This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Speedbit-Google Homepage Hijack [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Made the mistake of checking the make speedbit my homepage box when installing DAP. I then lost the ability to change my homepage. After trying a half dozen fixes which didn't work I went back to Speedbit and made my second mistake. They have a tool for download which switches the Speedbit homepage to the Google homepage. It did exactly that. My homepage is now google and I am still not able to change the homepage to anything else.

I am running Windows 7 sp 1. I use SystemSuite 10 as my antivirus and have no other anti malware programs etc installed. Let me know if you need anything else and thanks.
Alan Nolan



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:29:48 PM, on 9/21/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Common Files\Speedbit\SbUpdate\SBUpdate.exe
C:\Users\Heidi\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Sony MSS.lnk = C:\Program Files (x86)\Sony\MSS\3.0.271\SSScheduler.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SystemSuite Professional Process Monitor (.AVQWindowsMonitorService) - Avanquest Software - C:\Program Files (x86)\Avanquest\SystemSuite\AVQWinMonEngine.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AQFileRestoreSrv - Avanquest Software - C:\Program Files (x86)\Avanquest\SystemSuite\AQFileRestoreSrv.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DCDhcpService - Atheros Communication Inc. - C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Energy Server Service (ESRV_SVC) - Unknown owner - C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel® ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service for Sony (McComponentHostServiceSony) - McAfee, Inc. - C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SystemSuite (SBAMSvc) - GFI Software - C:\Program Files (x86)\Avanquest\SystemSuite\Antivirus\SBAMSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SystemSuite Professional Task Manager (SystemSuite Task Manager) - Avanquest Software - C:\PROGRA~2\AVANQU~1\SYSTEM~1\MxTask.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: User Energy Server Service (USER_ESRV_SVC) - Unknown owner - C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VCOM Cloud Agent (VCOMCloudAgent) - Avanquest Software North America - C:\Program Files (x86)\Avanquest\SystemSuite\VcomCloudAgent.exe
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

–
End of file - 14391 bytes
Hi WoundedBear,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

[external image: Posted Image] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: Posted Image] aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================
[external image: Posted Image] OTL

Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
Sorry I've got heart problems and my medications have really messed up my brain. Makes it hard to comprehend and follow instructions. I'm going to start over in my next posts. thanks for you patients Alan
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:00:14 AM, on 9/24/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\DAP\DAP.EXE
C:\Program Files (x86)\Common Files\Speedbit\SbUpdate\SBUpdate.exe
C:\Users\Heidi\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Sony MSS.lnk = C:\Program Files (x86)\Sony\MSS\3.0.271\SSScheduler.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SystemSuite Professional Process Monitor (.AVQWindowsMonitorService) - Avanquest Software - C:\Program Files (x86)\Avanquest\SystemSuite\AVQWinMonEngine.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AQFileRestoreSrv - Avanquest Software - C:\Program Files (x86)\Avanquest\SystemSuite\AQFileRestoreSrv.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DCDhcpService - Atheros Communication Inc. - C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Energy Server Service (ESRV_SVC) - Unknown owner - C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel® ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service for Sony (McComponentHostServiceSony) - McAfee, Inc. - C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SystemSuite (SBAMSvc) - GFI Software - C:\Program Files (x86)\Avanquest\SystemSuite\Antivirus\SBAMSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SystemSuite Professional Task Manager (SystemSuite Task Manager) - Avanquest Software - C:\PROGRA~2\AVANQU~1\SYSTEM~1\MxTask.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: User Energy Server Service (USER_ESRV_SVC) - Unknown owner - C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VCOM Cloud Agent (VCOMCloudAgent) - Avanquest Software North America - C:\Program Files (x86)\Avanquest\SystemSuite\VcomCloudAgent.exe
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgen

–
End of file - 14430 bytes




OTL logfile created on: 9/24/2013 8:41:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Heidi\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.90 Gb Total Physical Memory | 4.23 Gb Available Physical Memory | 71.67% Memory free
6.15 Gb Paging File | 4.15 Gb Available in Paging File | 67.52% Paging File free
Paging file location(s): c:\pagefile.sys 256 512

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 577.33 Gb Total Space | 531.46 Gb Free Space | 92.06% Space Free | Partition Type: NTFS

Computer Name: HEIDI-VAIO | User Name: Heidi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Heidi\Desktop\OTL_1.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\DAP\DAP.exe (Speedbit Ltd.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\VcomCloudAgent.exe (Avanquest Software North America)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\MXTask.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\AVQWinMonEngine.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\MXTask2.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\AQFileRestoreSrv.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe (Speedbit Ltd.)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\Antivirus\SBAMSvc.exe (GFI Software)
PRC - C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Care\listener.exe ()
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Sony Corporation)
PRC - c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\XSevenTo.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\ZShareMa.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\zsharenet.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\UploadStationCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\wuploadCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\weupcoil.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\SpdFileCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\UniBytesCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\UploadingCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\rapidsharecom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\ShareFlareNet.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\SendSpaceCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\OronCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\NetLoadIn.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\mediafirecom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\MetaCafeCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\MegaUploadCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\LetItBitNet.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\fivegiganet.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\filesoniccom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\FilePostCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\FileFlyerCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\DepositFilesCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\ExtaBitCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\FileFactoryCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\DailyMotionCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\189AE673-13C1-4133-A470-8C4DDD1ACB8C\1.0.1.3_0\DataFileHostCom.dll ()
MOD - C:\ProgramData\SpeedBit\DAP\Plugins\AddonsCondition.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\6c422db78c17838c3eb9f9fcc01ca63f\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\10054f798f1a896d5176581777ca7406\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\4d277a8481c203a35c58bd277a2e71df\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e043ad64456256a8ee5b934e227d9782\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\c0593e0b0fafb24a15548809f246d9e0\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\1327ad2637aab17189c5461fbf30dc19\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\d4493b0e5a5c6faf89cfeaa5f2a21034\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\6e3778958a8bfd03bf0f2f60c4e25623\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\6ebbfafc5521934f7e1c154937a2788b\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d473c19e69818875b9c739cad8f386a5\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\28ea347a952d20959ac6ae02d7457d39\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1f6f220f9efe936d1158c79b9d4b451f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\8f7d83126a3cf283e5ac97f2d6d99f12\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\56a1feb800860a3bc5d8a45ee92a77ec\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\1a3b614a84244ea5fa4147b5cf007333\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\001aeb860d7f2ba416e0fedc606fee98\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\228b114c79c5d9024bdb4cc580e32c09\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\c25ede0d0127774c504c4fc41d4de273\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\3a3fc0216674bdea0be809b305517c98\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\884bcbd22130ebeb1211bc7bcc3910c9\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\b3ed31a444f444325ddb64b290ed2f1e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\df40dab689e9d8febfb943599ba79f8d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\de853615c8224ba5d9aa9b76276c6d98\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\sqlite3.dll ()
MOD - C:\Windows\SysWOW64\EasyHook32.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\axis2_engine.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\axiom.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\axutil.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\neethi.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\axis2_http_sender.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\guththila.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\modules\addressing\axis2_mod_addr.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\axis2_parser.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\lib\axis2_http_receiver.dll ()
MOD - C:\Program Files (x86)\Avanquest\SystemSuite\axis2\modules\logging\axis2_mod_log.dll ()
MOD - C:\Program Files\Sony\VAIO Care\listener.exe ()
MOD - C:\Program Files (x86)\Sony\Keyboard Shortcuts\Utility.dll ()
MOD - C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe ()
MOD - C:\Program Files (x86)\Sony\Keyboard Shortcuts\MessageHook.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (VSNService) – C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (VUAgent) – C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation)
SRV:64bit: - (SampleCollector) – C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation)
SRV:64bit: - (USER_ESRV_SVC) – C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe ()
SRV:64bit: - (ESRV_SVC) – C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe ()
SRV:64bit: - (VCService) – C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation)
SRV:64bit: - (DCDhcpService) – C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe (Atheros Communication Inc.)
SRV:64bit: - (Intel® – c:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (VAIO Power Management) – C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
SRV:64bit: - (VcmINSMgr) – C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe (Sony Corporation)
SRV:64bit: - (VcmIAlzMgr) – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
SRV:64bit: - (SpfService) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation)
SRV:64bit: - (VcmXmlIfHelper) – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (Sony Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (VCOMCloudAgent) – C:\Program Files (x86)\Avanquest\SystemSuite\VcomCloudAgent.exe (Avanquest Software North America)
SRV - (SystemSuite Task Manager) – C:\Program Files (x86)\Avanquest\SystemSuite\MXTask.exe (Avanquest Software)
SRV - (.AVQWindowsMonitorService) – C:\Program Files (x86)\Avanquest\SystemSuite\AVQWinMonEngine.exe (Avanquest Software)
SRV - (AQFileRestoreSrv) – C:\Program Files (x86)\Avanquest\SystemSuite\AQFileRestoreSrv.exe (Avanquest Software)
SRV - (SBAMSvc) – C:\Program Files (x86)\Avanquest\SystemSuite\Antivirus\SBAMSvc.exe (GFI Software)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ZAtheros Bt&Wlan Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (McComponentHostServiceSony) – C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe (McAfee, Inc.)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (VAIO Event Service) – C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Sony Corporation)
SRV - (PMBDeviceInfoProvider) – c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (SOHDs) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation)
SRV - (SOHCImp) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation)
SRV - (VCFw) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Sony SCSI Helper Service) – C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe (Sony Corporation)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (uCamMonitor) – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AQFileRestore) – C:\Windows\SysNative\drivers\AQFileRestore.sys ()
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (semav6thermal64ro) – C:\Windows\SysNative\drivers\semav6thermal64ro.sys ()
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_VDP) – C:\Windows\SysNative\drivers\btath_vdp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) – C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SFEP) – C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (e1yexpress) – C:\Windows\SysNative\drivers\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ArcSoftKsUFilter) – C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)
DRV - (TFilter) – C:\Program Files (x86)\Avanquest\SystemSuite\TFilter.sys ()
DRV - (KFilter) – C:\Program Files (x86)\Avanquest\SystemSuite\Kfilter.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
IE - HKCU\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DAP\daplinkchecker [2013/09/18 19:43:28 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\athbttray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\btvstack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Safety present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.1.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8C6F14F-0316-4702-8BEF-E60D808E768E}: DhcpNameServer = 192.168.0.1 [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/09/24 08:36:53 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL_1.exe
[2013/09/24 08:32:56 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL.exe
[2013/09/24 08:29:39 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Heidi\Desktop\aswMBR.exe
[2013/09/24 08:18:34 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2013/09/23 13:32:48 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Microsoft Games
[2013/09/22 17:32:41 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/09/21 13:24:17 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Heidi\Desktop\HiJackThis.exe
[2013/09/19 15:36:20 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\ElevatedDiagnostics
[2013/09/19 13:34:48 | 000,000,000 | —D | C] – C:\Users\Heidi\Desktop\Desktop Folder
[2013/09/18 21:53:12 | 000,000,000 | —D | C] – C:\ProgramData\Oracle
[2013/09/18 21:53:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/09/18 21:52:47 | 000,264,616 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/09/18 21:52:41 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/09/18 21:52:41 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/09/18 21:52:41 | 000,096,168 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/09/18 21:52:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/09/18 21:52:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/09/18 21:47:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/09/18 21:47:02 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/09/18 21:46:59 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2013/09/18 21:46:49 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Google
[2013/09/18 21:46:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/09/18 21:46:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2013/09/18 21:46:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/09/18 21:43:39 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Adobe
[2013/09/18 20:32:34 | 000,039,504 | —- | C] (ThreatTrack Security) – C:\Windows\SysNative\drivers\gfiark.sys
[2013/09/18 20:32:24 | 000,000,000 | RHSD | C] – C:\_Backup.RC
[2013/09/18 20:31:51 | 000,047,496 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2013/09/18 20:31:39 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Avanquest
[2013/09/18 20:31:38 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Avanquest Software
[2013/09/18 20:31:09 | 000,000,000 | —D | C] – C:\ProgramData\Avanquest
[2013/09/18 20:29:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Avanquest
[2013/09/18 20:23:45 | 000,000,000 | —D | C] – C:\_Backup
[2013/09/18 20:11:22 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Copernic
[2013/09/18 20:11:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Copernic
[2013/09/18 20:11:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Copernic Agent
[2013/09/18 19:44:08 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\EQATEC Analytics
[2013/09/18 19:43:29 | 000,000,000 | —D | C] – C:\Users\Heidi\Documents\My DAP Downloads
[2013/09/18 19:43:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Download Accelerator Plus (DAP)
[2013/09/18 19:43:28 | 000,000,000 | —D | C] – C:\ProgramData\SpeedBit
[2013/09/18 19:43:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAP
[2013/09/18 19:42:57 | 000,172,032 | —- | C] (Jin Hui E-mail: [removed] Web: http://www.jcomsoft.com) – C:\Windows\SysWow64\AniGIF.ocx
[2013/09/18 19:42:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SpeedBit
[2013/09/18 19:21:35 | 000,868,264 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/09/18 19:09:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/09/18 19:08:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2013/09/18 19:06:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2013/09/18 19:05:30 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Microsoft Help
[2013/09/18 19:05:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/09/18 19:04:59 | 000,000,000 | RH-D | C] – C:\MSOCache
[2013/09/18 18:55:56 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Skype
[2013/09/18 18:55:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/09/18 18:55:51 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/09/18 18:55:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/09/18 18:55:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/09/18 18:54:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/09/18 18:54:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/09/18 18:44:41 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/09/18 18:41:07 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Macromedia
[2013/09/18 18:38:31 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\WindowsUpdate
[2013/09/18 18:31:48 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\en-US\tsusbflt.sys.mui
[2013/09/18 18:31:46 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/09/18 18:31:46 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/09/18 18:31:46 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/09/18 18:31:44 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/09/18 18:31:44 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbGD.sys
[2013/09/18 18:31:44 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/09/18 18:31:38 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/09/18 18:31:38 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/09/18 18:31:38 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/09/18 18:31:38 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/09/18 18:31:38 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/09/18 18:31:38 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/09/18 18:31:38 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/09/18 18:31:38 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/09/18 18:31:37 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/09/18 18:31:37 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/09/18 18:31:37 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/09/18 18:31:37 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/09/18 18:31:37 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/09/18 18:31:37 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/09/18 18:31:37 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/09/18 18:31:36 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/09/18 18:31:36 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/09/18 18:31:36 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/09/18 18:31:36 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/09/18 18:30:53 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/09/18 18:30:53 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/09/18 18:30:52 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/09/18 18:26:55 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/09/18 18:20:47 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Adobe
[2013/09/18 18:11:06 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/09/18 18:11:06 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/09/18 18:11:06 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/09/18 18:11:05 | 003,959,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/18 18:11:05 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/09/18 18:11:05 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/09/18 18:11:05 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/09/18 18:11:05 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/09/18 18:11:05 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/18 18:11:05 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/09/18 18:11:05 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/18 18:11:05 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/09/18 18:11:05 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/18 18:11:05 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/09/18 18:11:05 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/09/18 18:11:05 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/09/18 18:11:05 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/09/18 18:11:05 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/09/18 18:11:05 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/09/18 18:11:05 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/09/18 18:11:05 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/09/18 18:11:05 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/09/18 18:11:05 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/09/18 18:11:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/09/18 18:11:05 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/09/18 18:11:05 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/09/18 18:11:05 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/09/18 18:11:05 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/09/18 18:11:05 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/09/18 18:11:05 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/09/18 18:11:05 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/09/18 18:11:05 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/09/18 18:11:05 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/18 18:11:05 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/09/18 18:11:05 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/09/18 18:11:05 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/09/18 18:11:05 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/18 18:11:05 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/09/18 18:11:05 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/09/18 18:11:05 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/09/18 18:11:05 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/09/18 18:11:05 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/09/18 18:11:05 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/09/18 18:11:05 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/09/18 18:11:05 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/18 18:11:05 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/09/18 18:11:05 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/09/18 18:11:05 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/18 18:11:05 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/09/18 18:11:05 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/18 18:11:05 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/09/18 18:11:05 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/18 18:11:05 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/18 18:11:05 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/09/18 18:11:05 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/09/18 18:11:05 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/09/18 18:11:05 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/09/18 18:11:05 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/09/18 18:09:12 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/09/18 18:09:12 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/09/18 18:09:12 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/09/18 18:09:12 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/09/18 18:09:12 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/09/18 18:09:12 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/09/18 18:09:12 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/09/18 18:09:12 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/09/18 18:09:12 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/09/18 18:09:12 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/09/18 18:09:12 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/09/18 18:09:12 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/09/18 18:09:12 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/09/18 18:09:12 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/09/18 18:09:12 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 17:16:39 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/09/18 17:16:39 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/09/18 17:16:39 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/09/18 17:16:38 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/09/18 17:16:09 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2013/09/18 17:16:09 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2013/09/18 17:14:23 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2013/09/18 17:14:23 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2013/09/18 17:07:27 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2013/09/18 17:07:27 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2013/09/18 17:07:27 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\en-US\wdf01000.sys.mui
[2013/09/18 16:49:39 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2013/09/18 16:49:39 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2013/09/18 16:49:39 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2013/09/18 16:49:39 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2013/09/18 16:42:16 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/09/18 16:42:16 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/09/18 16:41:07 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/09/18 16:41:06 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/09/18 16:41:06 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/09/18 16:34:51 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2013/09/18 16:34:49 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2013/09/18 16:34:49 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2013/09/18 16:33:17 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2013/09/18 16:33:17 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2013/09/18 16:29:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2013/09/18 16:29:20 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2013/09/18 16:27:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2013/09/18 16:24:38 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2013/09/18 16:24:22 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/09/18 16:24:21 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/09/18 16:24:20 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/09/18 16:24:19 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/09/18 16:24:19 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/09/18 16:24:19 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/09/18 16:24:19 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/09/18 16:24:19 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/09/18 16:24:19 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/09/18 16:24:19 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/09/18 16:24:19 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/09/18 16:24:19 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/09/18 16:24:18 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/09/18 16:24:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/09/18 16:24:18 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/09/18 16:24:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/09/18 16:24:18 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/09/18 16:24:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/09/18 16:24:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/09/18 16:24:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/09/18 16:24:18 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/09/18 16:24:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/09/18 16:24:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/18 16:24:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/18 16:24:16 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/09/18 16:24:16 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apisetschema.dll
[2013/09/18 16:24:16 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/09/18 16:24:16 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/18 16:24:16 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/18 16:24:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/09/18 16:24:15 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/09/18 16:24:15 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/09/18 16:24:15 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/09/18 16:23:57 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/09/18 16:23:57 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/09/18 16:23:51 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/09/18 16:23:47 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/09/18 16:23:29 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2013/09/18 16:23:29 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2013/09/18 16:23:29 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2013/09/18 16:23:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2013/09/18 16:23:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2013/09/18 16:20:12 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/09/18 16:20:11 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/09/18 16:20:11 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/09/18 16:20:05 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2013/09/18 16:20:05 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2013/09/18 16:20:05 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2013/09/18 16:19:45 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2013/09/18 16:19:45 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2013/09/18 16:19:40 | 000,155,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ataport.sys
[2013/09/18 16:19:39 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/09/18 16:19:39 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/09/18 16:19:26 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/09/18 16:19:26 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/09/18 16:17:59 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2013/09/18 16:17:58 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2013/09/18 16:17:58 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2013/09/18 16:17:58 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2013/09/18 16:17:58 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2013/09/18 16:17:57 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2013/09/18 16:17:57 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2013/09/18 16:15:58 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2013/09/18 16:15:06 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/09/18 16:15:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/09/18 16:15:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/09/18 16:15:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/09/18 16:15:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/09/18 16:15:02 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/09/18 16:15:02 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/09/18 16:15:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/09/18 16:15:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/09/18 16:15:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/09/18 16:15:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/09/18 16:15:02 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/09/18 16:15:02 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/09/18 16:15:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/09/18 16:15:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/09/18 16:15:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/09/18 16:15:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/09/18 16:15:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/09/18 16:15:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/09/18 16:15:00 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/09/18 16:14:59 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/09/18 16:14:58 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/09/18 16:14:58 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/09/18 16:14:56 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/09/18 16:14:56 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/09/18 16:14:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/09/18 16:14:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/09/18 16:14:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/09/18 16:14:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/09/18 16:14:56 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/09/18 16:14:55 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/09/18 16:14:55 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/09/18 16:14:55 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/09/18 16:10:23 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2013/09/18 15:57:11 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2013/09/18 15:54:58 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2013/09/18 15:54:58 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2013/09/18 15:54:38 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/09/18 15:54:15 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/09/18 15:54:15 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/09/18 15:54:02 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/09/18 15:53:28 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/09/18 15:53:28 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/09/18 15:53:20 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Atheros
[2013/09/18 15:52:40 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
[2013/09/18 15:52:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Atheros
[2013/09/18 15:52:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bluetooth Suite
[2013/09/18 15:52:02 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/09/18 15:51:52 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netapi32.dll
[2013/09/18 15:51:52 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browcli.dll
[2013/09/18 15:51:51 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\browcli.dll
[2013/09/18 15:51:40 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\srcore.dll
[2013/09/18 15:51:38 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2013/09/18 15:51:25 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/09/18 15:51:24 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/09/18 15:51:19 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/09/18 15:51:19 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/09/18 15:50:21 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2013/09/18 15:49:17 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2013/09/18 15:49:15 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2013/09/18 15:48:39 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/09/18 15:48:39 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/09/18 15:48:03 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\splwow64.exe
[2013/09/18 15:31:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote for VAIO
[2013/09/18 15:31:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Evernote
[2013/09/18 15:31:14 | 000,000,000 | —D | C] – C:\ProgramData\Evernote
[2013/09/18 15:30:37 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2013/09/18 15:29:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2013/09/18 15:28:51 | 000,000,000 | —D | C] – C:\ProgramData\DDNi
[2013/09/18 15:28:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\DDNi
[2013/09/18 15:28:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2013/09/18 15:27:31 | 000,000,000 | —D | C] – C:\ProgramData\CLSK
[2013/09/18 15:23:41 | 000,069,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\offreg.dll
[2013/09/18 15:23:41 | 000,021,176 | —- | C] (iolo technologies, LLC) – C:\Windows\SysNative\iolorgdf64.exe
[2013/09/18 15:23:41 | 000,000,000 | —D | C] – C:\ProgramData\iolo
[2013/09/18 15:19:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2013/09/18 15:15:41 | 000,000,000 | —D | C] – C:\Windows\en
[2013/09/18 15:15:14 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013/09/18 15:14:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2013/09/18 15:14:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2013/09/18 15:14:06 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2013/09/18 15:14:04 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2013/09/18 15:13:55 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/09/18 15:13:55 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/09/18 15:13:55 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/09/18 15:13:53 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2013/09/18 15:13:53 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2013/09/18 15:13:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2013/09/18 15:10:35 | 000,000,000 | —D | C] – C:\Windows\SysWow64\spool
[2013/09/18 15:10:24 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\iolo
[2013/09/18 15:10:10 | 000,000,000 | RH-D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
[2013/09/18 15:10:10 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/09/18 15:05:44 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Vegas Movie Studio HD Platinum 10.0
[2013/09/18 15:05:28 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Sound Forge Audio Studio 10.0
[2013/09/18 15:04:54 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Songs
[2013/09/18 15:03:34 | 000,000,000 | —D | C] – C:\Users\Public\Documents\ACID Music Studio 8.0
[2013/09/18 15:02:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\15 ACID Projects for VAIO
[2013/09/18 15:00:50 | 000,000,000 | —D | C] – C:\Update
[2013/09/18 14:56:12 | 000,000,000 | —D | C] – C:\VAIO Sample Contents
[2013/09/18 14:52:10 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\BMExplorer
[2013/09/18 14:52:10 | 000,000,000 | —D | C] – C:\Users\Heidi\Documents\Bluetooth Folder
[2013/09/18 14:52:03 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Intel Corporation
[2013/09/18 14:51:00 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/09/18 14:51:00 | 000,000,000 | R–D | C] – C:\Users\Heidi\Searches
[2013/09/18 14:51:00 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/09/18 14:50:59 | 000,000,000 | -H-D | C] – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/09/18 14:50:47 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Identities
[2013/09/18 14:50:45 | 000,000,000 | R–D | C] – C:\Users\Heidi\Contacts
[2013/09/18 14:50:01 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\VirtualStore
[2013/09/18 14:48:57 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/09/18 14:48:29 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Sony Corporation
[2013/09/18 14:47:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\VAIO Startup Setting Tool
[2013/09/18 14:47:48 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/09/18 14:47:38 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/09/18 14:47:38 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/09/18 14:47:38 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2013/09/18 14:47:13 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/09/18 14:47:13 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/09/18 14:47:13 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2013/09/18 14:47:05 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Sony Corporation
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\AppData\Local\Temporary Internet Files
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Templates
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Start Menu
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\SendTo
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Recent
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\PrintHood
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\NetHood
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Documents\My Videos
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Documents\My Pictures
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Documents\My Music
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\My Documents
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Local Settings
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\AppData\Local\History
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Cookies
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Application Data
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\AppData\Local\Application Data
[2013/09/18 14:46:53 | 000,000,000 | –SD | C] – C:\Users\Heidi\AppData\Roaming\Microsoft
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Videos
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Saved Games
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Pictures
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Music
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Links
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Favorites
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Downloads
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Documents
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Desktop
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/09/18 14:46:53 | 000,000,000 | -H-D | C] – C:\Users\Heidi\AppData
[2013/09/18 14:46:53 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Temp
[2013/09/18 14:46:53 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Microsoft
[2013/09/18 14:46:53 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Media Center Programs
[2013/09/18 14:46:50 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/09/18 14:46:50 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/09/18 14:44:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home
[2013/09/18 14:42:45 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/09/18 14:42:45 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/09/18 14:42:45 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/09/18 14:40:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013/09/18 14:39:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony Media Go Install
[2013/09/18 14:36:37 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/09/18 14:36:37 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/09/18 14:36:37 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/09/18 14:36:36 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/09/18 14:36:35 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 3D
[2013/09/18 14:36:35 | 000,000,000 | —D | C] – C:\ProgramData\DDD
[2013/09/18 14:36:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\TriDef 3D
[2013/09/18 14:33:56 | 000,029,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2013/09/18 14:33:45 | 000,000,000 | —D | C] – C:\ProgramData\Temp
[2013/09/18 14:31:52 | 000,212,480 | —- | C] (Eastman Kodak) – C:\Windows\SysWow64\PCDLIB32.DLL
[2013/09/18 14:31:50 | 000,055,808 | —- | C] (ArcSoft, Inc.) – C:\Windows\System\ArcSoftKsUFilter.dll
[2013/09/18 14:31:50 | 000,019,968 | —- | C] (ArcSoft, Inc.) – C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys
[2013/09/18 14:31:49 | 000,245,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\unicows.dll
[2013/09/18 14:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Webcam Suite
[2013/09/18 14:28:23 | 000,000,000 | —D | C] – C:\ProgramData\ArcSoft
[2013/09/18 14:28:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ArcSoft
[2013/09/18 14:28:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ArcSoft
[2013/09/18 14:25:55 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2013/09/18 14:25:37 | 000,692,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/18 14:25:36 | 000,071,048 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/18 14:25:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2013/09/18 14:25:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2013/09/18 14:19:22 | 000,000,000 | —D | C] – C:\Documentation
[2013/09/18 14:06:47 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Main
[2013/09/18 13:59:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2013/09/18 13:56:07 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/09/18 13:56:07 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/09/18 13:56:07 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/09/18 13:56:07 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/09/18 13:56:06 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/09/18 13:56:06 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2013/09/18 13:56:06 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/09/18 13:56:06 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2013/09/18 13:56:06 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2013/09/18 13:56:06 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2013/09/18 13:56:06 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2013/09/18 13:56:06 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2013/09/18 13:56:06 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/09/18 13:56:06 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/09/18 13:56:06 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2013/09/18 13:56:06 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2013/09/18 13:53:52 | 000,000,000 | —D | C] – C:\ProgramData\eBay_icon
[2013/09/18 13:48:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reader for PC
[2013/09/18 13:47:56 | 000,000,000 | —D | C] – C:\Program Files\PlayReady
[2013/09/18 13:47:36 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2013/09/18 13:46:28 | 000,000,000 | —D | C] – C:\ProgramData\Sony Corporation
[2013/09/18 13:46:27 | 000,000,000 | —D | C] – C:\Program Files\Sony
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\winrm
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\UMDF
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\sysprep
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\slmgr
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\UMDF\en-US
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\en-US
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\en
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\0409
[2013/09/18 13:45:17 | 000,000,000 | —D | C] – C:\Windows\SysWow64\WCN
[2013/09/18 13:45:17 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Printing_Admin_Scripts
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\winrm
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\slmgr
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\en
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\0409
[2013/09/18 13:45:06 | 000,000,000 | —D | C] – C:\Windows\SysNative\WCN
[2013/09/18 13:45:06 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\en-US
[2013/09/18 13:45:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\Printing_Admin_Scripts
[2013/09/18 13:39:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2013/09/18 13:35:58 | 000,000,000 | —D | C] – C:\Windows\Sonysys
[2013/09/18 13:34:15 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/09/18 13:34:10 | 000,790,440 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/09/18 13:33:57 | 000,627,600 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/09/18 13:33:57 | 000,252,296 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/09/18 13:33:57 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/09/18 13:33:57 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/09/18 13:33:54 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/09/18 13:33:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Sony Shared
[2013/09/18 13:33:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Sony Shared
[2013/09/18 13:33:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel Corporation
[2013/09/18 13:28:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2013/09/18 13:27:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony Corporation
[2013/09/18 13:24:46 | 002,807,808 | —- | C] (Atheros Communications, Inc.) – C:\Windows\SysNative\drivers\athrx.sys
[2013/09/18 13:24:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation
[2013/09/18 13:23:48 | 000,000,000 | —D | C] – C:\ProgramData\Qualcomm Atheros
[2013/09/18 13:21:56 | 000,041,984 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\USB3Ver.dll
[2013/09/18 13:20:38 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2013/09/18 13:20:12 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2013/09/18 13:18:10 | 000,000,000 | —D | C] – C:\Windows\SysWow64\sda
[2013/09/18 13:18:08 | 000,339,048 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\drivers\RtsPStor.sys
[2013/09/18 13:18:07 | 009,888,872 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysWow64\RtsPStorIcon.dll
[2013/09/18 13:16:21 | 000,000,000 | —D | C] – C:\ProgramData\Intel
[2013/09/18 13:16:19 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2013/09/18 13:16:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\postureAgent
[2013/09/18 13:15:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intel
[2013/09/18 13:15:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel
[2013/09/18 13:08:13 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2013/09/18 13:08:13 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2013/09/18 13:08:03 | 005,996,376 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek.dll
[2013/09/18 13:08:03 | 003,846,248 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2013/09/18 13:08:03 | 003,308,376 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEP64A.dll
[2013/09/18 13:08:03 | 002,728,960 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoRes64.dat
[2013/09/18 13:08:03 | 002,652,264 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2013/09/18 13:08:03 | 002,603,864 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib.dll
[2013/09/18 13:08:03 | 002,131,288 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ.dll
[2013/09/18 13:08:03 | 001,560,168 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2013/09/18 13:08:03 | 001,361,336 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tosade.dll
[2013/09/18 13:08:03 | 001,247,848 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2013/09/18 13:08:03 | 001,247,576 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek264.dll
[2013/09/18 13:08:03 | 000,958,296 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPOShell64.dll
[2013/09/18 13:08:03 | 000,836,544 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tadefxapo264.dll
[2013/09/18 13:08:03 | 000,823,912 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2013/09/18 13:08:03 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2013/09/18 13:08:03 | 000,426,328 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EED64A.dll
[2013/09/18 13:08:03 | 000,375,128 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2013/09/18 13:08:03 | 000,334,680 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2013/09/18 13:08:03 | 000,331,880 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2013/09/18 13:08:03 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2013/09/18 13:08:03 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2013/09/18 13:08:03 | 000,221,024 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFNHK64.dll
[2013/09/18 13:08:03 | 000,220,776 | —- | C] (Sony Corporation) – C:\Windows\SysNative\SFSS_APO.dll
[2013/09/18 13:08:03 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2013/09/18 13:08:03 | 000,204,120 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2013/09/18 13:08:03 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2013/09/18 13:08:03 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2013/09/18 13:08:03 | 000,149,608 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2013/09/18 13:08:03 | 000,148,416 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tadefxapo.dll
[2013/09/18 13:08:03 | 000,136,024 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEL64A.dll
[2013/09/18 13:08:03 | 000,118,104 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEA64A.dll
[2013/09/18 13:08:03 | 000,101,208 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2013/09/18 13:08:03 | 000,100,968 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInstII64.dll
[2013/09/18 13:08:03 | 000,081,248 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFCOM64.dll
[2013/09/18 13:08:03 | 000,078,688 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFAPO64.dll
[2013/09/18 13:08:03 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2013/09/18 13:08:03 | 000,074,072 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEG64A.dll
[2013/09/18 13:08:03 | 000,074,064 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:\Windows\SysWow64\SFCOM.dll
[2013/09/18 13:08:03 | 000,065,944 | —- | C] (TOSHIBA CORPORATION.) – C:\Windows\SysNative\tepeqapo64.dll
[2013/09/18 13:08:03 | 000,014,952 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCoLDR64.dll
[2013/09/18 13:08:02 | 000,603,984 | —- | C] (Knowles Acoustics ) – C:\Windows\SysNative\KAAPORT64.dll
[2013/09/18 13:08:02 | 000,341,336 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO30.dll
[2013/09/18 13:08:02 | 000,318,808 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2013/09/18 13:08:01 | 002,528,832 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2013/09/18 13:08:01 | 001,756,264 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2013/09/18 13:08:01 | 001,568,360 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2013/09/18 13:08:01 | 001,486,952 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2013/09/18 13:08:01 | 000,728,680 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2013/09/18 13:08:01 | 000,712,296 | —- | C] (DTS) – C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2013/09/18 13:08:01 | 000,693,352 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2013/09/18 13:08:01 | 000,537,456 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PLFX64.dll
[2013/09/18 13:08:01 | 000,524,656 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PGFX64.dll
[2013/09/18 13:08:01 | 000,491,112 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2013/09/18 13:08:01 | 000,449,392 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PREC64.dll
[2013/09/18 13:08:01 | 000,432,744 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2013/09/18 13:08:01 | 000,428,648 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2013/09/18 13:08:01 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2013/09/18 13:08:01 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2013/09/18 13:08:01 | 000,241,768 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPONS64.dll
[2013/09/18 13:08:01 | 000,200,800 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2013/09/18 13:08:01 | 000,108,960 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2013/09/18 13:08:01 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2013/09/18 13:08:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2013/09/18 13:08:00 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/09/18 13:07:59 | 001,698,408 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2013/09/18 13:07:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2013/09/18 13:05:39 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\SysWow64\CSVer.dll
[2013/09/18 13:05:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2013/09/18 13:05:36 | 000,000,000 | —D | C] – C:\Intel
[2013/09/18 13:03:19 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2013/09/18 13:03:19 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2013/09/18 13:03:19 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2013/09/18 13:03:19 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2013/09/18 13:03:19 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2013/09/18 13:03:19 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2013/09/18 13:03:18 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2013/09/18 12:53:17 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2013/09/18 12:47:04 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2013/09/24 08:36:53 | 000,001,260 | —- | M] () – C:\Users\Heidi\Desktop\My DAP Downloads.lnk
[2013/09/24 08:36:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL_1.exe
[2013/09/24 08:32:51 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL.exe
[2013/09/24 08:30:14 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Heidi\Desktop\aswMBR.exe
[2013/09/24 08:25:37 | 000,020,992 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/24 08:25:37 | 000,020,992 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/24 08:18:03 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/24 08:17:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/24 08:17:46 | 460,079,103 | -HS- | M] () – C:\hiberfil.sys
[2013/09/23 16:59:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/23 16:58:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/23 10:48:26 | 000,001,188 | —- | M] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/09/23 10:18:48 | 000,891,144 | —- | M] () – C:\Users\Heidi\Desktop\SecurityCheck.exe
[2013/09/21 13:24:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Heidi\Desktop\HiJackThis.exe
[2013/09/21 12:59:13 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/21 12:59:13 | 000,660,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/21 12:59:13 | 000,121,214 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/19 17:47:23 | 000,659,968 | —- | M] () – C:\Users\Heidi\Documents\MicrosoftFixit50195.msi
[2013/09/19 17:00:36 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/19 17:00:36 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/19 15:57:50 | 000,659,456 | —- | M] () – C:\Users\Heidi\Documents\MicrosoftFixit50526_1.msi
[2013/09/19 15:55:54 | 000,659,456 | —- | M] () – C:\Users\Heidi\Documents\MicrosoftFixit50526.msi
[2013/09/19 11:23:14 | 001,310,720 | —- | M] () – C:\Users\Heidi\NTUSER.BAK
[2013/09/19 08:50:23 | 000,002,279 | —- | M] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/18 21:52:23 | 000,868,264 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/09/18 21:52:23 | 000,790,440 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/09/18 21:52:23 | 000,264,616 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/09/18 21:52:23 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/09/18 21:52:23 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/09/18 21:52:23 | 000,096,168 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/09/18 21:39:43 | 000,443,800 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/18 21:38:43 | 001,048,576 | -HS- | M] () – C:\Users\Heidi\NTUSER.BK1
[2013/09/18 20:18:12 | 000,001,098 | —- | M] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Copernic Agent Personal.lnk
[2013/09/18 19:42:57 | 000,172,032 | —- | M] (Jin Hui E-mail: [removed] Web: http://www.jcomsoft.com) – C:\Windows\SysWow64\AniGIF.ocx
[2013/09/18 19:19:43 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013/09/18 18:36:26 | 000,001,407 | —- | M] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/09/18 18:11:06 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/09/18 18:11:06 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/09/18 18:11:06 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/09/18 18:11:05 | 003,959,296 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/18 18:11:05 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/09/18 18:11:05 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/09/18 18:11:05 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/09/18 18:11:05 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/09/18 18:11:05 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/18 18:11:05 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/09/18 18:11:05 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/18 18:11:05 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/09/18 18:11:05 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/18 18:11:05 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/09/18 18:11:05 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/09/18 18:11:05 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/09/18 18:11:05 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/09/18 18:11:05 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/09/18 18:11:05 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/09/18 18:11:05 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/09/18 18:11:05 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/09/18 18:11:05 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/09/18 18:11:05 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/09/18 18:11:05 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/09/18 18:11:05 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/09/18 18:11:05 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/09/18 18:11:05 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/09/18 18:11:05 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/09/18 18:11:05 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/09/18 18:11:05 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/09/18 18:11:05 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/09/18 18:11:05 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/09/18 18:11:05 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/18 18:11:05 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/09/18 18:11:05 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/09/18 18:11:05 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/09/18 18:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/18 18:11:05 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/09/18 18:11:05 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/09/18 18:11:05 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/09/18 18:11:05 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/09/18 18:11:05 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/09/18 18:11:05 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/09/18 18:11:05 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/09/18 18:11:05 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/18 18:11:05 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/09/18 18:11:05 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/09/18 18:11:05 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/18 18:11:05 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/09/18 18:11:05 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/18 18:11:05 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/09/18 18:11:05 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/18 18:11:05 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/18 18:11:05 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/09/18 18:11:05 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/09/18 18:11:05 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/09/18 18:11:05 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/09/18 18:11:05 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/09/18 18:11:05 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/09/18 18:11:05 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/09/18 18:09:12 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/09/18 18:09:12 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/09/18 18:09:12 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/09/18 18:09:12 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/09/18 18:09:12 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/09/18 18:09:12 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/09/18 18:09:12 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/09/18 18:09:12 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/09/18 18:09:12 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/09/18 18:09:12 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/09/18 18:09:12 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/09/18 18:09:12 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/09/18 18:09:12 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/09/18 18:09:12 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/09/18 18:09:12 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 17:57:48 | 000,773,050 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/09/18 15:53:22 | 000,246,804 | —- | M] () – C:\Windows\SysNative\drivers\AtherosBt.bin
[2013/09/18 15:53:22 | 000,001,796 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x11020000_40.dfu
[2013/09/18 15:53:22 | 000,001,434 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x31010000_40.dfu
[2013/09/18 15:53:22 | 000,001,242 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2013/09/18 15:53:22 | 000,001,228 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2013/09/18 15:53:22 | 000,001,214 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2013/09/18 15:53:22 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020201_40.dfu
[2013/09/18 15:53:22 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2013/09/18 15:53:22 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40.dfu
[2013/09/18 15:53:22 | 000,001,198 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020201_26.dfu
[2013/09/18 15:53:22 | 000,001,198 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_26.dfu
[2013/09/18 15:53:22 | 000,001,192 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2013/09/18 15:38:27 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2013/09/18 15:38:27 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2013/09/18 15:33:04 | 000,002,073 | —- | M] () – C:\Windows\SysNative\snyinst.oem
[2013/09/18 15:29:16 | 000,029,480 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2013/09/18 15:23:41 | 000,074,703 | —- | M] () – C:\Windows\SysWow64\mfc45.dll
[2013/09/18 15:10:11 | 000,002,044 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Sony MSS.lnk
[2013/09/18 14:50:39 | 000,000,000 | RH– | M] () – C:\Windows\SysWow64\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 14:50:39 | 000,000,000 | RH– | M] () – C:\Windows\SysNative\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 13:51:42 | 000,196,608 | —- | M] () – C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2013/09/18 13:33:55 | 000,627,600 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/09/18 13:33:55 | 000,252,296 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/09/18 13:33:55 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/09/18 13:33:55 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/09/18 13:30:16 | 000,014,960 | —- | M] () – C:\Windows\SysNative\results.xml
[2013/09/18 13:22:33 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/09/18 13:20:17 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2013/09/18 13:12:43 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf

========== Files Created - No Company Name ==========

[2013/09/23 10:48:26 | 000,001,188 | —- | C] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/09/23 10:18:43 | 000,891,144 | —- | C] () – C:\Users\Heidi\Desktop\SecurityCheck.exe
[2013/09/19 17:47:16 | 000,659,968 | —- | C] () – C:\Users\Heidi\Documents\MicrosoftFixit50195.msi
[2013/09/19 15:57:38 | 000,659,456 | —- | C] () – C:\Users\Heidi\Documents\MicrosoftFixit50526_1.msi
[2013/09/19 15:55:52 | 000,659,456 | —- | C] () – C:\Users\Heidi\Documents\MicrosoftFixit50526.msi
[2013/09/18 21:47:35 | 000,002,279 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/18 21:46:55 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/18 21:46:53 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/18 21:46:22 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/09/18 20:31:52 | 000,035,000 | —- | C] () – C:\Windows\SysNative\mxntdfg.exe
[2013/09/18 20:31:51 | 000,020,488 | —- | C] () – C:\Windows\SysNative\drivers\AQFileRestore.sys
[2013/09/18 20:31:51 | 000,001,984 | —- | C] () – C:\Windows\SysNative\drivers\AQFileRestore.inf
[2013/09/18 20:31:38 | 000,002,210 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SystemSuite Professional.lnk
[2013/09/18 20:18:12 | 000,001,098 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Copernic Agent Personal.lnk
[2013/09/18 20:11:21 | 000,001,086 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Copernic Agent Personal.lnk
[2013/09/18 20:11:19 | 000,109,782 | —- | C] () – C:\Windows\CopernicAgentUninstall.exe
[2013/09/18 19:43:42 | 000,001,260 | —- | C] () – C:\Users\Heidi\Desktop\My DAP Downloads.lnk
[2013/09/18 19:19:43 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013/09/18 18:36:26 | 000,001,407 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/09/18 18:11:05 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/09/18 18:11:05 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/09/18 17:07:29 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/09/18 16:49:39 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/09/18 15:36:50 | 000,001,141 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
[2013/09/18 15:33:04 | 460,079,103 | -HS- | C] () – C:\hiberfil.sys
[2013/09/18 15:23:41 | 000,074,703 | —- | C] () – C:\Windows\SysWow64\mfc45.dll
[2013/09/18 15:15:07 | 000,001,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2013/09/18 15:14:58 | 000,001,374 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2013/09/18 15:14:42 | 000,001,458 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013/09/18 15:14:37 | 000,002,486 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013/09/18 15:10:11 | 000,002,044 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Sony MSS.lnk
[2013/09/18 15:10:10 | 000,002,017 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care.lnk
[2013/09/18 14:56:22 | 000,001,275 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Transfer.lnk
[2013/09/18 14:52:56 | 000,002,072 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Gate.lnk
[2013/09/18 14:51:31 | 000,002,679 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Easy Connect.lnk
[2013/09/18 14:51:05 | 000,001,413 | —- | C] () – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/09/18 14:50:39 | 000,000,000 | RH– | C] () – C:\Windows\SysWow64\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 14:50:39 | 000,000,000 | RH– | C] () – C:\Windows\SysNative\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 14:50:33 | 000,002,067 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music Unlimited.lnk
[2013/09/18 14:46:53 | 000,000,290 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/09/18 14:46:53 | 000,000,272 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/09/18 14:46:52 | 001,310,720 | —- | C] () – C:\Users\Heidi\NTUSER.BAK
[2013/09/18 14:46:52 | 001,048,576 | -HS- | C] () – C:\Users\Heidi\NTUSER.BK1
[2013/09/18 14:44:11 | 000,001,297 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home.lnk
[2013/09/18 14:25:37 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/18 14:23:27 | 000,002,197 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Smart Network.lnk
[2013/09/18 14:19:24 | 000,001,995 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Manual.lnk
[2013/09/18 14:16:24 | 000,002,269 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Data Restore Tool.lnk
[2013/09/18 14:15:15 | 000,001,531 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Control Center.lnk
[2013/09/18 14:13:55 | 000,002,390 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Gesture Control.lnk
[2013/09/18 14:12:41 | 000,001,396 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO3DPortal.lnk
[2013/09/18 13:54:58 | 000,002,241 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Gallery.lnk
[2013/09/18 13:51:24 | 000,196,608 | —- | C] () – C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2013/09/18 13:47:35 | 000,000,869 | —- | C] () – C:\Windows\SysWow64\media_center.png
[2013/09/18 13:44:46 | 000,001,203 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Keyboard Shortcuts.lnk
[2013/09/18 13:30:16 | 000,014,960 | —- | C] () – C:\Windows\SysNative\results.xml
[2013/09/18 13:22:33 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/09/18 13:20:17 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2013/09/18 13:16:24 | 000,015,128 | —- | C] () – C:\Windows\SysNative\drivers\IntelMEFWVer.dll
[2013/09/18 13:12:43 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2013/09/18 13:08:03 | 000,227,876 | —- | C] () – C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2013/09/18 12:49:36 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013/09/18 12:49:24 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013/03/07 05:07:20 | 000,091,264 | —- | C] () – C:\Windows\SysWow64\EasyHook32.dll
[2012/03/14 14:54:37 | 000,734,772 | —- | C] () – C:\Windows\SysWow64\igkrng700.bin
[2012/03/14 14:54:36 | 012,978,688 | —- | C] () – C:\Windows\SysWow64\ig7icd32.dll
[2012/03/14 14:54:36 | 000,557,476 | —- | C] () – C:\Windows\SysWow64\igfcg700m.bin
[2012/03/14 14:54:36 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/02/02 23:08:26 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/07/25 20:24:57 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/07/25 19:55:59 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 19:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 21:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 19:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/09/18 21:52:13 | 000,000,000 | —D | M] – C:\Users\Heidi\AppData\Roaming\Avanquest
[2013/09/18 20:18:22 | 000,000,000 | —D | M] – C:\Users\Heidi\AppData\Roaming\Copernic
[2013/09/24 08:29:37 | 000,000,000 | —D | M] – C:\Users\Heidi\AppData\Roaming\EQATEC Analytics
[2013/09/18 15:10:24 | 000,000,000 | —D | M] – C:\Users\Heidi\AppData\Roaming\iolo

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009/07/13 23:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/13 23:08:49 | 000,013,646 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2013/09/18 14:25:37 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/09/18 21:46:53 | 000,000,892 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013/09/18 21:46:55 | 000,000,896 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 01:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 14:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2012/02/23 18:18:12 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2012/02/23 18:18:12 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2012/02/23 18:18:12 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2012/02/23 18:18:12 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 21:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2012/02/23 18:18:12 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2012/02/23 18:18:12 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 21:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 01:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 01:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 01:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 01:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/09/18 21:53:22 | 000,052,350 | —- | M] () MD5=5F0A8ECC2E6703A70C09F0571BF774A3 – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: IEXPLORE.EXE >
[2013/07/31 04:18:24 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=10C1F2EC48D524AE10229AACD37B172A – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20617_none_1843b546cdda6584\iexplore.exe
[2013/09/18 18:11:05 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Program Files\Internet Explorer\iexplore.exe
[2013/09/18 18:11:05 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_168ab5d61e3c99b7\iexplore.exe
[2013/09/18 18:11:05 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/09/18 18:11:05 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_20df6028529d5bb2\iexplore.exe
[2010/11/20 21:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/02/23 18:21:12 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2013/07/31 08:22:10 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=A818D637533302BA58C685F332388FC0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16506_none_0d6f3dcb8054ce77\iexplore.exe
[2013/07/31 04:39:59 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=AA9CBDCD4675A48755DDA3A73BE3E283 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16506_none_17c3e81db4b59072\iexplore.exe
[2010/11/20 21:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/07/31 07:01:01 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=E1D016741AA03A959586A7818595BF46 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20617_none_0def0af49979a389\iexplore.exe
[2012/02/23 18:21:11 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/02/23 18:21:12 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/02/23 18:21:12 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/09/18 18:11:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/09/18 18:11:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/09/18 18:11:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/09/18 18:11:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 20:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 20:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 15:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/09/05 08:04:00 | 000,559,090 | —- | M] () MD5=8ADD48E413D05BF2E7AEC00173DDFABC – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 19:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 19:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 01:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 01:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 22:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 14:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 14:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 01:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 14:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 01:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 15:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 01:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 14:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 01:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 15:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 14:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 14:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 01:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 15:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 21:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 21:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 01:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 01:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 01:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 01:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 14:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 14:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/09/18 17:58:21 | 000,000,842 | —- | M] () – C:\Asp_20130918.log
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/09/24 08:17:46 | 460,079,103 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2013/09/24 08:17:47 | 268,435,456 | -HS- | M] () – C:\pagefile.sys
[2013/09/18 13:08:27 | 000,002,197 | —- | M] () – C:\RHDSetup.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 16:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 8CF8-AC88
Directory of C:\
07/13/2009 11:08 PM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\Program Files (x86)\Evernote
09/18/2013 03:31 PM Evernote3.5 [C:\Program Files (x86)\Evernote\Evernote\]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/13/2009 11:08 PM Application Data [C:\ProgramData]
07/13/2009 11:08 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 11:08 PM Documents [C:\Users\Public\Documents]
07/13/2009 11:08 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 11:08 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 11:08 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/13/2009 11:08 PM All Users [C:\ProgramData]
07/13/2009 11:08 PM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/13/2009 11:08 PM Application Data [C:\ProgramData]
07/13/2009 11:08 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 11:08 PM Documents [C:\Users\Public\Documents]
07/13/2009 11:08 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 11:08 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 11:08 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/13/2009 11:08 PM Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009 11:08 PM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/13/2009 11:08 PM Local Settings [C:\Users\Default\AppData\Local]
07/13/2009 11:08 PM My Documents [C:\Users\Default\Documents]
07/13/2009 11:08 PM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009 11:08 PM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 11:08 PM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009 11:08 PM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 11:08 PM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 11:08 PM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/13/2009 11:08 PM Application Data [C:\Users\Default\AppData\Local]
07/13/2009 11:08 PM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009 11:08 PM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/13/2009 11:08 PM My Music [C:\Users\Default\Music]
07/13/2009 11:08 PM My Pictures [C:\Users\Default\Pictures]
07/13/2009 11:08 PM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Heidi
09/18/2013 02:46 PM Application Data [C:\Users\Heidi\AppData\Roaming]
09/18/2013 02:46 PM Cookies [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Cookies]
09/18/2013 02:46 PM Local Settings [C:\Users\Heidi\AppData\Local]
09/18/2013 02:46 PM My Documents [C:\Users\Heidi\Documents]
09/18/2013 02:46 PM NetHood [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/18/2013 02:46 PM PrintHood [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/18/2013 02:46 PM Recent [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Recent]
09/18/2013 02:46 PM SendTo [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\SendTo]
09/18/2013 02:46 PM Start Menu [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu]
09/18/2013 02:46 PM Templates [C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Heidi\AppData\Local
09/18/2013 02:46 PM Application Data [C:\Users\Heidi\AppData\Local]
09/18/2013 02:46 PM History [C:\Users\Heidi\AppData\Local\Microsoft\Windows\History]
09/18/2013 02:46 PM Temporary Internet Files [C:\Users\Heidi\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Heidi\Documents
09/18/2013 02:46 PM My Music [C:\Users\Heidi\Music]
09/18/2013 02:46 PM My Pictures [C:\Users\Heidi\Pictures]
09/18/2013 02:46 PM My Videos [C:\Users\Heidi\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/13/2009 11:08 PM My Music [C:\Users\Public\Music]
07/13/2009 11:08 PM My Pictures [C:\Users\Public\Pictures]
07/13/2009 11:08 PM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
51 Dir(s) 570,108,641,280 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/09/18 18:36:26 | 000,000,221 | -HS- | M] () – C:\Users\Heidi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/09/24 08:30:14 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Heidi\Desktop\aswMBR.exe
[2013/09/21 13:24:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Heidi\Desktop\HiJackThis.exe
[2013/09/24 08:32:51 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL.exe
[2013/09/24 08:36:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL_1.exe
[2013/09/23 10:18:48 | 000,891,144 | —- | M] () – C:\Users\Heidi\Desktop\SecurityCheck.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2011/12/19 03:04:46 | 000,000,698 | —- | M] () – C:\Windows\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Base Services ==========
SRV:64bit: - [2009/07/13 19:40:01 | 000,072,192 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\aelupsvc.dll – (AeLookupSvc)
SRV:64bit: - [2013/02/26 23:47:10 | 000,070,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\appinfo.dll – (Appinfo)
SRV:64bit: - [2009/07/13 19:38:55 | 000,079,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\alg.exe – (ALG)
SRV:64bit: - [2010/11/20 21:23:51 | 000,849,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\qmgr.dll – (BITS)
SRV:64bit: - [2010/11/20 21:24:00 | 000,705,024 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\BFE.DLL – (BFE)
SRV:64bit: - [2012/02/23 18:24:04 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\lsass.exe – (KeyIso)
SRV:64bit: - [2009/07/13 19:40:50 | 000,402,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\es.dll – (EventSystem)
SRV - [2009/07/13 19:15:19 | 000,271,360 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\es.dll – (EventSystem)
SRV:64bit: - [2012/07/04 16:13:27 | 000,136,704 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\browser.dll – (Browser)
SRV:64bit: - [2013/07/08 23:46:20 | 000,184,320 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\cryptsvc.dll – (CryptSvc)
SRV - [2013/07/08 22:46:31 | 000,140,288 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\cryptsvc.dll – (CryptSvc)
SRV:64bit: - [2010/11/20 21:24:01 | 000,512,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\rpcss.dll – (DcomLaunch)
SRV:64bit: - [2010/11/20 21:24:00 | 000,317,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV - [2010/11/20 21:24:09 | 000,254,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2012/02/23 18:17:34 | 000,183,296 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dnsrslvr.dll – (Dnscache)
SRV:64bit: - [2009/07/13 19:40:35 | 000,111,104 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\eapsvc.dll – (EapHost)
SRV:64bit: - [2009/07/13 19:41:00 | 000,038,912 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\hidserv.dll – (hidserv)
SRV - [2009/07/13 19:15:24 | 000,049,152 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\hidserv.dll – (hidserv)
SRV:64bit: - [2009/07/13 19:41:10 | 000,359,424 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\SysNative\ipnathlp.dll – (SharedAccess)
SRV:64bit: - [2010/11/20 21:23:48 | 000,501,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\IPSECSVC.DLL – (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:64bit: - [2009/07/13 19:41:54 | 000,524,288 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\swprv.dll – (swprv)
SRV:64bit: - [2009/07/13 19:41:26 | 000,067,584 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\mmcss.dll – (MMCSS)
SRV:64bit: - [2009/07/13 19:41:52 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netman.dll – (Netman)
SRV:64bit: - [2009/07/13 19:41:52 | 000,459,776 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofm.dll – (netprofm)
SRV - [2009/07/13 19:16:03 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\netprofm.dll – (netprofm)
SRV:64bit: - [2012/10/03 11:44:21 | 000,303,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\nlasvc.dll – (NlaSvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,025,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\nsisvc.dll – (nsi)
SRV:64bit: - [2012/02/23 18:20:09 | 000,404,480 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpnpmgr.dll – (PlugPlay)
SRV:64bit: - [2012/02/11 00:36:02 | 000,559,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\spoolsv.exe – (Spooler)
SRV:64bit: - [2012/02/23 18:24:04 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\lsass.exe – (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009/07/13 19:41:53 | 000,099,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\rasauto.dll – (RasAuto)
SRV:64bit: - [2010/11/20 21:24:17 | 000,344,064 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\rasmans.dll – (RasMan)
SRV:64bit: - [2010/11/20 21:24:01 | 000,512,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\rpcss.dll – (RpcSs)
SRV:64bit: - [2010/11/20 21:24:16 | 000,030,720 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\seclogon.dll – (seclogon)
SRV:64bit: - [2012/02/23 18:24:04 | 000,031,232 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsass.exe – (SamSs)
SRV:64bit: - [2009/07/13 19:41:58 | 000,097,280 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wscsvc.dll – (wscsvc)
SRV:64bit: - [2010/11/20 21:23:48 | 000,236,032 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\srvsvc.dll – (LanmanServer)
SRV:64bit: - [2010/11/20 21:23:55 | 000,370,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\shsvcs.dll – (ShellHWDetection)
SRV - [2010/11/20 21:24:03 | 000,328,192 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\shsvcs.dll – (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010/11/20 21:24:16 | 001,110,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\schedsvc.dll – (Schedule)
SRV:64bit: - [2010/11/20 21:24:32 | 000,316,928 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\tapisrv.dll – (TapiSrv)
SRV - [2010/11/20 21:24:00 | 000,242,176 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\tapisrv.dll – (TapiSrv)
SRV:64bit: - [2009/07/13 19:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2012/04/30 23:40:20 | 000,209,920 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\profsvc.dll – (ProfSvc)
SRV:64bit: - [2010/11/20 21:23:55 | 001,600,512 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\VSSVC.exe – (VSS)
SRV:64bit: - [2010/11/20 21:24:32 | 000,679,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\audiosrv.dll – (AudioSrv)
SRV:64bit: - [2010/11/20 21:24:32 | 000,679,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\audiosrv.dll – (AudioEndpointBuilder)
SRV:64bit: - [2010/11/20 21:25:06 | 000,170,496 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sdrsvc.dll – (SDRSVC)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2010/11/20 21:23:55 | 001,646,080 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wevtsvc.dll – (eventlog)
SRV:64bit: - [2010/11/20 21:24:28 | 000,828,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\MPSSVC.dll – (MpsSvc)
SRV:64bit: - [2010/11/20 21:24:48 | 000,580,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wiaservc.dll – (stisvc)
SRV:64bit: - [2010/11/20 21:24:15 | 000,128,000 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\msiexec.exe – (msiserver)
SRV - [2010/11/20 21:24:28 | 000,073,216 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWow64\msiexec.exe – (msiserver)
SRV:64bit: - [2009/07/13 19:41:56 | 000,242,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wbem\WMIsvc.dll – (Winmgmt)
SRV:64bit: - [2012/06/02 16:19:43 | 002,428,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wuaueng.dll – (wuauserv)
SRV:64bit: - [2010/11/20 21:24:09 | 000,252,416 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\dot3svc.dll – (dot3svc)
SRV:64bit: - [2009/07/13 19:41:56 | 000,886,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wlansvc.dll – (Wlansvc)
SRV:64bit: - [2010/11/20 21:24:32 | 000,118,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wkssvc.dll – (LanmanWorkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HTS547564A9E384
Partitions: 3
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 18.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 350.00MB
Starting Offset: 19861078016
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 577.00GB
Starting Offset: 20228079616
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:56E2E879

< End of report >




OTL Extras logfile created on: 9/24/2013 8:41:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Heidi\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.90 Gb Total Physical Memory | 4.23 Gb Available Physical Memory | 71.67% Memory free
6.15 Gb Paging File | 4.15 Gb Available in Paging File | 67.52% Paging File free
Paging file location(s): c:\pagefile.sys 256 512

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 577.33 Gb Total Space | 531.46 Gb Free Space | 92.06% Space Free | Partition Type: NTFS

Computer Name: HEIDI-VAIO | User Name: Heidi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe" = C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe:*:Enabled:TriDef 3D Media Player – (DDD Group Plc.)
"C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe" = C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe:*:Enabled:TriDef 3D Media Player – (DDD Group Plc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B4356AB-EE50-4AE4-86F9-77EB093596B8}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{21904328-C2C9-47B4-9599-B24039BEF7E4}" = lport=3888 | protocol=6 | dir=in | app=c:\program files (x86)\sony\vaio creations\vaio movie story\vmstory.exe |
"{45646135-94B9-40C6-8D7A-14A7CF2D9FE8}" = lport=53 | protocol=17 | dir=in | app=c:\program files\sony\vaio smart network\wfda\dcdhcpservice.exe |
"{5A60A8F6-876B-4918-A475-8B5EF010F5B5}" = lport=3880 | protocol=6 | dir=in | app=c:\program files (x86)\sony\vaio creations\vaio movie story\vmstory.exe |
"{6E0BCE98-C96A-4798-BE14-BC53A8EF9204}" = lport=3888 | protocol=17 | dir=in | app=c:\program files (x86)\sony\vaio creations\vaio movie story\vmstory.exe |
"{7D23F2CD-9729-494E-99D2-F7F813128B6A}" = lport=80 | protocol=6 | dir=in | app=c:\program files\sony\vaio smart network\wfda\wifidirectapplication.exe |
"{857779E2-015C-4E83-8003-27DF78014950}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BAAE19B1-2593-4B70-9ABF-3B244C3A5920}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{581D603E-31B6-497C-B258-1A15C1D363D5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{6977714B-DE5A-4B49-BE66-18A0D4E6DD20}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{8507E59F-EB31-40F6-91C4-2A4D30BB9477}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{875B9CD2-0FAE-452F-9D6D-48B64FD2E6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{A1A96639-A4AF-48BA-B0FC-8BF708AFBEB5}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{EEE2F73E-EC99-4BF5-82BE-8D5AC9633414}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FDD30926-5878-4EBB-A80D-6D69DC9F4DEF}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client
"{0EB7792D-EFA2-42AB-9A22-F33D9458E974}" = Media Gallery
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Atheros Bluetooth Suite (64)
"{26A24AE4-039D-4CA4-87B4-2F86417001FF}" = Java™ 7 Update 1 (64-bit)
"{312395BC-7CC2-434C-A660-30250276A926}" = SSLx64
"{34EB42BE-F4D3-44C1-B28E-9740115DB72C}" = VAIO - Microsoft Visual C++ 2010 SP1 Runtime 10.0.40219.325
"{4F31AC31-0A28-4F5A-8416-513972DA1F79}" = VSSTx64
"{549AD5FB-F52D-4307-864A-C0008FB35D96}" = VCCx64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{886C0C18-F905-49B2-90BA-EFC0FEDF27C6}" = VAIO - PlayMemories Home Plug-in
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99E6C2F3-59B2-4308-B1CD-4928B55B7E30}" = VGClientX64
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{D55EAC07-7207-44BD-B524-0F063F327743}" = VIx64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}" = VPMx64
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EC635BC0-0D7C-4CA2-9B87-2A330C298CB2}" = VAIO Care
"{F2611404-06BF-4E67-A5B7-8DB2FFC1CBF6}" = VSNx64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07441A52-E208-478A-92B7-5C337CA8C131}" = VAIO - Remote Play with PlayStation®3
"{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
"{0A013EA1-A1D3-11E0-8DCF-005056C00008}" = Sound Forge Audio Studio 10.0
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{167A1F6A-9BF2-4B24-83DB-C6D659F680EA}" = Media Go
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DD6041-7251-40FA-9D06-C5EB30268E0F}" = Qualcomm Atheros Direct Connect
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 40
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2F41EF61-A066-4EBF-84F8-21C1B317A780}" = VAIO - TrackID™ with BRAVIA
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3490653F-2789-46A1-B1BF-6BD4CF4131AB}" = FDUx86
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3A26D9BD-0F73-432D-B522-2BA18138F7EF}" = VAIO Improvement
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5156C9BF-1C27-430B-96D8-7129F11699A8}" = VAIO Data Restore Tool
"{547C9EB4-4CA6-402F-9D1B-8BD30DC71E44}" = VAIO Sample Contents
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
"{61438020-DDD4-42FA-99A2-50225441980A}" = ArcSoft Magic-i Visual Effects 2
"{63C43435-F428-42BA-8E7B-5848749D9262}" = SSLx86
"{6466EF6E-700E-470F-94CB-D0050302C84E}" = Remote Keyboard
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{692955F2-DE9F-4078-8FAA-858D6F3A1776}" = VAIO Gesture Control
"{6FD21053-829D-40E7-B04C-CAFB7D5CD025}" = KUx86
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}" = VAIO - Remote Keyboard
"{79E06DF1-24FE-11E1-913F-F04DA23A5C58}" = DVD Architect Studio 5.0
"{7A6374F0-6D04-11E0-92E0-005056C00008}" = ACID Music Studio 8.0
"{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
"{7E5A5CA6-B7D0-406E-A75E-157CAB47EB94}" = VMLx86
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{858B32BD-121C-4AC8-BD87-CE37C51C03E2}" = TrackID™ with BRAVIA
"{890EAAEE-CB92-4C3F-BE0D-C31B426F82A3}" = SystemSuite
"{8B583EF5-FA7B-4AE2-9008-51B7FD505886}" = VGClientX86
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CE152BA-1D16-11E1-867D-984BE15F174E}" = Evernote v. 4.5.2
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E797841-A110-41FD-B17A-3ABC0641187A}" = VAIO Control Center
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A49A517F-5332-4665-922C-6D9AD31ADD4F}" = VSNx86
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
"{A7E8CB11-B09E-46F8-9BAE-B2E01EBF7E51}" = Bing Bar
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.04)
"{AE5F3379-8B81-457E-8E09-7E61D941AFA4}" = VAIO Gate
"{B24BB74E-8359-43AA-985A-8E80C9219C70}" = VSSTx86
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B8991D99-88FD-41F2-8C32-DB70278D5C30}" = VWSTx86
"{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}" = VAIO CPU Fan Diagnostic
"{C14EAE86-C526-4E00-B245-CFF86233C3D2}" = VAIO 3D Portal
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
"{C793AD32-2BB8-4CC4-ABD3-A1469C21593C}" = ArcSoft WebCam Companion 4
"{C8544A9A-76BE-4F82-811E-979799AE493B}" = VAIO Gesture Control
"{C9EFF66F-B0CF-4B1A-9371-2FC647658CDF}" = VAIO Help and Support
"{CE3DE3AE-F384-11E0-B00E-F04DA23A5C58}" = Vegas Movie Studio HD Platinum 11.0
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF5B430D-C563-4EE6-803D-A8A133DFCE5E}" = Reader for PC
"{CFE8121D-67CE-4828-ADDD-F8AC1845C37E}" = SystemSuite
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}" = VIx86
"{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4E7BB46-310E-4A21-B261-052A5997EA2F}" = V3DPx86
"{D56DA747-5FDB-4AD5-9A6A-3481C0ED44BD}" = Remote Play with PlayStation®3
"{D9777637-33B7-47A9-800C-F6A2CD4EB0FE}" = VAIO OOBE
"{DB1A3EA7-0C25-4BEC-A108-176195190369}" = VHD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF184496-1CA2-4D07-92E7-0BD251D7DEF0}" = VCCx86
"{E03CD71A-F595-49DF-9ADC-0CFC93B1B211}" = PlayMemories Home
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E682702C-609C-4017-99E7-3129C163955F}" = VAIO - Remote Keyboard with PlayStation®3
"{E727B31A-8B24-4C1C-934A-69634E0D2C0B}" = Qualcomm Atheros WiFi Driver Installation
"{EBBB8461-52A2-11E1-8EBF-005056C00008}" = MSVCRT Redists
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® OpenCL CPU Runtime
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE8974B4-479C-4DBA-8544-9E5342ABB26A}" = Keyboard_Shortcuts
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Application Manager for VAIO" = Application Manager for VAIO
"Copernic Agent Personal" = Copernic Agent Personal
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"experience-sony-bundle" = TriDef 3D (Sony) 2.0.5
"Google Chrome" = Google Chrome
"InstallShield_{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD
"Office14.SingleImage" = Microsoft Office Professional 2010
"VAIO Satisfaction Survey.3.0" = VAIO Satisfaction Survey.
"WinLiveSuite" = Windows Live Essentials

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/18/2013 7:12:07 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 7:21:07 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 8:01:06 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 8:20:43 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 8:35:55 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 8:59:43 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 9:07:52 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 9:15:21 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 11:40:54 PM | Computer Name = Heidi-VAIO | Source = WinMgmt | ID = 10
Description =

Error - 9/18/2013 11:41:32 PM | Computer Name = Heidi-VAIO | Source = Application Error | ID = 1000
Description = Faulting application name: BtvStack.exe, version: 7.4.0.135, time
stamp: 0x4f9b491c Faulting module name: BtvStack.exe, version: 7.4.0.135, time stamp:
0x4f9b491c Exception code: 0xc0000005 Fault offset: 0x0000000000064422 Faulting process
id: 0x838 Faulting application start time: 0x01ceb4e9e704c84f Faulting application
path: C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe Faulting module path:
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe Report Id: 5fb26a65-20dd-11e3-a7d8-844bf5d46060

[ System Events ]
Error - 9/18/2013 11:38:16 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 12:14:38 AM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 11:37:32 AM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 11:46:45 AM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 12:25:54 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 1:09:58 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7030
Description = The VCOM Cloud Agent service is marked as an interactive service.
However, the system is configured to not allow interactive services. This service
may not function properly.

Error - 9/19/2013 1:22:47 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 2:36:23 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 3:06:51 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/19/2013 5:04:12 PM | Computer Name = Heidi-VAIO | Source = Service Control Manager | ID = 7034
Description = The SystemSuite Professional Process Monitor service terminated unexpectedly.
It has done this 1 time(s).


< End of report >




aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-09-24 09:00:56
—————————–
09:00:56.735 OS Version: Windows x64 6.1.7601 Service Pack 1
09:00:56.735 Number of processors: 4 586 0x3A09
09:00:56.736 ComputerName: HEIDI-VAIO UserName: Heidi
09:00:58.374 Initialize success
09:02:34.393 AVAST engine defs: 13092400
09:02:50.727 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:02:50.731 Disk 0 Vendor: Size: 0MB BusType: 0
09:02:50.840 Disk 0 MBR read successfully
09:02:50.841 Disk 0 MBR scan
09:02:50.844 Disk 0 Windows 7 default MBR code
09:02:50.846 Disk 0 MBR hidden
09:02:50.849 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 18940 MB offset 2048
09:02:50.860 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 350 MB offset 38791168
09:02:50.867 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 591188 MB offset 39507968
09:02:50.993 Disk 0 scanning C:\Windows\system32\drivers
09:02:59.278 Service scanning
09:03:28.022 Modules scanning
09:03:28.034 Disk 0 trace - called modules:
09:03:28.064 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
09:03:28.071 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008ab8060]
09:03:28.078 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006283050]
09:03:29.738 AVAST engine scan C:\Windows
09:03:32.439 AVAST engine scan C:\Windows\system32
09:06:01.015 AVAST engine scan C:\Windows\system32\drivers
09:06:10.849 AVAST engine scan C:\Users\Heidi
09:07:04.552 AVAST engine scan C:\ProgramData
09:08:37.433 Scan finished successfully
09:10:21.682 Disk 0 MBR has been saved successfully to "C:\Users\Heidi\Desktop\MBR.dat"
09:10:21.685 The log file has been saved successfully to "C:\Users\Heidi\Desktop\aswMBR.txt"

Attachments:

Hi WoundedBear,

You're doing just fine. I have a few questions:
  • Did you do a System Restore back to 09/18/2013?
  • Is the homepage issue to only problem you are experiencing?
  • Which browser or browsers do you use?
  • What would you like the homepage to be set as?

Hi WoundedBear,

You're doing just fine. I have a few questions:

  • Did you do a System Restore back to 09/18/2013?
  • Is the homepage issue to only problem you are experiencing?
  • Which browser or browsers do you use?
  • What would you like the homepage to be set as?


09/18/2013 sounds right
The homepage thing is my only issue. It's my wife's computer and she hates google which makes it an issue.
IE 10
www.newsminer.com
Alan
Hi WoundedBear,
  • Open Internet Explorer > locate the the gear symbol [external image: Posted Image] in the upper right hand corner.
  • Left click and select Internet Options > under the Home Page section remove whatever URL is listed and type http://www.newsminer.com/
  • Next click Apply, then OK
  • Exit Internet Explorer options menu.
Close Internet Explorer and reboot.

Test and see if homepage has been set to www.newsminer.com

Report back with the results.

Hi WoundedBear,

  • Open Internet Explorer > locate the the gear symbol [external image: Posted Image] in the upper right hand corner.
  • Left click and select Internet Options > under the Home Page section remove whatever URL is listed and type http://www.newsminer.com/
  • Next click Apply, then OK
  • Exit Internet Explorer options menu.
Close Internet Explorer and reboot.

Test and see if homepage has been set to www.newsminer.com

Report back with the results.



Stayed on google. No surprise there. I tried every fix I could find. The best I could do was to get newsminer to stay put after I closed the browser. It would open the homepage to newsminer every time I closed and opened it. As soon as I rebooted though I was back to google. Did that using several different fixes but I always came back to google after reboot.
Alan
Hi WoundedBear,

[external image: Posted Image] Run OTL.exe

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKLM\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
    IE - HKLM\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}\prefs.js JS/SecurityDisabler.A.Gen
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    IE - HKCU\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
    IE - HKCU\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

[external image: Posted Image] Reboot

=========================

  • Open Internet Explorer > locate the the gear symbol [external image: Posted Image] in the upper right hand corner.
  • Left click and select Internet Options > under the Home Page section remove whatever URL is listed and type http://www.newsminer.com/
  • Next click Apply, then OK
  • Exit Internet Explorer options menu.
Close Internet Explorer.

=========================

[external image: Posted Image] Reboot

=========================

[external image: Posted Image] Re-run OTL (it should be located on your desktop).
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • Any change to the homepage?
  • OTL.txt
No change. Google was back as soon as I restarted IE.


OTL logfile created on: 9/26/2013 10:26:12 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Heidi\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.90 Gb Total Physical Memory | 4.43 Gb Available Physical Memory | 75.05% Memory free
6.15 Gb Paging File | 4.50 Gb Available in Paging File | 73.21% Paging File free
Paging file location(s): c:\pagefile.sys 256 512

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 577.33 Gb Total Space | 529.84 Gb Free Space | 91.77% Space Free | Partition Type: NTFS
Drive D: | 148.34 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: HEIDI-VAIO | User Name: Heidi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Heidi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\VcomCloudAgent.exe (Avanquest Software North America)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\MXTask.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\AVQWinMonEngine.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\MXTask2.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\AQFileRestoreSrv.exe (Avanquest Software)
PRC - C:\Program Files (x86)\Common Files\SpeedBit\SBUpdate\SBUpdate.exe (Speedbit Ltd.)
PRC - C:\Program Files (x86)\Avanquest\SystemSuite\Antivirus\SBAMSvc.exe (GFI Software)
PRC - C:\Program Files\Sony\VAIO Care\listener.exe ()
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Sony Corporation)
PRC - c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\6c422db78c17838c3eb9f9fcc01ca63f\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\10054f798f1a896d5176581777ca7406\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\4d277a8481c203a35c58bd277a2e71df\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\d4493b0e5a5c6faf89cfeaa5f2a21034\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\6e3778958a8bfd03bf0f2f60c4e25623\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\6ebbfafc5521934f7e1c154937a2788b\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d473c19e69818875b9c739cad8f386a5\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\28ea347a952d20959ac6ae02d7457d39\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1f6f220f9efe936d1158c79b9d4b451f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\8f7d83126a3cf283e5ac97f2d6d99f12\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\56a1feb800860a3bc5d8a45ee92a77ec\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\1a3b614a84244ea5fa4147b5cf007333\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\001aeb860d7f2ba416e0fedc606fee98\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\228b114c79c5d9024bdb4cc580e32c09\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\c25ede0d0127774c504c4fc41d4de273\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\3a3fc0216674bdea0be809b305517c98\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\884bcbd22130ebeb1211bc7bcc3910c9\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\b3ed31a444f444325ddb64b290ed2f1e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\df40dab689e9d8febfb943599ba79f8d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\de853615c8224ba5d9aa9b76276c6d98\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\Windows\SysWOW64\EasyHook32.dll ()
MOD - C:\Program Files\Sony\VAIO Care\listener.exe ()
MOD - C:\Program Files (x86)\Sony\Keyboard Shortcuts\Utility.dll ()
MOD - C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe ()
MOD - C:\Program Files (x86)\Sony\Keyboard Shortcuts\MessageHook.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (VSNService) – C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (VUAgent) – C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation)
SRV:64bit: - (SampleCollector) – C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation)
SRV:64bit: - (USER_ESRV_SVC) – C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe ()
SRV:64bit: - (ESRV_SVC) – C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe ()
SRV:64bit: - (VCService) – C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation)
SRV:64bit: - (DCDhcpService) – C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe (Atheros Communication Inc.)
SRV:64bit: - (Intel® – c:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (VAIO Power Management) – C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
SRV:64bit: - (VcmINSMgr) – C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe (Sony Corporation)
SRV:64bit: - (VcmIAlzMgr) – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
SRV:64bit: - (SpfService) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation)
SRV:64bit: - (VcmXmlIfHelper) – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (Sony Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (VCOMCloudAgent) – C:\Program Files (x86)\Avanquest\SystemSuite\VcomCloudAgent.exe (Avanquest Software North America)
SRV - (SystemSuite Task Manager) – C:\Program Files (x86)\Avanquest\SystemSuite\MXTask.exe (Avanquest Software)
SRV - (.AVQWindowsMonitorService) – C:\Program Files (x86)\Avanquest\SystemSuite\AVQWinMonEngine.exe (Avanquest Software)
SRV - (AQFileRestoreSrv) – C:\Program Files (x86)\Avanquest\SystemSuite\AQFileRestoreSrv.exe (Avanquest Software)
SRV - (SBAMSvc) – C:\Program Files (x86)\Avanquest\SystemSuite\Antivirus\SBAMSvc.exe (GFI Software)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ZAtheros Bt&Wlan Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (McComponentHostServiceSony) – C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe (McAfee, Inc.)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (VAIO Event Service) – C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Sony Corporation)
SRV - (PMBDeviceInfoProvider) – c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (SOHDs) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation)
SRV - (SOHCImp) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation)
SRV - (VCFw) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Sony SCSI Helper Service) – C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe (Sony Corporation)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (uCamMonitor) – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AQFileRestore) – C:\Windows\SysNative\drivers\AQFileRestore.sys ()
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (semav6thermal64ro) – C:\Windows\SysNative\drivers\semav6thermal64ro.sys ()
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_VDP) – C:\Windows\SysNative\drivers\btath_vdp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) – C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SFEP) – C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (e1yexpress) – C:\Windows\SysNative\drivers\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ArcSoftKsUFilter) – C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)
DRV - (TFilter) – C:\Program Files (x86)\Avanquest\SystemSuite\TFilter.sys ()
DRV - (KFilter) – C:\Program Files (x86)\Avanquest\SystemSuite\Kfilter.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://www.google.com/search?hl=en&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DAP\daplinkchecker [2013/09/18 19:43:28 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\athbttray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\btvstack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Safety present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.1.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8C6F14F-0316-4702-8BEF-E60D808E768E}: DhcpNameServer = 192.168.0.1 [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/09/26 10:24:22 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2013/09/26 09:34:17 | 000,000,000 | —D | C] – C:\_OTL
[2013/09/24 13:19:44 | 000,000,000 | —D | C] – C:\Users\Heidi\Desktop\HUM 105
[2013/09/24 08:32:56 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL.exe
[2013/09/23 13:32:48 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Microsoft Games
[2013/09/22 17:32:41 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/09/19 15:36:20 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\ElevatedDiagnostics
[2013/09/19 13:34:48 | 000,000,000 | —D | C] – C:\Users\Heidi\Desktop\Desktop Folder
[2013/09/18 21:53:12 | 000,000,000 | —D | C] – C:\ProgramData\Oracle
[2013/09/18 21:53:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/09/18 21:52:47 | 000,264,616 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/09/18 21:52:41 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/09/18 21:52:41 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/09/18 21:52:41 | 000,096,168 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/09/18 21:52:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/09/18 21:52:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/09/18 21:47:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/09/18 21:47:02 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/09/18 21:46:59 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2013/09/18 21:46:49 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Google
[2013/09/18 21:46:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/09/18 21:46:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2013/09/18 21:46:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/09/18 21:43:39 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Adobe
[2013/09/18 20:32:34 | 000,039,504 | —- | C] (ThreatTrack Security) – C:\Windows\SysNative\drivers\gfiark.sys
[2013/09/18 20:32:24 | 000,000,000 | RHSD | C] – C:\_Backup.RC
[2013/09/18 20:31:51 | 000,047,496 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2013/09/18 20:31:39 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Avanquest
[2013/09/18 20:31:38 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Avanquest Software
[2013/09/18 20:31:09 | 000,000,000 | —D | C] – C:\ProgramData\Avanquest
[2013/09/18 20:29:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Avanquest
[2013/09/18 20:23:45 | 000,000,000 | —D | C] – C:\_Backup
[2013/09/18 20:11:22 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Copernic
[2013/09/18 20:11:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Copernic
[2013/09/18 20:11:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Copernic Agent
[2013/09/18 19:44:08 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\EQATEC Analytics
[2013/09/18 19:43:29 | 000,000,000 | —D | C] – C:\Users\Heidi\Documents\My DAP Downloads
[2013/09/18 19:43:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Download Accelerator Plus (DAP)
[2013/09/18 19:43:28 | 000,000,000 | —D | C] – C:\ProgramData\SpeedBit
[2013/09/18 19:43:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAP
[2013/09/18 19:42:57 | 000,172,032 | —- | C] (Jin Hui E-mail: [removed] Web: http://www.jcomsoft.com) – C:\Windows\SysWow64\AniGIF.ocx
[2013/09/18 19:42:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SpeedBit
[2013/09/18 19:21:35 | 000,868,264 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/09/18 19:09:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/09/18 19:08:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2013/09/18 19:06:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2013/09/18 19:05:30 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Microsoft Help
[2013/09/18 19:05:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/09/18 19:04:59 | 000,000,000 | RH-D | C] – C:\MSOCache
[2013/09/18 18:55:56 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Skype
[2013/09/18 18:55:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/09/18 18:55:51 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/09/18 18:55:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/09/18 18:55:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/09/18 18:54:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/09/18 18:54:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/09/18 18:44:41 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/09/18 18:41:07 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Macromedia
[2013/09/18 18:38:31 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\WindowsUpdate
[2013/09/18 18:31:48 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\en-US\tsusbflt.sys.mui
[2013/09/18 18:31:46 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/09/18 18:31:46 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/09/18 18:31:46 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/09/18 18:31:44 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/09/18 18:31:44 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbGD.sys
[2013/09/18 18:31:44 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/09/18 18:31:38 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/09/18 18:31:38 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/09/18 18:31:38 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/09/18 18:31:38 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/09/18 18:31:38 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/09/18 18:31:38 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/09/18 18:31:38 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/09/18 18:31:38 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/09/18 18:31:37 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/09/18 18:31:37 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/09/18 18:31:37 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/09/18 18:31:37 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/09/18 18:31:37 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/09/18 18:31:37 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/09/18 18:31:37 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/09/18 18:31:36 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/09/18 18:31:36 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/09/18 18:31:36 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/09/18 18:31:36 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/09/18 18:30:53 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/09/18 18:30:53 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/09/18 18:30:52 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/09/18 18:26:55 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/09/18 18:20:47 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Adobe
[2013/09/18 18:11:06 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/09/18 18:11:06 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/09/18 18:11:06 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/09/18 18:11:05 | 003,959,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/18 18:11:05 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/09/18 18:11:05 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/09/18 18:11:05 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/09/18 18:11:05 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/09/18 18:11:05 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/18 18:11:05 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/09/18 18:11:05 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/18 18:11:05 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/09/18 18:11:05 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/18 18:11:05 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/09/18 18:11:05 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/09/18 18:11:05 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/09/18 18:11:05 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/09/18 18:11:05 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/09/18 18:11:05 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/09/18 18:11:05 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/09/18 18:11:05 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/09/18 18:11:05 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/09/18 18:11:05 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/09/18 18:11:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/09/18 18:11:05 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/09/18 18:11:05 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/09/18 18:11:05 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/09/18 18:11:05 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/09/18 18:11:05 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/09/18 18:11:05 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/09/18 18:11:05 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/09/18 18:11:05 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/09/18 18:11:05 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/18 18:11:05 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/09/18 18:11:05 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/09/18 18:11:05 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/09/18 18:11:05 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/18 18:11:05 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/09/18 18:11:05 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/09/18 18:11:05 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/09/18 18:11:05 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/09/18 18:11:05 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/09/18 18:11:05 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/09/18 18:11:05 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/09/18 18:11:05 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/18 18:11:05 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/09/18 18:11:05 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/09/18 18:11:05 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/18 18:11:05 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/09/18 18:11:05 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/18 18:11:05 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/09/18 18:11:05 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/18 18:11:05 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/18 18:11:05 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/09/18 18:11:05 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/09/18 18:11:05 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/09/18 18:11:05 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/09/18 18:11:05 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/09/18 18:09:12 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/09/18 18:09:12 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/09/18 18:09:12 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/09/18 18:09:12 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/09/18 18:09:12 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/09/18 18:09:12 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/09/18 18:09:12 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/09/18 18:09:12 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/09/18 18:09:12 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/09/18 18:09:12 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/09/18 18:09:12 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/09/18 18:09:12 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/09/18 18:09:12 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/09/18 18:09:12 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/09/18 18:09:12 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 17:16:39 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/09/18 17:16:39 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/09/18 17:16:39 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/09/18 17:16:38 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/09/18 17:16:09 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2013/09/18 17:16:09 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2013/09/18 17:14:23 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2013/09/18 17:14:23 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2013/09/18 17:07:27 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2013/09/18 17:07:27 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2013/09/18 17:07:27 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\en-US\wdf01000.sys.mui
[2013/09/18 16:49:39 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2013/09/18 16:49:39 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2013/09/18 16:49:39 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2013/09/18 16:49:39 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2013/09/18 16:42:16 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/09/18 16:42:16 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/09/18 16:41:07 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/09/18 16:41:06 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/09/18 16:41:06 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/09/18 16:34:51 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2013/09/18 16:34:49 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2013/09/18 16:34:49 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2013/09/18 16:33:17 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2013/09/18 16:33:17 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2013/09/18 16:29:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2013/09/18 16:29:20 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2013/09/18 16:27:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2013/09/18 16:24:38 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2013/09/18 16:24:22 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/09/18 16:24:21 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/09/18 16:24:20 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/09/18 16:24:19 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/09/18 16:24:19 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/09/18 16:24:19 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/09/18 16:24:19 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/09/18 16:24:19 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/09/18 16:24:19 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/09/18 16:24:19 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/09/18 16:24:19 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/09/18 16:24:19 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/09/18 16:24:18 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/09/18 16:24:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/09/18 16:24:18 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/09/18 16:24:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/09/18 16:24:18 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/09/18 16:24:18 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/09/18 16:24:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/09/18 16:24:18 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/09/18 16:24:18 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/09/18 16:24:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/18 16:24:18 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/09/18 16:24:18 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/09/18 16:24:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/18 16:24:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/18 16:24:16 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/09/18 16:24:16 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apisetschema.dll
[2013/09/18 16:24:16 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/09/18 16:24:16 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/18 16:24:16 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/18 16:24:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/18 16:24:15 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/09/18 16:24:15 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/09/18 16:24:15 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/09/18 16:24:15 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/09/18 16:23:57 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/09/18 16:23:57 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/09/18 16:23:51 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/09/18 16:23:47 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/09/18 16:23:29 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2013/09/18 16:23:29 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2013/09/18 16:23:29 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2013/09/18 16:23:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2013/09/18 16:23:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2013/09/18 16:20:12 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/09/18 16:20:11 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/09/18 16:20:11 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/09/18 16:20:05 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2013/09/18 16:20:05 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2013/09/18 16:20:05 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2013/09/18 16:19:45 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2013/09/18 16:19:45 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2013/09/18 16:19:40 | 000,155,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ataport.sys
[2013/09/18 16:19:39 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/09/18 16:19:39 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/09/18 16:19:26 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/09/18 16:19:26 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/09/18 16:17:59 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2013/09/18 16:17:58 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2013/09/18 16:17:58 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2013/09/18 16:17:58 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2013/09/18 16:17:58 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2013/09/18 16:17:57 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2013/09/18 16:17:57 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2013/09/18 16:15:58 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2013/09/18 16:15:06 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/09/18 16:15:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/09/18 16:15:02 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/09/18 16:15:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/09/18 16:15:02 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/09/18 16:15:02 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/09/18 16:15:02 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/09/18 16:15:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/09/18 16:15:02 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/09/18 16:15:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/09/18 16:15:02 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/09/18 16:15:02 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/09/18 16:15:02 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/09/18 16:15:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/09/18 16:15:01 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/09/18 16:15:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/09/18 16:15:01 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/09/18 16:15:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/09/18 16:15:01 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/09/18 16:15:00 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/09/18 16:14:59 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/09/18 16:14:58 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/09/18 16:14:58 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/09/18 16:14:56 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/09/18 16:14:56 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/09/18 16:14:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/09/18 16:14:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/09/18 16:14:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/09/18 16:14:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/09/18 16:14:56 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/09/18 16:14:55 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/09/18 16:14:55 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/09/18 16:14:55 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/09/18 16:10:23 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2013/09/18 15:57:11 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2013/09/18 15:54:58 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2013/09/18 15:54:58 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2013/09/18 15:54:38 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/09/18 15:54:15 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/09/18 15:54:15 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/09/18 15:54:02 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/09/18 15:53:28 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/09/18 15:53:28 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/09/18 15:53:20 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Atheros
[2013/09/18 15:52:40 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
[2013/09/18 15:52:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Atheros
[2013/09/18 15:52:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bluetooth Suite
[2013/09/18 15:52:02 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/09/18 15:51:52 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netapi32.dll
[2013/09/18 15:51:52 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browcli.dll
[2013/09/18 15:51:51 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\browcli.dll
[2013/09/18 15:51:40 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\srcore.dll
[2013/09/18 15:51:38 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2013/09/18 15:51:25 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/09/18 15:51:24 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/09/18 15:51:19 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/09/18 15:51:19 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/09/18 15:50:21 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2013/09/18 15:49:17 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2013/09/18 15:49:15 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2013/09/18 15:48:39 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/09/18 15:48:39 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/09/18 15:48:03 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\splwow64.exe
[2013/09/18 15:31:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote for VAIO
[2013/09/18 15:31:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Evernote
[2013/09/18 15:31:14 | 000,000,000 | —D | C] – C:\ProgramData\Evernote
[2013/09/18 15:30:37 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2013/09/18 15:29:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2013/09/18 15:28:51 | 000,000,000 | —D | C] – C:\ProgramData\DDNi
[2013/09/18 15:28:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\DDNi
[2013/09/18 15:28:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2013/09/18 15:27:31 | 000,000,000 | —D | C] – C:\ProgramData\CLSK
[2013/09/18 15:23:41 | 000,069,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\offreg.dll
[2013/09/18 15:23:41 | 000,021,176 | —- | C] (iolo technologies, LLC) – C:\Windows\SysNative\iolorgdf64.exe
[2013/09/18 15:23:41 | 000,000,000 | —D | C] – C:\ProgramData\iolo
[2013/09/18 15:19:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2013/09/18 15:15:41 | 000,000,000 | —D | C] – C:\Windows\en
[2013/09/18 15:15:14 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013/09/18 15:14:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2013/09/18 15:14:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2013/09/18 15:14:06 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2013/09/18 15:14:04 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2013/09/18 15:13:55 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/09/18 15:13:55 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/09/18 15:13:55 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/09/18 15:13:53 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2013/09/18 15:13:53 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2013/09/18 15:13:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2013/09/18 15:10:35 | 000,000,000 | —D | C] – C:\Windows\SysWow64\spool
[2013/09/18 15:10:24 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\iolo
[2013/09/18 15:10:10 | 000,000,000 | RH-D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
[2013/09/18 15:10:10 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/09/18 15:05:44 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Vegas Movie Studio HD Platinum 10.0
[2013/09/18 15:05:28 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Sound Forge Audio Studio 10.0
[2013/09/18 15:04:54 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Songs
[2013/09/18 15:03:34 | 000,000,000 | —D | C] – C:\Users\Public\Documents\ACID Music Studio 8.0
[2013/09/18 15:02:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\15 ACID Projects for VAIO
[2013/09/18 15:00:50 | 000,000,000 | —D | C] – C:\Update
[2013/09/18 14:56:12 | 000,000,000 | —D | C] – C:\VAIO Sample Contents
[2013/09/18 14:52:10 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\BMExplorer
[2013/09/18 14:52:10 | 000,000,000 | —D | C] – C:\Users\Heidi\Documents\Bluetooth Folder
[2013/09/18 14:52:03 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Intel Corporation
[2013/09/18 14:51:00 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/09/18 14:51:00 | 000,000,000 | R–D | C] – C:\Users\Heidi\Searches
[2013/09/18 14:51:00 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/09/18 14:50:59 | 000,000,000 | -H-D | C] – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/09/18 14:50:47 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Identities
[2013/09/18 14:50:45 | 000,000,000 | R–D | C] – C:\Users\Heidi\Contacts
[2013/09/18 14:50:01 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\VirtualStore
[2013/09/18 14:48:57 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2013/09/18 14:48:29 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Sony Corporation
[2013/09/18 14:47:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\VAIO Startup Setting Tool
[2013/09/18 14:47:48 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/09/18 14:47:38 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/09/18 14:47:38 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/09/18 14:47:38 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2013/09/18 14:47:13 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/09/18 14:47:13 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/09/18 14:47:13 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2013/09/18 14:47:05 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Sony Corporation
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\AppData\Local\Temporary Internet Files
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Templates
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Start Menu
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\SendTo
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Recent
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\PrintHood
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\NetHood
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Documents\My Videos
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Documents\My Pictures
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Documents\My Music
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\My Documents
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Local Settings
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\AppData\Local\History
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Cookies
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\Application Data
[2013/09/18 14:46:56 | 000,000,000 | -HSD | C] – C:\Users\Heidi\AppData\Local\Application Data
[2013/09/18 14:46:53 | 000,000,000 | –SD | C] – C:\Users\Heidi\AppData\Roaming\Microsoft
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Videos
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Saved Games
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Pictures
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Music
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Links
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Favorites
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Downloads
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Documents
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\Desktop
[2013/09/18 14:46:53 | 000,000,000 | R–D | C] – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/09/18 14:46:53 | 000,000,000 | -H-D | C] – C:\Users\Heidi\AppData
[2013/09/18 14:46:53 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Temp
[2013/09/18 14:46:53 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Local\Microsoft
[2013/09/18 14:46:53 | 000,000,000 | —D | C] – C:\Users\Heidi\AppData\Roaming\Media Center Programs
[2013/09/18 14:46:50 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/09/18 14:46:50 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/09/18 14:44:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home
[2013/09/18 14:42:45 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/09/18 14:42:45 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/09/18 14:42:45 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/09/18 14:40:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013/09/18 14:39:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony Media Go Install
[2013/09/18 14:36:37 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/09/18 14:36:37 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/09/18 14:36:37 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/09/18 14:36:36 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/09/18 14:36:35 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 3D
[2013/09/18 14:36:35 | 000,000,000 | —D | C] – C:\ProgramData\DDD
[2013/09/18 14:36:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\TriDef 3D
[2013/09/18 14:33:56 | 000,029,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2013/09/18 14:33:45 | 000,000,000 | —D | C] – C:\ProgramData\Temp
[2013/09/18 14:31:52 | 000,212,480 | —- | C] (Eastman Kodak) – C:\Windows\SysWow64\PCDLIB32.DLL
[2013/09/18 14:31:50 | 000,055,808 | —- | C] (ArcSoft, Inc.) – C:\Windows\System\ArcSoftKsUFilter.dll
[2013/09/18 14:31:50 | 000,019,968 | —- | C] (ArcSoft, Inc.) – C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys
[2013/09/18 14:31:49 | 000,245,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\unicows.dll
[2013/09/18 14:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Webcam Suite
[2013/09/18 14:28:23 | 000,000,000 | —D | C] – C:\ProgramData\ArcSoft
[2013/09/18 14:28:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ArcSoft
[2013/09/18 14:28:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ArcSoft
[2013/09/18 14:25:55 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2013/09/18 14:25:37 | 000,692,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/18 14:25:36 | 000,071,048 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/18 14:25:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2013/09/18 14:25:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2013/09/18 14:19:22 | 000,000,000 | —D | C] – C:\Documentation
[2013/09/18 14:06:47 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Main
[2013/09/18 13:59:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2013/09/18 13:56:07 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/09/18 13:56:07 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/09/18 13:56:07 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/09/18 13:56:07 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/09/18 13:56:06 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/09/18 13:56:06 | 002,401,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_43.dll
[2013/09/18 13:56:06 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/09/18 13:56:06 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_43.dll
[2013/09/18 13:56:06 | 001,907,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_43.dll
[2013/09/18 13:56:06 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_43.dll
[2013/09/18 13:56:06 | 000,511,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_43.dll
[2013/09/18 13:56:06 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_43.dll
[2013/09/18 13:56:06 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/09/18 13:56:06 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/09/18 13:56:06 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_7.dll
[2013/09/18 13:56:06 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_7.dll
[2013/09/18 13:53:52 | 000,000,000 | —D | C] – C:\ProgramData\eBay_icon
[2013/09/18 13:48:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reader for PC
[2013/09/18 13:47:56 | 000,000,000 | —D | C] – C:\Program Files\PlayReady
[2013/09/18 13:47:36 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2013/09/18 13:46:28 | 000,000,000 | —D | C] – C:\ProgramData\Sony Corporation
[2013/09/18 13:46:27 | 000,000,000 | —D | C] – C:\Program Files\Sony
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\winrm
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\UMDF
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\sysprep
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\slmgr
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\UMDF\en-US
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\en-US
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\en
[2013/09/18 13:45:20 | 000,000,000 | —D | C] – C:\Windows\SysWow64\0409
[2013/09/18 13:45:17 | 000,000,000 | —D | C] – C:\Windows\SysWow64\WCN
[2013/09/18 13:45:17 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Printing_Admin_Scripts
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\winrm
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\slmgr
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\en
[2013/09/18 13:45:13 | 000,000,000 | —D | C] – C:\Windows\SysNative\0409
[2013/09/18 13:45:06 | 000,000,000 | —D | C] – C:\Windows\SysNative\WCN
[2013/09/18 13:45:06 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\en-US
[2013/09/18 13:45:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\Printing_Admin_Scripts
[2013/09/18 13:39:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2013/09/18 13:35:58 | 000,000,000 | —D | C] – C:\Windows\Sonysys
[2013/09/18 13:34:15 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/09/18 13:34:10 | 000,790,440 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/09/18 13:33:57 | 000,627,600 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/09/18 13:33:57 | 000,252,296 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/09/18 13:33:57 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/09/18 13:33:57 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/09/18 13:33:54 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/09/18 13:33:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Sony Shared
[2013/09/18 13:33:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Sony Shared
[2013/09/18 13:33:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel Corporation
[2013/09/18 13:28:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2013/09/18 13:27:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony Corporation
[2013/09/18 13:24:46 | 002,807,808 | —- | C] (Atheros Communications, Inc.) – C:\Windows\SysNative\drivers\athrx.sys
[2013/09/18 13:24:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation
[2013/09/18 13:23:48 | 000,000,000 | —D | C] – C:\ProgramData\Qualcomm Atheros
[2013/09/18 13:21:56 | 000,041,984 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\USB3Ver.dll
[2013/09/18 13:20:38 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2013/09/18 13:20:12 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2013/09/18 13:18:10 | 000,000,000 | —D | C] – C:\Windows\SysWow64\sda
[2013/09/18 13:18:08 | 000,339,048 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\drivers\RtsPStor.sys
[2013/09/18 13:18:07 | 009,888,872 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysWow64\RtsPStorIcon.dll
[2013/09/18 13:16:21 | 000,000,000 | —D | C] – C:\ProgramData\Intel
[2013/09/18 13:16:19 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2013/09/18 13:16:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\postureAgent
[2013/09/18 13:15:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intel
[2013/09/18 13:15:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel
[2013/09/18 13:08:13 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2013/09/18 13:08:13 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2013/09/18 13:08:03 | 005,996,376 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek.dll
[2013/09/18 13:08:03 | 003,846,248 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2013/09/18 13:08:03 | 003,308,376 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEP64A.dll
[2013/09/18 13:08:03 | 002,728,960 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoRes64.dat
[2013/09/18 13:08:03 | 002,652,264 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2013/09/18 13:08:03 | 002,603,864 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib.dll
[2013/09/18 13:08:03 | 002,131,288 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ.dll
[2013/09/18 13:08:03 | 001,560,168 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2013/09/18 13:08:03 | 001,361,336 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tosade.dll
[2013/09/18 13:08:03 | 001,247,848 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2013/09/18 13:08:03 | 001,247,576 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek264.dll
[2013/09/18 13:08:03 | 000,958,296 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPOShell64.dll
[2013/09/18 13:08:03 | 000,836,544 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tadefxapo264.dll
[2013/09/18 13:08:03 | 000,823,912 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2013/09/18 13:08:03 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2013/09/18 13:08:03 | 000,426,328 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EED64A.dll
[2013/09/18 13:08:03 | 000,375,128 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2013/09/18 13:08:03 | 000,334,680 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2013/09/18 13:08:03 | 000,331,880 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2013/09/18 13:08:03 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2013/09/18 13:08:03 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2013/09/18 13:08:03 | 000,221,024 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFNHK64.dll
[2013/09/18 13:08:03 | 000,220,776 | —- | C] (Sony Corporation) – C:\Windows\SysNative\SFSS_APO.dll
[2013/09/18 13:08:03 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2013/09/18 13:08:03 | 000,204,120 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2013/09/18 13:08:03 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2013/09/18 13:08:03 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2013/09/18 13:08:03 | 000,149,608 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2013/09/18 13:08:03 | 000,148,416 | —- | C] (TOSHIBA Corporation) – C:\Windows\SysNative\tadefxapo.dll
[2013/09/18 13:08:03 | 000,136,024 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEL64A.dll
[2013/09/18 13:08:03 | 000,118,104 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEA64A.dll
[2013/09/18 13:08:03 | 000,101,208 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2013/09/18 13:08:03 | 000,100,968 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInstII64.dll
[2013/09/18 13:08:03 | 000,081,248 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFCOM64.dll
[2013/09/18 13:08:03 | 000,078,688 | —- | C] (Synopsys, Inc.) – C:\Windows\SysNative\SFAPO64.dll
[2013/09/18 13:08:03 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2013/09/18 13:08:03 | 000,074,072 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\R4EEG64A.dll
[2013/09/18 13:08:03 | 000,074,064 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:\Windows\SysWow64\SFCOM.dll
[2013/09/18 13:08:03 | 000,065,944 | —- | C] (TOSHIBA CORPORATION.) – C:\Windows\SysNative\tepeqapo64.dll
[2013/09/18 13:08:03 | 000,014,952 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCoLDR64.dll
[2013/09/18 13:08:02 | 000,603,984 | —- | C] (Knowles Acoustics ) – C:\Windows\SysNative\KAAPORT64.dll
[2013/09/18 13:08:02 | 000,341,336 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO30.dll
[2013/09/18 13:08:02 | 000,318,808 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2013/09/18 13:08:01 | 002,528,832 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2013/09/18 13:08:01 | 001,756,264 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2013/09/18 13:08:01 | 001,568,360 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2013/09/18 13:08:01 | 001,486,952 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2013/09/18 13:08:01 | 000,728,680 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2013/09/18 13:08:01 | 000,712,296 | —- | C] (DTS) – C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2013/09/18 13:08:01 | 000,693,352 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2013/09/18 13:08:01 | 000,537,456 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PLFX64.dll
[2013/09/18 13:08:01 | 000,524,656 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PGFX64.dll
[2013/09/18 13:08:01 | 000,491,112 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2013/09/18 13:08:01 | 000,449,392 | —- | C] (DTS) – C:\Windows\SysNative\DTSU2PREC64.dll
[2013/09/18 13:08:01 | 000,432,744 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2013/09/18 13:08:01 | 000,428,648 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2013/09/18 13:08:01 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2013/09/18 13:08:01 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2013/09/18 13:08:01 | 000,241,768 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPONS64.dll
[2013/09/18 13:08:01 | 000,200,800 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2013/09/18 13:08:01 | 000,108,960 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2013/09/18 13:08:01 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2013/09/18 13:08:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2013/09/18 13:08:00 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/09/18 13:07:59 | 001,698,408 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2013/09/18 13:07:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2013/09/18 13:05:39 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\SysWow64\CSVer.dll
[2013/09/18 13:05:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2013/09/18 13:05:36 | 000,000,000 | —D | C] – C:\Intel
[2013/09/18 13:03:19 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2013/09/18 13:03:19 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2013/09/18 13:03:19 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2013/09/18 13:03:19 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2013/09/18 13:03:19 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2013/09/18 13:03:19 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2013/09/18 13:03:18 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2013/09/18 12:53:17 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2013/09/18 12:47:04 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2013/09/26 10:23:26 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/26 10:23:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/26 10:23:08 | 460,079,103 | -HS- | M] () – C:\hiberfil.sys
[2013/09/26 10:08:30 | 000,020,992 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 10:08:30 | 000,020,992 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 09:59:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/26 09:58:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/24 15:32:24 | 000,001,380 | —- | M] () – C:\Users\Heidi\Desktop\My DAP Downloads.lnk
[2013/09/24 08:32:51 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Heidi\Desktop\OTL.exe
[2013/09/23 10:48:26 | 000,001,188 | —- | M] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/09/21 12:59:13 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/21 12:59:13 | 000,660,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/21 12:59:13 | 000,121,214 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/19 17:47:23 | 000,659,968 | —- | M] () – C:\Users\Heidi\Documents\MicrosoftFixit50195.msi
[2013/09/19 17:00:36 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/19 17:00:36 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/19 15:57:50 | 000,659,456 | —- | M] () – C:\Users\Heidi\Documents\MicrosoftFixit50526_1.msi
[2013/09/19 15:55:54 | 000,659,456 | —- | M] () – C:\Users\Heidi\Documents\MicrosoftFixit50526.msi
[2013/09/19 11:23:14 | 001,310,720 | —- | M] () – C:\Users\Heidi\NTUSER.BAK
[2013/09/19 08:50:23 | 000,002,279 | —- | M] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/18 21:52:23 | 000,868,264 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/09/18 21:52:23 | 000,790,440 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/09/18 21:52:23 | 000,264,616 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/09/18 21:52:23 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/09/18 21:52:23 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/09/18 21:52:23 | 000,096,168 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/09/18 21:39:43 | 000,443,800 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/18 21:38:43 | 001,048,576 | -HS- | M] () – C:\Users\Heidi\NTUSER.BK1
[2013/09/18 20:18:12 | 000,001,098 | —- | M] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Copernic Agent Personal.lnk
[2013/09/18 19:42:57 | 000,172,032 | —- | M] (Jin Hui E-mail: [removed] Web: http://www.jcomsoft.com) – C:\Windows\SysWow64\AniGIF.ocx
[2013/09/18 19:19:43 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013/09/18 18:36:26 | 000,001,407 | —- | M] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/09/18 18:11:06 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/09/18 18:11:06 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/09/18 18:11:06 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/09/18 18:11:05 | 003,959,296 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/18 18:11:05 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/09/18 18:11:05 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/09/18 18:11:05 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/09/18 18:11:05 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/09/18 18:11:05 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/18 18:11:05 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/09/18 18:11:05 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/09/18 18:11:05 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/18 18:11:05 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/09/18 18:11:05 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/18 18:11:05 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/09/18 18:11:05 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/09/18 18:11:05 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/09/18 18:11:05 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/09/18 18:11:05 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/09/18 18:11:05 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/09/18 18:11:05 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/09/18 18:11:05 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/09/18 18:11:05 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/09/18 18:11:05 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/09/18 18:11:05 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/09/18 18:11:05 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/09/18 18:11:05 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/09/18 18:11:05 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/09/18 18:11:05 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/09/18 18:11:05 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/09/18 18:11:05 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/09/18 18:11:05 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/09/18 18:11:05 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/09/18 18:11:05 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/18 18:11:05 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/09/18 18:11:05 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/09/18 18:11:05 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/09/18 18:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/09/18 18:11:05 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/18 18:11:05 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/09/18 18:11:05 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/09/18 18:11:05 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/09/18 18:11:05 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/09/18 18:11:05 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/09/18 18:11:05 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/09/18 18:11:05 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/09/18 18:11:05 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/18 18:11:05 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/09/18 18:11:05 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/18 18:11:05 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/09/18 18:11:05 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/09/18 18:11:05 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/18 18:11:05 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/09/18 18:11:05 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/18 18:11:05 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/09/18 18:11:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/09/18 18:11:05 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/18 18:11:05 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/18 18:11:05 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/09/18 18:11:05 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/09/18 18:11:05 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/09/18 18:11:05 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/09/18 18:11:05 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/09/18 18:11:05 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/09/18 18:11:05 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/09/18 18:09:12 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/09/18 18:09:12 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/09/18 18:09:12 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/09/18 18:09:12 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/09/18 18:09:12 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/09/18 18:09:12 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/09/18 18:09:12 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/09/18 18:09:12 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/09/18 18:09:12 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/09/18 18:09:12 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/09/18 18:09:12 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/09/18 18:09:12 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/09/18 18:09:12 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/09/18 18:09:12 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/09/18 18:09:12 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/09/18 18:09:12 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/09/18 18:09:12 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 18:09:12 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/09/18 17:57:48 | 000,773,050 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/09/18 15:53:22 | 000,246,804 | —- | M] () – C:\Windows\SysNative\drivers\AtherosBt.bin
[2013/09/18 15:53:22 | 000,001,796 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x11020000_40.dfu
[2013/09/18 15:53:22 | 000,001,434 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x31010000_40.dfu
[2013/09/18 15:53:22 | 000,001,242 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2013/09/18 15:53:22 | 000,001,228 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2013/09/18 15:53:22 | 000,001,214 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2013/09/18 15:53:22 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020201_40.dfu
[2013/09/18 15:53:22 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2013/09/18 15:53:22 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40.dfu
[2013/09/18 15:53:22 | 000,001,198 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020201_26.dfu
[2013/09/18 15:53:22 | 000,001,198 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_26.dfu
[2013/09/18 15:53:22 | 000,001,192 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2013/09/18 15:38:27 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2013/09/18 15:38:27 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2013/09/18 15:33:04 | 000,002,073 | —- | M] () – C:\Windows\SysNative\snyinst.oem
[2013/09/18 15:29:16 | 000,029,480 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2013/09/18 15:23:41 | 000,074,703 | —- | M] () – C:\Windows\SysWow64\mfc45.dll
[2013/09/18 15:10:11 | 000,002,044 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Sony MSS.lnk
[2013/09/18 14:50:39 | 000,000,000 | RH– | M] () – C:\Windows\SysWow64\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 14:50:39 | 000,000,000 | RH– | M] () – C:\Windows\SysNative\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 13:51:42 | 000,196,608 | —- | M] () – C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2013/09/18 13:33:55 | 000,627,600 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/09/18 13:33:55 | 000,252,296 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/09/18 13:33:55 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/09/18 13:33:55 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/09/18 13:30:16 | 000,014,960 | —- | M] () – C:\Windows\SysNative\results.xml
[2013/09/18 13:22:33 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/09/18 13:20:17 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2013/09/18 13:12:43 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf

========== Files Created - No Company Name ==========

[2013/09/23 10:48:26 | 000,001,188 | —- | C] () – C:\Windows\SysWow64\ServiceConfig.xml
[2013/09/19 17:47:16 | 000,659,968 | —- | C] () – C:\Users\Heidi\Documents\MicrosoftFixit50195.msi
[2013/09/19 15:57:38 | 000,659,456 | —- | C] () – C:\Users\Heidi\Documents\MicrosoftFixit50526_1.msi
[2013/09/19 15:55:52 | 000,659,456 | —- | C] () – C:\Users\Heidi\Documents\MicrosoftFixit50526.msi
[2013/09/18 21:47:35 | 000,002,279 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/18 21:46:55 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/18 21:46:53 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/18 21:46:22 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/09/18 20:31:52 | 000,035,000 | —- | C] () – C:\Windows\SysNative\mxntdfg.exe
[2013/09/18 20:31:51 | 000,020,488 | —- | C] () – C:\Windows\SysNative\drivers\AQFileRestore.sys
[2013/09/18 20:31:51 | 000,001,984 | —- | C] () – C:\Windows\SysNative\drivers\AQFileRestore.inf
[2013/09/18 20:31:38 | 000,002,210 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SystemSuite Professional.lnk
[2013/09/18 20:18:12 | 000,001,098 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Copernic Agent Personal.lnk
[2013/09/18 20:11:21 | 000,001,086 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Copernic Agent Personal.lnk
[2013/09/18 20:11:19 | 000,109,782 | —- | C] () – C:\Windows\CopernicAgentUninstall.exe
[2013/09/18 19:43:42 | 000,001,380 | —- | C] () – C:\Users\Heidi\Desktop\My DAP Downloads.lnk
[2013/09/18 19:19:43 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013/09/18 18:36:26 | 000,001,407 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/09/18 18:11:05 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/09/18 18:11:05 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/09/18 17:07:29 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/09/18 16:49:39 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/09/18 15:36:50 | 000,001,141 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
[2013/09/18 15:33:04 | 460,079,103 | -HS- | C] () – C:\hiberfil.sys
[2013/09/18 15:23:41 | 000,074,703 | —- | C] () – C:\Windows\SysWow64\mfc45.dll
[2013/09/18 15:15:07 | 000,001,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2013/09/18 15:14:58 | 000,001,374 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2013/09/18 15:14:42 | 000,001,458 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013/09/18 15:14:37 | 000,002,486 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013/09/18 15:10:11 | 000,002,044 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Sony MSS.lnk
[2013/09/18 15:10:10 | 000,002,017 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care.lnk
[2013/09/18 14:56:22 | 000,001,275 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Transfer.lnk
[2013/09/18 14:52:56 | 000,002,072 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Gate.lnk
[2013/09/18 14:51:31 | 000,002,679 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Easy Connect.lnk
[2013/09/18 14:51:05 | 000,001,413 | —- | C] () – C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/09/18 14:50:39 | 000,000,000 | RH– | C] () – C:\Windows\SysWow64\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 14:50:39 | 000,000,000 | RH– | C] () – C:\Windows\SysNative\drivers\104D_Sony_SVE151190X.mrk
[2013/09/18 14:50:33 | 000,002,067 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music Unlimited.lnk
[2013/09/18 14:46:53 | 000,000,290 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/09/18 14:46:53 | 000,000,272 | —- | C] () – C:\Users\Heidi\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/09/18 14:46:52 | 001,310,720 | —- | C] () – C:\Users\Heidi\NTUSER.BAK
[2013/09/18 14:46:52 | 001,048,576 | -HS- | C] () – C:\Users\Heidi\NTUSER.BK1
[2013/09/18 14:44:11 | 000,001,297 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home.lnk
[2013/09/18 14:25:37 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/18 14:23:27 | 000,002,197 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Smart Network.lnk
[2013/09/18 14:19:24 | 000,001,995 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Manual.lnk
[2013/09/18 14:16:24 | 000,002,269 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Data Restore Tool.lnk
[2013/09/18 14:15:15 | 000,001,531 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Control Center.lnk
[2013/09/18 14:13:55 | 000,002,390 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Gesture Control.lnk
[2013/09/18 14:12:41 | 000,001,396 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO3DPortal.lnk
[2013/09/18 13:54:58 | 000,002,241 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Gallery.lnk
[2013/09/18 13:51:24 | 000,196,608 | —- | C] () – C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2013/09/18 13:47:35 | 000,000,869 | —- | C] () – C:\Windows\SysWow64\media_center.png
[2013/09/18 13:44:46 | 000,001,203 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Keyboard Shortcuts.lnk
[2013/09/18 13:30:16 | 000,014,960 | —- | C] () – C:\Windows\SysNative\results.xml
[2013/09/18 13:22:33 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/09/18 13:20:17 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2013/09/18 13:16:24 | 000,015,128 | —- | C] () – C:\Windows\SysNative\drivers\IntelMEFWVer.dll
[2013/09/18 13:12:43 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2013/09/18 13:08:03 | 000,227,876 | —- | C] () – C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2013/09/18 12:49:36 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013/09/18 12:49:24 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013/03/07 05:07:20 | 000,091,264 | —- | C] () – C:\Windows\SysWow64\EasyHook32.dll
[2012/03/14 14:54:37 | 000,734,772 | —- | C] () – C:\Windows\SysWow64\igkrng700.bin
[2012/03/14 14:54:36 | 012,978,688 | —- | C] () – C:\Windows\SysWow64\ig7icd32.dll
[2012/03/14 14:54:36 | 000,557,476 | —- | C] () – C:\Windows\SysWow64\igfcg700m.bin
[2012/03/14 14:54:36 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/02/02 23:08:26 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/07/25 20:24:57 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/07/25 19:55:59 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 19:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 21:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 19:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:56E2E879

< End of report >
Hi WoundedBear,

That's rather odd. The steps taken above should have removed Google as the homepage.

=========================

[external image: Posted Image] Reset Internet Explorer

Go to the Start menu > Control Panel > Look in the upper right hand corner and make sure the "Category" drop down menu says Small or Large Icons
Locate Internet Options > Advanced tab > Reset button at the bottom of the menu.

=========================

[external image: Posted Image] Reboot

=========================

Check and see if Google is still the homepage. If so continue on and remove Internet Explorer 10 the re-download and do a fresh install.

=========================

[external image: Posted Image] Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Internet Explorer 10
=========================

[external image: Posted Image] Internet Explorer 10
=========================

[external image: Posted Image] Reboot

=========================

In your next post please provide the following:
  • Status update
No change when I reset IE. I removed Google Chrome and Google toolbar just in case something was hidden. No change. There was only one reference to IE. I removed Internet Explorer enable (DEP) or Internet Explorer (DEP) I can't remember if the (enable) was there or not. It just flashed and was gone, not even a removal program. There was no other reference to Internet Explorer 10. I tried to copy to show you but couldn't figure out how.

No change when I reset IE. I removed Google Chrome and Google toolbar just in case something was hidden. No change.
There was only one reference to IE. I removed Internet Explorer enable (DEP) or Internet Explorer (DEP) I can't remember if the (enable) was there or not. It just flashed and was gone, not even a removal program.
There was no other reference to Internet Explorer 10. I tried to copy to show you but couldn't figure out how.


one hour later:
Looked it up. I did remember there is no way known to man to separate IE from Windows, at least none that I've ever heard of. I went into Programs view updates and uninstalled the IE 10 update. After reboot I was back into IE 9. Google was still there. Re-downloaded IE 10 and rebooted same problem. I noticed that when I went into Internet options and changed the home page to newsminer Google was back immediately. That is when I closed Internet options after changing the homepage I went back in immediately and Google was already back. I didn't even have to close and reopen iE 10 to make it happen.

No change when I reset IE. I removed Google Chrome and Google toolbar just in case something was hidden. No change.
There was only one reference to IE. I removed Internet Explorer enable (DEP) or Internet Explorer (DEP) I can't remember if the (enable) was there or not. It just flashed and was gone, not even a removal program.
There was no other reference to Internet Explorer 10. I tried to copy to show you but couldn't figure out how.


one hour later:
Looked it up. I did remember there is no way known to man to separate IE from Windows, at least none that I've ever heard of. I went into Programs view updates and uninstalled the IE 10 update. After reboot I was back into IE 9. Google was still there. Re-downloaded IE 10 and rebooted same problem. I noticed that when I went into Internet options and changed the home page to newsminer Google was back immediately. That is when I closed Internet options after changing the homepage I went back in immediately and Google was already back. I didn't even have to close and reopen iE 10 to make it happen.

FYI the bar at the top of the page says Speedbit-Google Homepage

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI