DrPepperSoda
Topic Starter
OTL Extras logfile created on: 12/11/2013 8:00:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\N\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.67 Gb Available Physical Memory | 61.27% Memory free
11.98 Gb Paging File | 9.73 Gb Available in Paging File | 81.21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.24 Gb Total Space | 19.37 Gb Free Space | 16.25% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 58.19 Gb Free Space | 19.52% Space Free | Partition Type: NTFS
Drive E: | 119.24 Gb Total Space | 38.28 Gb Free Space | 32.11% Space Free | Partition Type: NTFS
Computer Name: N-PC | User Name: N | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "D:\Program Files\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "D:\Program Files\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "D:\Program Files\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "D:\Program Files\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{153DD011-281E-43B5-8F9B-048307FA9FF4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{254B3E6C-475C-483B-BC0E-B1D6B05D7ABF}" = rport=80 | protocol=6 | dir=out | app=d:\steamlibrary\steamapps\common\warframe\tools\launcher.exe |
"{2C47FF67-D253-4837-B9A2-A00F3F12A29E}" = lport=1542 | protocol=6 | dir=in | name=realtek wps tcp prot |
"{2E0ED53D-91B4-4E3D-887A-59E563B5D63B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{39F8F3C0-75D9-4A55-A7E8-997C7A73986A}" = lport=445 | protocol=6 | dir=in | app=system |
"{3B858EC3-6C86-437F-B5AF-10A7CB56CFB2}" = rport=139 | protocol=6 | dir=out | app=system |
"{40946A94-3772-4899-994C-323C794BE3DF}" = lport=139 | protocol=6 | dir=in | app=system |
"{4C6C3A96-DC63-4941-9838-45E29793A0E0}" = lport=1542 | protocol=17 | dir=in | name=realtek wps udp prot |
"{4C82E18C-16DB-4053-B394-4DA38D172E19}" = lport=137 | protocol=17 | dir=in | app=system |
"{4CB4A3B0-AC15-4498-8BAA-1561B6F7268A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{64D769AE-D0A1-447C-9318-1B3B6451A5D5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6C8DE7E1-2E6A-43C9-940D-DA3720065AF1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{73DC80C3-DDBC-433F-8EE2-487FC693DA98}" = lport=53 | protocol=17 | dir=in | name=realtek ap udp prot |
"{7D6F450B-A3C0-4F47-91CC-471B861E7235}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{84129976-C3B6-4F06-868F-2F4556B4CF0C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8475B39B-51A9-4C2D-96D7-9502AB01E47C}" = rport=445 | protocol=6 | dir=out | app=system |
"{8CF719B2-85CA-4E14-93AE-E4E55155197D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8D52961E-1698-4FD7-95AB-C446DD4B7D8C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A255216B-BE81-4EE9-81C3-2776F8C5019D}" = lport=138 | protocol=17 | dir=in | app=system |
"{B2B0C79B-02B6-4CB4-9456-C3F3A462DDEB}" = rport=138 | protocol=17 | dir=out | app=system |
"{C034C72D-0749-476F-9255-181F0AAB2A8F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C42B8988-BACD-43D1-AADD-848D991B4AD2}" = rport=80 | protocol=6 | dir=out | app=d:\steamlibrary\steamapps\common\warframe\warframe.x64.exe |
"{C6D88C9E-C91B-49E4-8B9A-A0CB1C8D91F8}" = rport=80 | protocol=6 | dir=out | app=d:\steamlibrary\steamapps\common\warframe\warframe.exe |
"{D464FC74-91BA-4B03-97F7-D48A09148A37}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D9FA7346-4235-411D-A472-C69C83777FA2}" = rport=137 | protocol=17 | dir=out | app=system |
"{DACD79D6-1662-4C68-B35D-01EA90C52441}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EB997FD3-D78C-4CD5-8AB0-0E46D9D9691B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03801721-0500-4A8E-BAE2-01132F2169DA}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{058EC654-CAE2-4B9D-99E0-498C27B6988D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{07588985-A795-4F88-8068-922726BA663A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{083BE669-915E-4C51-89D8-E8E9C484DFEC}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{0F249ED6-8CAD-4284-9AEE-40C46ECBF954}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{11F3A838-D1DB-468B-AB34-0D5392283E7A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{135448BD-339F-4416-811D-4C9BD0D7B372}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe |
"{176BECE3-8FC7-4CD0-A8CD-6E1DD9005159}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\warframe\warframe.exe |
"{17B04C34-49A0-4D33-B688-CE4BE1D6B097}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\state of decay\stateofdecay.exe |
"{18EEB0B9-AB8B-4E97-ADF2-C5A16A1C9AAC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1C356E25-96C9-4AF0-98EA-993D0ED465E3}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe |
"{1D7AB02B-A3F6-42F4-A0C6-5131B08D9019}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1D9BA64B-6187-4B17-87D4-9B65FA20353B}" = protocol=6 | dir=in | app=e:\program files\star wars-the old republic\launcher.exe |
"{1FEF69C9-22CB-447B-8399-8DECAAB9C9CF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{209ECEB6-3085-4896-9D27-2E65A10C2B92}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2164B3DA-B340-4396-B290-4E3495019312}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{28B380C9-F9FC-4FF5-A681-9ECE1BC36A43}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\warframe\warframe.x64.exe |
"{3BC4B6B7-7EE6-4EA9-B822-47CE8AD1F3F0}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{3ECA3C92-B222-4CB0-A1B3-92389149AD68}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{492075EF-0E26-448F-B7EB-6A5CC4DF64A3}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{507A5EE5-B842-4CD2-98BC-9FE80F02A6AD}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed iv black flag\ac4bfmp.exe |
"{556E901E-E430-473B-B8E6-5FA12B96D82F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5824E0A4-AD08-4A5C-A23B-1A8A84211EB7}" = protocol=6 | dir=in | app=c:\users\n\appdata\roaming\spotify\spotify.exe |
"{5999F30F-48F1-4E64-9A4E-DF9B93D1D6F8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5BB4390A-DF21-4450-BBCF-A38CD709A6E4}" = protocol=17 | dir=in | app=c:\users\n\appdata\roaming\spotify\spotify.exe |
"{5E7FB039-F177-4841-821D-92722F44A09E}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed iv black flag\ac4bfsp.exe |
"{5F69852F-5186-4836-9011-56DD94809DE1}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed iv black flag\ac4bfmp.exe |
"{61C17B1E-4E3B-4659-A924-4A5E84F52EF6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{63C0A0EB-8477-455A-8E77-B7DA52441B0F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{6413854E-E320-4713-B2CA-6E626CB8DCC9}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\usb-n13 wlan card utilities\rtwlan.exe |
"{648D53E2-1037-41D2-A0BC-841306A97644}" = protocol=17 | dir=in | app=e:\program files\origin games\battlefield 4\bf4_x86.exe |
"{66B796A7-6D40-43D1-8AE1-469C5051C0D3}" = protocol=6 | dir=in | app=e:\program files\star wars-the old republic\launcher.exe |
"{756D6BAD-03AD-4836-9AA5-B45F897555BF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{7703539B-0A43-4EC6-B197-2EDA08B0BD2B}" = protocol=17 | dir=in | app=e:\program files\star wars-the old republic\launcher.exe |
"{771F6364-B308-4A8C-AF52-134E4EEA5899}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{7B2899D6-AC5D-4526-A6D6-6F331187D787}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{7C97EBD5-B89B-4D5E-A20F-E419DFEBA38F}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{7F9EBD2D-EB48-4DA2-87E9-A9E0BB89DC94}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{7FC9BB1D-64B4-46A2-A555-A984A012E4F9}" = protocol=17 | dir=in | app=d:\program files\diablo iii\diablo iii.exe |
"{8021CF31-A2D6-45EC-B3BF-E8698B26108D}" = protocol=6 | dir=in | app=e:\program files\origin games\battlefield 4\bf4_x86.exe |
"{81B89775-8F9E-4806-8787-566279D8D3EB}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{906E2EC9-58B3-43D3-9424-02114E475F22}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{90C35246-3186-40FD-8968-34D563AD631B}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{94DAC923-C47C-4654-8DEF-A8F696B8D878}" = protocol=17 | dir=in | app=e:\program files\steam\steam.exe |
"{974F878A-A901-4AB6-88C4-94C26FA7EAB3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{976A07DB-896C-4D9B-8475-4BBEA0E4D025}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{99D43E46-D3E7-4A4E-810E-835D85975021}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{9BAC8C65-C52F-4469-8A67-4F59892064AB}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{9C2281E8-CE18-478D-A6EA-1217BF7ABC70}" = protocol=17 | dir=in | app=e:\program files\star wars-the old republic\launcher.exe |
"{9D129C75-A15B-4B45-9324-06F33FB7280B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{9EDB909F-4956-4B33-8E5B-3045D4A62430}" = protocol=17 | dir=in | app=c:\program files (x86)\qbittorrent\qbittorrent.exe |
"{A159414F-41C6-47BA-92E2-43307D374321}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A3D3188B-E411-463D-BDE6-41ECA6E556B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A65EC14C-9F76-4C1B-950C-81AC4098C2C6}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{A778E011-018B-4F24-9060-62BC851B30E1}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{AB01CEF5-8BA9-4EC3-83C5-F8A0CC3D434F}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\state of decay\stateofdecay.exe |
"{AB5F35E1-932E-412E-923C-922931301392}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AFEA65BC-3050-4CF4-9D08-FBE10AE17882}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{B81289F2-4F26-44BF-9CAB-17411DBC3685}" = protocol=6 | dir=in | app=e:\program files\origin games\battlefield 4\bf4.exe |
"{BABE0923-D38A-4C2F-8B0A-6285BBDF325F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BAF4C540-4A56-4BDA-BF19-CA18A6032348}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BE48C410-C58F-4259-A8E8-5792E3240EC0}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\the stanley parable\stanley.exe |
"{C12DE3C3-C78E-4F3B-9DAA-EFC08B9B55DC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{C2BC6F1F-D6CB-4A57-B95F-CA06DC8C2439}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C3FFA7C7-2E97-4FAB-8F56-BACAB1B3EDE3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{C6884A71-49A3-48BC-A206-2B3F6100E319}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\assassin's creed iv black flag\ac4bfsp.exe |
"{C70DF427-BA59-49FE-A042-929178D405E2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{C855C8CE-1027-487D-8CF4-423628CE7035}" = protocol=17 | dir=in | app=c:\users\n\appdata\roaming\spotify\spotify.exe |
"{CB0F61ED-39CF-4BAC-A8B0-2F78C52A33C3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{CBBD2B72-A9B0-4DF4-A69D-8C08C82B2272}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CE214F1A-F0AF-4115-8343-93FD5BC9C979}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\usb-n13 wlan card utilities\rtwlan.exe |
"{D0B30AD5-8F26-4743-823A-520EEB1ABE48}" = protocol=6 | dir=in | app=c:\program files (x86)\qbittorrent\qbittorrent.exe |
"{D1D7738F-F87C-4EB5-8AA8-073A43B2DDD5}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D2B75BF5-AB6B-4959-B74D-48FC7F75B737}" = protocol=6 | dir=in | app=c:\users\n\appdata\roaming\spotify\spotify.exe |
"{D3CD4BB5-C3BD-49C6-8749-88BA14710658}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{D3DA22C9-CE5D-463D-81C8-E3519CF28E9E}" = protocol=17 | dir=out | app=d:\steamlibrary\steamapps\common\warframe\warframe.x64.exe |
"{D4839CAC-6A43-4422-B254-F316EA212EA6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{D633DE1A-AE34-4263-9786-963F19A5FC18}" = protocol=6 | dir=out | app=system |
"{D86A8AFB-67E5-4E8E-80D7-E3D121421F80}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{DA671962-7531-4222-B472-7893C784CA01}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{DB7D0A1A-6EAE-47DB-AB73-2FAFC3DF5FC4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DD243255-EB6A-4C99-954A-25531C978E15}" = protocol=6 | dir=in | app=d:\program files\diablo iii\diablo iii.exe |
"{E5BED3C7-EEF9-4A8B-BA6C-4C8681A4A5D6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{E7F8E50A-9D84-4672-875E-941192A8E6C2}" = protocol=6 | dir=in | app=e:\program files\steam\steam.exe |
"{EB98ACA1-487F-41A5-ACB9-0797D50BC4B7}" = protocol=17 | dir=out | app=d:\steamlibrary\steamapps\common\warframe\warframe.exe |
"{EEE10B21-A62E-4355-B1CE-7C484E5FEE86}" = protocol=17 | dir=in | app=e:\program files\origin games\battlefield 4\bf4.exe |
"{F06D350A-1E8F-4FAA-9F61-F3F1338FF5DC}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F40D883E-3BD6-4CBF-A58C-203B5FB2194B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\the stanley parable\stanley.exe |
"{FC4FB9C7-FF6E-4157-B857-3606C4060BAE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{FE982C64-ED2B-47C1-A5E8-6FAF9B8601F8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"TCP Query User{01A5A3A1-5E1A-4A85-A331-695A6BDF31D3}D:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=d:\program files\xfire\xfire.exe |
"TCP Query User{0A6BF6CD-A181-4AA7-8B2D-EE969DBDC7C7}C:\users\n\downloads\diablo-iii-8370-enus-installer-downloader.exe" = protocol=6 | dir=in | app=c:\users\n\downloads\diablo-iii-8370-enus-installer-downloader.exe |
"TCP Query User{1E7547C0-D6BA-4DF0-BAC8-9CE356180310}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{5286F5AE-EB0D-4D6F-B6A0-D85D739ED4E8}D:\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=d:\guild wars 2\gw2.exe |
"TCP Query User{61591338-07B1-4E44-B86E-88FA81D43380}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"TCP Query User{6B42B683-51F2-4D72-9960-672CE91C143E}C:\users\n\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\n\appdata\local\temp\gw2.exe |
"TCP Query User{8DC30944-2003-4BBB-B371-46E129CE970A}E:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
"TCP Query User{91DE89A8-3CD8-4A16-9BEC-85D0D575FBEF}E:\program files\steam\steamapps\[removed]\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\[removed]\team fortress 2\hl2.exe |
"TCP Query User{9307BA2F-DB60-4C62-BF56-44E69CE24BB9}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"TCP Query User{989F8D17-B49D-4D4B-8FCD-7957FD1A022C}E:\program files\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"TCP Query User{A291CFBB-DF6C-41F6-AC47-D363C7CCA932}E:\program files\games\tribes alpha\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=e:\program files\games\tribes alpha\binaries\win32\tribesascend.exe |
"TCP Query User{C8DFB06D-165A-4FC2-833A-C976CE4152DB}D:\steamlibrary\steamapps\common\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\planetside 2\planetside2.exe |
"TCP Query User{C9C86B3D-5ECE-4A0B-B65E-0271E7BD77C0}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"TCP Query User{EDA7BE6B-6BE7-4A94-9437-F7043BE5AFD9}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{0AEC5928-A43C-424E-8285-586A19EC0DAE}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"UDP Query User{153AD3BD-77A2-48B4-B5D6-FB1CBFAC5056}D:\steamlibrary\steamapps\common\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\planetside 2\planetside2.exe |
"UDP Query User{3388752F-F764-4D40-9EA4-A050EE5ABF11}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{6F1A16C4-B1C3-4661-98C6-8FCA68980194}E:\program files\games\tribes alpha\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=e:\program files\games\tribes alpha\binaries\win32\tribesascend.exe |
"UDP Query User{802604E4-C090-4F4B-A5CE-04F7219D1C61}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe |
"UDP Query User{905818E2-7F35-40E9-8ADA-A803AD95A680}C:\users\n\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\n\appdata\local\temp\gw2.exe |
"UDP Query User{B4D63610-ACA1-4A2E-900A-2463AB8B9E01}D:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=d:\program files\xfire\xfire.exe |
"UDP Query User{C8639717-8C7F-4D37-97C6-34F32AC838D3}E:\program files\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"UDP Query User{D3A8A1DF-9FE5-4E0B-8DE1-C87ECAB577F1}C:\users\n\downloads\diablo-iii-8370-enus-installer-downloader.exe" = protocol=17 | dir=in | app=c:\users\n\downloads\diablo-iii-8370-enus-installer-downloader.exe |
"UDP Query User{D4E0734B-82C8-4529-A2BA-E79AAEB59679}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{DA456B62-13D2-4B22-AD25-69263DDA8203}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"UDP Query User{DAB9BBED-DFEF-4DE3-940E-C3A04894C3A4}D:\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=d:\guild wars 2\gw2.exe |
"UDP Query User{E428A7AB-F27D-4645-B68C-575181F7C135}E:\program files\steam\steamapps\[removed]\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\[removed]\team fortress 2\hl2.exe |
"UDP Query User{FE77B998-FCFA-468F-8BF4-6CE1EDC3F93D}E:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{22D8AE6F-3C6B-47E8-8F04-629F23DBE978}" = iTunes
"{26A24AE4-039D-4CA4-87B4-2F86417011FF}" = Java 7 Update 11 (64-bit)
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89BDAE1A-7B8E-4A0E-A169-02F7F366451D}" = iCloud
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 RC
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{E102B843-786A-4F58-AF75-6504570E207B}" = Microsoft Security Client
"{E70808B9-78FE-3081-9658-A3C9DBC9A798}" = Microsoft .NET Framework 4.5.1 RC
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"Microsoft Security Client" = Microsoft Security Essentials
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"UDK-ae99c9c4-7e6c-44e4-b900-640bd69ecf40" = My Game Long Name
"WinRAR archiver" = WinRAR 4.01 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse 2.0
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20288888-A7AF-4B24-8AEB-398D20CD563C}" = Sound Blaster X-Fi
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{52E225FC-FCB4-41F7-837B-6E37FB05BD7B}" = Adobe AIR
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79B1FF35-9EA8-48ED-98D6-19ABE004BE89}" = DefianceRuntimes
"{7DECB2A6-C226-6042-9C2B-83316950D30E}" = Pandora
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{99BEB67F-B288-44F5-8B2A-23F5A52FA1AE}_is1" = Universal AntiCheat 3 v1.064
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C049499-055C-4a0c-A916-1D12314F45EB}" = ASUS USB-N13 WLAN Card Utilities & Driver
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABADE36E-EC37-413B-8179-B432AD3FACE7}" = Battlefield 4™
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.8)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{C0C31BCC-56FB-42A7-8766-D29E1BD74C7C}" = Python 2.7.3
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA66CFD7-0977-4C45-AACD-A8BB994B1A05}" = Quake Live Mozilla Plugin
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"AudioCS" = Creative Audio Control Panel
"Battlelog Web Plugins" = Battlelog Web Plugins
"com.pandora.desktop.E7C14276FFE9EEF0BC7DCE654C467D9A299EFD21.1" = Pandora
"DivX Setup" = DivX Setup
"ESN Sonar-0.70.4" = ESN Sonar
"Google Chrome" = Google Chrome
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.7.0 (Basic)
"Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"OpenAL" = OpenAL
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"qbittorrent" = qBittorrent 3.0.11
"SMPlayer" = SMPlayer 0.8.6.5781
"Steam App 221910" = The Stanley Parable
"Steam App 241540" = State of Decay
"Steam App 242050" = Assassin’s Creed IV Black Flag
"Steam App 730" = Counter-Strike: Global Offensive
"Steam App 7940" = Call of Duty 4: Modern Warfare
"SysInfo" = Creative System Information
"Uplay" = Uplay
"VLC media player" = VLC media player 2.1.1
"WebClient" = WebClient
"Xfire" = Xfire (remove only)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Flux" = f.lux
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SpotifyHelper.exe, version: 0.0.0.0, time
stamp: 0x5256d7d9 Faulting module name: libcef.dll, version: 3.1453.1447.0, time
stamp: 0x52382571 Exception code: 0xc000001d Fault offset: 0x00c7daaf Faulting process
id: 0x1274 Faulting application start time: 0x01cee4c442f22a9a Faulting application
path: C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyHelper.exe Faulting module
path: C:\Users\N\AppData\Roaming\Spotify\Data\libcef.dll Report Id: 80c4b6d9-50b7-11e3-977c-001fbc012ef9
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SpotifyHelper.exe, version: 0.0.0.0, time
stamp: 0x5256d7d9 Faulting module name: libcef.dll, version: 3.1453.1447.0, time
stamp: 0x52382571 Exception code: 0xc000001d Fault offset: 0x00c7daaf Faulting process
id: 0x1840 Faulting application start time: 0x01cee4c442f381ed Faulting application
path: C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyHelper.exe Faulting module
path: C:\Users\N\AppData\Roaming\Spotify\Data\libcef.dll Report Id: 80c504f9-50b7-11e3-977c-001fbc012ef9
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SpotifyHelper.exe, version: 0.0.0.0, time
stamp: 0x5256d7d9 Faulting module name: libcef.dll, version: 3.1453.1447.0, time
stamp: 0x52382571 Exception code: 0xc000001d Fault offset: 0x00c7daaf Faulting process
id: 0x15f0 Faulting application start time: 0x01cee4c442f41a83 Faulting application
path: C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyHelper.exe Faulting module
path: C:\Users\N\AppData\Roaming\Spotify\Data\libcef.dll Report Id: 80c4dde9-50b7-11e3-977c-001fbc012ef9
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program SpotifyHelper.exe because of this error. Program: SpotifyHelper.exe
File:
The error value is listed in the Additional Data section. User Action 1. Open the
file again. This situation might be a temporary problem that corrects itself when
the program runs again. 2. If the file still cannot be accessed and - It is on the
network, your network administrator should verify that there is not a problem with
the network and that the server can be contacted. - It is on a removable disk, for
example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the
computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK,
click Start, click Run, type CMD, and then click OK. At the command prompt, type
CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from
a backup copy. 5. Determine whether other files on the same disk can be opened.
If not, the disk might be damaged. If it is a hard disk, contact your administrator
or computer hardware vendor for further assistance. Additional Data Error value: 00000000
Disk
type: 0
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program SpotifyHelper.exe because of this error. Program: SpotifyHelper.exe
File:
The error value is listed in the Additional Data section. User Action 1. Open the
file again. This situation might be a temporary problem that corrects itself when
the program runs again. 2. If the file still cannot be accessed and - It is on the
network, your network administrator should verify that there is not a problem with
the network and that the server can be contacted. - It is on a removable disk, for
example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the
computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK,
click Start, click Run, type CMD, and then click OK. At the command prompt, type
CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from
a backup copy. 5. Determine whether other files on the same disk can be opened.
If not, the disk might be damaged. If it is a hard disk, contact your administrator
or computer hardware vendor for further assistance. Additional Data Error value: 00000000
Disk
type: 0
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program SpotifyHelper.exe because of this error. Program: SpotifyHelper.exe
File:
The error value is listed in the Additional Data section. User Action 1. Open the
file again. This situation might be a temporary problem that corrects itself when
the program runs again. 2. If the file still cannot be accessed and - It is on the
network, your network administrator should verify that there is not a problem with
the network and that the server can be contacted. - It is on a removable disk, for
example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the
computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK,
click Start, click Run, type CMD, and then click OK. At the command prompt, type
CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from
a backup copy. 5. Determine whether other files on the same disk can be opened.
If not, the disk might be damaged. If it is a hard disk, contact your administrator
or computer hardware vendor for further assistance. Additional Data Error value: 00000000
Disk
type: 0
Error - 11/18/2013 9:11:23 PM | Computer Name = N-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program SpotifyHelper.exe because of this error. Program: SpotifyHelper.exe
File:
The error value is listed in the Additional Data section. User Action 1. Open the
file again. This situation might be a temporary problem that corrects itself when
the program runs again. 2. If the file still cannot be accessed and - It is on the
network, your network administrator should verify that there is not a problem with
the network and that the server can be contacted. - It is on a removable disk, for
example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the
computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK,
click Start, click Run, type CMD, and then click OK. At the command prompt, type
CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from
a backup copy. 5. Determine whether other files on the same disk can be opened.
If not, the disk might be damaged. If it is a hard disk, contact your administrator
or computer hardware vendor for further assistance. Additional Data Error value: 00000000
Disk
type: 0
Error - 11/18/2013 9:49:32 PM | Computer Name = N-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DivXUpdate.exe, version: 1.0.6.88, time
stamp: 0x511afc59 Faulting module name: ntdll.dll, version: 6.1.7601.18247, time
stamp: 0x521ea8e7 Exception code: 0xc0000005 Fault offset: 0x0002e3be Faulting process
id: 0xe24 Faulting application start time: 0x01cee1d6cd3ff897 Faulting application
path: C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: d51dcbd8-50bc-11e3-977c-001fbc012ef9
Error - 11/19/2013 12:45:29 AM | Computer Name = N-PC | Source = Application Error | ID = 1000
Description = Faulting application name: LolClient.exe, version: 0.0.0.0, time stamp:
0x515663e0 Faulting module name: Adobe AIR.dll, version: 3.7.0.1530, time stamp:
0x5156646c Exception code: 0xc0000005 Fault offset: 0x0006dd76 Faulting process id:
0x19b4 Faulting application start time: 0x01cee4dd0f3fe77f Faulting application path:
D:\Program Files\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.57\deploy\LolClient.exe
Faulting
module path: D:\Program Files\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.57\deploy\Adobe
AIR\Versions\1.0\Adobe AIR.dll Report Id: 69d3bbad-50d5-11e3-977c-001fbc012ef9
Error - 11/19/2013 9:41:19 PM | Computer Name = N-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iw3mp.exe, version: 0.0.0.0, time stamp:
0x4859a219 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00000000 Faulting process id: 0x1acc Faulting application
start time: 0x01cee591836dd8e1 Faulting application path: e:\program files\Steam\steamapps\common\call
of duty 4\iw3mp.exe Faulting module path: unknown Report Id: da0b1812-5184-11e3-977c-001fbc012ef9
[ System Events ]
Error - 12/11/2013 9:13:46 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:11 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:17 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:17 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:17 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:17 PM | Computer Name = N-PC | Source = Service Control Manager | ID = 7023
Description = The Windows Search service terminated with the following error: %%1392
Error - 12/11/2013 9:14:17 PM | Computer Name = N-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
683 time(s).
Error - 12/11/2013 9:14:17 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:18 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
Error - 12/11/2013 9:14:18 PM | Computer Name = N-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume Windows.
< End of report >
OTL logfile created on: 12/11/2013 8:00:22 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\N\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.67 Gb Available Physical Memory | 61.27% Memory free
11.98 Gb Paging File | 9.73 Gb Available in Paging File | 81.21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.24 Gb Total Space | 19.37 Gb Free Space | 16.25% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 58.19 Gb Free Space | 19.52% Space Free | Partition Type: NTFS
Drive E: | 119.24 Gb Total Space | 38.28 Gb Free Space | 32.11% Space Free | Partition Type: NTFS
Computer Name: N-PC | User Name: N | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\N\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\N\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
PRC - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtWLan.exe (ASUSTeK Computer Inc.)
PRC - C:\Windows\SysWOW64\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\Windows\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe (Realtek)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\119dbb1f8385c58f2bee709d39bbb90d\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\896c51e0c895a7d3125856d303a3495f\UIAutomationTypes.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\e2bc7466bfb562cdc37c7de5fb176537\PresentationFramework-SystemXml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio4b37ff64#\858ea27d6a6315f02c23755d1574e777\PresentationFramework-SystemXmlLinq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\dc7d3cf3ed23c066cf958991e0c5a2ee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7ce7f36d6ddd95c15fa5bdefbfcbf0c\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5af458179c5c48dd9f400159b23c2398\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\66e122de5ff2bad83e6150461fd1f3a4\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d04bc8678d72be74f11365ced3c3cfe6\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\7b986cec878db3a6ab533de03fc552be\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\f12d4d2c367056d466b413892422cfb6\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\f1c8087380e2a00c4925353ff41819ef\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\3a77639e6d14a90630ff1cce877134ae\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\35ff79b0dd6c57013ea52df5a95efd72\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\f56c031ccb3c19bfcdd668cdd0d0babc\System.ServiceModel.Internals.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\3ae392116532056a505ee49002341288\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\42f19eab7abb6a12442e3a9572ad370d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\aaadf3ca1bcec0c03ce992dec33a45fa\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\ab78c8f8e5568f893308833861fc11d7\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf0c209df74c672dfdbd31f9c3e15195\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Windows\SysWOW64\CtxfiRes.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (IEEtwCollectorService) – C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (NisSrv) – C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Realtek11nCU) – C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe (Realtek)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (rzudd) – C:\Windows\SysNative\drivers\rzudd.sys (Razer Inc)
DRV:64bit: - (rzdaendpt) – C:\Windows\SysNative\drivers\rzdaendpt.sys (Razer Inc)
DRV:64bit: - (rzvkeyboard) – C:\Windows\SysNative\drivers\rzvkeyboard.sys (Razer Inc)
DRV:64bit: - (rzendpt) – C:\Windows\SysNative\drivers\rzendpt.sys (Razer Inc)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (AE3000) – C:\Windows\SysNative\drivers\AE3000w764.sys (Ralink Technology Corp.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8192cu) – C:\Windows\SysNative\drivers\rtwlanu.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (bulkadi) – C:\Windows\SysNative\drivers\bulkrazer_x64.sys (Windows (R) Codename Longhorn DDK provider)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (VKbms) – C:\Windows\SysNative\drivers\VKbms.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (ha20x22k) – C:\Windows\SysNative\drivers\ha20x22k.sys (Creative Technology Ltd)
DRV:64bit: - (ha20x2k) – C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (emupia) – C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctprxy2k) – C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (ossrv) – C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) – C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT.SYS) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT.SYS) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (DAdderFltr) – C:\Windows\SysNative\drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT2304157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=U019&ocid;=U019DHP&dt;=070913
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4B CD CF 70 E2 94 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://www.bing.com/search?FORM=U019DF&PC;=U019&dt;=070913&q;={searchTerms}&src;=IE-SearchBox
IE - HKCU\..\SearchScopes\4C7F52207A584899B7495A52936DA25E: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT2304157
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "XfireXO Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: DivXWebPlayer%40divx.com:2.0.2.039
FF - prefs.js..extensions.enabledAddons: bernd%40staege.info:0.7.3
FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:2.1.2.172
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.16
FF - prefs.js..extensions.enabledAddons: cryenginebrowserplugin%40crytek.com:0.37.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1206147.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@EDVR/WebClient: C:\windows\system32\WebClient\npwebclient.dll (Google)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.116.0: C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.3.2: C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: D:\Program Files\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\N\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/02/19 18:17:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/09/09 10:06:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/09/14 05:48:07 | 000,000,000 | —D | M]
[2011/10/27 15:08:45 | 000,000,000 | —D | M] (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Extensions
[2013/12/07 10:52:10 | 000,000,000 | —D | M] (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions
[2013/09/25 05:55:17 | 000,000,000 | —D | M] (GFACE Experience Plugin) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\[removed]
[2013/12/07 10:52:10 | 000,000,000 | —D | M] (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\staged
[2013/01/28 14:08:03 | 000,008,757 | —- | M] () (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\[removed]
[2011/10/29 08:19:54 | 000,550,833 | —- | M] () (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\[removed]
[2012/05/08 19:04:24 | 000,401,328 | —- | M] () (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\[removed]
[2013/12/07 10:52:08 | 000,915,554 | —- | M] () (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/04/03 22:58:57 | 000,714,654 | —- | M] () (No name found) – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2011/10/26 10:58:24 | 000,000,917 | —- | M] () – C:\Users\N\AppData\Roaming\Mozilla\Firefox\Profiles\laqk22os.default\searchplugins\conduit.xml
[2013/09/09 10:06:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/09/09 10:06:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/09/09 10:06:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/09/09 10:06:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/09/09 10:06:52 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/02/19 18:17:02 | 000,000,000 | —D | M] (No name found) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Disabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: QUAKE LIVE (Enabled) = C:\ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\N\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: DVR Client (Enabled) = C:\windows\system32\WebClient\npwebclient.dll
CHR - Extension: VLC for YouTube\u2122 = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablmclcliiiegfmpbkfhnhipoejclmel\1.1_0\
CHR - Extension: Google Drive = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: James White = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3_0\
CHR - Extension: YouTube = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0\
CHR - Extension: Google Search = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Cloud Reader = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd\1.4.0_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.3.1.2_0\
CHR - Extension: Google Wallet = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0\
CHR - Extension: Gmail = C:\Users\N\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKCU..\Run: [f.lux] C:\Users\N\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6845E5A8-3C78-4BF1-BEB1-B041B467E165}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9380999-89FD-4DDB-8394-EE9B94A1405A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E808D6AF-454B-4BA5-90DF-14ADAA137DFD}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{1abf95cc-0633-11e1-9031-001fbc012ef9}\Shell - "" = AutoRun
O33 - MountPoints2\{1abf95cc-0633-11e1-9031-001fbc012ef9}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: VIDC.XFR1 - xfcodec64.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/12/11 19:48:04 | 000,000,000 | —D | C] – C:\Users\N\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/12/11 19:48:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/12/05 06:43:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/12/03 13:20:07 | 000,000,000 | —D | C] – C:\Users\N\Documents\Battlefield 4
[2013/12/03 13:19:42 | 000,000,000 | —D | C] – C:\Users\N\AppData\Local\ESN
[2013/12/02 21:30:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4
[2013/12/02 21:30:15 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Common Files\EAInstaller
[2013/12/02 21:30:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Battlelog Web Plugins
[2013/12/02 21:29:26 | 000,000,000 | —D | C] – C:\ProgramData\Package Cache
[2013/12/02 07:38:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Origin Games
[2013/11/28 10:29:57 | 000,000,000 | -HSD | C] – C:\found.001
[2013/11/27 23:17:22 | 000,028,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEUDINIT.EXE
[2013/11/27 23:15:29 | 000,940,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/11/27 23:15:29 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/11/27 23:15:25 | 001,926,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/11/27 23:15:25 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/11/27 23:15:25 | 000,645,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsIntl.dll
[2013/11/27 23:15:25 | 000,616,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/11/27 23:15:25 | 000,440,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/11/27 23:15:25 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/11/27 23:15:25 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/11/27 23:15:25 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/11/27 23:15:25 | 000,164,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/11/27 23:15:25 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/11/27 23:15:25 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/11/27 23:15:25 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/11/27 23:15:25 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013/11/27 23:15:24 | 001,051,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/11/27 23:15:24 | 000,610,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/11/27 23:15:24 | 000,553,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9diag.dll
[2013/11/27 23:15:24 | 000,151,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/11/27 23:15:24 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/11/27 23:15:24 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/11/27 23:15:24 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/11/27 23:15:24 | 000,112,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/11/27 23:15:24 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/11/27 23:15:24 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/11/27 23:15:24 | 000,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/11/27 23:15:24 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/11/27 23:15:24 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/11/27 23:15:24 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MshtmlDac.dll
[2013/11/27 23:15:24 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/11/27 23:15:24 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/11/27 23:15:24 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieetwproxystub.dll
[2013/11/27 23:15:24 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/11/27 23:15:24 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/11/27 23:15:24 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/11/27 23:15:24 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/11/27 23:15:23 | 005,765,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/11/27 23:15:23 | 001,993,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/11/27 23:15:23 | 001,228,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/11/27 23:15:23 | 000,942,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jsIntl.dll
[2013/11/27 23:15:23 | 000,817,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/11/27 23:15:23 | 000,708,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9diag.dll
[2013/11/27 23:15:23 | 000,626,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/11/27 23:15:23 | 000,616,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/11/27 23:15:23 | 000,574,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/11/27 23:15:23 | 000,548,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/11/27 23:15:23 | 000,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/11/27 23:15:23 | 000,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/11/27 23:15:23 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/11/27 23:15:23 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/11/27 23:15:23 | 000,235,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/11/27 23:15:23 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/11/27 23:15:23 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/11/27 23:15:23 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/11/27 23:15:23 | 000,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/11/27 23:15:23 | 000,131,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/11/27 23:15:23 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/11/27 23:15:23 | 000,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/11/27 23:15:23 | 000,090,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/11/27 23:15:23 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/11/27 23:15:23 | 000,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/11/27 23:15:23 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/11/27 23:15:23 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/11/27 23:15:23 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/11/27 23:15:23 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/11/27 23:15:23 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013/11/27 23:15:23 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/11/27 23:15:23 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/11/27 23:15:23 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/11/27 23:15:22 | 000,774,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/11/27 23:15:22 | 000,147,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/11/27 23:15:22 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/11/27 23:15:22 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/11/27 23:15:22 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieetwcollector.exe
[2013/11/27 23:15:22 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MshtmlDac.dll
[2013/11/27 23:15:22 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/11/27 23:15:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieetwproxystub.dll
[2013/11/27 23:15:22 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/11/27 23:15:22 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/11/27 23:15:22 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieetwcollectorres.dll
[2013/11/25 14:07:33 | 000,000,000 | —D | C] – C:\Users\N\AppData\Local\Ubisoft Game Launcher
[2013/11/25 14:07:33 | 000,000,000 | —D | C] – C:\Users\N\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2013/11/25 14:07:33 | 000,000,000 | —D | C] – C:\Users\N\Documents\Assassin's Creed IV Black Flag
[2013/11/25 14:07:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ubisoft
[2013/11/25 14:04:28 | 000,000,000 | —D | C] – C:\Windows\Migration
[2013/11/13 06:11:40 | 001,474,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/11/13 06:11:37 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/11/13 06:11:37 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/11/13 06:11:37 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\credui.dll
[2013/11/13 06:11:37 | 000,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2013/11/13 06:11:36 | 000,152,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2013/11/13 06:11:34 | 001,447,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/11/13 06:11:34 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspicli.dll
[2013/11/13 06:11:33 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/11/13 06:11:33 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspisrv.dll
[2013/11/13 06:11:33 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2013/11/13 06:11:29 | 000,830,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\nshwfp.dll
[2013/11/13 06:11:29 | 000,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\nshwfp.dll
[2013/11/13 06:11:29 | 000,404,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/11/13 06:11:29 | 000,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FWPUCLNT.DLL
[2013/11/13 06:11:29 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\FWPUCLNT.DLL
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/12/11 19:57:22 | 000,002,921 | —- | M] () – C:\Users\N\Desktop\HiJackThis (2).lnk
[2013/12/11 19:50:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/12/11 19:48:04 | 000,002,955 | —- | M] () – C:\Users\N\Desktop\HiJackThis.lnk
[2013/12/11 19:42:11 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/12/11 14:58:17 | 000,281,768 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/12/11 14:58:17 | 000,281,768 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/12/11 14:57:51 | 000,271,200 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/12/11 11:42:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/12/11 02:50:22 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/12/11 02:50:22 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/12/07 10:39:54 | 000,014,832 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/12/07 10:39:54 | 000,014,832 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/12/07 10:38:53 | 000,782,470 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/12/07 10:38:53 | 000,662,384 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/12/07 10:38:53 | 000,122,252 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/12/07 10:32:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/12/07 10:32:47 | 529,932,287 | -HS- | M] () – C:\hiberfil.sys
[2013/12/07 00:17:48 | 000,062,308 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000009-00000000-00000000-00001102-0000000B-00431102}.rfx
[2013/12/07 00:17:48 | 000,062,308 | —- | M] () – C:\Windows\SysNative\BMXState-{00000009-00000000-00000000-00001102-0000000B-00431102}.rfx
[2013/12/07 00:17:48 | 000,000,820 | —- | M] () – C:\Windows\SysNative\DVCState-{00000009-00000000-00000000-00001102-0000000B-00431102}.rfx
[2013/12/05 06:43:27 | 000,000,630 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013/12/03 12:53:37 | 000,000,835 | —- | M] () – C:\Users\Public\Desktop\Battlefield 4.lnk
[2013/12/03 12:53:37 | 000,000,819 | —- | M] () – C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
[2013/12/02 21:29:49 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[2013/11/27 23:15:29 | 000,940,032 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/11/27 23:15:29 | 000,194,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/11/27 23:15:25 | 001,926,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/11/27 23:15:25 | 000,703,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/11/27 23:15:25 | 000,645,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jsIntl.dll
[2013/11/27 23:15:25 | 000,616,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/11/27 23:15:25 | 000,440,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/11/27 23:15:25 | 000,337,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/11/27 23:15:25 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/11/27 23:15:25 | 000,233,472 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/11/27 23:15:25 | 000,164,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/11/27 23:15:25 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/11/27 23:15:25 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/11/27 23:15:25 | 000,062,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/11/27 23:15:25 | 000,034,816 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013/11/27 23:15:25 | 000,024,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/11/27 23:15:24 | 001,051,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/11/27 23:15:24 | 000,610,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/11/27 23:15:24 | 000,553,472 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9diag.dll
[2013/11/27 23:15:24 | 000,151,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/11/27 23:15:24 | 000,139,264 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/11/27 23:15:24 | 000,127,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/11/27 23:15:24 | 000,116,736 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/11/27 23:15:24 | 000,112,128 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/11/27 23:15:24 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/11/27 23:15:24 | 000,086,016 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/11/27 23:15:24 | 000,083,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/11/27 23:15:24 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/11/27 23:15:24 | 000,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/11/27 23:15:24 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\MshtmlDac.dll
[2013/11/27 23:15:24 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/11/27 23:15:24 | 000,056,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/11/27 23:15:24 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieetwproxystub.dll
[2013/11/27 23:15:24 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/11/27 23:15:24 | 000,032,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/11/27 23:15:24 | 000,016,284 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/11/27 23:15:24 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/11/27 23:15:23 | 005,765,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/11/27 23:15:23 | 001,993,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/11/27 23:15:23 | 001,228,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/11/27 23:15:23 | 000,942,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jsIntl.dll
[2013/11/27 23:15:23 | 000,817,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/11/27 23:15:23 | 000,708,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9diag.dll
[2013/11/27 23:15:23 | 000,626,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/11/27 23:15:23 | 000,616,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/11/27 23:15:23 | 000,574,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/11/27 23:15:23 | 000,548,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/11/27 23:15:23 | 000,453,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/11/27 23:15:23 | 000,413,696 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/11/27 23:15:23 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/11/27 23:15:23 | 000,247,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/11/27 23:15:23 | 000,235,520 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/11/27 23:15:23 | 000,218,624 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/11/27 23:15:23 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/11/27 23:15:23 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/11/27 23:15:23 | 000,143,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/11/27 23:15:23 | 000,131,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/11/27 23:15:23 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/11/27 23:15:23 | 000,101,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/11/27 23:15:23 | 000,090,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/11/27 23:15:23 | 000,086,016 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/11/27 23:15:23 | 000,084,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/11/27 23:15:23 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/11/27 23:15:23 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/11/27 23:15:23 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/11/27 23:15:23 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/11/27 23:15:23 | 000,040,448 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013/11/27 23:15:23 | 000,033,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/11/27 23:15:23 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/11/27 23:15:23 | 000,016,284 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/11/27 23:15:23 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/11/27 23:15:22 | 000,774,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/11/27 23:15:22 | 000,147,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/11/27 23:15:22 | 000,139,264 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/11/27 23:15:22 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/11/27 23:15:22 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieetwcollector.exe
[2013/11/27 23:15:22 | 000,083,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MshtmlDac.dll
[2013/11/27 23:15:22 | 000,062,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/11/27 23:15:22 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieetwproxystub.dll
[2013/11/27 23:15:22 | 000,048,128 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/11/27 23:15:22 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/11/27 23:15:22 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieetwcollectorres.dll
[2013/11/25 14:07:33 | 000,001,208 | —- | M] () – C:\Users\N\Desktop\Uplay.lnk
[2013/11/25 14:05:22 | 000,774,592 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/11/25 12:36:15 | 003,123,272 | —- | M] () – C:\Windows\SysWow64\pbsvc.exe
[2013/11/25 06:37:34 | 000,000,216 | —- | M] () – C:\Users\N\Desktop\Assassins Creed IV Black Flag.url
[2013/11/22 20:43:23 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/12/11 19:57:22 | 000,002,921 | —- | C] () – C:\Users\N\Desktop\HiJackThis (2).lnk
[2013/12/11 19:48:04 | 000,002,955 | —- | C] () – C:\Users\N\Desktop\HiJackThis.lnk
[2013/12/05 06:43:27 | 000,000,630 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013/12/02 21:30:16 | 000,000,835 | —- | C] () – C:\Users\Public\Desktop\Battlefield 4.lnk
[2013/12/02 21:30:16 | 000,000,819 | —- | C] () – C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
[2013/11/27 23:15:24 | 000,016,284 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/11/27 23:15:23 | 000,016,284 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/11/25 14:07:33 | 000,001,208 | —- | C] () – C:\Users\N\Desktop\Uplay.lnk
[2013/11/25 06:37:34 | 000,000,216 | —- | C] () – C:\Users\N\Desktop\Assassins Creed IV Black Flag.url
[2013/03/20 23:10:18 | 000,042,880 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2013/03/05 12:52:26 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2013/01/28 15:01:49 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/03/15 20:24:07 | 003,123,272 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2012/03/11 18:14:41 | 000,847,952 | —- | C] () – C:\Users\N\ts3_recording_12_03_11_19_14_39.wav
[2012/02/19 12:46:34 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2011/11/25 10:54:12 | 000,000,022 | —- | C] () – C:\Program Files (x86)\zipnew.dat
[2011/11/25 10:54:12 | 000,000,020 | —- | C] () – C:\Program Files (x86)\rarnew.dat
[2011/11/25 10:54:10 | 001,163,264 | —- | C] () – C:\Program Files (x86)\WinRAR.exe
[2011/11/25 10:54:10 | 000,276,992 | —- | C] () – C:\Program Files (x86)\UnRAR.exe
[2011/11/25 10:54:10 | 000,266,230 | —- | C] () – C:\Program Files (x86)\WinRAR.chm
[2011/11/25 10:54:10 | 000,164,864 | —- | C] () – C:\Program Files (x86)\RarExt.dll
[2011/11/25 10:54:10 | 000,140,288 | —- | C] () – C:\Program Files (x86)\RarExt32.dll
[2011/11/25 10:54:10 | 000,132,608 | —- | C] () – C:\Program Files (x86)\Uninstall.exe
[2011/11/25 10:54:10 | 000,128,000 | —- | C] () – C:\Program Files (x86)\Default64.SFX
[2011/11/25 10:54:10 | 000,098,816 | —- | C] () – C:\Program Files (x86)\Default.SFX
[2011/11/25 10:54:10 | 000,098,304 | —- | C] () – C:\Program Files (x86)\Zip64.SFX
[2011/11/25 10:54:10 | 000,094,720 | —- | C] () – C:\Program Files (x86)\WinCon64.SFX
[2011/11/25 10:54:10 | 000,078,848 | —- | C] () – C:\Program Files (x86)\Zip.SFX
[2011/11/25 10:54:10 | 000,072,704 | —- | C] () – C:\Program Files (x86)\WinCon.SFX
[2011/11/25 10:54:10 | 000,003,266 | —- | C] () – C:\Program Files (x86)\Order.htm
[2011/11/25 10:54:10 | 000,001,233 | —- | C] () – C:\Program Files (x86)\RarFiles.lst
[2011/11/25 10:47:08 | 000,417,792 | —- | C] () – C:\Program Files (x86)\Rar.exe
[2011/11/25 10:47:08 | 000,001,063 | —- | C] () – C:\Program Files (x86)\Descript.ion
[2011/11/25 10:47:08 | 000,000,700 | —- | C] () – C:\Program Files (x86)\Uninstall.lst
[2011/11/25 10:47:08 | 000,000,496 | —- | C] () – C:\Program Files (x86)\File_Id.diz
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/07/25 21:24:57 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/07/25 20:55:59 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/04/27 19:21:53 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\.minecraft
[2013/02/11 18:50:10 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\Awesomium
[2013/08/21 16:30:55 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\com.pandora.desktop
[2012/12/13 13:16:12 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\com.pandora.desktop.E7C14276FFE9EEF0BC7DCE654C467D9A299EFD21.1
[2011/12/06 17:37:27 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
[2013/08/03 18:11:13 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\Dropbox
[2011/11/05 14:11:54 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\LolClient
[2012/06/15 15:31:05 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\LolClient2
[2012/05/07 21:21:40 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\NationRed
[2012/10/31 05:28:23 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\Natural Selection 2
[2013/07/09 06:03:47 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\OpenCandy
[2013/12/02 07:38:28 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\Origin
[2013/06/27 23:22:37 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\qBittorrent
[2011/10/27 15:37:58 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\Razer
[2012/08/05 09:40:03 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\runic games
[2013/12/07 17:17:50 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\Spotify
[2011/12/22 22:05:26 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\SystemRequirementsLab
[2013/12/03 17:19:43 | 000,000,000 | —D | M] – C:\Users\N\AppData\Roaming\TS3Client
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | —- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows.old.000\Windows\PolicyDefinitions\en-US\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | —- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20c9bd966d6a6189\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2006/11/02 07:34:28 | 000,002,840 | —- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows.old.000\Windows\PolicyDefinitions\Explorer.admx
[2006/11/02 07:34:28 | 000,002,840 | —- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.0.6000.16386_none_1383e7b7f3eacf3c\Explorer.admx
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows.old.001\Windows\SysWOW64\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] () MD5=4DDD2D55609A1466C8B19FF2B1709479 – C:\Windows.old\Windows\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] () MD5=4DDD2D55609A1466C8B19FF2B1709479 – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows.old.001\Windows\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows.old.001\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows.old.000\Windows\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:39:48 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows.old.000\Windows\en-US\explorer.exe.mui
[2006/11/02 07:39:48 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows.old.001\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows.old.001\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows.old.001\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2009/09/20 09:34:15 | 000,031,760 | —- | M] () MD5=CB71A1BA182796E03875E64C7B151A2A – C:\Windows.old.000\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf
< MD5 for: IEXPLORE.EXE >
[2011/11/05 00:28:03 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=0377589BF14A6E5667B730D6D6DB59B4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_0fae4f323e42a646\iexplore.exe
[2013/03/03 23:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_1a42c5438bf82907\iexplore.exe
[2013/11/27 23:15:23 | 000,804,560 | —- | M] (Microsoft Corporation) MD5=0685765C0CBE095BA0C6C8790BAE21EF – C:\Program Files\Internet Explorer\iexplore.exe
[2013/11/27 23:15:23 | 000,804,560 | —- | M] (Microsoft Corporation) MD5=0685765C0CBE095BA0C6C8790BAE21EF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_7b0d6f67c2d3f97a\iexplore.exe
[2012/10/27 00:02:44 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=06A8334D76DCF0DFFA738A512BDCD5F7 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17153_none_19d8942672c321c5\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/02/28 00:42:27 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=09F6A10AB424E2DE445153065FA076BF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_19d2eba472c68c00\iexplore.exe
[2007/07/11 10:28:14 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16473_none_2d330f011d0e0526\iexplore.exe
[2013/07/26 01:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2012/06/27 02:05:59 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=156169FAD6DEACEEF4BAFFEE8A662C4F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_0f81e75a3e642ff5\iexplore.exe
[2013/02/28 11:18:24 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=19025A34D3EAD0FA9634B504194D214D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17256_none_19db96ea72c06af1\iexplore.exe
[2013/08/10 01:31:28 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=1F3B062444AD6F667B5336E78D5A02B7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_ffb36d2837eafb72\iexplore.exe
[2012/04/20 00:08:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=27019747D97AB5CEFB97677DBB5CF577 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_1a11a2ba7297e4ee\iexplore.exe
[2007/08/15 09:33:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16512_none_2d72f0251cde4150\iexplore.exe
[2013/06/11 23:41:27 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows.old.001\Program Files (x86)\Internet Explorer\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2013/04/05 00:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/08/10 01:10:22 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_168ab5d61e3c99b7\iexplore.exe
[2013/08/09 23:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_20df6028529d5bb2\iexplore.exe
[2011/12/16 03:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_19eb591872b56d75\iexplore.exe
[2013/05/16 20:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2013/10/12 16:42:28 | 000,775,344 | —- | M] (Microsoft Corporation) MD5=39D0074C59F6D1A62731942C7FA8B60B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16736_none_167ae4781e4936f5\iexplore.exe
[2007/10/09 16:26:03 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3C1B2AD79DBF750A15A8832AF8192DB4 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20663_none_2dc77d9e36238626\iexplore.exe
[2013/10/12 04:49:48 | 000,775,344 | —- | M] (Microsoft Corporation) MD5=3C8C00380462B1023C9F8EA2A9A7A137 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20848_none_ffa340aa37f7ff34\iexplore.exe
[2011/08/19 23:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_19d3ea0872c5a830\iexplore.exe
[2011/11/05 00:34:31 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=441C397A9ECF07747920F7F5E40B419B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_0fef13a357968bc7\iexplore.exe
[2012/12/20 08:27:39 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=45C1FCF818565D44531007526CDEF7EF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21406_none_1a9b45378bb57c2d\iexplore.exe
[2012/04/19 23:53:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=4866404D6657D6E50619CCAF56B17D27 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_1a3bf0cd8bfcb2df\iexplore.exe
[2013/08/10 00:13:42 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=48A1306191216997F717C451B8D15139 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_0a08177a6c4bbd6d\iexplore.exe
[2012/08/24 12:15:32 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=4ADB84297505A1627DEEA18529BF4B16 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_1a05d46a72a0e4af\iexplore.exe
[2007/12/11 18:38:42 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4C1528C481FFE6E4EFE4BAC7271CE251 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20697_none_2dab0f0236383f55\iexplore.exe
[2012/10/27 00:56:51 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=4CDF8DE0C9F0A245B7348FDD2866F176 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21355_none_100f8919577e2f69\iexplore.exe
[2012/06/27 02:06:52 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=5421E66F9F91F221B9B88AAE11B0CFE7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_101a571f57761651\iexplore.exe
[2012/06/27 01:05:29 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=555D62228092C7F87B9930F85F833297 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_19d691ac72c4f1f0\iexplore.exe
[2013/03/02 00:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_19d1c74872c7a039\iexplore.exe
[2013/04/30 21:43:42 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2012/02/28 01:38:39 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=69073D126F71A4F0FFF1DEE5082A0052 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_0f7e41523e65ca05\iexplore.exe
[2007/12/11 18:38:42 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=7023BC3AF58F0C47856AF147E290D81A – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16575_none_2d35117b1d0c34fb\iexplore.exe
[2013/07/25 22:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2012/10/27 00:37:44 | 000,696,400 | —- | M] (Microsoft Corporation) MD5=7BF529AEFBAD8946747A1D592BCD31AB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17153_none_0f83e9d43e625fca\iexplore.exe
[2008/02/12 17:57:21 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=7F2693693511F7ECD2762081F2F19864 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20734_none_2de8ef92360a48d1\iexplore.exe
[2006/11/02 04:45:14 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=8308F01F27DF839E0010B0F72F855E35 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16386_none_2d2b3e0d1d136ff5\iexplore.exe
[2006/11/02 04:45:14 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=8308F01F27DF839E0010B0F72F855E35 – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16386_none_2d2b3e0d1d136ff5\iexplore.exe
[2012/08/24 13:10:19 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=85275D3D81C23C8A8D3C915888D11C66 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_0fb12a183e4022b4\iexplore.exe
[2010/11/20 08:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/02/28 00:44:39 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8AFD61FB2D96C8229B7D8604F62FA692 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1a67307d8bdc431b\iexplore.exe
[2013/07/26 00:47:06 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2011/11/04 23:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_1a02f98472a36841\iexplore.exe
[2013/05/16 22:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2008/02/12 17:57:21 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9143C721DD6482374EFB35BC35944324 – C:\Windows.old.000\Program Files\Internet Explorer\iexplore.exe
[2008/02/12 17:57:21 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9143C721DD6482374EFB35BC35944324 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16609_none_2d84c3fd1ccfd3e7\iexplore.exe
[2013/06/11 21:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2007/07/11 10:28:14 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20583_none_2db1dbe03633c0e1\iexplore.exe
[2012/06/27 01:11:42 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=9B80D4B1CAD7C4160D9B2D65D468E336 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_1a6f01718bd6d84c\iexplore.exe
[2013/10/12 02:16:06 | 000,770,736 | —- | M] (Microsoft Corporation) MD5=9DFE1678738DD968D7BA5559B52706D1 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20848_none_09f7eafc6c58c12f\iexplore.exe
[2011/12/16 03:45:57 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=A3F56CED7B94A30BE8954387F0E2B5D2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_0f96aec63e54ab7a\iexplore.exe
[2011/11/04 23:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_1a43bdf58bf74dc2\iexplore.exe
[2013/02/28 12:29:52 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=A976A480AA8FE1AE85B33F543D51752B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21471_none_0ff5e9ff5791ff16\iexplore.exe
[2013/04/05 01:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2011/08/20 00:46:07 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=AC1CC7CD5CBE60EFF105BB3C0DC199C5 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_0f7f3fb63e64e635\iexplore.exe
[2013/03/02 00:50:08 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=AFB0FE34A9B7F1B7A70276B9C1A78114 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_0f7d1cf63e66de3e\iexplore.exe
[2013/03/04 00:42:51 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=B1B17B56E0F9AE84A1F75E757217154E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_0fee1af15797670c\iexplore.exe
[2007/08/15 09:33:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20627_none_2df6be7635ff7bbe\iexplore.exe
[2011/12/16 03:42:35 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=C152529FD67ABB61F0609EF5A299794C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_104895c75752f56b\iexplore.exe
[2011/12/16 04:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_1a9d40198bb3b766\iexplore.exe
[2010/11/20 07:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/08/20 00:42:38 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=C66C8BF791F9DB974022506265518EE0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_102322ab576fcd64\iexplore.exe
[2012/08/24 12:10:38 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=C6E8F6DB0FD7B28924D1CBC8AE03ECEE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1a8d72878bc04ef2\iexplore.exe
[2013/11/27 23:15:25 | 000,806,096 | —- | M] (Microsoft Corporation) MD5=C8A8321292A459B0A17FB39A782A5C74 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/11/27 23:15:25 | 000,806,096 | —- | M] (Microsoft Corporation) MD5=C8A8321292A459B0A17FB39A782A5C74 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_856219b9f734bb75\iexplore.exe
[2013/06/12 02:51:43 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=CA88A25280B1D85ED0BC26B042ABBCCF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2012/10/26 23:57:50 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=CAB945F6B0700D84DE40ED1FA6DB15F2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21355_none_1a64336b8bdef164\iexplore.exe
[2013/04/05 02:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012/12/20 08:01:03 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=D1F65F76FA03619706C43CBEF9C1EEC3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17197_none_19b1559e72dff6e5\iexplore.exe
[2013/09/22 18:54:30 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=D6B7DDB68436F13C3CAE2B92524F1FEC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16721_none_20cf006852aa5f74\iexplore.exe
[2013/10/12 02:44:13 | 000,770,736 | —- | M] (Microsoft Corporation) MD5=D7D5768B8A697FCBAEE2CFE137070F02 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16736_none_20cf8eca52a9f8f0\iexplore.exe
[2012/04/20 01:26:39 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=D889681C78E7BFE45587398AC42FC2D4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_0fbcf8683e3722f3\iexplore.exe
[2013/09/22 19:01:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=DB352EBF77E8655E0C46B6923F3C9950 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20831_none_09f78a2a6c58f471\iexplore.exe
[2013/04/05 02:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2012/08/24 13:24:56 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=E3C361C85ADECFF3A485E4FE17859E0F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1038c835575f8cf7\iexplore.exe
[2013/04/30 21:43:43 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/07/26 00:09:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2013/02/28 12:21:37 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=E9194413FBF8CF085DD548F489BA44F2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21471_none_1a4a94518bf2c111\iexplore.exe
[2013/09/22 20:55:58 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=E9F843E7E412AE9A507FD5ABBBD06462 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20831_none_ffa2dfd837f83276\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2007/10/09 16:26:02 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=EDEE147E416398BB3DD5B0DD4F6F1D32 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16546_none_2d5681891cf2fa7f\iexplore.exe
[2012/02/28 01:56:21 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=EFCA1150F17BCE44357F03BB61A29966 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1012862b577b8120\iexplore.exe
[2012/04/20 01:13:05 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=F293ACB373FD8F090E08F183C06E07ED – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_0fe7467b579bf0e4\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows.old.001\Program Files\Internet Explorer\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows.old.001\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/12/20 09:08:37 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=F44F02FEEB5AC24C37D70BC83A578A7D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21406_none_10469ae55754ba32\iexplore.exe
[2013/09/22 20:25:59 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=F6A7D9C0BC326F695526069C1DA1E8B7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16721_none_167a56161e499d79\iexplore.exe
[2013/02/28 11:36:35 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=F9F2279A5EBAFB343CDB79FDC5C408C0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17256_none_0f86ec983e5fa8f6\iexplore.exe
[2011/08/19 23:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_1a77ccfd8bd08f5f\iexplore.exe
[2012/12/20 09:09:06 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=FE004EA8558B9C8BF066483A3EA9FDDB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17197_none_0f5cab4c3e7f34ea\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2013/11/27 23:15:26 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/11/27 23:15:24 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/11/27 23:15:24 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.2.9600.16428_en-us_74ba04defa813a61\iexplore.exe.mui
[2013/11/27 23:15:26 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.2.9600.16428_en-us_7f0eaf312ee1fc5c\iexplore.exe.mui
[2006/11/02 07:39:45 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows.old.000\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2006/11/02 07:39:45 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2006/11/02 07:39:45 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows.old\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2006/11/02 07:39:45 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2013/04/30 21:43:42 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/04/30 21:43:43 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows.old.001\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows.old.001\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows.old.001\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-1B894AFB.PF >
[2009/09/20 10:06:41 | 000,074,368 | —- | M] () MD5=8E286B341E94438D8965BDA15D38F47A – C:\Windows.old.000\Windows\Prefetch\IEXPLORE.EXE-1B894AFB.pf
< MD5 for: SERVICES >
[2006/09/18 16:37:24 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\$INPLACE.~TR\Machine\DATA\Windows\System32\drivers\etc\services
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows.old.000\Windows\System32\drivers\etc\services
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows.old.001\Windows\System32\drivers\etc\services
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2013/09/03 08:53:56 | 000,558,864 | —- | M] () MD5=4097D9DB7F5DB4533DDA8271136C9B7B – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows.old.001\Windows\System32\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2006/11/02 04:45:40 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 – C:\Windows.old.000\Windows\System32\services.exe
[2006/11/02 04:45:40 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 07:39:23 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows.old.000\Windows\System32\en-US\services.exe.mui
[2006/11/02 07:39:23 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows.old.001\Windows\System32\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.000\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.000\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.000\ProgramData\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.000\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\ProgramData\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old.001\Users\All Users\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old\ProgramData\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Windows.old\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2006/11/02 07:52:39 | 000,001,688 | —- | M] () MD5=FCDB193E85408D9C5EDBCFCBFABFD677 – C:\Windows.old.000\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2013/11/03 06:57:06 | 000,000,414 | —- | M] () MD5=0838FAAA37FDA1911BB32594E0768BEE – C:\Users\N\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T7CZA5XR\mochiads.com\services.mochiads.com.sol
[2013/11/03 06:57:06 | 000,000,414 | —- | M] () MD5=0838FAAA37FDA1911BB32594E0768BEE – C:\Windows.old.000\Documents and Settings\N\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T7CZA5XR\mochiads.com\services.mochiads.com.sol
[2013/11/03 06:57:06 | 000,000,414 | —- | M] () MD5=0838FAAA37FDA1911BB32594E0768BEE – C:\Windows.old\Documents and Settings\N\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\T7CZA5XR\mochiads.com\services.mochiads.com.sol
< MD5 for: SERVICES.MOF >
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows.old.000\Windows\System32\wbem\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows.old.001\Windows\System32\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2006/11/02 07:39:59 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.000\Windows\System32\en-US\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.000\Windows\System32\services.msc
[2006/11/02 07:39:59 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6000.16386_none_cd2d20a848cfd40f\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.001\Windows\System32\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.001\Windows\System32\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.001\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows.old.001\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows.old.001\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2006/11/02 07:40:19 | 000,008,051 | —- | M] () MD5=5911AB4AD86759363C6C00408A522692 – C:\Windows.old.000\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2006/11/02 07:40:19 | 000,008,051 | —- | M] () MD5=5911AB4AD86759363C6C00408A522692 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_en-us_92cd4f8bdff6e8f5\WinLogon.adml
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2006/11/02 07:34:27 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows.old.000\Windows\PolicyDefinitions\WinLogon.admx
[2006/11/02 07:34:27 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.0.6000.16386_none_78d69ac67c572ad2\WinLogon.admx
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows.old.001\Windows\System32\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2006/11/02 04:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows.old.000\Windows\System32\winlogon.exe
[2006/11/02 04:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows.old.001\Windows\System32\en-US\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui
[2006/11/02 07:39:20 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows.old.000\Windows\System32\en-US\winlogon.exe.mui
[2006/11/02 07:39:20 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows.old.001\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows.old.000\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows.old.001\Windows\System32\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 07:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/10/27 18:14:45 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/03/17 06:41:22 | 000,171,136 | RHS- | M] () – C:\grldr
[2013/12/07 10:32:47 | 529,932,287 | -HS- | M] () – C:\hiberfil.sys
[2013/12/07 10:32:46 | 2138,234,879 | -HS- | M] () – C:\pagefile.sys
[2013/07/27 17:31:29 | 000,006,412 | —- | M] () – C:\Pokemon Gold.clt
[2012/01/14 19:52:38 | 000,296,516 | —- | M] () – C:\shared.log
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2011/05/28 22:04:30 | 000,098,816 | —- | M] () – C:\Program Files (x86)\Default.SFX
[2011/05/28 22:04:34 | 000,128,000 | —- | M] () – C:\Program Files (x86)\Default64.SFX
[2006/09/18 21:13:58 | 000,001,063 | —- | M] () – C:\Program Files (x86)\Descript.ion
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2011/05/28 22:02:57 | 000,000,496 | —- | M] () – C:\Program Files (x86)\File_Id.diz
[2010/09/28 12:23:11 | 000,007,019 | —- | M] () – C:\Program Files (x86)\License.txt
[2010/11/25 14:15:03 | 000,003,266 | —- | M] () – C:\Program Files (x86)\Order.htm
[2011/05/28 22:03:29 | 000,417,792 | —- | M] () – C:\Program Files (x86)\Rar.exe
[2011/05/10 17:28:32 | 000,078,667 | —- | M] () – C:\Program Files (x86)\Rar.txt
[2011/05/28 22:05:00 | 000,164,864 | —- | M] () – C:\Program Files (x86)\RarExt.dll
[2011/05/28 22:04:56 | 000,140,288 | —- | M] () – C:\Program Files (x86)\RarExt32.dll
[2010/11/26 19:23:48 | 000,001,233 | —- | M] () – C:\Program Files (x86)\RarFiles.lst
[2011/11/25 10:54:12 | 000,000,020 | —- | M] () – C:\Program Files (x86)\rarnew.dat
[2011/01/23 15:41:25 | 000,001,411 | —- | M] () – C:\Program Files (x86)\ReadMe.txt
[2011/05/10 17:28:33 | 000,009,234 | —- | M] () – C:\Program Files (x86)\TechNote.txt
[2011/05/28 22:05:07 | 000,132,608 | —- | M] () – C:\Program Files (x86)\Uninstall.exe
[2011/05/28 22:05:49 | 000,000,700 | —- | M] () – C:\Program Files (x86)\Uninstall.lst
[2011/05/28 22:03:37 | 000,276,992 | —- | M] () – C:\Program Files (x86)\UnRAR.exe
[2005/05/12 18:02:30 | 000,000,090 | —- | M] () – C:\Program Files (x86)\UnrarSrc.txt
[2011/05/28 22:02:41 | 000,023,970 | —- | M] () – C:\Program Files (x86)\WhatsNew.txt
[2011/05/28 22:03:40 | 000,072,704 | —- | M] () – C:\Program Files (x86)\WinCon.SFX
[2011/05/28 22:03:44 | 000,094,720 | —- | M] () – C:\Program Files (x86)\WinCon64.SFX
[2011/05/28 22:05:15 | 000,266,230 | —- | M] () – C:\Program Files (x86)\WinRAR.chm
[2011/05/28 22:03:20 | 001,163,264 | —- | M] () – C:\Program Files (x86)\WinRAR.exe
[2011/05/28 22:04:38 | 000,078,848 | —- | M] () – C:\Program Files (x86)\Zip.SFX
[2011/05/28 22:04:42 | 000,098,304 | —- | M] () – C:\Program Files (x86)\Zip64.SFX
[2011/11/25 10:54:12 | 000,000,022 | —- | M] () – C:\Program Files (x86)\zipnew.dat
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Windows
Volume Serial Number is 5C4C-043B
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/27 14:55:53 | 000,000,221 | -HS- | M] () – C:\Users\N\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:31:41 PM, on 12/11/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\N\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Windows\SysWOW64\Ctxfihlp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Xfire\Xfire.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
O4 - HKCU\..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\N\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [f.lux] "C:\Users\N\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-276375098-274075240-1777420528-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-276375098-274075240-1777420528-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Realtek11nCU - Realtek - C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10987 bytes