OTL logfile created on: 6/24/2012 9:27:33 PM - Run 1 OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\t\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.86 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 55.81% Memory free 7.73 Gb Paging File | 5.22 Gb Available in Paging File | 67.52% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 179.00 Gb Total Space | 57.71 Gb Free Space | 32.24% Space Free | Partition Type: NTFS Drive D: | 266.66 Gb Total Space | 94.58 Gb Free Space | 35.47% Space Free | Partition Type: NTFS Drive F: | 3.94 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF Computer Name: T-KOMPUTER | User Name: t | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/06/24 21:27:20 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\t\Desktop\OTL.exe PRC - [2012/06/19 23:00:34 | 000,529,232 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe PRC - [2012/06/15 22:36:21 | 000,935,008 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe PRC - [2012/06/15 22:36:19 | 001,107,552 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe PRC - [2012/06/13 15:11:41 | 001,020,816 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe PRC - [2012/05/24 19:22:03 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe PRC - [2012/05/08 11:25:10 | 001,091,320 | ---- | M] (Bogdan Sharkov) -- C:\Program Files (x86)\Clownfish\Clownfish.exe PRC - [2012/02/28 17:38:56 | 001,987,976 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012/02/03 13:34:58 | 000,793,048 | ---- | M] (PC Tools) -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe PRC - [2012/02/03 13:34:56 | 000,103,896 | ---- | M] (PC Tools) -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe PRC - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe PRC - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe PRC - [2011/08/02 09:33:30 | 004,910,912 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe PRC - [2010/05/07 07:10:44 | 000,846,848 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe PRC - [2010/05/06 08:44:44 | 001,749,504 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe PRC - [2010/02/10 16:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe PRC - [2010/01/19 04:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe PRC - [2009/01/23 03:46:14 | 000,203,280 | ---- | M] () -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe PRC - [2008/06/24 16:06:06 | 001,840,424 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe PRC - [2006/12/19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Windows\SysWOW64\IoctlSvc.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/06/19 23:00:33 | 020,313,384 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll MOD - [2012/06/19 23:00:05 | 000,895,312 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll MOD - [2012/06/19 23:00:04 | 001,099,576 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll MOD - [2012/06/19 23:00:04 | 000,190,776 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll MOD - [2012/06/19 23:00:04 | 000,123,192 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll MOD - [2012/06/15 22:36:21 | 000,132,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll MOD - [2012/06/15 22:36:19 | 001,107,552 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe MOD - [2009/01/23 03:46:18 | 000,013,840 | ---- | M] () -- C:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll MOD - [2006/08/12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012/06/13 14:13:30 | 000,199,280 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\Common\ArcaTasksService.exe -- (AVTasks2) SRV:[b]64bit:[/b] - [2012/05/22 13:51:46 | 000,964,720 | ---- | M] () [Auto | Running] -- C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe -- (ArcaRemoteService) SRV:[b]64bit:[/b] - [2012/04/12 15:46:24 | 000,200,784 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\ArcaUpdate\update.exe -- (AVUpdate) SRV:[b]64bit:[/b] - [2012/04/02 22:41:30 | 000,225,712 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\ArcaVir\ArcaMainSV.exe -- (ABMainSV) SRV:[b]64bit:[/b] - [2012/02/08 15:56:08 | 000,256,080 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\ArcaTools\ArcaBackup\ArcaBackupService.exe -- (AVBackup) SRV:[b]64bit:[/b] - [2012/01/09 14:39:04 | 000,204,880 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\Common\ArcaConfSV.exe -- (ABConfSV) SRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,245,352 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire) SRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,200,056 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield) SRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,149,032 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp) SRV:[b]64bit:[/b] - [2010/10/07 21:34:28 | 000,509,416 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS) SRV:[b]64bit:[/b] - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (MSK80Service) SRV:[b]64bit:[/b] - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy) SRV:[b]64bit:[/b] - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc) SRV:[b]64bit:[/b] - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn) SRV:[b]64bit:[/b] - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc) SRV:[b]64bit:[/b] - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc) SRV:[b]64bit:[/b] - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2012/06/19 23:00:34 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012/06/15 22:36:21 | 000,935,008 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -- (vToolbarUpdater11.2.0) SRV - [2012/04/19 22:23:38 | 000,736,104 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService) SRV - [2012/02/28 17:38:54 | 002,343,816 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012/02/21 14:33:54 | 002,143,552 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc) SRV - [2012/02/03 13:34:58 | 000,793,048 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc) SRV - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa) SRV - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist) SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009/01/23 03:46:14 | 000,203,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service) SRV - [2006/12/19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012/04/07 16:27:22 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:[b]64bit:[/b] - [2012/03/16 12:48:14 | 000,042,696 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:[b]64bit:[/b] - [2012/03/01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011/11/15 19:20:34 | 000,040,016 | ---- | M] (ArcaBit) [Kernel | On_Demand | Stopped] -- C:\Program Files\ArcaBit\ArcaVir\ABWFP.sys -- (ABWFP) DRV:[b]64bit:[/b] - [2011/11/06 09:47:17 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2011/10/01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol) DRV:[b]64bit:[/b] - [2011/10/01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay) DRV:[b]64bit:[/b] - [2011/10/01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir) DRV:[b]64bit:[/b] - [2011/10/01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs) DRV:[b]64bit:[/b] - [2011/09/30 11:29:46 | 000,082,000 | ---- | M] (ArcaBit) [File_System | On_Demand | Running] -- C:\Program Files\ArcaBit\ArcaVir\ABFLT.sys -- (ABFLT) DRV:[b]64bit:[/b] - [2011/03/11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/03/11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011/02/21 16:57:34 | 000,046,160 | ---- | M] (ArcaBit) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\abndis.sys -- (ABndisMP) DRV:[b]64bit:[/b] - [2011/02/21 16:57:34 | 000,046,160 | ---- | M] (ArcaBit) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\abndis.sys -- (ABndis) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,529,128 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,441,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,283,360 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,190,136 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,121,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,094,864 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,075,032 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk) DRV:[b]64bit:[/b] - [2010/10/13 23:28:54 | 000,062,800 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids) DRV:[b]64bit:[/b] - [2010/04/22 04:51:46 | 003,062,336 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX) DRV:[b]64bit:[/b] - [2010/03/31 02:35:26 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI) DRV:[b]64bit:[/b] - [2010/03/03 12:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2010/02/27 02:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) DRV:[b]64bit:[/b] - [2010/02/26 20:32:58 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2009/12/21 09:52:04 | 000,190,976 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gtuhs62.sys -- (GTNDIS62) DRV:[b]64bit:[/b] - [2009/12/15 12:36:10 | 000,089,600 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gtuhsbus.sys -- (GTUHSBUS) DRV:[b]64bit:[/b] - [2009/12/15 12:33:54 | 000,010,624 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gtuhsser.sys -- (GTUHSSER) DRV:[b]64bit:[/b] - [2009/11/12 22:14:30 | 000,084,584 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2009/09/28 11:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:[b]64bit:[/b] - [2009/09/16 08:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle) DRV:[b]64bit:[/b] - [2009/08/06 00:24:16 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:[b]64bit:[/b] - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/06/10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009/03/18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi) DRV - [2012/02/09 13:16:38 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv) DRV - [2010/09/18 21:39:41 | 000,015,144 | ---- | M] (Windows (R) 2003 DDK 3790 provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\rtport.sys -- (rtport) DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idd/idd_1335122613_167677 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = pl.v9.com/idd/idd_1335122613_167677 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=stonicpl&s={searchTerms}&f=4 IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - No CLSID value found IE - HKLM\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{11BAB7A8-BA60-48C4-8B81-B05A40FCC1A4}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN IE - HKLM\..\SearchScopes\{14BF31A3-74FB-4BB7-B47B-4340DCC1ECFD}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKLM\..\SearchScopes\{1CABE4A8-36B3-4290-9E6F-C3507E5C6962}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKLM\..\SearchScopes\{64C62E60-BBA0-4A1D-8474-A779302A49C8}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{78593FF4-A42D-43D1-BBC2-DC95D6FF5FBF}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392 IE - HKLM\..\SearchScopes\{C5825272-9378-41F1-8137-459A4A824101}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20111225133200683&tb_oid=25-12-2011&tb_mrud=25-12-2011 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idd/idd_1335122613_167677 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com/?cid={24372B4C-64E4-42E2-BA6D-FE333E846BAB}&mid=df6358f6e93847d0a814397099f95e29-933946b292ee20b136c8bcf47a247e14258047dd&lang=en&ds=ft011&pr=sa&d=2012-06-15 22:36:21&v=11.1.0.12&sap=hp IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - No CLSID value found IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - No CLSID value found IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=stonicpl&s={searchTerms}&f=4 IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=119998&babsrc=SP_ss&mntrId=eeec42c6000000000000e839df264090 IE - HKCU\..\SearchScopes\{11BAB7A8-BA60-48C4-8B81-B05A40FCC1A4}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_pl___PL422 IE - HKCU\..\SearchScopes\{12368E27-DAE6-412C-BFFE-66DBCAA16BDC}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=FV&apn_dtid=YYYYYYYYPL&apn_uid=F034DFA8-FDFE-4107-8A30-F4384FF36290&apn_sauid=81CDCC55-0BE4-483D-ADC7-50B82E31ED37& IE - HKCU\..\SearchScopes\{14BF31A3-74FB-4BB7-B47B-4340DCC1ECFD}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_pl___PL422 IE - HKCU\..\SearchScopes\{1CABE4A8-36B3-4290-9E6F-C3507E5C6962}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_pl___PL422 IE - HKCU\..\SearchScopes\{24588FA4-10F1-41D7-B19D-6E22361E47FA}: "URL" = http://www.go2000.cn/p/?q={searchTerms} IE - HKCU\..\SearchScopes\{3C6A80C1-E933-45B3-903A-3B4EC9D10A78}: "URL" = http://search.softonic.com/MON00084/tb_v1?q={searchTerms}&SearchSource=4&cc= IE - HKCU\..\SearchScopes\{5F970FDE-702B-4ef9-920C-5F2848A5AF26}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms} IE - HKCU\..\SearchScopes\{64C62E60-BBA0-4A1D-8474-A779302A49C8}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_pl___PL422 IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_plPL422PL422 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7SMSN_pl___PL422&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=TqHKGOSH4diIgCPKYLX2-IUXIwI?q={searchTerms} IE - HKCU\..\SearchScopes\{78593FF4-A42D-43D1-BBC2-DC95D6FF5FBF}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_pl___PL422 IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={24372B4C-64E4-42E2-BA6D-FE333E846BAB}&mid=df6358f6e93847d0a814397099f95e29-933946b292ee20b136c8bcf47a247e14258047dd&lang=en&ds=ft011&pr=sa&d=2012-06-15 22:36:21&v=11.1.0.12&sap=dsp&q={searchTerms} IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/hypercam/{FA6F7769-BBD4-40BA-9CA2-F3F1F72E43B7}?q={searchTerms} IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms} IE - HKCU\..\SearchScopes\{C5825272-9378-41F1-8137-459A4A824101}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da&q={searchTerms} IE - HKCU\..\SearchScopes\{EE82D800-466D-4B05-81E2-5995093B066F}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_pl___PL422 IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20111225133200683&tb_oid=25-12-2011&tb_mrud=25-12-2011 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search" FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=1&cf=fa45f068-dbd5-11e0-ba86-e839df1db7da"user_pref("extensions.autoDisableScopes", 0); FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: C:\Program Files (x86)\Ganymede\Plugins\npganymedenet.dll File not found FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@powerchallenge.com/PowerLoader: C:\Users\t\AppData\LocalLow\POWERC~1\nppowerloader.dll (Power Challenge Sweden AB) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\t\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\t\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\t\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\t\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/03/11 18:17:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.12\ [2012/06/15 22:36:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/08 23:12:22 | 000,000,000 | ---D | M] [2012/03/07 18:44:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\t\AppData\Roaming\mozilla\Extensions [2012/06/15 22:33:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions [2012/06/13 15:12:04 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03} [2012/03/10 19:51:10 | 000,000,000 | ---D | M] (DealBulldog Toolbar) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC} [2012/06/15 22:33:46 | 000,000,000 | ---D | M] ("I Want This") -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\crossriderapp2258@crossrider.com [2012/03/24 00:41:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\ffxtlbr@babylon.com [2012/03/24 00:45:52 | 000,000,000 | ---D | M] (Iplex to ALLPlayer) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\IplextoALL@ALLPlayer.org [2012/03/27 16:16:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\IvonaFirefoxToolbar@ivona.com [2012/05/16 22:11:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\t\AppData\Roaming\mozilla\Firefox\Profiles\ed04rji6.default\extensions\staged [2012/03/11 21:27:41 | 000,002,059 | ---- | M] () -- C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\ed04rji6.default\searchplugins\absearch-search.xml [2012/01/30 21:54:15 | 000,002,060 | ---- | M] () -- C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\ed04rji6.default\searchplugins\softonic.xml [2012/03/21 22:55:05 | 000,000,792 | ---- | M] () -- C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\ed04rji6.default\searchplugins\startsear.xml [2012/04/03 21:06:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2012/04/03 21:06:12 | 000,000,000 | ---D | M] (z) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{af187fab-4027-0685-1f16-c3cd00d9b3b9} [2012/01/02 11:48:42 | 000,083,456 | ---- | M] (StartSearch ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: AVG Secure Search (Enabled) CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={24372B4C-64E4-42E2-BA6D-FE333E846BAB}&mid=df6358f6e93847d0a814397099f95e29-933946b292ee20b136c8bcf47a247e14258047dd&lang=en&ds=ft011&pr=sa&d=2012-06-15 22:36:21&v=11.1.0.12&sap=dsp&q={searchTerms} CHR - default_search_provider: suggest_url = http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding} CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\t\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\t\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\t\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll CHR - plugin: Shockwave Flash (Disabled) = C:\Users\t\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: StartSearch Video plug-in (Enabled) = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\bildoibdboopgomcbiplincneeicgipj\1.3_0\chvsharetvplg.dll CHR - plugin: StartSearch Video plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 7 U3 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Power Challenge Loader (Enabled) = C:\Users\t\AppData\LocalLow\POWERC~1\nppowerloader.dll CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\t\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll CHR - Extension: StartSearch Video plug-in = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\bildoibdboopgomcbiplincneeicgipj\1.3_0\ CHR - Extension: YouTube = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Click 2 Save = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpemhbnfmfneldahkdmoemdpimnhfhl\1.1_0\ CHR - Extension: Szukaj w Google = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: vshare plugin = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\ CHR - Extension: I Want This = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.18.59_0\crossrider CHR - Extension: I Want This = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.18.59_0\ CHR - Extension: uTorrentControl2 = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.11.0_0\ CHR - Extension: LiveVDO plugin = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\ CHR - Extension: Gmail = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ CHR - Extension: wxDfast = C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndjkggppfppmkimjpgfpjoefbgbehd\1.0_0\ O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho64.dll () O2:[b]64bit:[/b] - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) O2:[b]64bit:[/b] - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110312165641.dll (McAfee, Inc.) O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:[b]64bit:[/b] - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll () O2:[b]64bit:[/b] - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found. O2 - BHO: (I Want This) - {11111111-1111-1111-1111-110011221158} - C:\Program Files (x86)\I Want This\I Want This.dll (215 Apps) O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll () O2 - BHO: (no name) - {2EECD738-5844-4a99-B4B6-146BF802613B} - No CLSID value found. O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.) O2 - BHO: (no name) - {64182481-4F71-486b-A045-B233BD0DA8FC} - No CLSID value found. O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110312165641.dll (McAfee, Inc.) O2 - BHO: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found. O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll () O2 - BHO: (wxDfast Class) - {C71CCB2C-4303-EAD9-762E-F6D4DF6FBF7C} - C:\ProgramData\wxDfast\bhoclass.dll () O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (no name) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - No CLSID value found. O2 - BHO: (no name) - {E87806B5-E908-45FD-AF5E-957D83E58E68} - No CLSID value found. O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\DealBulldog Toolbar\tbcore3.dll () O3:[b]64bit:[/b] - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll () O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll () O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKLM\..\Toolbar: (DealBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\DealBulldog Toolbar\tbcore3.dll () O3 - HKLM\..\Toolbar: (no name) - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - No CLSID value found. O3 - HKLM\..\Toolbar: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKLM\..\Toolbar: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found. O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - No CLSID value found. O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:[b]64bit:[/b] - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (DealBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\DealBulldog Toolbar\tbcore3.dll () O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl2 Toolbar) - {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O4:[b]64bit:[/b] - HKLM..\Run: [AvMenu] C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe (ArcaBit) O4:[b]64bit:[/b] - HKLM..\Run: [NvCplDaemon] C:\windows\SysNative\NvCpl.dll (NVIDIA Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG) O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe () O4 - HKCU..\Run: [Clownfish] C:\Program Files (x86)\Clownfish\Clownfish.exe (Bogdan Sharkov) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Facebook Update] C:\Users\t\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKCU..\Run: [FreeRAM XP] C:\Program Files (x86)\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions (TM)) O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG) O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) O4 - HKCU..\Run: [Update] C:\Users\t\Documents\MSDCSC\msdcsc.exe (Microsoft Corporation) O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:[b]64bit:[/b] - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\MenuExt.html () O8:[b]64bit:[/b] - Extra context menu item: 使用快车3下载 - C:\Users\t\AppData\Roaming\FlashGetBHO\GetUrl.htm () O8:[b]64bit:[/b] - Extra context menu item: 使用快车3下载全部链接 - C:\Users\t\AppData\Roaming\FlashGetBHO\GetAllUrl.htm () O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\MenuExt.html () O8 - Extra context menu item: 使用快车3下载 - C:\Users\t\AppData\Roaming\FlashGetBHO\GetUrl.htm () O8 - Extra context menu item: 使用快车3下载全部链接 - C:\Users\t\AppData\Roaming\FlashGetBHO\GetAllUrl.htm () O9:[b]64bit:[/b] - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (ArcaBit sp. z o.o) O9:[b]64bit:[/b] - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (ArcaBit sp. z o.o) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16:[b]64bit:[/b] - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.) O16:[b]64bit:[/b] - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.) O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 10.3.0) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.152.34 8.8.8.8 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10CFD4D3-87D4-4ADA-8DE8-DE8E0E99A443}: NameServer = 217.116.100.65 79.163.127.70 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{58FC4467-4F49-457B-8B03-9DA50B75BEBE}: NameServer = 217.116.100.65 79.163.127.70 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C023C4A-F81F-42C8-9E64-1D2D21FCC73F}: NameServer = 217.116.100.65 79.163.127.70 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC33F1C7-3D0E-4EA4-9152-209AC750F8C2}: DhcpNameServer = 194.204.152.34 8.8.8.8 O18:[b]64bit:[/b] - Protocol\Handler\msdaipp - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap11 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll () O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll () O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll () O18:[b]64bit:[/b] - Protocol\Filter\text/xml - No CLSID value found O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~4\GO36F4~1.DLL) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Users\t\Documents\MSDCSC\msdcsc.exe) - C:\Users\t\Documents\MSDCSC\msdcsc.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - ("C:\Users\t\AppData\Roaming\lsass.exe") - File not found O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - Unable to obtain root file information for disk F:\ O33 - MountPoints2\{1dd5d30e-9412-11e0-8d6d-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{1dd5d30e-9412-11e0-8d6d-e839df1db7da}\Shell\AutoRun\command - "" = H:\autorun.exe O33 - MountPoints2\{8ccb1e3d-4a47-11e1-a6f7-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{8ccb1e3d-4a47-11e1-a6f7-e839df1db7da}\Shell\AutoRun\command - "" = G:\autorun.exe O33 - MountPoints2\{926c9c97-6c33-11e1-bcdc-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{926c9c97-6c33-11e1-bcdc-e839df1db7da}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{ac942480-5c66-11e0-bfd8-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{ac942480-5c66-11e0-bfd8-e839df1db7da}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{ac942485-5c66-11e0-bfd8-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{ac942485-5c66-11e0-bfd8-e839df1db7da}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{ac94248f-5c66-11e0-bfd8-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{ac94248f-5c66-11e0-bfd8-e839df1db7da}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{c19923ad-5b8a-11e0-b983-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{c19923ad-5b8a-11e0-b983-e839df1db7da}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{c19923b4-5b8a-11e0-b983-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{c19923b4-5b8a-11e0-b983-e839df1db7da}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{c19923ca-5b8a-11e0-b983-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{c19923ca-5b8a-11e0-b983-e839df1db7da}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{c19923cd-5b8a-11e0-b983-e839df1db7da}\Shell - "" = AutoRun O33 - MountPoints2\{c19923cd-5b8a-11e0-b983-e839df1db7da}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/06/24 21:27:05 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\t\Desktop\OTL.exe [2012/06/24 21:12:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee [2012/06/22 22:43:22 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\Unity [2012/06/22 22:17:10 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Local\Unity [2012/06/21 15:06:42 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll [2012/06/21 15:06:42 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe [2012/06/21 15:06:42 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups2.dll [2012/06/21 15:05:52 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll [2012/06/21 15:05:52 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe [2012/06/20 19:03:21 | 000,000,000 | ---D | C] -- C:\ProgramData\ArcaBit [2012/06/20 19:02:28 | 000,046,160 | ---- | C] (ArcaBit) -- C:\windows\SysNative\drivers\abndis.sys [2012/06/20 19:02:07 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArcaVir [2012/06/20 19:01:47 | 000,000,000 | ---D | C] -- C:\Program Files\ArcaBit [2012/06/20 17:55:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2012/06/20 16:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewFeature1 [2012/06/20 15:48:26 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Local\PMB Files [2012/06/20 15:48:19 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files [2012/06/17 21:35:15 | 000,000,000 | ---D | C] -- C:\Users\t\Desktop\mody [2012/06/17 21:35:04 | 000,000,000 | ---D | C] -- C:\Users\t\Desktop\mods [2012/06/17 09:42:31 | 000,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\windows\SysWow64\CmdLineExt.dll [2012/06/16 20:05:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games [2012/06/16 16:32:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KGB Archiver [2012/06/16 16:23:09 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\GTA San Andreas User Files [2012/06/15 22:45:22 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\SGP Systems [2012/06/15 22:44:33 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SGP Systems [2012/06/15 22:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\SGP Systems [2012/06/15 22:44:23 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\SGP Examples [2012/06/15 22:44:23 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\SGP [2012/06/15 22:39:12 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\IObit [2012/06/15 22:39:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegOptimizer [2012/06/15 22:39:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit [2012/06/15 22:36:35 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Local\AVG Secure Search [2012/06/15 22:36:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search [2012/06/15 22:36:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search [2012/06/15 22:36:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search [2012/06/15 22:34:42 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2012/06/15 22:33:46 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Local\I Want This [2012/06/15 22:33:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\I Want This [2012/06/15 16:14:54 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\My Games [2012/06/15 16:13:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA [2012/06/15 14:38:19 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll [2012/06/15 14:38:19 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll [2012/06/15 14:38:18 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll [2012/06/15 14:38:18 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll [2012/06/15 14:38:17 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll [2012/06/15 14:38:17 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll [2012/06/15 14:38:16 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieUnatt.exe [2012/06/15 14:38:16 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieUnatt.exe [2012/06/15 14:38:15 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl [2012/06/15 14:38:15 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl [2012/06/15 14:38:14 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll [2012/06/15 14:38:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll [2012/06/15 14:38:13 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll [2012/06/14 16:01:22 | 001,460,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\crypt32.dll [2012/06/14 16:01:21 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cryptnet.dll [2012/06/14 15:58:20 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdpcorekmts.dll [2012/06/14 15:58:19 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdpwsx.dll [2012/06/14 15:58:19 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdrmemptylst.exe [2012/06/14 15:58:07 | 005,505,392 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe [2012/06/14 15:58:05 | 003,902,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntoskrnl.exe [2012/06/14 15:58:04 | 003,958,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntkrnlpa.exe [2012/06/14 15:57:40 | 003,213,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msi.dll [2012/06/14 15:18:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SGP Systems [2012/06/14 15:18:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SGP Systems [2012/06/13 15:12:05 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Local\CRE [2012/06/13 15:11:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrentControl2 [2012/06/08 19:19:32 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\RTCOM [2012/06/08 19:19:11 | 002,601,816 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\WavesGUILib.dll [2012/06/08 19:19:11 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSX64.dll [2012/06/08 19:19:11 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSWOW64.dll [2012/06/08 19:19:10 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSH64.dll [2012/06/08 19:19:10 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSHP64.dll [2012/06/08 19:19:08 | 001,146,984 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RTSnMg64.cpl [2012/06/08 19:19:07 | 002,018,920 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtPgEx64.dll [2012/06/08 19:19:07 | 000,332,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtlCPAPI64.dll [2012/06/08 19:19:07 | 000,149,608 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkCfg64.dll [2012/06/08 19:19:06 | 002,624,616 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkAPO64.dll [2012/06/08 19:19:06 | 001,210,984 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RTCOM64.dll [2012/06/08 19:19:06 | 000,476,264 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkApi64.dll [2012/06/08 19:19:06 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEP64A.dll [2012/06/08 19:19:06 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DHT64.dll [2012/06/08 19:19:06 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DAA64.dll [2012/06/08 19:19:06 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEED64A.dll [2012/06/08 19:19:06 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEL64A.dll [2012/06/08 19:19:06 | 000,076,904 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RCoInst64.dll [2012/06/08 19:19:06 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEG64A.dll [2012/06/08 19:19:04 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioEQ.dll [2012/06/08 19:19:04 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPO20.dll [2012/06/08 19:19:03 | 000,330,656 | ---- | C] (Fortemedia Corporation) -- C:\windows\SysNative\FMAPO64.dll [2012/06/08 19:19:02 | 000,168,288 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\SysNative\AERTAC64.dll [2012/06/08 19:19:02 | 000,108,960 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\SysNative\AERTAR64.dll [2012/06/08 19:19:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek [2012/06/08 19:18:39 | 001,251,944 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\RtlExUpd.dll [2012/06/04 11:31:59 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\LolClient2 [2012/06/04 10:55:44 | 000,000,000 | ---D | C] -- C:\Riot Games [2012/06/04 09:38:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks [2012/06/03 19:36:13 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\Pamela [2012/06/03 19:36:03 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\Pamela [2012/06/03 19:36:02 | 000,172,544 | ---- | C] (Scendix Software-Vertriebsges. mbH) -- C:\windows\SysWow64\RemoteControl.dll [2012/06/03 19:36:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pamela [2012/06/03 19:36:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pamela [2012/05/30 13:45:50 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\neutron games [2012/05/29 22:15:07 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\ProtectDISC [2012/05/29 22:12:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IHF Handball Challenge 12 [2012/05/29 22:09:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NeutronGames [2012/05/29 22:08:51 | 000,419,840 | ---- | C] (Creative Labs) -- C:\windows\SysNative\wrap_oal.dll [2012/05/29 22:08:51 | 000,413,696 | ---- | C] (Creative Labs) -- C:\windows\SysWow64\wrap_oal.dll [2012/05/29 22:08:51 | 000,133,632 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\windows\SysNative\OpenAL32.dll [2012/05/29 22:08:51 | 000,110,592 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\windows\SysWow64\OpenAL32.dll [2012/05/29 22:08:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL [2012/05/27 17:06:41 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\Skype Voice Records [2012/05/27 17:06:41 | 000,000,000 | ---D | C] -- C:\Users\t\Documents\Clownfish Avatars [2012/05/27 17:06:05 | 000,000,000 | ---D | C] -- C:\Users\t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Clownfish [2012/05/27 17:06:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clownfish [2012/05/27 17:06:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Clownfish [3 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/06/24 21:27:20 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\t\Desktop\OTL.exe [2012/06/24 21:19:42 | 000,014,144 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/06/24 21:19:42 | 000,014,144 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/06/24 21:16:00 | 000,001,048 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2012/06/24 21:11:34 | 000,000,314 | ---- | M] () -- C:\windows\tasks\GlaryInitialize.job [2012/06/24 21:11:15 | 000,001,044 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2012/06/24 21:10:54 | 000,065,536 | ---- | M] () -- C:\windows\SysNative\Ikeext.etl [2012/06/24 21:10:19 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2012/06/24 20:57:02 | 000,001,042 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2284253831-1864166507-3544911301-1000UA.job [2012/06/24 20:21:28 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempU11696.html [2012/06/24 20:16:47 | 000,000,278 | ---- | M] () -- C:\windows\tasks\RMSchedule.job [2012/06/24 20:13:47 | 000,000,912 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2284253831-1864166507-3544911301-1000UA.job [2012/06/24 17:12:03 | 000,000,890 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2284253831-1864166507-3544911301-1000Core.job [2012/06/23 22:57:03 | 000,000,990 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2284253831-1864166507-3544911301-1000Core.job [2012/06/23 12:56:11 | 000,000,440 | -H-- | M] () -- C:\windows\tasks\Norton Security Scan for t.job [2012/06/22 23:59:10 | 036,696,064 | ---- | M] () -- C:\Users\t\Desktop\capture-1.camrec [2012/06/22 23:56:39 | 000,010,752 | ---- | M] () -- C:\Users\t\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/06/22 20:39:45 | 002,646,405 | ---- | M] () -- C:\Users\t\Desktop\nagranie.wav [2012/06/22 15:23:07 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempM22276.html [2012/06/21 20:24:41 | 009,191,424 | ---- | M] () -- C:\Users\t\Desktop\xd.camrec [2012/06/21 20:14:49 | 000,000,098 | ---- | M] () -- C:\Users\t\AppData\Roaming\default.pls [2012/06/20 17:03:57 | 000,001,722 | ---- | M] () -- C:\Users\Public\Desktop\Graj w League of Legends.lnk [2012/06/20 16:59:15 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempGI5220.html [2012/06/20 16:59:15 | 000,002,089 | ---- | M] () -- C:\Users\t\AppData\Local\TempyM5220.html [2012/06/20 14:14:36 | 199,696,384 | ---- | M] () -- C:\Users\t\Desktop\capture-1.avi [2012/06/19 23:02:52 | 000,002,089 | ---- | M] () -- C:\Users\t\AppData\Local\TempLG3900.html [2012/06/19 23:02:51 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\Tempmh3900.html [2012/06/19 22:56:45 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempN54920.html [2012/06/17 20:17:16 | 001,559,272 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2012/06/17 20:17:16 | 000,701,494 | ---- | M] () -- C:\windows\SysNative\perfh015.dat [2012/06/17 20:17:16 | 000,619,590 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2012/06/17 20:17:16 | 000,136,254 | ---- | M] () -- C:\windows\SysNative\perfc015.dat [2012/06/17 20:17:16 | 000,107,652 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2012/06/17 20:17:04 | 000,000,683 | ---- | M] () -- C:\Users\t\Desktop\Dokument.rtf [2012/06/17 19:58:17 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\Tempuc6396.html [2012/06/17 09:47:41 | 000,001,203 | ---- | M] () -- C:\Users\t\Desktop\GTA San Andreas.lnk [2012/06/17 09:42:31 | 000,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\windows\SysWow64\CmdLineExt.dll [2012/06/15 22:44:34 | 000,002,126 | ---- | M] () -- C:\Users\t\Desktop\SGP Baltie 4 C# DEMO.lnk [2012/06/15 17:03:17 | 004,994,536 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT [2012/06/15 16:59:50 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempM11416.html [2012/06/15 16:59:50 | 000,002,089 | ---- | M] () -- C:\Users\t\AppData\Local\TempV11416.html [2012/06/13 20:18:39 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempK11128.html [2012/06/13 17:08:28 | 000,310,147 | ---- | M] () -- C:\Users\t\Desktop\2012-06-13_17.06.50.png [2012/06/13 15:11:44 | 000,000,907 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012/06/12 15:13:00 | 000,002,383 | ---- | M] () -- C:\Users\t\Desktop\Google Chrome.lnk [2012/06/12 15:11:36 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\Tempsg9064.html [2012/06/11 17:37:41 | 000,000,132 | ---- | M] () -- C:\Users\t\AppData\Roaming\Adobe PNG Format CS5 Prefs [2012/06/10 16:15:55 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempY11408.html [2012/06/08 18:56:31 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TempwZ6844.html [2012/06/08 18:56:31 | 000,002,089 | ---- | M] () -- C:\Users\t\AppData\Local\TempiL6844.html [2012/06/04 20:35:23 | 1213,189,862 | ---- | M] () -- C:\Users\t\Desktop\Gameplay LOL.wmv [2012/06/03 19:47:06 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\TemppR3584.html [2012/06/03 19:36:08 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\Pamela for Skype.lnk [2012/06/03 19:36:02 | 000,172,544 | ---- | M] (Scendix Software-Vertriebsges. mbH) -- C:\windows\SysWow64\RemoteControl.dll [2012/06/03 00:19:42 | 000,057,880 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe [2012/06/03 00:19:42 | 000,044,056 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wups2.dll [2012/06/03 00:15:31 | 002,622,464 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll [2012/06/02 15:19:42 | 000,186,752 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll [2012/06/02 15:15:12 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe [2012/05/29 22:15:28 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00002DCE.LCS [2012/05/29 22:12:18 | 000,419,840 | ---- | M] (Creative Labs) -- C:\windows\SysNative\wrap_oal.dll [2012/05/29 22:12:18 | 000,133,632 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\windows\SysNative\OpenAL32.dll [2012/05/29 22:12:17 | 000,413,696 | ---- | M] (Creative Labs) -- C:\windows\SysWow64\wrap_oal.dll [2012/05/29 22:12:17 | 000,110,592 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\windows\SysWow64\OpenAL32.dll [2012/05/29 22:12:16 | 000,002,179 | ---- | M] () -- C:\Users\Public\Desktop\IHF Handball Challenge 12.lnk [2012/05/29 15:07:29 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\Tempew7120.html [2012/05/28 13:45:46 | 000,001,387 | ---- | M] () -- C:\Users\t\Desktop\Minecraft Updater.exe — skrót.lnk [2012/05/27 17:56:03 | 000,002,432 | ---- | M] () -- C:\Users\t\AppData\Local\Temps10756.html [2012/05/27 17:56:03 | 000,002,089 | ---- | M] () -- C:\Users\t\AppData\Local\TempH10756.html [2012/05/27 17:06:05 | 000,001,865 | ---- | M] () -- C:\Users\t\Desktop\Clownfish.lnk [3 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/06/23 20:12:17 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempU11696.html [2012/06/22 23:59:08 | 036,696,064 | ---- | C] () -- C:\Users\t\Desktop\capture-1.camrec [2012/06/22 20:39:39 | 002,646,405 | ---- | C] () -- C:\Users\t\Desktop\nagranie.wav [2012/06/21 20:24:01 | 009,191,424 | ---- | C] () -- C:\Users\t\Desktop\xd.camrec [2012/06/21 20:14:49 | 000,000,098 | ---- | C] () -- C:\Users\t\AppData\Roaming\default.pls [2012/06/21 19:28:36 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempM22276.html [2012/06/20 17:03:57 | 000,001,722 | ---- | C] () -- C:\Users\Public\Desktop\Graj w League of Legends.lnk [2012/06/20 16:59:15 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempGI5220.html [2012/06/20 16:59:15 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempyM5220.html [2012/06/20 12:42:50 | 199,696,384 | ---- | C] () -- C:\Users\t\Desktop\capture-1.avi [2012/06/19 23:02:52 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempLG3900.html [2012/06/19 23:02:51 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempmh3900.html [2012/06/19 22:26:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempN54920.html [2012/06/17 20:17:04 | 000,000,683 | ---- | C] () -- C:\Users\t\Desktop\Dokument.rtf [2012/06/17 15:44:56 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempuc6396.html [2012/06/17 09:47:41 | 000,001,203 | ---- | C] () -- C:\Users\t\Desktop\GTA San Andreas.lnk [2012/06/15 22:44:34 | 000,002,126 | ---- | C] () -- C:\Users\t\Desktop\SGP Baltie 4 C# DEMO.lnk [2012/06/14 22:03:47 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempM11416.html [2012/06/14 22:03:47 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempV11416.html [2012/06/13 17:47:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempK11128.html [2012/06/13 17:08:01 | 000,310,147 | ---- | C] () -- C:\Users\t\Desktop\2012-06-13_17.06.50.png [2012/06/11 14:41:17 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempsg9064.html [2012/06/09 17:34:38 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempY11408.html [2012/06/07 19:55:32 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempwZ6844.html [2012/06/07 19:55:32 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempiL6844.html [2012/06/04 19:12:38 | 1213,189,862 | ---- | C] () -- C:\Users\t\Desktop\Gameplay LOL.wmv [2012/06/03 19:36:08 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\Pamela for Skype.lnk [2012/05/30 22:34:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemppR3584.html [2012/05/29 22:15:15 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00002DCE.LCS [2012/05/29 22:12:16 | 000,002,179 | ---- | C] () -- C:\Users\Public\Desktop\IHF Handball Challenge 12.lnk [2012/05/28 22:15:58 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempew7120.html [2012/05/28 13:45:46 | 000,001,387 | ---- | C] () -- C:\Users\t\Desktop\Minecraft Updater.exe — skrót.lnk [2012/05/27 17:56:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temps10756.html [2012/05/27 17:56:03 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempH10756.html [2012/05/27 17:06:05 | 000,001,865 | ---- | C] () -- C:\Users\t\Desktop\Clownfish.lnk [2012/05/24 19:48:54 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\Access.dat [2012/05/20 13:54:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempzB1996.html [2012/05/18 22:50:21 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempHk4104.html [2012/05/18 22:50:21 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempEv4104.html [2012/05/16 22:59:44 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXN4744.html [2012/05/16 22:59:44 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempsl4744.html [2012/05/16 18:49:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Templc6616.html [2012/05/15 22:34:50 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempwv2364.html [2012/05/15 18:11:10 | 000,000,132 | ---- | C] () -- C:\Users\t\AppData\Roaming\Adobe PNG Format CS5 Prefs [2012/05/14 14:25:39 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempbt6848.html [2012/05/13 10:35:40 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPK1804.html [2012/05/12 09:54:58 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempTa7144.html [2012/05/05 23:39:15 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemphV6852.html [2012/05/05 00:13:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempgN3360.html [2012/05/03 20:03:26 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemptB6808.html [2012/04/30 22:25:58 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLZ5204.html [2012/04/30 20:46:38 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempuU6292.html [2012/04/30 18:14:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempfO4268.html [2012/04/27 19:55:40 | 000,000,026 | ---- | C] () -- C:\windows\Irremote.ini [2012/04/27 19:55:15 | 000,001,024 | ---- | C] () -- C:\Users\t\.rnd [2012/04/27 15:38:26 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVL2452.html [2012/04/25 16:15:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempYu6048.html [2012/04/24 19:35:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempvI6972.html [2012/04/21 22:09:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempam6020.html [2012/04/21 17:00:15 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempMO5836.html [2012/04/21 11:50:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempiY6528.html [2012/04/21 10:05:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempDC5184.html [2012/04/20 20:45:28 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempWn6012.html [2012/04/20 18:18:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempuc2416.html [2012/04/20 14:39:00 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempeYp916.html [2012/04/19 20:27:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempeI4492.html [2012/04/19 15:41:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempdxN164.html [2012/04/16 19:37:45 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempFY2828.html [2012/04/15 12:59:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempZK2136.html [2012/04/15 10:16:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemphL2308.html [2012/04/15 10:16:05 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempGr2308.html [2012/04/14 16:26:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLm1896.html [2012/04/14 09:22:18 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempva4216.html [2012/04/13 21:30:50 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempuo3000.html [2012/04/13 18:18:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempNk5492.html [2012/04/12 19:36:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempto1656.html [2012/04/10 21:27:44 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempUQ2072.html [2012/04/10 10:55:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempcW4868.html [2012/04/08 23:47:43 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempYR6704.html [2012/04/05 09:45:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempnR3404.html [2012/04/05 09:45:57 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempQq3404.html [2012/04/04 23:20:53 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempoL7300.html [2012/04/03 18:52:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempKx6352.html [2012/04/03 18:52:02 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Templr6352.html [2012/04/03 18:45:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempo12392.html [2012/04/03 18:45:54 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempP12392.html [2012/04/01 13:07:16 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvk7056.html [2012/03/31 23:48:28 | 000,026,777 | ---- | C] () -- C:\Users\t\AppData\Local\recently-used.xbel [2012/03/31 11:58:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempAw3612.html [2012/03/30 23:21:22 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempbX2624.html [2012/03/30 23:07:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempfF3780.html [2012/03/30 23:07:03 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempwB3780.html [2012/03/27 14:57:36 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempJf2940.html [2012/03/26 22:38:16 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempzA6888.html [2012/03/26 22:38:16 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TemprX6888.html [2012/03/26 18:19:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempDT2576.html [2012/03/26 18:19:41 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempiW2576.html [2012/03/26 14:03:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXi3332.html [2012/03/26 14:03:19 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempyp3332.html [2012/03/25 23:31:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempfV7828.html [2012/03/25 10:37:39 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPq5744.html [2012/03/24 22:57:36 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempSl5200.html [2012/03/24 00:45:54 | 000,644,608 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll [2012/03/24 00:45:53 | 000,258,048 | ---- | C] () -- C:\windows\SysWow64\libFLAC.dll.bak [2012/03/23 22:53:43 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempSC7848.html [2012/03/23 22:53:43 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempjY7848.html [2012/03/23 18:01:08 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temprp2988.html [2012/03/23 18:01:08 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempBu2988.html [2012/03/22 21:12:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempwB7480.html [2012/03/22 21:12:03 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempXN7480.html [2012/03/21 22:55:24 | 000,075,045 | ---- | C] () -- C:\windows\SysWow64\16b5f185.exe [2012/03/20 23:53:27 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvk5748.html [2012/03/20 16:45:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemprN2620.html [2012/03/20 16:45:19 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempQk2620.html [2012/03/19 00:45:01 | 000,000,376 | ---- | C] () -- C:\windows\ODBC.INI [2012/03/19 00:21:33 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXa3888.html [2012/03/18 17:06:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempwj4516.html [2012/03/18 13:29:21 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempFA3016.html [2012/03/18 13:29:21 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempRD3016.html [2012/03/17 22:39:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempDO6764.html [2012/03/17 15:23:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLM3704.html [2012/03/17 15:18:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempqm2536.html [2012/03/17 15:18:09 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempKw2536.html [2012/03/17 15:16:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPt5296.html [2012/03/17 15:16:41 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempex5296.html [2012/03/17 14:58:45 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempoy4800.html [2012/03/17 14:58:45 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempYP4800.html [2012/03/17 11:43:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempwo4040.html [2012/03/16 19:39:16 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempyi4408.html [2012/03/16 16:22:35 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempM15856.html [2012/03/15 20:27:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempuc3480.html [2012/03/14 19:23:36 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempt11700.html [2012/03/14 17:24:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempf11608.html [2012/03/13 00:31:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temph11416.html [2012/03/12 19:16:17 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temph17476.html [2012/03/12 17:54:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempCa8784.html [2012/03/12 16:29:56 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempQ18008.html [2012/03/11 21:42:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempjQ7936.html [2012/03/11 18:19:38 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempbN4344.html [2012/03/11 17:11:11 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVD2240.html [2012/03/11 10:18:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempYT2908.html [2012/03/10 18:38:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempG10536.html [2012/03/10 12:36:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXv5908.html [2012/03/09 22:49:23 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempxz2800.html [2012/03/09 17:10:36 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempaU1260.html [2012/03/09 17:10:36 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempQq1260.html [2012/03/08 20:37:40 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempaK8000.html [2012/03/08 20:35:13 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempMn3812.html [2012/03/08 20:35:13 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempLg3812.html [2012/03/08 17:22:50 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemptD2644.html [2012/03/08 17:22:50 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempPa2644.html [2012/03/07 19:02:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempGr7044.html [2012/03/07 13:37:29 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempWb2796.html [2012/03/06 15:09:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempu12660.html [2012/03/06 00:19:22 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempqL9232.html [2012/03/05 23:42:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempjl8628.html [2012/03/05 19:14:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempfz4344.html [2012/03/05 17:25:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temppf7800.html [2012/03/05 09:22:49 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempMV6348.html [2012/03/05 01:11:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLZ3536.html [2012/03/05 00:39:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempGz7992.html [2012/03/04 23:25:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempWe6556.html [2012/03/03 14:20:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempcc3684.html [2012/03/02 14:31:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempiz9556.html [2012/03/01 20:16:52 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempHF7300.html [2012/03/01 16:41:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempIy6748.html [2012/02/29 22:55:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVK2180.html [2012/02/29 15:05:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempvN1588.html [2012/02/28 15:54:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempcq1456.html [2012/02/26 19:05:29 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempdD7140.html [2012/02/25 14:22:51 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempjR2428.html [2012/02/25 00:13:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempyc8580.html [2012/02/24 20:59:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temph16392.html [2012/02/21 16:48:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempad9548.html [2012/02/20 16:58:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempha3820.html [2012/02/20 15:50:46 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempf19356.html [2012/02/19 22:49:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempo10476.html [2012/02/18 09:17:58 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempCj3612.html [2012/02/17 23:02:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempc13044.html [2012/02/17 23:02:59 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempY13044.html [2012/02/17 19:20:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempJk3820.html [2012/02/17 17:39:26 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempS10812.html [2012/02/17 13:10:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempjh1536.html [2012/02/16 19:20:21 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempfm3504.html [2012/02/16 19:20:21 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempwX3504.html [2012/02/16 16:35:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempUE7500.html [2012/02/15 23:59:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempiS8072.html [2012/02/14 22:51:33 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temprm4332.html [2012/02/13 17:29:44 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempW10604.html [2012/02/13 17:29:44 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempG10604.html [2012/02/12 01:09:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempb10948.html [2012/02/11 18:16:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempDo3280.html [2012/02/11 17:49:13 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempzb5488.html [2012/02/10 14:10:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempcO2116.html [2012/02/10 14:10:48 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempUJ2116.html [2012/02/09 19:11:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempkI4608.html [2012/02/09 13:22:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempH11876.html [2012/02/08 23:52:45 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempd11744.html [2012/02/08 09:39:26 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempAo2236.html [2012/02/07 22:35:58 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempFc5716.html [2012/02/07 22:35:58 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempXB5716.html [2012/02/07 09:32:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temps13000.html [2012/02/07 08:57:39 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempdS4452.html [2012/02/06 14:49:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempGy6036.html [2012/02/06 03:48:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempw12040.html [2012/02/05 19:42:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temps12812.html [2012/02/05 17:43:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempu12624.html [2012/02/05 14:37:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempL11636.html [2012/02/05 08:49:49 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempT11608.html [2012/02/05 08:14:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempc13764.html [2012/02/04 21:20:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempW11272.html [2012/02/04 15:37:47 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXg9628.html [2012/02/04 15:03:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempfQ8924.html [2012/02/04 14:46:33 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempOV9900.html [2012/02/04 08:44:45 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPn8860.html [2012/02/03 22:10:24 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempor9208.html [2012/02/03 16:34:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempGS3436.html [2012/02/03 15:27:28 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempTo8756.html [2012/02/03 08:29:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempaF8712.html [2012/02/02 22:48:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempwO7952.html [2012/02/02 21:21:15 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempme2868.html [2012/02/02 14:38:52 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempva2508.html [2012/02/02 09:11:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempna4784.html [2012/02/01 20:04:43 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempEu7812.html [2012/02/01 19:02:32 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temps10804.html [2012/02/01 14:01:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temppe9584.html [2012/02/01 13:27:22 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvk6136.html [2012/02/01 08:22:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempz10232.html [2012/01/31 23:27:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temppj6492.html [2012/01/31 23:10:13 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempdh5280.html [2012/01/31 22:18:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempiK7932.html [2012/01/31 18:41:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempZF6704.html [2012/01/31 18:21:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempzd6704.html [2012/01/31 18:00:17 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempmN5504.html [2012/01/31 17:32:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempCd3520.html [2012/01/31 14:44:28 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempi11984.html [2012/01/31 09:14:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempQE8728.html [2012/01/30 21:43:45 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempif9552.html [2012/01/29 09:09:08 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempwp3060.html [2012/01/28 19:00:45 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempy19972.html [2012/01/28 19:00:45 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempu19972.html [2012/01/27 18:34:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempX13292.html [2012/01/26 21:34:00 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempk13716.html [2012/01/24 22:56:31 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempK11376.html [2012/01/23 22:35:15 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempN10300.html [2012/01/23 14:52:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temprh3668.html [2012/01/23 14:52:04 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempui3668.html [2012/01/22 15:04:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempzP2972.html [2012/01/22 15:04:12 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempuj2972.html [2012/01/21 00:05:37 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPP8484.html [2012/01/21 00:05:37 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempMO8484.html [2012/01/18 23:27:13 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempnt3192.html [2012/01/18 16:10:12 | 000,001,963 | ---- | C] () -- C:\Users\t\BotAslambekTROLE.rbc [2012/01/18 14:55:18 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempqi2532.html [2012/01/16 18:55:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempI19488.html [2012/01/16 18:55:55 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempJ19488.html [2012/01/14 19:59:22 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempdk1304.html [2012/01/14 19:32:23 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempUa9380.html [2012/01/14 11:22:52 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempue3660.html [2012/01/14 11:21:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPT2676.html [2012/01/14 11:21:10 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TemppL2676.html [2012/01/13 19:34:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempPP7408.html [2012/01/13 19:34:14 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempLt7408.html [2012/01/13 16:31:57 | 000,049,262 | ---- | C] () -- C:\Users\t\AppData\Roaming\tibiacam [2012/01/13 13:56:34 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempHf4688.html [2012/01/13 09:11:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempyE3132.html [2012/01/12 20:29:21 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempo16104.html [2012/01/10 21:10:42 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempRg3536.html [2012/01/10 21:03:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempr27392.html [2012/01/10 20:40:31 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempI40132.html [2012/01/10 20:40:31 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempo40132.html [2012/01/10 20:16:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempA33716.html [2012/01/10 20:16:59 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempf33716.html [2012/01/10 19:19:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempP33768.html [2012/01/08 23:46:46 | 000,514,321 | ---- | C] () -- C:\windows\windate.exe [2012/01/08 23:46:46 | 000,105,760 | ---- | C] () -- C:\windows\os4.exe [2012/01/08 23:46:45 | 000,059,904 | ---- | C] () -- C:\windows\zlib1.dll [2012/01/08 15:02:22 | 001,867,776 | ---- | C] () -- C:\windows\SysWow64\python24.dll [2012/01/06 10:23:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temppi2868.html [2012/01/03 16:02:23 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempyW3624.html [2012/01/03 16:02:23 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempVj3624.html [2012/01/01 15:04:01 | 000,122,880 | ---- | C] () -- C:\windows\UnGins.exe [2011/12/28 11:20:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempSu4584.html [2011/12/28 11:20:05 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempCu4584.html [2011/12/26 23:37:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempmw9316.html [2011/12/26 23:37:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempcO9316.html [2011/12/26 23:37:14 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempXF9316.html [2011/12/26 23:37:14 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempBD9316.html [2011/12/26 11:27:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempKn3060.html [2011/12/26 11:27:06 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempsS3060.html [2011/12/26 11:27:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempwR3060.html [2011/12/22 11:55:50 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemplT3848.html [2011/12/22 11:55:50 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempgz3848.html [2011/12/22 11:55:50 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempkE3848.html [2011/12/22 11:55:50 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Temphr3848.html [2011/12/22 11:55:11 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempbL2716.html [2011/12/22 11:55:11 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvx2716.html [2011/12/22 11:55:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempdB2716.html [2011/12/22 11:55:09 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempWO2716.html [2011/12/17 09:10:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempen3408.html [2011/12/17 09:10:57 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TemphM3408.html [2011/12/17 09:10:56 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempKa3408.html [2011/12/17 09:10:56 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempGf3408.html [2011/12/17 09:10:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVg4024.html [2011/12/17 09:10:03 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempWW4024.html [2011/12/17 09:10:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempTd4024.html [2011/12/17 09:10:02 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempco4024.html [2011/12/16 08:36:02 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempbq3112.html [2011/12/16 08:36:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXY3112.html [2011/12/16 08:36:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempkJ3112.html [2011/12/16 08:36:01 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempjX3112.html [2011/12/14 15:58:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempcc4280.html [2011/12/14 15:58:05 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempoj4280.html [2011/12/14 15:58:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempfz4280.html [2011/12/14 15:58:04 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempzu4280.html [2011/12/14 14:30:16 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempEd1664.html [2011/12/14 14:30:16 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempRg1664.html [2011/12/14 14:30:13 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempST1664.html [2011/12/14 14:30:13 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempjo1664.html [2011/12/13 16:46:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempGQ6728.html [2011/12/13 16:46:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempDy6728.html [2011/12/13 16:46:06 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempWt6728.html [2011/12/13 16:46:06 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempKl6728.html [2011/12/13 08:23:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempEE2568.html [2011/12/13 08:23:06 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempqW2568.html [2011/12/13 08:23:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempZu2568.html [2011/12/13 08:23:04 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Temput2568.html [2011/12/06 19:45:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempP28100.html [2011/12/06 19:45:04 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Temps28100.html [2011/12/06 19:45:02 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempL28100.html [2011/12/06 19:45:02 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempm28100.html [2011/11/27 11:58:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempV19352.html [2011/11/27 11:58:07 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempq19352.html [2011/11/27 11:58:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempR19352.html [2011/11/27 11:58:06 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempz19352.html [2011/11/26 21:16:25 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemplD8748.html [2011/11/16 15:08:14 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempxS8748.html [2011/11/14 19:12:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempT10032.html [2011/11/14 19:05:29 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempx10032.html [2011/11/14 19:05:28 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempZ10032.html [2011/11/12 16:51:25 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempZq4692.html [2011/11/10 21:45:44 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempfZ1752.html [2011/11/10 21:45:44 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempVg1752.html [2011/11/10 21:45:42 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempcE1752.html [2011/11/10 21:45:42 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempvK1752.html [2011/11/09 20:28:05 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLi2676.html [2011/11/09 20:28:05 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempZx2676.html [2011/11/09 20:28:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempHc2676.html [2011/11/09 20:28:04 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempDz2676.html [2011/11/08 19:56:44 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempan2592.html [2011/11/08 19:56:44 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempEv2592.html [2011/11/06 09:39:54 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempmt2592.html [2011/11/06 09:39:53 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVL2592.html [2011/11/05 09:29:34 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempQZ9900.html [2011/11/05 09:29:34 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempXV9900.html [2011/11/04 23:26:21 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXm9900.html [2011/11/04 23:26:21 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempUw9900.html [2011/11/04 23:26:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temppx9900.html [2011/11/04 08:24:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempmg4036.html [2011/11/04 08:24:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempJT4036.html [2011/11/01 19:29:08 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempX11420.html [2011/11/01 19:29:08 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempu11420.html [2011/10/30 14:36:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemprQ4196.html [2011/10/30 14:36:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempSY4196.html [2011/10/29 15:47:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempoy8656.html [2011/10/27 19:55:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempOi9236.html [2011/10/27 11:58:50 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempTP2584.html [2011/10/27 11:58:50 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempTm2584.html [2011/10/27 11:58:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempsl2584.html [2011/10/27 11:58:48 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempjb2584.html [2011/10/24 19:04:35 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempYW9552.html [2011/10/24 19:04:34 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempEs9552.html [2011/10/22 16:02:53 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempSZ6904.html [2011/10/22 16:02:53 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempRA6904.html [2011/10/19 17:52:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempxy9144.html [2011/10/19 17:52:57 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempTF9144.html [2011/10/19 17:52:57 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempXX9144.html [2011/10/19 17:52:57 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvv9144.html [2011/10/16 21:37:03 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempsd2996.html [2011/10/16 21:37:00 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempMy2996.html [2011/10/15 16:21:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempRJ4052.html [2011/10/15 16:21:41 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempBq4052.html [2011/10/15 16:21:39 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempsa4052.html [2011/10/15 16:21:39 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempZJ4052.html [2011/10/14 13:58:27 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempF21956.html [2011/10/14 13:58:27 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempu21956.html [2011/10/14 13:58:26 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempa21956.html [2011/10/14 13:58:26 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Temps21956.html [2011/10/08 14:04:30 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempdx8020.html [2011/10/06 19:21:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvq8020.html [2011/10/06 19:21:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLF8020.html [2011/10/05 16:57:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempud9104.html [2011/10/05 16:57:49 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempFf9104.html [2011/09/25 08:39:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempq20868.html [2011/09/25 08:39:10 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempn20868.html [2011/09/21 21:35:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempv20868.html [2011/09/21 21:35:48 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempG20868.html [2011/09/16 07:02:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempw13752.html [2011/09/16 07:02:59 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempa13752.html [2011/09/11 14:35:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempr16608.html [2011/09/11 14:35:48 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempN16608.html [2011/09/01 14:15:18 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempUM6272.html [2011/08/30 07:51:00 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempJ27612.html [2011/08/22 20:34:52 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempgk8404.html [2011/08/17 18:31:00 | 000,094,208 | ---- | C] () -- C:\windows\SysWow64\ImageSearchDLL.dll [2011/08/16 12:32:39 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempxw3024.html [2011/08/16 12:32:39 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempmv3024.html [2011/08/16 12:27:59 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVa2940.html [2011/08/16 12:27:59 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempVS2940.html [2011/08/16 10:59:23 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempvj2228.html [2011/08/16 10:59:23 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempTU2228.html [2011/08/14 01:21:15 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempnt4044.html [2011/08/14 01:21:15 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Temptr4044.html [2011/08/09 12:22:47 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempzC3296.html [2011/08/09 12:22:47 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempWQ3296.html [2011/08/08 14:41:00 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempJ12016.html [2011/08/08 14:41:00 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempS12016.html [2011/08/08 13:15:56 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempb13036.html [2011/08/08 12:09:31 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempS13116.html [2011/08/08 12:09:31 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempD13116.html [2011/08/07 23:54:32 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempC15416.html [2011/08/07 23:54:32 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempD15416.html [2011/08/06 08:11:56 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempQ15568.html [2011/08/06 08:11:56 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempF15568.html [2011/07/31 22:02:27 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempyUR476.html [2011/07/31 22:02:27 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempwgx476.html [2011/07/29 13:32:58 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempwj2820.html [2011/07/29 12:49:36 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempeo2308.html [2011/07/29 12:49:36 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempUb2308.html [2011/07/28 21:25:32 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempz11444.html [2011/07/28 21:25:32 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempD11444.html [2011/07/27 10:48:00 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempRG8752.html [2011/07/17 01:04:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXe2356.html [2011/07/14 10:30:43 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVe7676.html [2011/07/14 10:30:43 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempQI7676.html [2011/07/05 08:24:22 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempCz2336.html [2011/07/05 08:24:22 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempsU2336.html [2011/07/02 19:05:46 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempuZ2640.html [2011/07/02 19:05:46 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempAf2640.html [2011/07/01 21:56:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempVQ7908.html [2011/06/30 17:37:53 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempyl1564.html [2011/06/30 17:37:53 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Templb1564.html [2011/06/30 10:01:12 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempW15292.html [2011/06/30 10:01:12 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempx15292.html [2011/06/29 21:42:23 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Temp101800.html [2011/06/29 21:42:23 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempa01800.html [2011/06/17 15:07:19 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempM10272.html [2011/06/16 09:40:38 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempBq3436.html [2011/06/11 12:06:51 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempJg4920.html [2011/06/11 12:06:51 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Temphb4920.html [2011/06/11 09:07:04 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempSj3032.html [2011/06/08 17:04:41 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempdJ3096.html [2011/06/08 17:04:41 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempVF3096.html [2011/06/07 19:37:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempDo2784.html [2011/06/02 13:05:06 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempmK2916.html [2011/05/29 19:08:04 | 000,010,752 | ---- | C] () -- C:\Users\t\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/05/24 14:21:20 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemprX2220.html [2011/05/14 18:18:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempma2220.html [2011/05/14 18:18:55 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempDP2220.html [2011/05/14 15:57:48 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempsl1336.html [2011/05/14 15:57:48 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempfX1336.html [2011/05/14 11:06:09 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempbe1616.html [2011/05/14 11:06:09 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempKE1616.html [2011/05/13 16:46:35 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempFp1952.html [2011/05/13 15:54:29 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempae6428.html [2011/05/13 15:54:29 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempQM6428.html [2011/05/10 21:51:33 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempqT3176.html [2011/05/07 13:48:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TemppW3092.html [2011/05/04 08:09:55 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempXF3556.html [2011/05/04 08:09:55 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempVL3556.html [2011/05/03 19:54:50 | 000,008,192 | ---- | C] () -- C:\windows\d3dx.dat [2011/05/02 13:30:16 | 082,498,147 | ---- | C] () -- C:\Users\t\Gothic.W03 [2011/05/02 13:29:58 | 430,080,000 | ---- | C] () -- C:\Users\t\Gothic.W02 [2011/05/02 13:29:45 | 430,080,000 | ---- | C] () -- C:\Users\t\Gothic.EXE [2011/04/30 09:34:52 | 000,462,793 | ---- | C] () -- C:\windows\ServicePack2.exe [2011/04/30 09:34:52 | 000,134,829 | ---- | C] () -- C:\windows\ServicePack-2.exe [2011/04/29 22:18:05 | 001,577,190 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI [2011/04/27 13:57:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempb10888.html [2011/04/27 13:57:01 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\TempT10888.html [2011/04/26 13:37:01 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\Tempxe2092.html [2011/04/26 09:02:24 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempiM7428.html [2011/04/26 09:02:24 | 000,002,089 | ---- | C] () -- C:\Users\t\AppData\Local\Tempcq7428.html [2011/04/26 00:17:10 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempOn6488.html [2011/04/25 19:34:07 | 000,002,432 | ---- | C] () -- C:\Users\t\AppData\Local\TempLb6812.html [2011/04/11 17:47:01 | 000,000,025 | ---- | C] () -- C:\windows\libem.INI [2011/03/19 15:39:09 | 000,165,376 | ---- | C] () -- C:\windows\SysWow64\unrar.dll [2011/03/12 11:21:19 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011/03/11 00:30:41 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 508 bytes -> C:\ProgramData\Temp:05EE1EEF @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:D1B5B4F1 < End of report >