OTL logfile created on: 6/26/2013 6:18:35 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\\Users\\Felicia\\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.97 Gb Total Physical Memory | 2.65 Gb Available Physical Memory | 66.76% Memory free
7.93 Gb Paging File | 6.21 Gb Available in Paging File | 78.32% Paging File free
Paging file location(s): ?:\\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)
Drive C: | 581.48 Gb Total Space | 523.88 Gb Free Space | 90.09% Space Free | Partition Type: NTFS
Computer Name: FELICIA-PC | User Name: Felicia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/06/26 18:17:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Felicia\\Desktop\\OTL.exe
PRC - [2013/05/11 05:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe
PRC - [2009/12/03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\\Program Files (x86)\\Epson Software\\Event Manager\\EEventManager.exe
PRC - [2009/08/14 20:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) -- C:\\Windows\\SysWOW64\\vmnetdhcp.exe
PRC - [2009/08/14 20:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) -- C:\\Windows\\SysWOW64\\vmnat.exe
PRC - [2009/08/14 20:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-authd.exe
PRC - [2009/07/20 04:00:00 | 000,077,824 | ---- | M] () -- C:\\Program Files\\Logitech\\SetPoint\\x86\\SetPoint32.exe
PRC - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\\Program Files\\Dell\\DellDock\\DockLogin.exe
PRC - [2009/06/04 19:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAAnotif.exe
PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAANTmon.exe
PRC - [2007/07/19 17:54:48 | 000,689,408 | ---- | M] (American Power Conversion Corporation) -- C:\\Program Files (x86)\\APC\\APC PowerChute Personal Edition\\mainserv.exe
========== Modules (No Company Name) ==========
MOD - [2009/07/20 04:00:00 | 000,077,824 | ---- | M] () -- C:\\Program Files\\Logitech\\SetPoint\\x86\\SetPoint32.exe
========== Services (SafeList) ==========
SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\\Program Files\\Microsoft Security Client\\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\\Program Files\\Microsoft Security Client\\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/20 12:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Logishrd\\Bluetooth\\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\\Program Files\\Dell\\DellDock\\DockLogin.exe -- (DockLoginService)
SRV - [2013/06/12 11:57:23 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/11 05:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe -- (AdobeARMservice)
SRV - [2011/01/13 14:37:02 | 000,705,856 | ---- | M] (SoftThinks SAS) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell DataSafe Local Backup\\SftService.exe -- (SftService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/08/14 20:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Windows\\SysWOW64\\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2009/08/14 20:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Windows\\SysWOW64\\vmnat.exe -- (VMware NAT Service)
SRV - [2009/08/14 20:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-authd.exe -- (VMAuthdService)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAANTmon.exe -- (IAANTMON)
SRV - [2008/12/01 11:49:02 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-ufad.exe -- (ufad-ws60)
SRV - [2007/07/19 17:54:48 | 000,689,408 | ---- | M] (American Power Conversion Corporation) [Auto | Running] -- C:\\Program Files (x86)\\APC\\APC PowerChute Personal Edition\\mainserv.exe -- (APC UPS Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/25 20:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/08/14 20:20:54 | 000,038,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\hcmon.sys -- (hcmon)
DRV:64bit: - [2009/08/14 20:20:48 | 000,030,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2009/08/14 20:20:44 | 000,065,072 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmci.sys -- (vmci)
DRV:64bit: - [2009/08/14 20:20:44 | 000,029,744 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2009/08/14 20:14:28 | 000,076,336 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmx86.sys -- (vmx86)
DRV:64bit: - [2009/08/14 13:40:04 | 000,038,960 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2009/08/14 13:40:04 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2009/07/30 22:58:42 | 000,236,544 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 19:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 19:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/07/09 04:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/17 11:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009/06/17 11:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009/06/17 11:54:14 | 000,013,328 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2009/06/17 11:54:06 | 000,074,256 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 21:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/05/26 07:13:10 | 000,138,752 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2006/11/01 11:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WimFltr.sys -- (WimFltr)
DRV - [2010/02/17 11:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 11:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 11:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\SASENUM.SYS -- (SASENUM)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)
DRV - [2008/12/01 11:46:58 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vstor2-ws60.sys -- (vstor2-ws60)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\\..\\SearchScopes\\{5AAEB2D7-D0EB-47E4-94BF-54BC862E9E8F}: \"URL\" = http://www.bing.com/search?q=%7BsearchTerms%7D&form=DLCDF8&pc=MDDC&src=IE-SearchBox\'>http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE:64bit: - HKLM\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
IE - HKLM\\..\\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\\..\\SearchScopes\\{A136A9CC-255C-4131-AAB3-7407C8B4C1E5}: \"URL\" = http://www.bing.com/search?q=%7BsearchTerms%7D&form=DLCDF8&pc=MDDC&src=IE-SearchBox\'>http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\\..\\SearchScopes\\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=%7BsearchTerms%7D&SearchSource=4&ctid=CT2438727\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2438727
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://g.msn.com/USCON/1\'>http://g.msn.com/USCON/1
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://att.my.yahoo.com/\'>http://att.my.yahoo.com/
IE - HKCU\\..\\SearchScopes,DefaultScope = {6A50FBDC-5DF4-4c9c-9B3B-2749F6FF4D24}
IE - HKCU\\..\\SearchScopes\\{03B0EE02-7915-4D0C-BAE9-17A3827F4713}: \"URL\" = http://search.yahoo.com/search?fr=mcafee&p=%7BSearchTerms\'>http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKCU\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7ADSA_en\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADSA_en
IE - HKCU\\..\\SearchScopes\\{6A50FBDC-5DF4-4c9c-9B3B-2749F6FF4D24}: \"URL\" = http://search.yahoo.com/search?fr=chr-atty&p=%7BsearchTerms\'>http://search.yahoo.com/search?fr=chr-atty&p={searchTerms}
IE - HKCU\\..\\SearchScopes\\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=%7BsearchTerms%7D&SearchSource=4&ctid=CT2438727\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2438727
IE - HKCU\\..\\SearchScopes\\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: \"URL\" = http://mystart.incredimail.com/?search=%7BsearchTerms%7D&loc=search_box_im2_test_v2\'>http://mystart.incredimail.com/?search={searchTerms}&loc=search_box_im2_test_v2
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
========== FireFox ==========
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~2\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/ShockwavePlayer: C:\\Windows\\system32\\Adobe\\Director\\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.25.2: C:\\Windows\\SysWOW64\\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.25.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@mcafee.com/MVT: C:\\Program Files (x86)\\McAfee\\Supportability\\MVT\\NPMVTPlugin.dll File not found
FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~2\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~2\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3502.0922: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3508.1109: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3555.0308: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Program Files (x86)\\Google\\Update\\1.3.21.145\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Program Files (x86)\\Google\\Update\\1.3.21.145\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\\Software\\MozillaPlugins\\Adobe Reader: C:\\Program Files (x86)\\Adobe\\Reader 11.0\\Reader\\AIR\\nppdf32.dll (Adobe Systems Inc.)
[2011/08/25 07:19:25 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions
[2011/07/29 12:34:07 | 000,000,000 | ---D | M] (Java Console) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/03/18 13:32:12 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\\Program Files (x86)\\mozilla firefox\\plugins\\npCouponPrinter.dll
[2011/07/29 12:33:36 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\\Program Files (x86)\\mozilla firefox\\plugins\\npdeployJava1.dll
[2011/03/18 13:32:14 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\\Program Files (x86)\\mozilla firefox\\plugins\\npMozCouponPrinter.dll
[2011/03/24 10:07:32 | 000,002,024 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\McSiteAdvisor.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.msn.com/?pc=UP21&ocid=UP21DHP&dt=022313\'>http://www.msn.com/?pc=UP21&ocid=UP21DHP&dt=022313
CHR - plugin: Shockwave Flash (Enabled) = C:\\Program Files (x86)\\Google\\Chrome\\Application\\27.0.1453.116\\PepperFlash\\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\\Program Files (x86)\\Google\\Chrome\\Application\\27.0.1453.116\\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\\Program Files (x86)\\Google\\Chrome\\Application\\27.0.1453.116\\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\\Program Files (x86)\\Adobe\\Reader 11.0\\Reader\\Browser\\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~2\\Office14\\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\\PROGRA~2\\MICROS~2\\Office14\\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\\Program Files (x86)\\Google\\Update\\1.3.21.145\\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\\Program Files (x86)\\Java\\jre6\\bin\\plugin2\\npjp2.dll
CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_7_700_224.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\\Windows\\system32\\Adobe\\Director\\np32dsw.dll
CHR - Extension: Google Docs = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.5_0\\
CHR - Extension: Google Drive = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf\\6.3_0\\
CHR - Extension: YouTube = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\
CHR - Extension: Google Search = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\
CHR - Extension: Gmail = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_0\\
O1 HOSTS File: ([2013/06/18 14:08:55 | 000,001,307 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts
O1 - Hosts: 64.78.157.110 vof01.alpineaccess.com #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
O1 - Hosts: 64.78.157.110 vof01 #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
O1 - Hosts: 64.78.157.94 a2fp3.alpineaccess.com #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
O1 - Hosts: 64.78.157.94 a2fp3 #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
O1 - Hosts: 64.78.157.93 a2fp2.alpineaccess.com #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
O1 - Hosts: 64.78.157.93 a2fp2 #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\\Program Files (x86)\\Epson Software\\Easy Photo Print\\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\\..\\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\\Program Files (x86)\\Epson Software\\Easy Photo Print\\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3:64bit: - HKLM\\..\\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\\..\\Toolbar: (no name) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - No CLSID value found.
O3 - HKLM\\..\\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\\Run: [IAAnotif] C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [Kernel and Hardware Abstraction Layer] C:\\Windows\\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\\Run: [Logitech Download Assistant] C:\\Windows\\SysNative\\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\\Run: [MSC] c:\\Program Files\\Microsoft Security Client\\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [RtHDVCpl] C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\\Run: [EEventManager] C:\\Program Files (x86)\\Epson Software\\Event Manager\\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKCU..\\Run: [EPSON NX420 Series] C:\\Windows\\system32\\spool\\DRIVERS\\x64\\3\\E_IATIGCA.EXE /FU \"C:\\Windows\\TEMP\\E_S444.tmp\" /EF \"HKCU\" File not found
O4 - HKLM..\\RunOnce: [\"C:\\Program Files (x86)\\Dell DataSafe Local Backup\\Components\\DSUpdate\\DSUpdate.exe\"] C:\\Program Files (x86)\\Dell DataSafe Local Backup\\Components\\DSUpdate\\DSUpdate.exe (Dell)
O4 - Startup: C:\\Users\\Felicia\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Dell Dock.lnk = File not found
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: LogonHoursAction = 2
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: DontDisplayLogonHoursWarnings = 1
O10:64bit: - Protocol_Catalog9\\Catalog_Entries64\\000000000011 - C:\\Program Files (x86)\\VMware\\VMware Player\\x64\\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\\Catalog_Entries64\\000000000012 - C:\\Program Files (x86)\\VMware\\VMware Player\\x64\\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000011 - C:\\Program Files (x86)\\VMware\\VMware Player\\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000012 - C:\\Program Files (x86)\\VMware\\VMware Player\\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\\..Trusted Domains: alpineaccess.com ([]* in Trusted sites)
O15 - HKCU\\..Trusted Domains: alpineaccess.net ([]* in Trusted sites)
O15 - HKCU\\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKCU\\..Trusted Ranges: Range2 ([http] in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab\'>http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab\'>http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} http://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID=%7B896A23A1-5821-4609-A6C6-6D5536C585C9\'>http://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9} (WebIQ Engine Application Object)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab\'>http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB\'>http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1274551454442\'>http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1274551454442 (MUCatalogWebControl Class)
O16 - DPF: {66F7F252-3FE1-4650-B1E5-94B2A38271C5} http://treehouse.no-ip.biz/ActiveView.cab\'>http://treehouse.no-ip.biz/ActiveView.cab (ActiveView Control)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB\'>http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.att.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab\'>http://games.att.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab\'>http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{28C31212-6713-4A47-8872-34C779D8B726}: NameServer = 10.124.6.3,10.124.3.2
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{471273CC-2F13-4283-A8E4-077C3C484F05}: DhcpNameServer = 192.168.1.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{47AF739C-9211-470F-8886-1F12156AA75E}: NameServer = 10.124.6.3,10.124.3.2
O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found
O18:64bit: - Protocol\\Handler\\ms-itss - No CLSID value found
O18:64bit: - Protocol\\Handler\\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\\Handler\\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\\Notify\\GoToAssist: DllName - (C:\\Program Files (x86)\\Citrix\\GoToAssist\\514\\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\\Notify\\LBTWlgn: DllName - (c:\\program files\\common files\\logishrd\\bluetooth\\LBTWlgn.dll) - c:\\Program Files\\Common Files\\Logishrd\\Bluetooth\\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\\Notify\\!SASWinLogon: DllName - (C:\\Program Files (x86)\\SUPERAntiSpyware\\SASWINLO.dll) - C:\\Program Files (x86)\\SUPERAntiSpyware\\SASWINLO.dll (SUPERAntiSpyware.com)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\\Program Files (x86)\\SUPERAntiSpyware\\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\\{d6ee6399-344d-11e0-bf24-463500000031}\\Shell\\AutoRun\\command - \"\" = J:\\autorun.exe
O33 - MountPoints2\\{d6ee6399-344d-11e0-bf24-463500000031}\\Shell\\phone\\command - \"\" = J:\\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*
O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*
O35 - HKLM\\..comfile [open] -- \"%1\" %*
O35 - HKLM\\..exefile [open] -- \"%1\" %*
O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*
O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/06/26 18:17:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Felicia\\Desktop\\OTL.exe
[2013/06/24 23:05:00 | 000,000,000 | ---D | C] -- C:\\Users\\Felicia\\Documents\\MyConnection Detail Analysis_files
[2013/06/24 22:55:01 | 000,000,000 | ---D | C] -- C:\\Users\\Felicia\\AppData\\Roaming\\Oracle
[2013/06/24 22:52:35 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Common Files\\Java
[2013/06/24 22:52:18 | 000,867,240 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\npDeployJava1.dll
[2013/06/24 22:52:17 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe
[2013/06/24 22:51:52 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe
[2013/06/24 22:51:52 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe
[2013/06/24 22:51:52 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll
[2013/06/24 22:51:23 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Java
[2013/06/24 22:50:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\McAfee
[2013/06/24 20:30:59 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Belarc
[2013/06/24 18:44:47 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WindowsCodecs.dll
[2013/06/24 12:10:24 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Google Chrome
[2013/06/24 11:55:00 | 000,000,000 | ---D | C] -- C:\\ProgramData\\SecTaskMan
[2013/06/24 11:54:56 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Security Task Manager
[2013/06/24 03:27:52 | 001,054,720 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\MsSpellCheckingFacility.exe
[2013/06/24 03:27:52 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\elshyph.dll
[2013/06/24 03:27:52 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\elshyph.dll
[2013/06/24 03:27:52 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\RegisterIEPKEYs.exe
[2013/06/24 03:27:51 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mshtmlmedia.dll
[2013/06/24 03:27:51 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\jscript.dll
[2013/06/24 03:27:51 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieui.dll
[2013/06/24 03:27:51 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\msrating.dll
[2013/06/24 03:27:51 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\iexpress.exe
[2013/06/24 03:27:51 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wextract.exe
[2013/06/24 03:27:51 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieUnatt.exe
[2013/06/24 03:27:51 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\occache.dll
[2013/06/24 03:27:51 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\iepeers.dll
[2013/06/24 03:27:51 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\IEAdvpack.dll
[2013/06/24 03:27:51 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\iesysprep.dll
[2013/06/24 03:27:51 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\inseng.dll
[2013/06/24 03:27:51 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mshtmled.dll
[2013/06/24 03:27:51 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\SetIEInstalledDate.exe
[2013/06/24 03:27:51 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\pngfilt.dll
[2013/06/24 03:27:51 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mshtmler.dll
[2013/06/24 03:27:51 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\msfeedssync.exe
[2013/06/24 03:27:50 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\inetcpl.cpl
[2013/06/24 03:27:50 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieapfltr.dat
[2013/06/24 03:27:50 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieapfltr.dat
[2013/06/24 03:27:50 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieapfltr.dll
[2013/06/24 03:27:50 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieapfltr.dll
[2013/06/24 03:27:50 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\dxtmsft.dll
[2013/06/24 03:27:50 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\html.iec
[2013/06/24 03:27:50 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\html.iec
[2013/06/24 03:27:50 | 000,281,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\dxtrans.dll
[2013/06/24 03:27:50 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\url.dll
[2013/06/24 03:27:50 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msls31.dll
[2013/06/24 03:27:50 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msrating.dll
[2013/06/24 03:27:50 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\RegisterIEPKEYs.exe
[2013/06/24 03:27:50 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\icardie.dll
[2013/06/24 03:27:50 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\icardie.dll
[2013/06/24 03:27:50 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\iesetup.dll
[2013/06/24 03:27:50 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tdc.ocx
[2013/06/24 03:27:50 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\iesetup.dll
[2013/06/24 03:27:50 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ie4uinit.exe
[2013/06/24 03:27:50 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\iernonce.dll
[2013/06/24 03:27:50 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\iernonce.dll
[2013/06/24 03:27:50 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\licmgr10.dll
[2013/06/24 03:27:49 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\jscript9.dll
[2013/06/24 03:27:49 | 001,509,376 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\inetcpl.cpl
[2013/06/24 03:27:49 | 000,905,728 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mshtmlmedia.dll
[2013/06/24 03:27:49 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\jscript.dll
[2013/06/24 03:27:49 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msfeeds.dll
[2013/06/24 03:27:49 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\vbscript.dll
[2013/06/24 03:27:49 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieui.dll
[2013/06/24 03:27:49 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\url.dll
[2013/06/24 03:27:49 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieUnatt.exe
[2013/06/24 03:27:49 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\iexpress.exe
[2013/06/24 03:27:49 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\occache.dll
[2013/06/24 03:27:49 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wextract.exe
[2013/06/24 03:27:49 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\iesysprep.dll
[2013/06/24 03:27:49 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\iepeers.dll
[2013/06/24 03:27:49 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\IEAdvpack.dll
[2013/06/24 03:27:49 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\inseng.dll
[2013/06/24 03:27:49 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mshtmled.dll
[2013/06/24 03:27:49 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\SetIEInstalledDate.exe
[2013/06/24 03:27:49 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tdc.ocx
[2013/06/24 03:27:49 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\pngfilt.dll
[2013/06/24 03:27:49 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\imgutil.dll
[2013/06/24 03:27:49 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mshtmler.dll
[2013/06/24 03:27:49 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\licmgr10.dll
[2013/06/24 03:27:49 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mshta.exe
[2013/06/24 03:27:49 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msfeedssync.exe
[2013/06/24 03:26:36 | 002,776,576 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msmpeg2vdec.dll
[2013/06/24 03:26:36 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\msmpeg2vdec.dll
[2013/06/24 03:26:36 | 001,682,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\XpsPrint.dll
[2013/06/24 03:26:36 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\XpsPrint.dll
[2013/06/24 03:26:36 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\XpsGdiConverter.dll
[2013/06/24 03:26:36 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WMPhoto.dll
[2013/06/24 03:26:36 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\WMPhoto.dll
[2013/06/24 03:26:36 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\XpsGdiConverter.dll
[2013/06/24 03:26:36 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/24 03:26:36 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/24 03:26:36 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/24 03:26:36 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/24 03:26:36 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/24 03:26:36 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/24 03:26:36 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/24 03:26:36 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/24 03:26:36 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/24 03:26:36 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/24 03:26:36 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/24 03:26:35 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d2d1.dll
[2013/06/24 03:26:35 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d3d10warp.dll
[2013/06/24 03:26:35 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\DWrite.dll
[2013/06/24 03:26:35 | 001,238,528 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d3d10.dll
[2013/06/24 03:26:35 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d3d10level9.dll
[2013/06/24 03:26:35 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\dxgi.dll
[2013/06/24 03:26:35 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d3d10_1core.dll
[2013/06/24 03:26:35 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d3d10core.dll
[2013/06/24 03:26:35 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\WindowsCodecsExt.dll
[2013/06/24 03:26:35 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\UIAnimation.dll
[2013/06/24 03:26:35 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\d3d10_1.dll
[2013/06/24 03:26:35 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\UIAnimation.dll
[2013/06/24 03:10:30 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysNative\\atmlib.dll
[2013/06/24 03:10:30 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\\Windows\\SysWow64\\atmlib.dll
[2013/06/24 03:10:29 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysNative\\atmfd.dll
[2013/06/24 03:10:29 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\\Windows\\SysWow64\\atmfd.dll
[2013/06/23 23:17:56 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\dxgmms1.sys
[2013/06/23 23:17:56 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\cdd.dll
[2013/06/23 23:17:41 | 003,717,632 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mstscax.dll
[2013/06/23 23:17:40 | 003,217,408 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mstscax.dll
[2013/06/23 23:17:39 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\aaclient.dll
[2013/06/23 23:17:39 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\aaclient.dll
[2013/06/23 23:17:39 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\tsgqec.dll
[2013/06/23 23:17:39 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\tsgqec.dll
[2013/06/23 23:17:28 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\FWPKCLNT.SYS
[2013/06/23 23:16:59 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\authui.dll
[2013/06/23 23:16:59 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\authui.dll
[2013/06/23 23:16:59 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\shdocvw.dll
[2013/06/23 23:16:59 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\consent.exe
[2013/06/23 23:16:44 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wwanprotdim.dll
[2013/06/23 23:16:41 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\usb8023.sys
[2013/06/23 23:15:53 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\dpnet.dll
[2013/06/23 23:15:52 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\dpnet.dll
[2013/06/23 23:15:51 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ncrypt.dll
[2013/06/23 23:15:49 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\winsrv.dll
[2013/06/23 23:15:48 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\setup16.exe
[2013/06/23 23:15:48 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ntvdm64.dll
[2013/06/23 23:15:48 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\instnm.exe
[2013/06/23 23:15:46 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\user.exe
[2013/06/23 23:15:42 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\usp10.dll
[2013/06/23 23:15:37 | 000,046,592 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\fpb.rs
[2013/06/23 23:15:37 | 000,046,592 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\fpb.rs
[2013/06/23 23:15:37 | 000,045,568 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\oflc-nz.rs
[2013/06/23 23:15:37 | 000,045,568 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\oflc-nz.rs
[2013/06/23 23:15:37 | 000,043,520 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\csrr.rs
[2013/06/23 23:15:37 | 000,043,520 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\csrr.rs
[2013/06/23 23:15:37 | 000,040,960 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\cob-au.rs
[2013/06/23 23:15:37 | 000,040,960 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\cob-au.rs
[2013/06/23 23:15:36 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\gameux.dll
[2013/06/23 23:15:36 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\gameux.dll
[2013/06/23 23:15:36 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\Wpc.dll
[2013/06/23 23:15:36 | 000,044,544 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\pegibbfc.rs
[2013/06/23 23:15:36 | 000,044,544 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\pegibbfc.rs
[2013/06/23 23:15:36 | 000,030,720 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\usk.rs
[2013/06/23 23:15:36 | 000,030,720 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\usk.rs
[2013/06/23 23:15:36 | 000,021,504 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\grb.rs
[2013/06/23 23:15:36 | 000,021,504 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\grb.rs
[2013/06/23 23:15:36 | 000,020,480 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\pegi-pt.rs
[2013/06/23 23:15:36 | 000,020,480 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\pegi-pt.rs
[2013/06/23 23:15:36 | 000,020,480 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\pegi.rs
[2013/06/23 23:15:36 | 000,020,480 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\pegi.rs
[2013/06/23 23:15:36 | 000,015,360 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\djctq.rs
[2013/06/23 23:15:36 | 000,015,360 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\djctq.rs
[2013/06/23 23:15:35 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\Wpc.dll
[2013/06/23 23:15:34 | 000,055,296 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\cero.rs
[2013/06/23 23:15:34 | 000,055,296 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\cero.rs
[2013/06/23 23:15:34 | 000,051,712 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\esrb.rs
[2013/06/23 23:15:34 | 000,051,712 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\esrb.rs
[2013/06/23 23:15:34 | 000,023,552 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\oflc.rs
[2013/06/23 23:15:34 | 000,023,552 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\oflc.rs
[2013/06/23 23:15:34 | 000,020,480 | ---- | C] (Microsoft) -- C:\\Windows\\SysWow64\\pegi-fi.rs
[2013/06/23 23:15:34 | 000,020,480 | ---- | C] (Microsoft) -- C:\\Windows\\SysNative\\pegi-fi.rs
[2013/06/23 23:15:00 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\KernelBase.dll
[2013/06/23 23:14:58 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\kernel32.dll
[2013/06/23 23:14:56 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64win.dll
[2013/06/23 23:14:56 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\conhost.exe
[2013/06/23 23:14:55 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64.dll
[2013/06/23 23:14:55 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ntvdm64.dll
[2013/06/23 23:14:55 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wow64cpu.dll
[2013/06/23 23:14:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-string-l1-1-0.dll
[2013/06/23 23:14:52 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-file-l1-1-0.dll
[2013/06/23 23:14:52 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-file-l1-1-0.dll
[2013/06/23 23:14:51 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-security-base-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-synch-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-synch-l1-1-0.dll
[2013/06/23 23:14:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-misc-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-misc-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-util-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-string-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-profile-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-profile-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/23 23:14:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/23 23:14:50 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-security-base-l1-1-0.dll
[2013/06/23 23:14:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/23 23:14:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-memory-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-memory-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-heap-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-heap-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-io-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-io-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-handle-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-handle-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-debug-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-debug-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/23 23:14:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/23 23:14:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/23 23:14:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-util-l1-1-0.dll
[2013/06/23 23:14:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/23 23:14:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-localization-l1-1-0.dll
[2013/06/23 23:14:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\api-ms-win-core-localization-l1-1-0.dll
[2013/06/23 23:14:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\api-ms-win-core-console-l1-1-0.dll