5/2013 11:03:18 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/5/2013 11:03:18 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 20421093

Error - 8/5/2013 11:03:18 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 20421093

Error - 8/5/2013 11:03:19 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/5/2013 11:03:19 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 20422107

Error - 8/5/2013 11:03:19 AM | Computer Name = domportera-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 20422107

[ System Events ]
Error - 8/3/2013 1:55:54 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.

Error - 8/3/2013 2:01:04 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.

Error - 8/3/2013 2:01:56 AM | Computer Name = domportera-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 8/3/2013 2:01:56 AM | Computer Name = domportera-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 8/3/2013 2:06:14 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.

Error - 8/3/2013 2:11:24 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.

Error - 8/3/2013 2:16:34 AM | Computer Name = domportera-PC | Source = BROWSER | ID = 8020
Description =

Error - 8/3/2013 2:16:34 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.

Error - 8/3/2013 2:21:44 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.

Error - 8/3/2013 2:26:54 AM | Computer Name = domportera-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.15. The computer with the IP address 192.168.1.1 did not
allow the name to be claimed by this computer.


< End of report >
Hello domportera,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

1. Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=========================

2. aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================

3. AdwCleaner

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

4. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [createrestorepoint]
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

In your next post please provide the following:

  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • AdwCleaner[S1].txt
  • OTL.txt
checkup.txt

Results of screen317's Security Check version 0.99.71
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Lavasoft Ad-Aware
Norton 360
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Ad-Aware
Java 7 Update 25
Google Chrome 28.0.1500.95
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
Ad-Aware Antivirus AdAwareService.exe
Ad-Aware Antivirus SBAMSvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 20% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


For the aswMBR I did it twice- one with default settings and one with the entire C drive since I wasn't sure which to do. Here:

aswMBR.txt
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-05 21:19:33
—————————–
21:19:33.865 OS Version: Windows x64 6.1.7601 Service Pack 1
21:19:33.865 Number of processors: 8 586 0x3C03
21:19:33.866 ComputerName: DOMPORTERA-PC UserName: domportera
21:19:38.071 Initialize success
21:20:26.360 AVAST engine defs: 13080502
21:22:15.590 The log file has been saved successfully to "C:\Users\domportera\Desktop\aswMBR.txt"



aswMBR-Cdrive.txt
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-05 21:19:33
—————————–
21:19:33.865 OS Version: Windows x64 6.1.7601 Service Pack 1
21:19:33.865 Number of processors: 8 586 0x3C03
21:19:33.866 ComputerName: DOMPORTERA-PC UserName: domportera
21:19:38.071 Initialize success
21:20:26.360 AVAST engine defs: 13080502
21:22:15.590 The log file has been saved successfully to "C:\Users\domportera\Desktop\aswMBR.txt"
21:22:41.418 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:22:41.420 Disk 0 Vendor: TOSHIBA_MQ01ABD100 AX001A Size: 953869MB BusType: 11
21:22:41.523 Disk 0 MBR read successfully
21:22:41.525 Disk 0 MBR scan
21:22:41.529 Disk 0 Windows 7 default MBR code
21:22:41.541 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
21:22:41.552 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953766 MB offset 206848
21:22:41.677 Disk 0 scanning C:\Windows\system32\drivers
21:22:53.314 Service scanning
21:23:28.594 Modules scanning
21:23:28.599 Disk 0 trace - called modules:
21:23:28.627 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
21:23:28.632 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007af5790]
21:23:28.636 3 CLASSPNP.SYS[fffff88001b3f43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800789d060]
21:23:31.861 AVAST engine scan C:\
21:26:10.762 Disk 0 MBR has been saved successfully to "C:\Users\domportera\Desktop\MBR.dat"
21:26:10.770 The log file has been saved successfully to "C:\Users\domportera\Desktop\aswMBR-Cdrive.txt"



ADWCleanup[S1].txt
# AdwCleaner v2.306 - Logfile created 08/05/2013 at 21:33:44
# Updated 19/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : domportera - DOMPORTERA-PC
# Boot Mode : Normal
# Running from : C:\Users\domportera\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\Users\domportera\AppData\LocalLow\adawaretb

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\adawaretb
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16635

[OK] Registry is clean.

-\\ Google Chrome v28.0.1500.95

File : C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.2720] : homepage = "hxxp://blekko.com/?source=c3348dd4&tbp=homepage&toolbarid=blekkotb&u=20120324786D4F6[…]

*************************

AdwCleaner[S1].txt - [2067 octets] - [05/08/2013 21:33:44]

########## EOF - C:\AdwCleaner[S1].txt - [2127 octets] ##########

OTL.txt

I ran OTL with the settings described in the "are you Infected" thread

OTL logfile created on: 8/5/2013 9:59:21 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\domportera\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.89 Gb Total Physical Memory | 4.58 Gb Available Physical Memory | 58.04% Memory free
15.78 Gb Paging File | 12.18 Gb Available in Paging File | 77.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 710.38 Gb Free Space | 76.27% Space Free | Partition Type: NTFS

Computer Name: DOMPORTERA-PC | User Name: domportera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\domportera\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe (Lavasoft Limited)
PRC - C:\Users\domportera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hotkey\Hotkey.exe ()
PRC - C:\Program Files (x86)\Hotkey\WRadio.exe ()
PRC - C:\Program Files (x86)\Hotkey\PowerBiosServer.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe (PandoraTV)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
PRC - C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe (AuthenTec Inc.)
PRC - C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\pysqlite2._sqlite.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\_elementtree.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32api.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\_socket.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32ts.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32com.shell.shell.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._html2.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\_multiprocessing.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._gdi_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\windows._cacheinvalidation.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32crypt.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._core_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._misc_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\pythoncom27.dll ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\PyWinTypes27.dll ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32security.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\_ctypes.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32profile.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\_ssl.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32pdh.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._windows_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\_hashlib.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._wizard.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32file.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32inet.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32process.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\wx._controls_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\unicodedata.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\pyexpat.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\win32event.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI49882\select.pyd ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a7a3ebc76a454af37918211506e81e31\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a2920ed81e097f8551231a9350697bbd\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\f752f8cf702b7c7eff6c659b2e0c760a\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fc4a8709f71eba20cc71c7905bba3dee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\178644ab40108f3becd8b91049a254c3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bfa7a95284aec941f4b03bae0debe07c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ef17be93e209cc95b9768c7822530432\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c25666b99761bc42322bae2e59968df8\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\32066405eb9ab14056b2af3115d2a6de\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\187c13e8967097d2ed1e5f123e7d890a\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Hotkey\Hotkey.exe ()
MOD - C:\Program Files (x86)\Hotkey\en\HotKey.resources.dll ()
MOD - C:\Program Files (x86)\Hotkey\en-US\HotKey.resources.dll ()
MOD - C:\Program Files (x86)\Hotkey\WRadio.exe ()
MOD - C:\Users\domportera\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Users\domportera\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Program Files (x86)\Hotkey\Audiodll.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NvStreamSvc) – C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AMPPALR3) – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (ZeroConfigService) – C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel® Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (BTHSSecurityMgr) – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV:64bit: - (FPLService) – C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (AuthenTec, Inc)
SRV:64bit: - (TrueService) – C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Ad-Aware Service) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (PowerBiosServer) – C:\Program Files (x86)\Hotkey\PowerBiosServer.exe ()
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (PanService) – C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
SRV - (SBAMSvc) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (gfibto) – C:\Windows\SysNative\drivers\gfibto.sys (GFI Software)
DRV:64bit: - (nvpciflt) – C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (nvvad_WaveExtensible) – C:\Windows\SysNative\drivers\nvvad64v.sys (NVIDIA Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\Netwsw00.sys (Intel Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (RSBASTOR) – C:\Windows\SysNative\drivers\RtsBaStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SmbDrvI) – C:\Windows\SysNative\drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (VMfilt) – C:\Windows\SysNative\drivers\VMfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130805.017\ex64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130805.017\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130802.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nmd.msn.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{CDEF1E49-EFBD-4A63-9F2E-F308510F2372}: "URL" = http://findgala.com/?&uid=5689&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@authentec.com/ffwloplugin: C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll (AuthenTec, Inc)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\coFFPlgn\ [2013/08/05 21:57:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\IPSFFPlgn\ [2013/08/05 12:25:22 | 000,000,000 | —D | M]

[2013/08/01 02:29:47 | 000,000,000 | —D | M] (No name found) – C:\Users\domportera\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:in
s
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: http://blekko.com/?source=c3348dd4&tbp…A6E1512B33797C6
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: TrueSuite (Enabled) = C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Missing e = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid\2.14.3_0\
CHR - Extension: YouTube = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Webpage & WebCam Screenshot = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki\9.2_0\
CHR - Extension: Google Search = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0\
CHR - Extension: Skyrim: Book of the Dragonborn Theme = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioigkhgefneinlgdahhpddckbpofpnfi\0.2.0.23_0\
CHR - Extension: Norton Identity Protection = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0\
CHR - Extension: iSideWith = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\nekniaobhkcioppbllliijfaillbaiik\1.5_0\
CHR - Extension: Website Logon = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelloajafbopojkjmieelljfkcmdpdhf\6.0_0\
CHR - Extension: Gmail = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/08/05 21:52:17 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (TrueSuite Browser Helper Object) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.dll (AuthenTec Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (TrueSuite Browser Helper Object) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [CECAPLF] C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [KeepSafe] C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (Authentec)
O4:64bit: - HKLM..\Run: [MBCfg64] C:\Windows\SysNative\MBCfg64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Sound Blaster Cinema] C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe (Dxtory Software)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\domportera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk = C:\Program Files (x86)\Dxtory Software\Dxtory2.0\Dxtory.exe (Dxtory Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Classes = C:\Users\domportera\AppData\Roaming\bauwefiv\ggeecugd.exe
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…30321/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19CD3E11-5A83-42C5-9C55-86F17F471CF0}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll C:\Windows\system32\nvinitx.dll) - C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll) - C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.xtor - DxtoryCodec.dll (Dxtory Software)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.xtor - C:\Windows\SysWow64\DxtoryCodec.dll (Dxtory Software)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/05 21:51:50 | 000,000,000 | —D | C] – C:\_OTL
[2013/08/05 20:41:29 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\domportera\Desktop\aswMBR.exe
[2013/08/05 19:46:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA
[2013/08/05 19:46:26 | 002,210,376 | —- | C] (VIA Technologies, Inc.) – C:\Windows\SysNative\drivers\viahduaa.sys
[2013/08/05 19:46:26 | 001,119,352 | —- | C] (VIA Technologies, Inc.) – C:\Windows\SysNative\ViaMicArrayAPO.dll
[2013/08/05 19:46:26 | 001,092,096 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\VMAPO264.DLL
[2013/08/05 19:46:26 | 000,908,288 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\VMAPO232.DLL
[2013/08/05 18:48:01 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\The Collector (working title)
[2013/08/05 18:46:45 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\GameMaker
[2013/08/05 18:45:55 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Subversion
[2013/08/05 18:43:37 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\gamemaker_studio
[2013/08/05 18:43:35 | 000,000,000 | —D | C] – C:\ProgramData\gamemaker_studio
[2013/08/05 18:43:32 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\GameMaker_Player
[2013/08/05 18:04:31 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\ElevatedDiagnostics
[2013/08/05 18:03:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\domportera\Desktop\OTL.exe
[2013/08/05 13:49:52 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2013/08/05 12:40:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2013/08/05 12:36:44 | 000,433,752 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnets.sys
[2013/08/05 12:36:43 | 001,139,800 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.sys
[2013/08/05 12:36:43 | 000,796,760 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.sys
[2013/08/05 12:36:43 | 000,493,656 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.sys
[2013/08/05 12:36:43 | 000,224,416 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ironx64.sys
[2013/08/05 12:36:43 | 000,169,048 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.sys
[2013/08/05 12:36:43 | 000,036,952 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.sys
[2013/08/05 12:36:43 | 000,023,448 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symelam.sys
[2013/08/05 12:35:44 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\1404000.028
[2013/08/05 12:24:21 | 000,177,312 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/08/05 12:24:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2013/08/05 12:24:21 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2013/08/05 12:21:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64
[2013/08/05 12:21:18 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2013/08/05 12:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360
[2013/08/05 12:21:17 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2013/08/05 12:20:03 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2013/08/05 12:20:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2013/08/05 12:15:00 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apple Computer
[2013/08/05 11:05:09 | 000,039,504 | —- | C] (ThreatTrack Security) – C:\Windows\SysNative\drivers\gfiark.sys
[2013/08/05 03:13:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\LavasoftStatistics
[2013/08/05 03:02:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/08/05 03:01:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/08/05 03:01:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/08/05 03:00:36 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2013/08/05 02:52:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2013/08/05 02:52:33 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2013/08/05 02:52:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2013/08/05 02:52:21 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\adawarebp
[2013/08/05 02:52:21 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2013/08/05 02:52:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2013/08/05 02:52:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2013/08/05 02:50:48 | 000,047,496 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2013/08/05 02:50:48 | 000,014,456 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/08/05 02:50:47 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Ad-Aware Antivirus
[2013/08/05 02:38:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/08/05 02:38:17 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/08/05 01:58:57 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\WinRAR
[2013/08/05 01:58:45 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/05 01:58:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/05 01:58:40 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2013/08/05 01:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Caphyon
[2013/08/04 19:49:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PANDORATV
[2013/08/04 19:49:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\PANDORA.TV
[2013/08/04 19:49:46 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2013/08/04 19:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\The KMPlayer
[2013/08/03 11:59:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
[2013/08/03 11:59:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Exact Audio Copy
[2013/08/03 11:18:04 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\EAC
[2013/08/03 11:17:58 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\AccurateRip
[2013/08/03 04:13:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
[2013/08/03 04:13:09 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Last.fm
[2013/08/03 04:13:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Last.fm
[2013/08/03 02:20:59 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Dxtory Software
[2013/08/03 02:20:58 | 008,043,008 | —- | C] (Dxtory Software) – C:\Windows\SysNative\DxtoryCodec.dll
[2013/08/03 02:20:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
[2013/08/03 02:20:57 | 008,300,544 | —- | C] (Dxtory Software) – C:\Windows\SysWow64\DxtoryCodec.dll
[2013/08/03 02:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dxtory Software
[2013/08/03 02:19:17 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\Wizards of the Coast
[2013/08/03 02:03:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft XNA
[2013/08/03 02:01:54 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\My Games
[2013/08/03 00:14:42 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/08/02 21:00:03 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Capsule Utilities
[2013/08/02 21:00:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Capsule
[2013/08/02 12:43:22 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\AuthenTec
[2013/08/02 10:52:28 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Malwarebytes
[2013/08/02 10:52:07 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/08/02 05:25:19 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Adobe
[2013/08/02 05:15:52 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/08/02 05:06:28 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2013/08/02 05:06:28 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2013/08/02 04:42:27 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/08/02 04:42:27 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/08/02 04:42:27 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/08/02 04:42:27 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/08/02 04:42:27 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2013/08/02 04:42:27 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2013/08/02 04:42:27 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/08/02 04:42:27 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/08/02 04:42:26 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2013/08/02 04:42:26 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2013/08/02 04:42:26 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2013/08/02 04:42:26 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2013/08/02 04:42:26 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/08/02 04:42:26 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/08/02 04:42:25 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2013/08/02 04:42:25 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2013/08/02 04:42:25 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_6.dll
[2013/08/02 04:42:25 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_6.dll
[2013/08/02 04:42:25 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_6.dll
[2013/08/02 04:42:25 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_6.dll
[2013/08/02 04:42:25 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_4.dll
[2013/08/02 04:42:25 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_4.dll
[2013/08/02 04:41:29 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_7.dll
[2013/08/02 04:41:29 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_7.dll
[2013/08/02 04:41:23 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_5.dll
[2013/08/02 04:41:22 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_5.dll
[2013/08/02 04:41:22 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_5.dll
[2013/08/02 04:41:21 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_42.dll
[2013/08/02 04:41:21 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2013/08/02 04:41:21 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_42.dll
[2013/08/02 04:41:21 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/08/02 04:41:20 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2013/08/02 04:41:20 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/08/02 04:41:18 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2013/08/02 04:41:18 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2013/08/02 04:41:17 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2013/08/02 04:41:17 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2013/08/02 04:41:16 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2013/08/02 04:41:16 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2013/08/02 04:41:16 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2013/08/02 04:41:16 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2013/08/02 04:41:16 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2013/08/02 04:41:15 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2013/08/02 04:41:15 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2013/08/02 04:41:15 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2013/08/02 04:41:15 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2013/08/02 04:41:14 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2013/08/02 04:41:14 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/08/02 04:41:14 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2013/08/02 04:41:14 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2013/08/02 04:41:14 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2013/08/02 04:41:14 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2013/08/02 04:41:14 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2013/08/02 04:41:14 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2013/08/02 04:41:14 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2013/08/02 04:41:14 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2013/08/02 04:41:14 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2013/08/02 04:41:14 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2013/08/02 04:41:14 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2013/08/02 04:41:14 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2013/08/02 04:41:13 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2013/08/02 04:41:13 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2013/08/02 04:41:13 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2013/08/02 04:41:13 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2013/08/02 04:41:13 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2013/08/02 04:41:13 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2013/08/02 04:41:13 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2013/08/02 04:41:13 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2013/08/02 04:41:13 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2013/08/02 04:41:13 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2013/08/02 04:41:12 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2013/08/02 04:41:12 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2013/08/02 04:41:12 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2013/08/02 04:41:12 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2013/08/02 04:41:12 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2013/08/02 04:41:12 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2013/08/02 04:41:11 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2013/08/02 04:41:11 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2013/08/02 04:41:11 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2013/08/02 04:41:11 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2013/08/02 04:41:10 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2013/08/02 04:41:10 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2013/08/02 04:41:10 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2013/08/02 04:41:10 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2013/08/02 04:41:10 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2013/08/02 04:41:10 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2013/08/02 04:41:09 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2013/08/02 04:41:09 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2013/08/02 04:41:09 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2013/08/02 04:41:09 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2013/08/02 04:41:09 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2013/08/02 04:41:09 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2013/08/02 04:41:02 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2013/08/02 04:41:02 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2013/08/02 04:41:02 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2013/08/02 04:41:02 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2013/08/02 04:41:01 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2013/08/02 04:41:01 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2013/08/02 04:40:59 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2013/08/02 04:40:59 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2013/08/02 04:40:59 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2013/08/02 04:40:59 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2013/08/02 04:40:59 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2013/08/02 04:40:59 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2013/08/02 04:40:58 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2013/08/02 04:40:58 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2013/08/02 04:40:58 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2013/08/02 04:40:58 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2013/08/02 04:40:57 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/08/02 04:40:57 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2013/08/02 04:40:57 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2013/08/02 04:40:57 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2013/08/02 04:40:57 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2013/08/02 04:40:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2013/08/02 04:40:56 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2013/08/02 04:40:56 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2013/08/02 04:40:56 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2013/08/02 04:40:56 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2013/08/02 04:40:43 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2013/08/02 04:40:43 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2013/08/02 04:40:43 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2013/08/02 04:40:43 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2013/08/02 04:40:40 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2013/08/02 04:40:40 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2013/08/02 04:40:40 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2013/08/02 04:40:40 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2013/08/02 04:40:38 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2013/08/02 04:40:38 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2013/08/02 04:40:35 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2013/08/02 04:40:35 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2013/08/02 04:40:34 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2013/08/02 04:40:34 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2013/08/02 04:40:31 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2013/08/02 04:40:31 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2013/08/02 04:40:29 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2013/08/02 04:40:29 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2013/08/02 04:40:27 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2013/08/02 04:40:27 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2013/08/02 04:40:25 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2013/08/02 04:40:25 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2013/08/02 04:40:16 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2013/08/02 04:40:16 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2013/08/02 04:40:16 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2013/08/02 04:40:16 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2013/08/02 04:40:14 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2013/08/02 04:40:14 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2013/08/02 04:40:14 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2013/08/02 04:40:14 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2013/08/02 04:40:14 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2013/08/02 04:40:14 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2013/08/02 04:40:13 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2013/08/02 04:40:13 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2013/08/02 04:40:13 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2013/08/02 04:40:13 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2013/08/02 04:40:13 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2013/08/02 04:40:13 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2013/08/02 04:40:12 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/08/02 04:40:12 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/08/02 04:40:10 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2013/08/02 04:40:10 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2013/08/02 04:40:10 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2013/08/02 04:40:10 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2013/08/02 04:40:10 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2013/08/02 04:40:10 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2013/08/02 04:40:10 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2013/08/02 04:40:10 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2013/08/02 04:40:10 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2013/08/02 04:40:10 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2013/08/02 04:40:10 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2013/08/02 04:40:10 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2013/08/02 04:40:09 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2013/08/02 04:40:09 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2013/08/02 04:40:09 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2013/08/02 04:40:09 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2013/08/02 04:31:39 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/08/02 04:05:32 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/02 04:05:32 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/02 04:05:32 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/02 04:05:32 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/08/02 04:05:32 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/08/02 04:05:32 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/08/02 04:05:32 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/02 04:05:32 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/08/02 04:05:32 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/02 04:05:32 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/08/02 04:05:32 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/02 04:05:32 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/02 04:05:32 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/02 04:05:32 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/08/02 04:05:32 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/08/02 04:05:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/02 04:05:32 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/08/02 04:05:32 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/08/02 04:05:32 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/02 04:05:32 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/02 04:05:32 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/08/02 04:05:32 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/08/02 04:05:32 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/08/02 04:05:32 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/08/02 04:05:32 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/02 04:05:32 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/08/02 04:05:32 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/08/02 04:05:32 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/08/02 04:05:32 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/08/02 04:05:32 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/08/02 04:05:32 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/08/02 04:05:32 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/02 04:05:32 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/08/02 04:05:32 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/08/02 04:05:32 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/08/02 04:05:32 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/08/02 04:05:32 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/08/02 04:05:32 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/08/02 04:05:32 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/02 04:05:32 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/08/02 04:05:32 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/08/02 04:05:32 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/02 04:05:32 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/08/02 04:05:32 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/08/02 04:05:32 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/08/02 04:05:32 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/08/02 04:05:32 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/08/02 04:05:32 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/08/02 04:05:32 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/08/02 04:05:32 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/08/02 04:05:32 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/08/02 04:05:32 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/08/02 04:05:32 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/08/02 04:05:32 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/08/02 04:05:32 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/08/02 04:05:32 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/08/02 04:05:32 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/08/02 04:05:32 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/08/02 04:00:34 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/08/02 04:00:34 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/08/02 04:00:34 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/08/02 04:00:34 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/08/02 04:00:34 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/08/02 04:00:34 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/08/02 04:00:34 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/08/02 04:00:34 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/08/02 04:00:34 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/08/02 04:00:34 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/08/02 04:00:34 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/08/02 04:00:34 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/08/02 04:00:34 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/08/02 04:00:34 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/08/02 04:00:34 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 03:36:33 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/08/02 03:36:33 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/08/02 03:36:33 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/08/02 03:36:32 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/08/02 03:35:10 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2013/08/02 03:35:10 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2013/08/02 03:35:10 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2013/08/02 03:35:10 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2013/08/02 03:10:47 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2013/08/02 03:10:46 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2013/08/01 12:02:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Sleep
[2013/08/01 12:02:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Sleep
[2013/08/01 11:37:40 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\vlc
[2013/08/01 11:29:35 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/08/01 11:29:34 | 002,079,816 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2013/08/01 10:04:06 | 000,000,000 | —D | C] – C:\NvidiaLogging
[2013/08/01 10:03:30 | 000,039,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvvad64v.sys
[2013/08/01 10:03:30 | 000,029,984 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvaudcap64v.dll
[2013/08/01 10:03:30 | 000,028,448 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvaudcap32v.dll
[2013/08/01 10:03:14 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\NVIDIA
[2013/08/01 09:41:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\AGEIA Technologies
[2013/08/01 09:40:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2013/08/01 09:40:30 | 000,000,000 | —D | C] – C:\Windows\SysWow64\NV
[2013/08/01 09:40:30 | 000,000,000 | —D | C] – C:\Windows\SysNative\NV
[2013/08/01 09:39:14 | 000,000,000 | —D | C] – C:\Users\domportera\Desktop\Game Design
[2013/08/01 09:38:04 | 000,000,000 | —D | C] – C:\Users\domportera\Desktop\Diversions Music
[2013/08/01 09:37:56 | 027,781,920 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2013/08/01 09:37:56 | 021,102,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2013/08/01 09:37:56 | 015,920,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2013/08/01 09:37:56 | 015,144,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2013/08/01 09:37:56 | 013,411,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2013/08/01 09:37:56 | 009,239,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2013/08/01 09:37:56 | 007,687,592 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2013/08/01 09:37:56 | 007,641,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2013/08/01 09:37:56 | 006,324,360 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2013/08/01 09:37:56 | 002,953,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2013/08/01 09:37:56 | 002,777,888 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2013/08/01 09:37:56 | 002,363,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2013/08/01 09:37:56 | 002,002,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2013/08/01 09:37:56 | 001,832,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco6432049.dll
[2013/08/01 09:37:56 | 001,511,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco6432049.dll
[2013/08/01 09:37:56 | 000,572,704 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvFBC64.dll
[2013/08/01 09:37:56 | 000,570,656 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvIFR64.dll
[2013/08/01 09:37:56 | 000,467,232 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NvIFR.dll
[2013/08/01 09:37:56 | 000,465,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NvFBC.dll
[2013/08/01 09:37:56 | 000,432,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvEncodeAPI64.dll
[2013/08/01 09:37:56 | 000,372,000 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvEncodeAPI.dll
[2013/08/01 09:37:56 | 000,218,592 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglshim64.dll
[2013/08/01 09:37:56 | 000,181,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglshim32.dll
[2013/08/01 09:37:56 | 000,030,496 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvpciflt.sys
[2013/08/01 09:37:55 | 025,256,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2013/08/01 09:37:55 | 017,560,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2013/08/01 09:37:55 | 002,597,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2013/08/01 09:31:17 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Tomahawk
[2013/08/01 09:31:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tomahawk
[2013/08/01 09:31:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tomahawk
[2013/08/01 09:22:17 | 000,000,000 | —D | C] – C:\NVIDIA
[2013/08/01 09:15:44 | 000,000,000 | —D | C] – C:\Windows\Sun
[2013/08/01 09:14:56 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/08/01 09:14:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/08/01 09:14:41 | 000,867,240 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/08/01 09:14:41 | 000,789,416 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/08/01 09:14:41 | 000,263,592 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/08/01 09:14:37 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/08/01 09:14:37 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/08/01 09:14:37 | 000,096,168 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/08/01 09:14:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/08/01 09:14:16 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/08/01 05:46:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2013/08/01 05:46:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2013/08/01 05:46:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/08/01 05:46:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/08/01 05:46:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/08/01 05:46:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/08/01 05:46:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/08/01 05:46:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/08/01 05:46:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/08/01 05:46:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/08/01 05:46:01 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/08/01 05:46:01 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/08/01 05:46:01 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/08/01 05:46:01 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/08/01 05:46:01 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/08/01 05:46:01 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/08/01 05:46:01 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/08/01 05:46:01 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/08/01 05:46:01 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/08/01 05:46:01 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/08/01 05:46:01 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/08/01 05:46:01 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/08/01 05:46:01 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/08/01 05:46:01 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/08/01 05:46:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/08/01 05:46:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/08/01 05:46:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/08/01 05:46:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/08/01 05:41:40 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2013/08/01 05:41:40 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2013/08/01 05:12:35 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2013/08/01 05:12:30 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/08/01 05:12:30 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/08/01 05:12:28 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2013/08/01 05:12:28 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2013/08/01 05:12:28 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2013/08/01 05:12:28 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2013/08/01 05:12:28 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2013/08/01 05:12:27 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2013/08/01 05:12:27 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2013/08/01 05:12:27 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2013/08/01 05:12:26 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2013/08/01 05:12:09 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2013/08/01 05:12:09 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2013/08/01 05:12:08 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2013/08/01 05:12:08 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2013/08/01 05:12:08 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2013/08/01 05:12:02 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/08/01 05:12:02 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/08/01 05:12:01 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/08/01 05:12:01 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/08/01 05:12:01 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/08/01 05:12:01 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/08/01 05:11:49 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/08/01 05:07:25 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2013/08/01 05:07:25 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2013/08/01 05:07:25 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/08/01 05:07:25 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/08/01 05:07:10 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2013/08/01 05:06:05 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/08/01 05:06:05 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/08/01 05:06:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/08/01 05:06:05 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/08/01 04:57:44 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/08/01 04:51:11 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2013/08/01 04:51:11 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2013/08/01 04:37:54 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2013/08/01 04:36:56 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/08/01 04:36:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2013/08/01 04:36:48 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2013/08/01 04:36:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2013/08/01 04:36:37 | 001,447,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/08/01 04:36:36 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspicli.dll
[2013/08/01 04:36:36 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspisrv.dll
[2013/08/01 04:36:36 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2013/08/01 04:36:35 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2013/08/01 04:36:35 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2013/08/01 04:36:35 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2013/08/01 04:36:35 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2013/08/01 04:36:35 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2013/08/01 04:36:34 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2013/08/01 04:36:34 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2013/08/01 04:36:10 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2013/08/01 04:36:09 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2013/08/01 04:36:07 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/08/01 04:36:07 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/08/01 04:36:05 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/08/01 04:36:00 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/01 04:35:55 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/01 04:35:55 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/01 04:35:51 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/08/01 04:35:51 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/01 04:35:51 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/01 04:35:51 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/01 04:35:51 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/01 04:35:51 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/01 04:34:33 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2013/08/01 04:28:24 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/08/01 04:28:08 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2013/08/01 04:28:08 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2013/08/01 04:28:08 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2013/08/01 04:28:08 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2013/08/01 04:27:24 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2013/08/01 04:27:20 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/08/01 04:27:20 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/08/01 04:27:20 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/08/01 04:27:20 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/08/01 04:27:18 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/01 04:27:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/08/01 04:27:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/08/01 04:27:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/08/01 04:27:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/08/01 04:27:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/08/01 04:27:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/08/01 04:20:43 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2013/08/01 04:20:43 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2013/08/01 04:20:39 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/08/01 04:20:39 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/08/01 04:19:51 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/08/01 04:16:55 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/08/01 04:16:55 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/08/01 04:12:22 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netapi32.dll
[2013/08/01 04:12:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browcli.dll
[2013/08/01 04:12:22 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\browcli.dll
[2013/08/01 04:12:18 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\srcore.dll
[2013/08/01 04:12:15 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2013/08/01 04:12:12 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/01 04:12:12 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/08/01 04:12:12 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/08/01 04:12:12 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/08/01 04:12:12 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/08/01 04:12:12 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/08/01 04:12:01 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2013/08/01 04:11:45 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2013/08/01 04:11:45 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2013/08/01 04:11:39 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2013/08/01 04:11:39 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2013/08/01 04:11:30 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/01 04:11:30 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/01 04:11:30 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/01 04:11:30 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/08/01 04:11:30 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/08/01 04:11:29 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/08/01 04:10:59 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2013/08/01 04:10:59 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2013/08/01 04:09:10 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/08/01 04:09:10 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/08/01 04:07:36 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/01 04:07:33 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\splwow64.exe
[2013/08/01 03:16:15 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2013/08/01 03:16:15 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2013/08/01 03:07:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2013/08/01 02:56:56 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Apple Computer
[2013/08/01 02:41:52 | 000,000,000 | —D | C] – C:\af24f2736e42f1c2053ea0b65e481b6e
[2013/08/01 02:41:06 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Programs
[2013/08/01 02:31:31 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2013/08/01 02:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/08/01 02:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/08/01 02:29:46 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Mozilla
[2013/08/01 01:21:10 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/08/01 01:21:10 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/01 01:19:48 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apple
[2013/08/01 01:19:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/08/01 01:18:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/08/01 01:18:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/08/01 01:18:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/08/01 01:18:21 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/08/01 01:18:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/08/01 00:51:32 | 000,000,000 | R–D | C] – C:\Users\domportera\Dropbox
[2013/08/01 00:49:39 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013/08/01 00:45:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\dumps
[2013/08/01 00:45:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2013/08/01 00:45:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/08/01 00:45:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2013/08/01 00:42:20 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Dropbox
[2013/08/01 00:42:15 | 000,000,000 | R–D | C] – C:\Users\domportera\Google Drive
[2013/08/01 00:41:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/08/01 00:38:18 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Creative
[2013/08/01 00:32:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/08/01 00:32:20 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Google
[2013/08/01 00:32:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/08/01 00:32:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Deployment
[2013/08/01 00:32:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apps
[2013/08/01 00:30:10 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2013/08/01 00:30:10 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2013/08/01 00:26:43 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\KeepSafe
[2013/08/01 00:26:27 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/08/01 00:26:27 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/08/01 00:26:27 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2013/08/01 00:26:15 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/08/01 00:26:15 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/08/01 00:26:15 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\Searches
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/08/01 00:26:14 | 000,000,000 | -H-D | C] – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/08/01 00:25:48 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/08/01 00:25:48 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/08/01 00:25:38 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Identities
[2013/08/01 00:25:35 | 000,000,000 | R–D | C] – C:\Users\domportera\Contacts
[2013/08/01 00:25:26 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Intel
[2013/08/01 00:25:24 | 000,000,000 | –SD | C] – C:\Users\domportera\AppData\Roaming\Microsoft
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Videos
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Saved Games
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Pictures
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Music
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Links
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Favorites
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Downloads
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Documents
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Desktop
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\Temporary Internet Files
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Templates
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Start Menu
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\SendTo
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Recent
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\PrintHood
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\NetHood
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Videos
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Pictures
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Music
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\My Documents
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Local Settings
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\History
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Cookies
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Application Data
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\Application Data
[2013/08/01 00:25:24 | 000,000,000 | -H-D | C] – C:\Users\domportera\AppData
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Temp
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\Roaming
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Microsoft
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Media Center Programs
[2013/08/01 00:25:10 | 000,000,000 | -HSD | C] – C:\Recovery
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\upeksce
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AuthenTec TrueSuite
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AuthenTec
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AuthenTec
[2013/07/25 14:42:15 | 000,000,000 | —D | C] – C:\Program Files\AuthenTec TrueSuite
[2013/07/25 14:42:12 | 000,000,000 | —D | C] – C:\ProgramData\Downloaded Installations
[2013/07/25 14:42:04 | 000,000,000 | —D | C] – C:\Program Files\AuthenTec
[2013/07/25 14:41:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\FingerPrinter
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/05 22:03:41 | 000,021,888 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/05 22:03:41 | 000,021,888 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/05 22:00:52 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/05 22:00:52 | 000,660,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/05 22:00:52 | 000,121,214 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/05 21:55:53 | 000,001,875 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013/08/05 21:54:32 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/05 21:54:09 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/05 21:53:53 | 2060,148,735 | -HS- | M] () – C:\hiberfil.sys
[2013/08/05 21:52:17 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2013/08/05 21:39:58 | 000,001,188 | —- | M] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/08/05 21:37:01 | 000,000,906 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/05 21:26:10 | 000,000,512 | —- | M] () – C:\Users\domportera\Desktop\MBR.dat
[2013/08/05 21:11:44 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\domportera\Desktop\aswMBR.exe
[2013/08/05 20:42:09 | 000,666,633 | —- | M] () – C:\Users\domportera\Desktop\AdwCleaner.exe
[2013/08/05 20:41:23 | 000,891,098 | —- | M] () – C:\Users\domportera\Desktop\SecurityCheck.exe
[2013/08/05 19:50:58 | 000,002,326 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/08/05 19:50:19 | 001,688,391 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\Cat.DB
[2013/08/05 19:46:37 | 000,001,213 | —- | M] () – C:\Users\Public\Desktop\HD VDeck.lnk
[2013/08/05 18:03:55 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\domportera\Desktop\OTL.exe
[2013/08/05 12:37:45 | 000,007,631 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/08/05 12:37:44 | 000,177,312 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/08/05 12:37:44 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/08/05 03:10:00 | 000,773,050 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/08/05 02:50:48 | 000,014,456 | —- | M] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/08/05 02:42:03 | 000,001,193 | —- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk
[2013/08/05 02:38:17 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/04 19:51:26 | 000,000,974 | —- | M] () – C:\Users\domportera\Desktop\KMPlayer.lnk
[2013/08/03 11:59:41 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\Exact Audio Copy.lnk
[2013/08/03 04:13:10 | 000,000,992 | —- | M] () – C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013/08/03 02:20:58 | 000,001,193 | —- | M] () – C:\Users\domportera\Desktop\Dxtory.lnk
[2013/08/02 21:00:03 | 000,001,092 | —- | M] () – C:\Users\domportera\Desktop\Capsule.lnk
[2013/08/02 05:10:01 | 000,275,712 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/08/02 04:05:32 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/02 04:05:32 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/02 04:05:32 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/02 04:05:32 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/08/02 04:05:32 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/08/02 04:05:32 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/08/02 04:05:32 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/02 04:05:32 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/08/02 04:05:32 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/02 04:05:32 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/08/02 04:05:32 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/02 04:05:32 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/02 04:05:32 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/02 04:05:32 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/08/02 04:05:32 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/08/02 04:05:32 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/02 04:05:32 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/08/02 04:05:32 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/08/02 04:05:32 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/02 04:05:32 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/02 04:05:32 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/08/02 04:05:32 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/08/02 04:05:32 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/08/02 04:05:32 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/08/02 04:05:32 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/02 04:05:32 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/08/02 04:05:32 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/08/02 04:05:32 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/08/02 04:05:32 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/08/02 04:05:32 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/08/02 04:05:32 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/08/02 04:05:32 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/02 04:05:32 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/08/02 04:05:32 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/08/02 04:05:32 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/08/02 04:05:32 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/08/02 04:05:32 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/08/02 04:05:32 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/08/02 04:05:32 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/02 04:05:32 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/08/02 04:05:32 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/08/02 04:05:32 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/02 04:05:32 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/08/02 04:05:32 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/08/02 04:05:32 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/08/02 04:05:32 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/08/02 04:05:32 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/08/02 04:05:32 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/08/02 04:05:32 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/08/02 04:05:32 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/08/02 04:05:32 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/08/02 04:05:32 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/08/02 04:05:32 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/08/02 04:05:32 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/08/02 04:05:32 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/08/02 04:05:32 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/08/02 04:05:32 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/08/02 04:05:32 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/08/02 04:05:32 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/08/02 04:05:32 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/08/02 04:00:34 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/08/02 04:00:34 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/08/02 04:00:34 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/08/02 04:00:34 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/08/02 04:00:34 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/08/02 04:00:34 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/08/02 04:00:34 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/08/02 04:00:34 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/08/02 04:00:34 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/08/02 04:00:34 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/08/02 04:00:34 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/08/02 04:00:34 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/08/02 04:00:34 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/08/02 04:00:34 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/08/02 04:00:34 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/01 12:22:01 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2013/08/01 12:22:01 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2013/08/01 09:31:07 | 000,001,018 | —- | M] () – C:\Users\domportera\Desktop\Tomahawk.lnk
[2013/08/01 09:14:31 | 000,867,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/08/01 09:14:31 | 000,789,416 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/08/01 09:14:31 | 000,263,592 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/08/01 09:14:31 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/08/01 09:14:31 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/08/01 09:14:31 | 000,096,168 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/08/01 00:51:32 | 000,001,057 | —- | M] () – C:\Users\domportera\Desktop\Dropbox.lnk
[2013/08/01 00:50:21 | 000,001,067 | —- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/01 00:45:24 | 000,000,924 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2013/08/01 00:42:17 | 000,002,290 | —- | M] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/01 00:42:16 | 000,001,717 | —- | M] () – C:\Users\domportera\Desktop\Google Drive.lnk
[2013/08/01 00:41:03 | 000,002,051 | —- | M] () – C:\Users\Public\Desktop\Google Slides.lnk
[2013/08/01 00:41:03 | 000,002,047 | —- | M] () – C:\Users\Public\Desktop\Google Sheets.lnk
[2013/08/01 00:41:03 | 000,002,035 | —- | M] () – C:\Users\Public\Desktop\Google Docs.lnk
[2013/08/01 00:32:51 | 000,002,266 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/01 00:31:33 | 000,001,448 | —- | M] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/07/25 14:42:09 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_tcwbf_01_09_00.Wdf
[2013/07/25 14:42:09 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/05 21:39:58 | 000,001,188 | —- | C] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/08/05 21:26:10 | 000,000,512 | —- | C] () – C:\Users\domportera\Desktop\MBR.dat
[2013/08/05 20:42:07 | 000,666,633 | —- | C] () – C:\Users\domportera\Desktop\AdwCleaner.exe
[2013/08/05 20:41:21 | 000,891,098 | —- | C] () – C:\Users\domportera\Desktop\SecurityCheck.exe
[2013/08/05 19:49:54 | 001,688,391 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\Cat.DB
[2013/08/05 12:40:04 | 000,014,818 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\VT20130115.021
[2013/08/05 12:36:44 | 000,009,670 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symelam64.cat
[2013/08/05 12:36:44 | 000,008,067 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnet64.cat
[2013/08/05 12:36:44 | 000,001,440 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnet.inf
[2013/08/05 12:36:43 | 000,007,667 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.cat
[2013/08/05 12:36:43 | 000,007,593 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\iron.cat
[2013/08/05 12:36:43 | 000,007,589 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.cat
[2013/08/05 12:36:43 | 000,007,587 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.cat
[2013/08/05 12:36:43 | 000,003,434 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa.inf
[2013/08/05 12:36:43 | 000,002,852 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds.inf
[2013/08/05 12:36:43 | 000,001,437 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.inf
[2013/08/05 12:36:43 | 000,001,420 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.inf
[2013/08/05 12:36:43 | 000,000,996 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symelam.inf
[2013/08/05 12:36:43 | 000,000,853 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.inf
[2013/08/05 12:36:43 | 000,000,767 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\iron.inf
[2013/08/05 12:35:44 | 000,008,067 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.cat
[2013/08/05 12:35:44 | 000,008,063 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.cat
[2013/08/05 12:35:44 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\1404000.028\isolate.ini
[2013/08/05 12:24:21 | 000,007,631 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/08/05 12:24:21 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/08/05 12:24:01 | 000,002,326 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2013/08/05 02:52:38 | 000,001,875 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013/08/05 02:42:03 | 000,001,193 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk
[2013/08/05 02:38:17 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/05 01:46:41 | 000,007,062 | —- | C] () – C:\Windows\SysWow64\audiopid.vxd
[2013/08/04 19:49:47 | 000,000,974 | —- | C] () – C:\Users\domportera\Desktop\KMPlayer.lnk
[2013/08/03 11:59:41 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\Exact Audio Copy.lnk
[2013/08/03 04:13:10 | 000,000,992 | —- | C] () – C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013/08/03 02:20:58 | 000,001,193 | —- | C] () – C:\Users\domportera\Desktop\Dxtory.lnk
[2013/08/02 21:00:03 | 000,001,200 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Capsule.lnk
[2013/08/02 21:00:03 | 000,001,092 | —- | C] () – C:\Users\domportera\Desktop\Capsule.lnk
[2013/08/02 04:05:32 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/08/02 04:05:32 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/08/02 03:35:10 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/08/01 09:31:07 | 000,001,018 | —- | C] () – C:\Users\domportera\Desktop\Tomahawk.lnk
[2013/08/01 03:15:03 | 000,773,050 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/08/01 01:19:47 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/08/01 00:51:32 | 000,001,057 | —- | C] () – C:\Users\domportera\Desktop\Dropbox.lnk
[2013/08/01 00:50:21 | 000,001,067 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/01 00:45:24 | 000,000,924 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2013/08/01 00:42:16 | 000,001,717 | —- | C] () – C:\Users\domportera\Desktop\Google Drive.lnk
[2013/08/01 00:41:03 | 000,002,051 | —- | C] () – C:\Users\Public\Desktop\Google Slides.lnk
[2013/08/01 00:41:03 | 000,002,047 | —- | C] () – C:\Users\Public\Desktop\Google Sheets.lnk
[2013/08/01 00:41:03 | 000,002,035 | —- | C] () – C:\Users\Public\Desktop\Google Docs.lnk
[2013/08/01 00:32:51 | 000,002,290 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/01 00:32:51 | 000,002,266 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/01 00:32:24 | 000,000,906 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/01 00:32:23 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/01 00:31:33 | 000,001,448 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/08/01 00:26:17 | 000,001,424 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/08/01 00:25:24 | 000,000,290 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/08/01 00:25:24 | 000,000,272 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/07/25 14:42:09 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_tcwbf_01_09_00.Wdf
[2013/07/25 14:42:09 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/06/20 19:16:35 | 000,008,570 | —- | C] () – C:\Windows\SysWow64\MBCfg32.ini
[2013/06/20 19:16:35 | 000,005,856 | —- | C] () – C:\Windows\SysWow64\MBCfgUninstall32.ini
[2013/06/20 19:16:35 | 000,002,835 | —- | C] () – C:\Windows\MBCfg_SP_APOIM.ini
[2013/06/20 19:16:35 | 000,002,783 | —- | C] () – C:\Windows\MBCfg_APOIM.ini
[2013/06/20 19:16:35 | 000,002,747 | —- | C] () – C:\Windows\MBCfg_HP_APOIM.ini
[2013/06/20 19:16:33 | 000,246,272 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2013/06/20 19:16:33 | 000,074,240 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2013/06/20 18:25:53 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2013/06/20 18:25:52 | 019,586,560 | —- | C] () – C:\Windows\SysWow64\igdfcl32.dll
[2013/06/20 18:25:52 | 000,103,936 | —- | C] () – C:\Windows\SysWow64\igdail32.dll
[2013/05/13 18:48:06 | 002,567,680 | —- | C] () – C:\Windows\SysWow64\DeviceControl.exe
[2012/12/10 17:12:50 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 03:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/05 21:58:06 | 000,147,438 | —- | M] () MD5=E4BC4A4DC23105FFF4124DCC56C5EE2A – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2013/08/02 04:05:32 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/08/02 04:05:32 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_184d84e8cdd3303c\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011/11/22 12:49:55 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2013/08/02 04:05:32 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/02 04:05:32 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/05/29 02:24:18 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=AFF2C99AD2C599108B6BD9E77C24B463 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_0d0dec99809dccc9\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/05/29 01:56:53 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=C9C29508A433DAF0118D28C4F38CDDFC – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_0df8da9699726e41\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_176296ebb4fe8ec4\iexplore.exe
[2011/11/22 12:49:55 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011/11/22 12:49:55 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/11/22 12:49:55 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/08/02 04:05:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 03:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/08/05 21:42:48 | 000,002,196 | —- | M] () – C:\AdwCleaner[S1].txt
[2013/08/05 21:53:53 | 2060,148,735 | -HS- | M] () – C:\hiberfil.sys
[2013/08/05 21:54:02 | 4178,522,111 | -HS- | M] () – C:\pagefile.sys
[2013/06/20 19:01:27 | 000,000,087 | —- | M] () – C:\setup.log

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 19:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Windows
Volume Serial Number is 6644-2D63
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\domportera
08/01/2013 12:25 AM Application Data [C:\Users\domportera\AppData\Roaming]
08/01/2013 12:25 AM Cookies [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Cookies]
08/01/2013 12:25 AM Local Settings [C:\Users\domportera\AppData\Local]
08/01/2013 12:25 AM My Documents [C:\Users\domportera\Documents]
08/01/2013 12:25 AM NetHood [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/01/2013 12:25 AM PrintHood [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/01/2013 12:25 AM Recent [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Recent]
08/01/2013 12:25 AM SendTo [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\SendTo]
08/01/2013 12:25 AM Start Menu [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu]
08/01/2013 12:25 AM Templates [C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\domportera\AppData\Local
08/01/2013 12:25 AM Application Data [C:\Users\domportera\AppData\Local]
08/01/2013 12:25 AM History [C:\Users\domportera\AppData\Local\Microsoft\Windows\History]
08/01/2013 12:25 AM Temporary Internet Files [C:\Users\domportera\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\domportera\Documents
08/01/2013 12:25 AM My Music [C:\Users\domportera\Music]
08/01/2013 12:25 AM My Pictures [C:\Users\domportera\Pictures]
08/01/2013 12:25 AM My Videos [C:\Users\domportera\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser
06/20/2013 06:29 PM Application Data [C:\Users\UpdatusUser\AppData\Roaming]
06/20/2013 06:29 PM Cookies [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies]
06/20/2013 06:29 PM Local Settings [C:\Users\UpdatusUser\AppData\Local]
06/20/2013 06:29 PM My Documents [C:\Users\UpdatusUser\Documents]
06/20/2013 06:29 PM NetHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/20/2013 06:29 PM PrintHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/20/2013 06:29 PM Recent [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent]
06/20/2013 06:29 PM SendTo [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo]
06/20/2013 06:29 PM Start Menu [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu]
06/20/2013 06:29 PM Templates [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\AppData\Local
06/20/2013 06:29 PM Application Data [C:\Users\UpdatusUser\AppData\Local]
06/20/2013 06:29 PM History [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History]
06/20/2013 06:29 PM Temporary Internet Files [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\Documents
06/20/2013 06:29 PM My Music [C:\Users\UpdatusUser\Music]
06/20/2013 06:29 PM My Pictures [C:\Users\UpdatusUser\Pictures]
06/20/2013 06:29 PM My Videos [C:\Users\UpdatusUser\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
66 Dir(s) 762,540,818,432 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/08/01 00:31:33 | 000,000,221 | -HS- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/08/05 20:42:09 | 000,666,633 | —- | M] () – C:\Users\domportera\Desktop\AdwCleaner.exe
[2013/08/05 21:11:44 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\domportera\Desktop\aswMBR.exe
[2013/08/05 18:03:55 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\domportera\Desktop\OTL.exe
[2013/08/05 20:41:23 | 000,891,098 | —- | M] () – C:\Users\domportera\Desktop\SecurityCheck.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Hello domportera,

Instructions for posting the aswMBR.dat file.

You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================

Re-post the logs and do not enclose them in code tags, just copy and paste them into the reply window.
Hi domportera,

1. Reset / Change Homepage in Chrome
  • Click the Chrome menu [external image: Posted Image] on the browser toolbar.
  • Select Settings.
  • Add the home button to the browser toolbar
    Home page button is off by default. Select the "Show Home button" checkbox in the "Appearance" section to show it on the browser toolbar.
  • Set your home page
    When the "Show Home button" checkbox is selected, a web address appears below it. This is the address you will want to change. (hxxp://www.blekko.com)
    Click Change to enter a link (i.e. http://www.google.com). You can also choose the New Tab page as your home page.
=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    CHR - homepage: http://blekko.com/?source=c3348dd4&tbp…A6E1512B33797C6
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

In your next post please provide the following:
  • OTL.txt
  • How is the computer running, what issues are you still experiencing?
All processes killed ========== OTL ========== Use Chrome's Settings page to change the HomePage. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: domportera ->Temp folder emptied: 351138451 bytes ->Temporary Internet Files folder emptied: 93589236 bytes ->Java cache emptied: 154277 bytes ->Google Chrome cache emptied: 463490942 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3446380 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42305215 bytes RecycleBin emptied: 585021509 bytes Total Files Cleaned = 1,468.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 08062013_012540 Files\Folders moved on Reboot… C:\Users\domportera\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\domportera\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot. PendingFileRenameOperations files… Registry entries deleted on Reboot… I've altered the homepage on Chrome back to google.com And all the symptoms of my computer's infection are gone. I am experiencing no issues. Thank you so much for your help, you are a saint, along with the others here who do tech help and provide this forum.
Hi domportera,

It's important that you follow through with the remainder of the steps I will outline. Absence of symptoms doesn't necessarily translate into malware free. We are making progress so please stay with me until I give you the "all clean" sign. :thumbup:

=========================

1. Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

Right click mbam-setup.exe and select "Run as Administrator" and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
=========================

2. ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:
  • MBAM log
  • ESET's log.txt
MBAM log

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.06.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
domportera :: DOMPORTERA-PC [administrator]

Protection: Disabled

8/6/2013 1:48:37 AM
mbam-log-2013-08-06 (01-48-37).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 236261
Time elapsed: 4 minute(s),

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Classes (Backdoor.Agent) -> Data: C:\Users\domportera\AppData\Roaming\bauwefiv\ggeecugd.exe -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)




There was no ESET log, it found no threats
Hi domportera,

We are making progress. :thumbup:

=========================

1. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • OTL.txt
  • Any remaining issues?
OTL logfile created on: 8/6/2013 11:01:13 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\domportera\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.89 Gb Total Physical Memory | 5.29 Gb Available Physical Memory | 67.00% Memory free
15.78 Gb Paging File | 13.07 Gb Available in Paging File | 82.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 713.23 Gb Free Space | 76.58% Space Free | Partition Type: NTFS

Computer Name: DOMPORTERA-PC | User Name: domportera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\domportera\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (NVIDIA Corporation)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Users\domportera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Hotkey\Hotkey.exe ()
PRC - C:\Program Files (x86)\Hotkey\WRadio.exe ()
PRC - C:\Program Files (x86)\Hotkey\PowerBiosServer.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe (PandoraTV)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
PRC - C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe (AuthenTec Inc.)
PRC - C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\_elementtree.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32api.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\_socket.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32ts.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\pysqlite2._sqlite.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32com.shell.shell.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._html2.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\_multiprocessing.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32crypt.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._gdi_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._misc_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\windows._cacheinvalidation.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\pythoncom27.dll ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\_ctypes.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32profile.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._core_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\_ssl.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._windows_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\_hashlib.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._wizard.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\PyWinTypes27.dll ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32security.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32process.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32pdh.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\wx._controls_.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\unicodedata.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\pyexpat.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32file.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32inet.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\win32event.pyd ()
MOD - C:\Users\domportera\AppData\Local\Temp\_MEI15762\select.pyd ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a7a3ebc76a454af37918211506e81e31\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a2920ed81e097f8551231a9350697bbd\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\f752f8cf702b7c7eff6c659b2e0c760a\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fc4a8709f71eba20cc71c7905bba3dee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\178644ab40108f3becd8b91049a254c3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bfa7a95284aec941f4b03bae0debe07c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ef17be93e209cc95b9768c7822530432\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c25666b99761bc42322bae2e59968df8\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\32066405eb9ab14056b2af3115d2a6de\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\187c13e8967097d2ed1e5f123e7d890a\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Hotkey\Hotkey.exe ()
MOD - C:\Program Files (x86)\Hotkey\en\HotKey.resources.dll ()
MOD - C:\Program Files (x86)\Hotkey\en-US\HotKey.resources.dll ()
MOD - C:\Program Files (x86)\Hotkey\WRadio.exe ()
MOD - C:\Users\domportera\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Users\domportera\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files (x86)\Hotkey\Audiodll.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NvStreamSvc) – C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AMPPALR3) – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (ZeroConfigService) – C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel® Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (BTHSSecurityMgr) – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV:64bit: - (FPLService) – C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (AuthenTec, Inc)
SRV:64bit: - (TrueService) – C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PowerBiosServer) – C:\Program Files (x86)\Hotkey\PowerBiosServer.exe ()
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (PanService) – C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (gfibto) – C:\Windows\SysNative\drivers\gfibto.sys (GFI Software)
DRV:64bit: - (nvpciflt) – C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (nvvad_WaveExtensible) – C:\Windows\SysNative\drivers\nvvad64v.sys (NVIDIA Corporation)
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\Netwsw00.sys (Intel Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (RSBASTOR) – C:\Windows\SysNative\drivers\RtsBaStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SmbDrvI) – C:\Windows\SysNative\drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (VMfilt) – C:\Windows\SysNative\drivers\VMfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nmd.msn.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{CDEF1E49-EFBD-4A63-9F2E-F308510F2372}: "URL" = http://findgala.com/?&uid=5689&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@authentec.com/ffwloplugin: C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll (AuthenTec, Inc)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)


[2013/08/01 02:29:47 | 000,000,000 | —D | M] (No name found) – C:\Users\domportera\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: TrueSuite (Enabled) = C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Missing e = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid\2.14.3_0\
CHR - Extension: YouTube = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Webpage & WebCam Screenshot = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki\9.2_0\
CHR - Extension: Google Search = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0\
CHR - Extension: Skyrim: Book of the Dragonborn Theme = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioigkhgefneinlgdahhpddckbpofpnfi\0.2.0.23_0\
CHR - Extension: iSideWith = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\nekniaobhkcioppbllliijfaillbaiik\1.5_0\
CHR - Extension: Website Logon = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelloajafbopojkjmieelljfkcmdpdhf\6.0_0\
CHR - Extension: Gmail = C:\Users\domportera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/08/05 21:52:17 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (TrueSuite Browser Helper Object) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.dll (AuthenTec Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (TrueSuite Browser Helper Object) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [CECAPLF] C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [KeepSafe] C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (Authentec)
O4:64bit: - HKLM..\Run: [MBCfg64] C:\Windows\SysNative\MBCfg64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Sound Blaster Cinema] C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe (Dxtory Software)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\domportera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk = C:\Program Files (x86)\Dxtory Software\Dxtory2.0\Dxtory.exe (Dxtory Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…30321/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19CD3E11-5A83-42C5-9C55-86F17F471CF0}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll C:\Windows\system32\nvinitx.dll) - C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll) - C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/06 10:43:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2013/08/06 10:43:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/08/06 02:05:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/08/05 21:51:50 | 000,000,000 | —D | C] – C:\_OTL
[2013/08/05 20:41:29 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\domportera\Desktop\aswMBR.exe
[2013/08/05 19:46:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA
[2013/08/05 19:46:26 | 002,210,376 | —- | C] (VIA Technologies, Inc.) – C:\Windows\SysNative\drivers\viahduaa.sys
[2013/08/05 19:46:26 | 001,119,352 | —- | C] (VIA Technologies, Inc.) – C:\Windows\SysNative\ViaMicArrayAPO.dll
[2013/08/05 19:46:26 | 001,092,096 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\VMAPO264.DLL
[2013/08/05 19:46:26 | 000,908,288 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\VMAPO232.DLL
[2013/08/05 18:48:01 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\The Collector (working title)
[2013/08/05 18:46:45 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\GameMaker
[2013/08/05 18:45:55 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Subversion
[2013/08/05 18:43:37 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\gamemaker_studio
[2013/08/05 18:43:35 | 000,000,000 | —D | C] – C:\ProgramData\gamemaker_studio
[2013/08/05 18:43:32 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\GameMaker_Player
[2013/08/05 18:04:31 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\ElevatedDiagnostics
[2013/08/05 18:03:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\domportera\Desktop\OTL.exe
[2013/08/05 13:49:52 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2013/08/05 12:40:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2013/08/05 12:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360
[2013/08/05 12:21:17 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2013/08/05 12:20:03 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2013/08/05 12:15:00 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apple Computer
[2013/08/05 11:05:09 | 000,039,504 | —- | C] (ThreatTrack Security) – C:\Windows\SysNative\drivers\gfiark.sys
[2013/08/05 03:13:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\LavasoftStatistics
[2013/08/05 03:02:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/08/05 03:01:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/08/05 03:01:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/08/05 02:52:21 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\adawarebp
[2013/08/05 02:52:21 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2013/08/05 02:52:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2013/08/05 02:52:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2013/08/05 02:50:48 | 000,014,456 | —- | C] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/08/05 02:38:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/08/05 02:38:17 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/08/05 01:58:57 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\WinRAR
[2013/08/05 01:58:45 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/05 01:58:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/08/05 01:58:40 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2013/08/05 01:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Caphyon
[2013/08/04 19:49:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PANDORATV
[2013/08/04 19:49:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\PANDORA.TV
[2013/08/04 19:49:46 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2013/08/04 19:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\The KMPlayer
[2013/08/03 11:59:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
[2013/08/03 11:59:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Exact Audio Copy
[2013/08/03 11:18:04 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\EAC
[2013/08/03 11:17:58 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\AccurateRip
[2013/08/03 04:13:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
[2013/08/03 04:13:09 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Last.fm
[2013/08/03 04:13:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Last.fm
[2013/08/03 02:20:59 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Dxtory Software
[2013/08/03 02:20:58 | 008,043,008 | —- | C] (Dxtory Software) – C:\Windows\SysNative\DxtoryCodec.dll
[2013/08/03 02:20:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
[2013/08/03 02:20:57 | 008,300,544 | —- | C] (Dxtory Software) – C:\Windows\SysWow64\DxtoryCodec.dll
[2013/08/03 02:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dxtory Software
[2013/08/03 02:19:17 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\Wizards of the Coast
[2013/08/03 02:03:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft XNA
[2013/08/03 02:01:54 | 000,000,000 | —D | C] – C:\Users\domportera\Documents\My Games
[2013/08/03 00:14:42 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/08/02 21:00:03 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Capsule Utilities
[2013/08/02 21:00:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Capsule
[2013/08/02 12:43:22 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\AuthenTec
[2013/08/02 10:52:28 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Malwarebytes
[2013/08/02 10:52:07 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/08/02 05:25:19 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Adobe
[2013/08/02 05:15:52 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/08/02 05:06:28 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2013/08/02 05:06:28 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2013/08/02 04:42:27 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/08/02 04:42:27 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/08/02 04:42:27 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/08/02 04:42:27 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/08/02 04:42:27 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2013/08/02 04:42:27 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2013/08/02 04:42:27 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/08/02 04:42:27 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/08/02 04:42:26 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2013/08/02 04:42:26 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2013/08/02 04:42:26 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2013/08/02 04:42:26 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2013/08/02 04:42:26 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/08/02 04:42:26 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/08/02 04:42:25 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2013/08/02 04:42:25 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2013/08/02 04:42:25 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_6.dll
[2013/08/02 04:42:25 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_6.dll
[2013/08/02 04:42:25 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_6.dll
[2013/08/02 04:42:25 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_6.dll
[2013/08/02 04:42:25 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_4.dll
[2013/08/02 04:42:25 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_4.dll
[2013/08/02 04:41:29 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_7.dll
[2013/08/02 04:41:29 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_7.dll
[2013/08/02 04:41:23 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_5.dll
[2013/08/02 04:41:22 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_5.dll
[2013/08/02 04:41:22 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_5.dll
[2013/08/02 04:41:21 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_42.dll
[2013/08/02 04:41:21 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2013/08/02 04:41:21 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_42.dll
[2013/08/02 04:41:21 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/08/02 04:41:20 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2013/08/02 04:41:20 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/08/02 04:41:18 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2013/08/02 04:41:18 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2013/08/02 04:41:17 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2013/08/02 04:41:17 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2013/08/02 04:41:16 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2013/08/02 04:41:16 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2013/08/02 04:41:16 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2013/08/02 04:41:16 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2013/08/02 04:41:16 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2013/08/02 04:41:15 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2013/08/02 04:41:15 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2013/08/02 04:41:15 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2013/08/02 04:41:15 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2013/08/02 04:41:14 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2013/08/02 04:41:14 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/08/02 04:41:14 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2013/08/02 04:41:14 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2013/08/02 04:41:14 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2013/08/02 04:41:14 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2013/08/02 04:41:14 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2013/08/02 04:41:14 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2013/08/02 04:41:14 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2013/08/02 04:41:14 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2013/08/02 04:41:14 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2013/08/02 04:41:14 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2013/08/02 04:41:14 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2013/08/02 04:41:14 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2013/08/02 04:41:13 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2013/08/02 04:41:13 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2013/08/02 04:41:13 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2013/08/02 04:41:13 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2013/08/02 04:41:13 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2013/08/02 04:41:13 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2013/08/02 04:41:13 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2013/08/02 04:41:13 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2013/08/02 04:41:13 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2013/08/02 04:41:13 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2013/08/02 04:41:12 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2013/08/02 04:41:12 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2013/08/02 04:41:12 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2013/08/02 04:41:12 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2013/08/02 04:41:12 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2013/08/02 04:41:12 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2013/08/02 04:41:11 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2013/08/02 04:41:11 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2013/08/02 04:41:11 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2013/08/02 04:41:11 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2013/08/02 04:41:10 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2013/08/02 04:41:10 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2013/08/02 04:41:10 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2013/08/02 04:41:10 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2013/08/02 04:41:10 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2013/08/02 04:41:10 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2013/08/02 04:41:09 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2013/08/02 04:41:09 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2013/08/02 04:41:09 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2013/08/02 04:41:09 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2013/08/02 04:41:09 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2013/08/02 04:41:09 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2013/08/02 04:41:02 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2013/08/02 04:41:02 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2013/08/02 04:41:02 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2013/08/02 04:41:02 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2013/08/02 04:41:01 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2013/08/02 04:41:01 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2013/08/02 04:40:59 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2013/08/02 04:40:59 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2013/08/02 04:40:59 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2013/08/02 04:40:59 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2013/08/02 04:40:59 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2013/08/02 04:40:59 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2013/08/02 04:40:58 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2013/08/02 04:40:58 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2013/08/02 04:40:58 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2013/08/02 04:40:58 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2013/08/02 04:40:57 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/08/02 04:40:57 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2013/08/02 04:40:57 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2013/08/02 04:40:57 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2013/08/02 04:40:57 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2013/08/02 04:40:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2013/08/02 04:40:56 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2013/08/02 04:40:56 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2013/08/02 04:40:56 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2013/08/02 04:40:56 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2013/08/02 04:40:43 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2013/08/02 04:40:43 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2013/08/02 04:40:43 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2013/08/02 04:40:43 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2013/08/02 04:40:40 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2013/08/02 04:40:40 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2013/08/02 04:40:40 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2013/08/02 04:40:40 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2013/08/02 04:40:38 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2013/08/02 04:40:38 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2013/08/02 04:40:35 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2013/08/02 04:40:35 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2013/08/02 04:40:34 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2013/08/02 04:40:34 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2013/08/02 04:40:31 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2013/08/02 04:40:31 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2013/08/02 04:40:29 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2013/08/02 04:40:29 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2013/08/02 04:40:27 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2013/08/02 04:40:27 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2013/08/02 04:40:25 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2013/08/02 04:40:25 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2013/08/02 04:40:16 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2013/08/02 04:40:16 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2013/08/02 04:40:16 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2013/08/02 04:40:16 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2013/08/02 04:40:14 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2013/08/02 04:40:14 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2013/08/02 04:40:14 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2013/08/02 04:40:14 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2013/08/02 04:40:14 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2013/08/02 04:40:14 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2013/08/02 04:40:13 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2013/08/02 04:40:13 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2013/08/02 04:40:13 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2013/08/02 04:40:13 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2013/08/02 04:40:13 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2013/08/02 04:40:13 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2013/08/02 04:40:12 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/08/02 04:40:12 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/08/02 04:40:10 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2013/08/02 04:40:10 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2013/08/02 04:40:10 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2013/08/02 04:40:10 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2013/08/02 04:40:10 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2013/08/02 04:40:10 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2013/08/02 04:40:10 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2013/08/02 04:40:10 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2013/08/02 04:40:10 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2013/08/02 04:40:10 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2013/08/02 04:40:10 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2013/08/02 04:40:10 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2013/08/02 04:40:09 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2013/08/02 04:40:09 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2013/08/02 04:40:09 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2013/08/02 04:40:09 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2013/08/02 04:31:39 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/08/02 04:05:32 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/02 04:05:32 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/02 04:05:32 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/02 04:05:32 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/08/02 04:05:32 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/08/02 04:05:32 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/08/02 04:05:32 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/02 04:05:32 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/08/02 04:05:32 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/02 04:05:32 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/08/02 04:05:32 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/02 04:05:32 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/02 04:05:32 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/02 04:05:32 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/08/02 04:05:32 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/08/02 04:05:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/02 04:05:32 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/08/02 04:05:32 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/08/02 04:05:32 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/02 04:05:32 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/02 04:05:32 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/08/02 04:05:32 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/08/02 04:05:32 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/08/02 04:05:32 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/08/02 04:05:32 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/02 04:05:32 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/08/02 04:05:32 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/08/02 04:05:32 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/08/02 04:05:32 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/08/02 04:05:32 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/08/02 04:05:32 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/08/02 04:05:32 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/02 04:05:32 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/08/02 04:05:32 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/08/02 04:05:32 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/08/02 04:05:32 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/08/02 04:05:32 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/08/02 04:05:32 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/08/02 04:05:32 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/02 04:05:32 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/08/02 04:05:32 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/08/02 04:05:32 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/02 04:05:32 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/08/02 04:05:32 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/08/02 04:05:32 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/08/02 04:05:32 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/08/02 04:05:32 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/08/02 04:05:32 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/08/02 04:05:32 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/08/02 04:05:32 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/08/02 04:05:32 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/08/02 04:05:32 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/08/02 04:05:32 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/08/02 04:05:32 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/08/02 04:05:32 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/08/02 04:05:32 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/08/02 04:05:32 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/08/02 04:05:32 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/08/02 04:00:34 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/08/02 04:00:34 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/08/02 04:00:34 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/08/02 04:00:34 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/08/02 04:00:34 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/08/02 04:00:34 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/08/02 04:00:34 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/08/02 04:00:34 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/08/02 04:00:34 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/08/02 04:00:34 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/08/02 04:00:34 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/08/02 04:00:34 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/08/02 04:00:34 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/08/02 04:00:34 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/08/02 04:00:34 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 03:36:33 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/08/02 03:36:33 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/08/02 03:36:33 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/08/02 03:36:32 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/08/02 03:35:10 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2013/08/02 03:35:10 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2013/08/02 03:35:10 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2013/08/02 03:35:10 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2013/08/02 03:10:47 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2013/08/02 03:10:46 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2013/08/01 12:02:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Sleep
[2013/08/01 12:02:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Sleep
[2013/08/01 11:37:40 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\vlc
[2013/08/01 11:29:35 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/08/01 11:29:34 | 002,079,816 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2013/08/01 10:04:06 | 000,000,000 | —D | C] – C:\NvidiaLogging
[2013/08/01 10:03:30 | 000,039,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvvad64v.sys
[2013/08/01 10:03:30 | 000,029,984 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvaudcap64v.dll
[2013/08/01 10:03:30 | 000,028,448 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvaudcap32v.dll
[2013/08/01 10:03:14 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\NVIDIA
[2013/08/01 09:41:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\AGEIA Technologies
[2013/08/01 09:40:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2013/08/01 09:40:30 | 000,000,000 | —D | C] – C:\Windows\SysWow64\NV
[2013/08/01 09:40:30 | 000,000,000 | —D | C] – C:\Windows\SysNative\NV
[2013/08/01 09:39:14 | 000,000,000 | —D | C] – C:\Users\domportera\Desktop\Game Design
[2013/08/01 09:38:04 | 000,000,000 | —D | C] – C:\Users\domportera\Desktop\Diversions Music
[2013/08/01 09:37:56 | 027,781,920 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2013/08/01 09:37:56 | 021,102,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2013/08/01 09:37:56 | 015,920,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2013/08/01 09:37:56 | 015,144,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2013/08/01 09:37:56 | 013,411,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2013/08/01 09:37:56 | 009,239,344 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2013/08/01 09:37:56 | 007,687,592 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2013/08/01 09:37:56 | 007,641,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2013/08/01 09:37:56 | 006,324,360 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2013/08/01 09:37:56 | 002,953,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2013/08/01 09:37:56 | 002,777,888 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2013/08/01 09:37:56 | 002,363,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2013/08/01 09:37:56 | 002,002,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2013/08/01 09:37:56 | 001,832,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco6432049.dll
[2013/08/01 09:37:56 | 001,511,712 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco6432049.dll
[2013/08/01 09:37:56 | 000,572,704 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvFBC64.dll
[2013/08/01 09:37:56 | 000,570,656 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\NvIFR64.dll
[2013/08/01 09:37:56 | 000,467,232 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NvIFR.dll
[2013/08/01 09:37:56 | 000,465,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NvFBC.dll
[2013/08/01 09:37:56 | 000,432,928 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvEncodeAPI64.dll
[2013/08/01 09:37:56 | 000,372,000 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvEncodeAPI.dll
[2013/08/01 09:37:56 | 000,218,592 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglshim64.dll
[2013/08/01 09:37:56 | 000,181,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglshim32.dll
[2013/08/01 09:37:56 | 000,030,496 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvpciflt.sys
[2013/08/01 09:37:55 | 025,256,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2013/08/01 09:37:55 | 017,560,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2013/08/01 09:37:55 | 002,597,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2013/08/01 09:31:17 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Tomahawk
[2013/08/01 09:31:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tomahawk
[2013/08/01 09:31:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tomahawk
[2013/08/01 09:22:17 | 000,000,000 | —D | C] – C:\NVIDIA
[2013/08/01 09:15:44 | 000,000,000 | —D | C] – C:\Windows\Sun
[2013/08/01 09:14:56 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/08/01 09:14:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/08/01 09:14:41 | 000,867,240 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/08/01 09:14:41 | 000,789,416 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/08/01 09:14:41 | 000,263,592 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/08/01 09:14:37 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/08/01 09:14:37 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/08/01 09:14:37 | 000,096,168 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/08/01 09:14:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/08/01 09:14:16 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/08/01 05:46:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2013/08/01 05:46:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2013/08/01 05:46:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/08/01 05:46:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/08/01 05:46:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/08/01 05:46:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/08/01 05:46:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/08/01 05:46:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/08/01 05:46:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/08/01 05:46:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/08/01 05:46:01 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/08/01 05:46:01 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/08/01 05:46:01 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/08/01 05:46:01 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/08/01 05:46:01 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/08/01 05:46:01 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/08/01 05:46:01 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/08/01 05:46:01 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/08/01 05:46:01 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/08/01 05:46:01 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/08/01 05:46:01 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/08/01 05:46:01 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/08/01 05:46:01 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/08/01 05:46:01 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/08/01 05:46:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/08/01 05:46:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/08/01 05:46:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/08/01 05:46:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/08/01 05:46:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/08/01 05:41:40 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2013/08/01 05:41:40 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2013/08/01 05:12:35 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2013/08/01 05:12:30 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/08/01 05:12:30 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/08/01 05:12:28 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2013/08/01 05:12:28 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2013/08/01 05:12:28 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2013/08/01 05:12:28 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2013/08/01 05:12:28 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2013/08/01 05:12:27 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2013/08/01 05:12:27 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2013/08/01 05:12:27 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2013/08/01 05:12:26 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2013/08/01 05:12:09 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2013/08/01 05:12:09 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2013/08/01 05:12:08 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2013/08/01 05:12:08 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2013/08/01 05:12:08 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2013/08/01 05:12:02 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/08/01 05:12:02 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/08/01 05:12:01 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/08/01 05:12:01 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/08/01 05:12:01 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/08/01 05:12:01 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/08/01 05:11:49 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/08/01 05:07:25 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2013/08/01 05:07:25 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2013/08/01 05:07:25 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/08/01 05:07:25 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/08/01 05:07:10 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2013/08/01 05:06:05 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/08/01 05:06:05 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/08/01 05:06:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/08/01 05:06:05 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/08/01 04:57:44 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/08/01 04:51:11 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2013/08/01 04:51:11 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2013/08/01 04:37:54 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2013/08/01 04:36:56 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/08/01 04:36:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2013/08/01 04:36:48 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2013/08/01 04:36:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2013/08/01 04:36:37 | 001,447,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/08/01 04:36:36 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspicli.dll
[2013/08/01 04:36:36 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspisrv.dll
[2013/08/01 04:36:36 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2013/08/01 04:36:35 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2013/08/01 04:36:35 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2013/08/01 04:36:35 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2013/08/01 04:36:35 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2013/08/01 04:36:35 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2013/08/01 04:36:34 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2013/08/01 04:36:34 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2013/08/01 04:36:10 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2013/08/01 04:36:09 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2013/08/01 04:36:07 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/08/01 04:36:07 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/08/01 04:36:05 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/08/01 04:36:00 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/01 04:35:55 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/01 04:35:55 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/01 04:35:51 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/08/01 04:35:51 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/01 04:35:51 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/01 04:35:51 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/01 04:35:51 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/01 04:35:51 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/01 04:34:33 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2013/08/01 04:28:24 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/08/01 04:28:08 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2013/08/01 04:28:08 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2013/08/01 04:28:08 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2013/08/01 04:28:08 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2013/08/01 04:27:24 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2013/08/01 04:27:20 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/08/01 04:27:20 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/08/01 04:27:20 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/08/01 04:27:20 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/08/01 04:27:18 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/01 04:27:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/08/01 04:27:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/08/01 04:27:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/08/01 04:27:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/08/01 04:27:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/08/01 04:27:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/08/01 04:27:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/08/01 04:27:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/08/01 04:20:43 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2013/08/01 04:20:43 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2013/08/01 04:20:39 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/08/01 04:20:39 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/08/01 04:19:51 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/08/01 04:16:55 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/08/01 04:16:55 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/08/01 04:12:22 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netapi32.dll
[2013/08/01 04:12:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browcli.dll
[2013/08/01 04:12:22 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\browcli.dll
[2013/08/01 04:12:18 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\srcore.dll
[2013/08/01 04:12:15 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2013/08/01 04:12:12 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/01 04:12:12 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/08/01 04:12:12 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/08/01 04:12:12 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/08/01 04:12:12 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/08/01 04:12:12 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/08/01 04:12:01 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2013/08/01 04:11:45 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2013/08/01 04:11:45 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2013/08/01 04:11:39 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2013/08/01 04:11:39 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2013/08/01 04:11:30 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/01 04:11:30 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/01 04:11:30 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/01 04:11:30 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/08/01 04:11:30 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/08/01 04:11:29 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/08/01 04:10:59 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2013/08/01 04:10:59 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2013/08/01 04:09:10 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/08/01 04:09:10 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/08/01 04:07:36 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/01 04:07:33 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\splwow64.exe
[2013/08/01 03:16:15 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2013/08/01 03:16:15 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2013/08/01 03:07:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2013/08/01 02:56:56 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Apple Computer
[2013/08/01 02:41:52 | 000,000,000 | —D | C] – C:\af24f2736e42f1c2053ea0b65e481b6e
[2013/08/01 02:41:06 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Programs
[2013/08/01 02:31:31 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2013/08/01 02:30:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/08/01 02:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/08/01 02:29:46 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Mozilla
[2013/08/01 01:21:10 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/08/01 01:21:10 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/01 01:19:48 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apple
[2013/08/01 01:19:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/08/01 01:18:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/08/01 01:18:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/08/01 01:18:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/08/01 01:18:21 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/08/01 01:18:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/08/01 00:51:32 | 000,000,000 | R–D | C] – C:\Users\domportera\Dropbox
[2013/08/01 00:49:39 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013/08/01 00:45:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\dumps
[2013/08/01 00:45:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2013/08/01 00:45:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/08/01 00:45:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2013/08/01 00:42:20 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Dropbox
[2013/08/01 00:42:15 | 000,000,000 | R–D | C] – C:\Users\domportera\Google Drive
[2013/08/01 00:41:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/08/01 00:38:18 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Creative
[2013/08/01 00:32:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/08/01 00:32:20 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Google
[2013/08/01 00:32:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/08/01 00:32:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Deployment
[2013/08/01 00:32:11 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Apps
[2013/08/01 00:30:10 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2013/08/01 00:30:10 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2013/08/01 00:26:43 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\KeepSafe
[2013/08/01 00:26:27 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/08/01 00:26:27 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/08/01 00:26:27 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2013/08/01 00:26:15 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/08/01 00:26:15 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/08/01 00:26:15 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\Searches
[2013/08/01 00:26:14 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/08/01 00:26:14 | 000,000,000 | -H-D | C] – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/08/01 00:25:48 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/08/01 00:25:48 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/08/01 00:25:38 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Identities
[2013/08/01 00:25:35 | 000,000,000 | R–D | C] – C:\Users\domportera\Contacts
[2013/08/01 00:25:26 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Intel
[2013/08/01 00:25:24 | 000,000,000 | –SD | C] – C:\Users\domportera\AppData\Roaming\Microsoft
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Videos
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Saved Games
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Pictures
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Music
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Links
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Favorites
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Downloads
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Documents
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\Desktop
[2013/08/01 00:25:24 | 000,000,000 | R–D | C] – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\Temporary Internet Files
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Templates
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Start Menu
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\SendTo
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Recent
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\PrintHood
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\NetHood
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Videos
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Pictures
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Documents\My Music
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\My Documents
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Local Settings
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\History
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Cookies
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\Application Data
[2013/08/01 00:25:24 | 000,000,000 | -HSD | C] – C:\Users\domportera\AppData\Local\Application Data
[2013/08/01 00:25:24 | 000,000,000 | -H-D | C] – C:\Users\domportera\AppData
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Temp
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\Roaming
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Local\Microsoft
[2013/08/01 00:25:24 | 000,000,000 | —D | C] – C:\Users\domportera\AppData\Roaming\Media Center Programs
[2013/08/01 00:25:10 | 000,000,000 | -HSD | C] – C:\Recovery
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\upeksce
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AuthenTec TrueSuite
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AuthenTec
[2013/07/25 14:42:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AuthenTec
[2013/07/25 14:42:15 | 000,000,000 | —D | C] – C:\Program Files\AuthenTec TrueSuite
[2013/07/25 14:42:12 | 000,000,000 | —D | C] – C:\ProgramData\Downloaded Installations
[2013/07/25 14:42:04 | 000,000,000 | —D | C] – C:\Program Files\AuthenTec
[2013/07/25 14:41:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\FingerPrinter
[1 C:\Users\domportera\AppData\Roaming\*.tmp files -> C:\Users\domportera\AppData\Roaming\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/06 11:00:33 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/08/06 10:37:00 | 000,000,906 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/06 02:06:57 | 000,021,888 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 02:06:57 | 000,021,888 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 02:02:53 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/06 02:02:53 | 000,660,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/06 02:02:53 | 000,121,214 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/06 01:56:45 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/06 01:55:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/06 01:55:20 | 2060,148,735 | -HS- | M] () – C:\hiberfil.sys
[2013/08/05 21:52:17 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2013/08/05 21:39:58 | 000,001,188 | —- | M] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/08/05 21:11:44 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\domportera\Desktop\aswMBR.exe
[2013/08/05 20:42:09 | 000,666,633 | —- | M] () – C:\Users\domportera\Desktop\AdwCleaner.exe
[2013/08/05 20:41:23 | 000,891,098 | —- | M] () – C:\Users\domportera\Desktop\SecurityCheck.exe
[2013/08/05 19:46:37 | 000,001,213 | —- | M] () – C:\Users\Public\Desktop\HD VDeck.lnk
[2013/08/05 18:03:55 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\domportera\Desktop\OTL.exe
[2013/08/05 03:10:00 | 000,773,050 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/08/05 02:50:48 | 000,014,456 | —- | M] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/08/05 02:42:03 | 000,001,193 | —- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk
[2013/08/05 02:38:17 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/04 19:51:26 | 000,000,974 | —- | M] () – C:\Users\domportera\Desktop\KMPlayer.lnk
[2013/08/03 11:59:41 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\Exact Audio Copy.lnk
[2013/08/03 04:13:10 | 000,000,992 | —- | M] () – C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013/08/03 02:20:58 | 000,001,193 | —- | M] () – C:\Users\domportera\Desktop\Dxtory.lnk
[2013/08/02 21:00:03 | 000,001,092 | —- | M] () – C:\Users\domportera\Desktop\Capsule.lnk
[2013/08/02 05:10:01 | 000,275,712 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/08/02 04:05:32 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/02 04:05:32 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/02 04:05:32 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/02 04:05:32 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/08/02 04:05:32 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/08/02 04:05:32 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/08/02 04:05:32 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/02 04:05:32 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/08/02 04:05:32 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/08/02 04:05:32 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/02 04:05:32 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/08/02 04:05:32 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/02 04:05:32 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/02 04:05:32 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/02 04:05:32 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/08/02 04:05:32 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/08/02 04:05:32 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/02 04:05:32 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/08/02 04:05:32 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/08/02 04:05:32 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/02 04:05:32 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/02 04:05:32 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/08/02 04:05:32 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/08/02 04:05:32 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/08/02 04:05:32 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/08/02 04:05:32 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/02 04:05:32 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/08/02 04:05:32 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/08/02 04:05:32 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/08/02 04:05:32 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/08/02 04:05:32 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/08/02 04:05:32 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/08/02 04:05:32 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/02 04:05:32 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/08/02 04:05:32 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/08/02 04:05:32 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/08/02 04:05:32 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/08/02 04:05:32 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/08/02 04:05:32 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/08/02 04:05:32 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/08/02 04:05:32 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/02 04:05:32 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/08/02 04:05:32 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/08/02 04:05:32 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/02 04:05:32 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/08/02 04:05:32 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/08/02 04:05:32 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/02 04:05:32 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/08/02 04:05:32 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/08/02 04:05:32 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/08/02 04:05:32 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/08/02 04:05:32 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/08/02 04:05:32 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/08/02 04:05:32 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/08/02 04:05:32 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/08/02 04:05:32 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/08/02 04:05:32 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/08/02 04:05:32 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/08/02 04:05:32 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/08/02 04:05:32 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/08/02 04:05:32 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/08/02 04:05:32 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/08/02 04:05:32 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/08/02 04:05:32 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/08/02 04:05:32 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/08/02 04:00:34 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/08/02 04:00:34 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/08/02 04:00:34 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/08/02 04:00:34 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/08/02 04:00:34 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/08/02 04:00:34 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/08/02 04:00:34 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/08/02 04:00:34 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/08/02 04:00:34 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/08/02 04:00:34 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/02 04:00:34 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/08/02 04:00:34 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/08/02 04:00:34 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/08/02 04:00:34 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/08/02 04:00:34 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/08/02 04:00:34 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/08/02 04:00:34 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/02 04:00:34 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/01 12:22:01 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2013/08/01 12:22:01 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2013/08/01 09:31:07 | 000,001,018 | —- | M] () – C:\Users\domportera\Desktop\Tomahawk.lnk
[2013/08/01 09:14:31 | 000,867,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/08/01 09:14:31 | 000,789,416 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/08/01 09:14:31 | 000,263,592 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/08/01 09:14:31 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/08/01 09:14:31 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/08/01 09:14:31 | 000,096,168 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/08/01 00:51:32 | 000,001,057 | —- | M] () – C:\Users\domportera\Desktop\Dropbox.lnk
[2013/08/01 00:50:21 | 000,001,067 | —- | M] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/01 00:45:24 | 000,000,924 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2013/08/01 00:42:17 | 000,002,290 | —- | M] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/01 00:42:16 | 000,001,717 | —- | M] () – C:\Users\domportera\Desktop\Google Drive.lnk
[2013/08/01 00:41:03 | 000,002,051 | —- | M] () – C:\Users\Public\Desktop\Google Slides.lnk
[2013/08/01 00:41:03 | 000,002,047 | —- | M] () – C:\Users\Public\Desktop\Google Sheets.lnk
[2013/08/01 00:41:03 | 000,002,035 | —- | M] () – C:\Users\Public\Desktop\Google Docs.lnk
[2013/08/01 00:32:51 | 000,002,266 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/01 00:31:33 | 000,001,448 | —- | M] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/07/25 14:42:09 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_tcwbf_01_09_00.Wdf
[2013/07/25 14:42:09 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[1 C:\Users\domportera\AppData\Roaming\*.tmp files -> C:\Users\domportera\AppData\Roaming\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/06 11:00:33 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/08/06 10:43:34 | 000,002,124 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/08/05 21:39:58 | 000,001,188 | —- | C] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/08/05 20:42:07 | 000,666,633 | —- | C] () – C:\Users\domportera\Desktop\AdwCleaner.exe
[2013/08/05 20:41:21 | 000,891,098 | —- | C] () – C:\Users\domportera\Desktop\SecurityCheck.exe
[2013/08/05 02:42:03 | 000,001,193 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.lnk
[2013/08/05 02:38:17 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/05 01:46:41 | 000,007,062 | —- | C] () – C:\Windows\SysWow64\audiopid.vxd
[2013/08/04 19:49:47 | 000,000,974 | —- | C] () – C:\Users\domportera\Desktop\KMPlayer.lnk
[2013/08/03 11:59:41 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\Exact Audio Copy.lnk
[2013/08/03 04:13:10 | 000,000,992 | —- | C] () – C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013/08/03 02:20:58 | 000,001,193 | —- | C] () – C:\Users\domportera\Desktop\Dxtory.lnk
[2013/08/02 21:00:03 | 000,001,200 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Capsule.lnk
[2013/08/02 21:00:03 | 000,001,092 | —- | C] () – C:\Users\domportera\Desktop\Capsule.lnk
[2013/08/02 04:05:32 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/08/02 04:05:32 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/08/02 03:35:10 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/08/01 09:31:07 | 000,001,018 | —- | C] () – C:\Users\domportera\Desktop\Tomahawk.lnk
[2013/08/01 03:15:03 | 000,773,050 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/08/01 01:19:47 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/08/01 00:51:32 | 000,001,057 | —- | C] () – C:\Users\domportera\Desktop\Dropbox.lnk
[2013/08/01 00:50:21 | 000,001,067 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/08/01 00:45:24 | 000,000,924 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2013/08/01 00:42:16 | 000,001,717 | —- | C] () – C:\Users\domportera\Desktop\Google Drive.lnk
[2013/08/01 00:41:03 | 000,002,051 | —- | C] () – C:\Users\Public\Desktop\Google Slides.lnk
[2013/08/01 00:41:03 | 000,002,047 | —- | C] () – C:\Users\Public\Desktop\Google Sheets.lnk
[2013/08/01 00:41:03 | 000,002,035 | —- | C] () – C:\Users\Public\Desktop\Google Docs.lnk
[2013/08/01 00:32:51 | 000,002,290 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/01 00:32:51 | 000,002,266 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/01 00:32:24 | 000,000,906 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/01 00:32:23 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/01 00:31:33 | 000,001,448 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/08/01 00:26:17 | 000,001,424 | —- | C] () – C:\Users\domportera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/08/01 00:25:24 | 000,000,290 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/08/01 00:25:24 | 000,000,272 | —- | C] () – C:\Users\domportera\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/07/25 14:42:09 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_tcwbf_01_09_00.Wdf
[2013/07/25 14:42:09 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/06/20 19:16:35 | 000,008,570 | —- | C] () – C:\Windows\SysWow64\MBCfg32.ini
[2013/06/20 19:16:35 | 000,005,856 | —- | C] () – C:\Windows\SysWow64\MBCfgUninstall32.ini
[2013/06/20 19:16:35 | 000,002,835 | —- | C] () – C:\Windows\MBCfg_SP_APOIM.ini
[2013/06/20 19:16:35 | 000,002,783 | —- | C] () – C:\Windows\MBCfg_APOIM.ini
[2013/06/20 19:16:35 | 000,002,747 | —- | C] () – C:\Windows\MBCfg_HP_APOIM.ini
[2013/06/20 19:16:33 | 000,246,272 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2013/06/20 19:16:33 | 000,074,240 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2013/06/20 18:25:53 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2013/06/20 18:25:52 | 019,586,560 | —- | C] () – C:\Windows\SysWow64\igdfcl32.dll
[2013/06/20 18:25:52 | 000,103,936 | —- | C] () – C:\Windows\SysWow64\igdail32.dll
[2013/05/13 18:48:06 | 002,567,680 | —- | C] () – C:\Windows\SysWow64\DeviceControl.exe
[2012/12/10 17:12:50 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/08/04 22:26:36 | 000,000,000 | -HSD | M] – C:\Users\domportera\AppData\Roaming\bauwefiv
[2013/08/06 01:58:59 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\Dropbox
[2013/08/03 11:18:05 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\EAC
[2013/08/01 00:30:11 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\KeepSafe
[2013/08/05 18:45:55 | 000,000,000 | —D | M] – C:\Users\domportera\AppData\Roaming\Subversion

========== Purity Check ==========



< End of report >


No remaining issues at all
Hi domportera,

1. Show Hidden Files & Folders in Windows 7
  • To show hidden files, just click on the Organize button in any folder, and then select “Folder and Search Options” from the menu.
  • Click the View tab, and then you should select “Show hidden files and folders” in the list.
  • Then click OK.
=========================

2. Delete a File/Folder

Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them (if still present):
  • C:\Users\domportera\AppData\Roaming\bauwefiv <– delete the folder, if present
Exit Explorer

=========================

Re-hide files & folders. Confirm you deleted the folder.
Hi domportera,

1. Disk Defragmenter in Windows 7

Click on the Start button, and type in "disk defragmenter" in the search window at the bottom.
"Disk Defragmenter" should appear at the top of the search results, click to open.

(a window similar to the one below will open)

[external image: Posted Image]

Locate your primary hard drive (usually C:), and select it.

[external image: Posted Image]

Next select the Defragment Disk button. Monitor the progress if you choose.

[external image: Posted Image]

Close when the defrag process has been completed.

= = = = = = = = = =

You can also Schedule the Disk Defragmenter to run on a predetermined schedule.

From the main Disk Defragmenter window

[external image: Posted Image]

Select the Configure / Schedule button

[external image: Posted Image]

Select a date and time that best suits your needs.
Close when finished.

=========================

2. Security Check

Re-run Security Check by screen317.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

In your next post please provide the following:
  • checkup.txt
  • Any remaining issues?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI