OTL logfile created on: 27/04/2013 0:34:27 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Julien\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16982) Locale: 0000080c | Country: Belgique | Language: FRB | Date Format: d/MM/yyyy 1022,69 Mb Total Physical Memory | 261,68 Mb Available Physical Memory | 25,59% Memory free 2,24 Gb Paging File | 1,43 Gb Available in Paging File | 63,83% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,88 Gb Total Space | 162,30 Gb Free Space | 69,69% Space Free | Partition Type: NTFS Computer Name: PCDEJULIEN | User Name: Julien | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013/04/26 21:30:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Julien\Desktop\OTL.exe PRC - [2013/04/26 00:21:09 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2013/02/05 17:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe PRC - [2013/01/18 16:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2013/01/18 16:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012/12/18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/08/30 16:31:37 | 000,045,056 | RHS- | M] () -- C:\Users\Julien\rioom.exe PRC - [2011/12/28 00:36:14 | 001,006,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2011/12/28 00:15:24 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011/04/20 18:58:02 | 001,204,224 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\ControlCenter4\BrCcUxSys.exe PRC - [2011/04/20 18:53:10 | 000,335,872 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\ControlCenter4\BrCtrlCntr.exe PRC - [2010/12/23 16:36:46 | 002,629,632 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Browny02\Brother\BrStMonW.exe PRC - [2010/03/05 21:11:30 | 000,636,192 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe PRC - [2010/01/25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Browny02\BrYNSvc.exe PRC - [2006/11/02 11:45:59 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013/04/26 00:21:08 | 003,121,048 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012/08/30 16:31:37 | 000,045,056 | RHS- | M] () -- C:\Users\Julien\rioom.exe MOD - [2009/02/27 17:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files\Brother\BrUtilities\BrLogAPI.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2013/04/26 00:21:08 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013/03/14 15:11:14 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/02/26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013/02/05 17:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService) SRV - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012/12/18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/11/09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2011/12/28 00:36:14 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2010/01/25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files\Browny02\BrYNSvc.exe -- (BrYNSvc) SRV - [2006/11/02 11:46:13 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2006/11/02 11:46:12 | 000,167,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2013/02/26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012/07/10 23:28:58 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbccid.sys -- (USBCCID) DRV - [2011/03/03 17:59:20 | 000,139,368 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA) DRV - [2009/11/03 05:06:12 | 000,011,520 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BrUsbSib.sys -- (BrUsbSIb) DRV - [2009/11/03 05:06:11 | 000,071,424 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BrSerIb.sys -- (BrSerIb) DRV - [2008/07/10 02:49:14 | 000,242,712 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\RsFx0102.sys -- (RsFx0102) DRV - [2006/12/19 14:29:36 | 000,020,736 | ---- | M] (USB Smart Card Reader) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\EMVSCARD.sys -- (EMVSCARD) DRV - [2006/11/02 10:57:06 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\irsir.sys -- (irsir) DRV - [2006/11/02 09:30:56 | 000,044,544 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2006/01/12 20:46:28 | 000,252,928 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rt73.sys -- (RT73) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=UP22DF&PC=UP22&dt=120812&q={searchTerms}&src=IE-SearchBox IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.3: "Bing " FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://fr.yahoo.com/" FF - prefs.js..extensions.enabledAddons: testpilot%40labs.mozilla.com:1.2.2 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\npctrl.1.0.30401.0.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/27 23:13:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Julien\AppData\Roaming\mozilla\Extensions [2013/04/15 19:14:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Julien\AppData\Roaming\mozilla\Firefox\Profiles\dbv297a9.default\extensions [2012/09/19 00:33:16 | 000,621,521 | ---- | M] () (No name found) -- C:\Users\Julien\AppData\Roaming\mozilla\firefox\profiles\dbv297a9.default\extensions\testpilot@labs.mozilla.com.xpi [2012/12/08 15:19:31 | 000,002,402 | ---- | M] () -- C:\Users\Julien\AppData\Roaming\mozilla\firefox\profiles\dbv297a9.default\searchplugins\bingp.xml [2013/04/26 00:21:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2013/04/26 00:21:02 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013/04/26 00:21:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions [2013/04/26 00:21:00 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2013/04/26 00:21:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\distribution\extensions [2013/04/26 00:21:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\distribution\extensions [2013/04/12 11:42:37 | 000,000,800 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\portaldosites.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://www.google.com/ CHR - homepage: http://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.95\PepperFlash\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.95\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.95\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: YouTube = C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Recherche Google = C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: Gmail = C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler File not found O4 - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000..\Run: [rioom] C:\Users\Julien\rioom.exe () O4 - HKU\S-1-5-21-4133778607-2017990771-4136200423-1000..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" File not found O4 - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler File not found O4 - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" File not found O4 - HKU\S-1-5-21-4133778607-2017990771-4136200423-1001..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Ouvrir avec PDF Viewer Plus - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation) O9 - Extra Button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 109.88.203.3 62.197.111.140 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C1230F98-C18E-4186-958F-D51ED1D3E8E5}: DhcpNameServer = 109.88.203.3 62.197.111.140 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{438d66b8-300c-11e1-9881-0022f7004f5c}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\xoAuSUf.eXE O33 - MountPoints2\{a8cdfeb1-4b5e-11e1-adb7-0022f7004f5c}\Shell - "" = AutoRun O33 - MountPoints2\{a8cdfeb1-4b5e-11e1-adb7-0022f7004f5c}\Shell\AutoRun\command - "" = I:\Startme.exe O33 - MountPoints2\{e708c4ed-0294-11e2-b551-0022f7004f5c}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\rioOm.Exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013/04/26 22:14:18 | 000,000,000 | ---D | C] -- C:\_OTL [2013/04/26 22:14:18 | 000,000,000 | ---D | C] -- \_OTL [2013/04/26 21:30:50 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Julien\Desktop\OTL.exe [2013/04/26 00:21:00 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013/04/18 21:39:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox.bak [2013/04/15 19:18:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2013/04/12 12:18:42 | 000,000,000 | ---D | C] -- C:\Users\Julien\AppData\Local\Temporary Projects [2013/04/12 12:15:41 | 000,000,000 | ---D | C] -- C:\Nouveau dossier [2013/04/12 12:15:41 | 000,000,000 | ---D | C] -- \Nouveau dossier [2013/04/12 12:09:09 | 000,050,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll [2013/04/12 12:08:54 | 000,079,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll [2013/04/12 12:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\RsFx [2013/04/12 12:04:58 | 000,000,000 | ---D | C] -- C:\Windows\System32\1033 [2013/04/12 12:03:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 [2013/04/12 11:54:25 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll [2013/04/12 11:54:25 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msimsg.dll [2013/04/12 11:53:23 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server [2013/04/12 11:53:18 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013/04/12 11:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services [2013/04/12 11:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition [2013/04/12 11:51:51 | 000,000,000 | ---D | C] -- C:\Users\Julien\Documents\Visual Studio 2008 [2013/04/12 11:49:10 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 9.0 [2013/04/12 11:48:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs [2013/04/12 11:42:50 | 000,773,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcr100.dll [2013/04/12 11:42:50 | 000,420,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp100.dll [2013/04/12 11:42:34 | 002,729,464 | ---- | C] (Microsoft Corporation) -- C:\Users\Julien\Desktop\vbsetup.exe [2013/04/02 22:49:35 | 000,000,000 | ---D | C] -- C:\Users\Julien\Desktop\Qbasic [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013/04/27 00:35:49 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [2013/04/27 00:31:35 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013/04/27 00:31:34 | 000,003,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013/04/27 00:31:34 | 000,003,952 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013/04/27 00:31:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/04/27 00:31:19 | 1073,012,736 | -HS- | M] () -- C:\hiberfil.sys [2013/04/27 00:11:24 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/04/26 23:29:25 | 000,000,991 | ---- | M] () -- C:\Users\Julien\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2013/04/26 23:29:25 | 000,000,870 | ---- | M] () -- C:\Users\Julien\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2013/04/26 23:29:25 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013/04/26 23:28:46 | 000,619,461 | ---- | M] () -- C:\Users\Julien\Desktop\adwcleaner.exe [2013/04/26 22:31:00 | 000,001,056 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013/04/26 21:30:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Julien\Desktop\OTL.exe [2013/04/26 00:52:40 | 000,018,109 | ---- | M] () -- C:\Users\Julien\Desktop\miche.jpg [2013/04/24 21:17:38 | 000,005,632 | ---- | M] () -- C:\Users\Julien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013/04/21 21:28:00 | 000,002,687 | ---- | M] () -- C:\Users\Julien\Desktop\Microsoft Office Word 2007.lnk [2013/04/15 20:49:23 | 000,755,906 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2013/04/15 20:49:23 | 000,675,256 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013/04/15 20:49:23 | 000,141,768 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2013/04/15 20:49:23 | 000,128,128 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013/04/12 11:42:44 | 000,773,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcr100.dll [2013/04/12 11:42:44 | 000,420,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcp100.dll [2013/04/12 11:42:36 | 002,729,464 | ---- | M] (Microsoft Corporation) -- C:\Users\Julien\Desktop\vbsetup.exe [2013/04/02 22:51:20 | 004,206,963 | ---- | M] () -- C:\Users\Julien\Desktop\Qbasic.zip [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/04/26 23:28:36 | 000,619,461 | ---- | C] () -- C:\Users\Julien\Desktop\adwcleaner.exe [2013/04/26 21:45:14 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin [2013/04/26 21:45:14 | 000,000,512 | ---- | C] () -- \PhysicalMBR.bin [2013/04/26 00:53:40 | 000,018,109 | ---- | C] () -- C:\Users\Julien\Desktop\miche.jpg [2013/04/12 11:51:33 | 000,001,264 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Basic 2008 Express Edition.lnk [2013/04/02 22:51:20 | 004,206,963 | ---- | C] () -- C:\Users\Julien\Desktop\Qbasic.zip [2012/12/05 23:45:22 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat [2012/08/30 16:31:37 | 000,045,056 | RHS- | C] () -- C:\Users\Julien\rioom.exe [2012/04/06 22:50:41 | 000,005,632 | ---- | C] () -- C:\Users\Julien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/02/09 21:55:55 | 000,000,820 | ---- | C] () -- C:\Windows\Brpfx04a.ini [2012/02/09 21:55:55 | 000,000,161 | ---- | C] () -- C:\Windows\brpcfx.ini [2012/02/09 21:53:13 | 000,000,066 | ---- | C] () -- C:\Windows\Brfaxrx.ini [2012/02/09 21:53:13 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat [2012/02/09 21:45:21 | 000,003,303 | ---- | C] () -- C:\Windows\BRPARAM.INI [2011/12/27 00:31:20 | 000,003,915 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [2011/12/27 00:31:18 | 000,005,824 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS [2011/12/26 23:55:13 | 1073,012,736 | -HS- | C] () -- \hiberfil.sys [2011/12/26 23:07:52 | 000,000,680 | ---- | C] () -- C:\Users\Julien\AppData\Local\d3d9caps.dat [2011/12/26 21:40:10 | 000,008,192 | R-S- | C] () -- \BOOTSECT.BAK [2011/12/26 21:40:09 | 000,438,840 | RHS- | C] () -- \bootmgr [2006/11/02 12:23:09 | 000,000,024 | ---- | C] () -- \autoexec.bat [2006/11/02 08:25:08 | 000,000,010 | ---- | C] () -- \config.sys [color=#E56717]========== ZeroAccess Check ==========[/color] [2006/11/02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2011/12/28 00:19:45 | 011,315,712 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2011/12/28 00:07:18 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2006/11/02 11:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2012/12/18 01:25:52 | 000,000,000 | ---D | M] -- C:\Users\Julien\AppData\Roaming\Argonyt [2012/02/09 22:16:58 | 000,000,000 | ---D | M] -- C:\Users\Julien\AppData\Roaming\ControlCenter4 [2012/02/09 21:38:40 | 000,000,000 | ---D | M] -- C:\Users\Julien\AppData\Roaming\Nuance [2012/12/19 01:33:45 | 000,000,000 | ---D | M] -- C:\Users\Julien\AppData\Roaming\PC-FAX TX [2012/12/14 21:31:52 | 000,000,000 | ---D | M] -- C:\Users\Julien\AppData\Roaming\PlayFirst [2012/12/16 11:08:21 | 000,000,000 | ---D | M] -- C:\Users\Julien\AppData\Roaming\SulusGames [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color] [2013/04/26 23:29:29 | 000,004,901 | ---- | M] () -- C:\AdwCleaner[S1].txt [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat [2006/11/02 11:53:57 | 000,438,840 | RHS- | M] () -- C:\bootmgr [2011/12/26 22:51:51 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK [2006/09/18 23:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys [2013/04/27 00:31:19 | 1073,012,736 | -HS- | M] () -- C:\hiberfil.sys [2013/04/27 00:31:18 | 1386,938,368 | -HS- | M] () -- C:\pagefile.sys [2013/04/27 00:35:49 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color] [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color] [2011/12/28 10:01:58 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini [color=#A23BEC]< %PROGRAMFILES%\*. >[/color] [2012/08/08 21:55:13 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe [2011/12/26 23:34:38 | 000,000,000 | ---D | M] -- C:\Program Files\ASUS [2012/11/16 21:18:08 | 000,000,000 | ---D | M] -- C:\Program Files\Avanquest [2012/01/10 19:23:25 | 000,000,000 | ---D | M] -- C:\Program Files\Avanquest update [2013/03/06 16:21:26 | 000,000,000 | ---D | M] -- C:\Program Files\AVS4YOU [2013/01/31 10:41:24 | 000,000,000 | ---D | M] -- C:\Program Files\BitZipper [2012/12/22 12:55:18 | 000,000,000 | ---D | M] -- C:\Program Files\BoontyGames [2012/02/09 21:53:11 | 000,000,000 | ---D | M] -- C:\Program Files\Brother [2012/02/09 21:53:37 | 000,000,000 | ---D | M] -- C:\Program Files\Browny02 [2013/04/26 23:29:20 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files [2012/02/09 21:53:34 | 000,000,000 | ---D | M] -- C:\Program Files\ControlCenter4 [2012/07/10 23:33:34 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX [2011/12/26 23:05:50 | 000,000,000 | -HSD | M] -- C:\Program Files\Fichiers communs [2012/08/24 23:25:15 | 000,000,000 | ---D | M] -- C:\Program Files\FR Office 2007 PRO [2013/03/03 12:20:54 | 000,000,000 | ---D | M] -- C:\Program Files\Google [2012/11/16 17:12:41 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information [2011/12/28 09:58:02 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer [2012/07/10 23:42:07 | 000,000,000 | ---D | M] -- C:\Program Files\Java [2013/02/14 00:11:43 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee Security Scan [2006/11/02 14:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games [2012/08/24 23:36:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office [2013/04/12 11:48:40 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SDKs [2013/04/12 11:53:18 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight [2013/04/12 12:07:29 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server [2013/04/12 11:53:06 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server Compact Edition [2013/04/12 11:53:06 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Synchronization Services [2012/08/24 23:36:07 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio [2012/08/24 23:32:53 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 8 [2013/04/12 11:53:13 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 9.0 [2012/08/24 23:36:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works [2013/04/12 12:04:28 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET [2011/12/28 09:57:51 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker [2013/04/26 00:21:10 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox [2013/04/26 21:02:07 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox.bak [2013/04/26 21:03:38 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Maintenance Service [2012/08/24 23:36:41 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild [2013/03/06 16:25:40 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache [2006/11/02 14:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\MSN [2012/02/09 21:35:02 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0 [2013/04/15 19:13:41 | 000,000,000 | ---D | M] -- C:\Program Files\Nuance [2013/04/15 18:55:48 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation [2012/07/10 23:43:48 | 000,000,000 | ---D | M] -- C:\Program Files\Oracle [2006/11/02 14:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies [2012/12/08 15:19:16 | 000,000,000 | R--D | M] -- C:\Program Files\Skype [2006/11/02 15:01:55 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information [2011/12/28 09:58:00 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Calendar [2006/11/02 14:42:32 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Collaboration [2011/12/28 09:57:53 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender [2006/11/02 14:42:32 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Journal [2011/12/28 11:23:13 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail [2011/12/27 22:48:19 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player [2011/12/26 23:05:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT [2006/11/02 14:42:32 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Photo Gallery [2011/12/28 09:57:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2008/01/19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys [2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows.old.000\Windows\System32\drivers\AGP440.sys [2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys [2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows.old\Windows\System32\drivers\AGP440.sys [2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys [2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys [2006/11/02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2008/01/19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys [2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows.old.000\Windows\System32\drivers\atapi.sys [2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows.old\Windows\System32\drivers\atapi.sys [2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [2006/11/02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [2011/12/28 00:16:33 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\drivers\atapi.sys [2011/12/28 00:16:33 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys [2011/12/28 00:16:33 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys [2011/12/28 00:16:33 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys [color=#A23BEC]< MD5 for: AUTOCHK.EXE >[/color] [2008/01/19 09:33:01 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe [2006/11/02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows.old.000\Windows\System32\autochk.exe [2006/11/02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe [2006/11/02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows.old\Windows\System32\autochk.exe [2006/11/02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe [2006/11/02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows\System32\autochk.exe [2006/11/02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe [color=#A23BEC]< MD5 for: BEEP.SYS >[/color] [2008/01/19 07:49:10 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=67E506B75BD5326A3EC7B70BD014DFB6 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.0.6001.18000_none_c420a153079d485b\beep.sys [2006/11/02 10:51:03 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=AC3DD1708B22761EBD7CBE14DCC3B5D7 -- C:\Windows.old.000\Windows\System32\drivers\beep.sys [2006/11/02 10:51:03 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=AC3DD1708B22761EBD7CBE14DCC3B5D7 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.0.6000.16386_none_c1e9df570ab23787\beep.sys [2006/11/02 10:51:03 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=AC3DD1708B22761EBD7CBE14DCC3B5D7 -- C:\Windows.old\Windows\System32\drivers\beep.sys [2006/11/02 10:51:03 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=AC3DD1708B22761EBD7CBE14DCC3B5D7 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.0.6000.16386_none_c1e9df570ab23787\beep.sys [2006/11/02 10:51:03 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=AC3DD1708B22761EBD7CBE14DCC3B5D7 -- C:\Windows\System32\drivers\beep.sys [2006/11/02 10:51:03 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=AC3DD1708B22761EBD7CBE14DCC3B5D7 -- C:\Windows\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.0.6000.16386_none_c1e9df570ab23787\beep.sys [color=#A23BEC]< MD5 for: CNGAUDIT.DLL >[/color] [2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows.old.000\Windows\System32\cngaudit.dll [2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll [2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows.old\Windows\System32\cngaudit.dll [2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll [2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll [2006/11/02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color] [2011/12/28 00:15:24 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\explorer.exe [2011/12/28 00:15:24 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe [2011/12/28 00:15:23 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe [2011/12/28 00:15:23 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe [2011/12/28 00:44:59 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe [2011/12/28 00:44:59 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe [2011/12/28 00:15:23 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe [2006/11/02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows.old.000\Windows\explorer.exe [2006/11/02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe [2006/11/02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows.old\Windows\explorer.exe [2006/11/02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe [2006/11/02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe [2008/01/19 09:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe [color=#A23BEC]< MD5 for: HIDSERV.DLL >[/color] [2006/11/02 11:46:05 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=8FA640195279ACE21BEA91396A0054FC -- C:\Windows.old.000\Windows\System32\hidserv.dll [2006/11/02 11:46:05 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=8FA640195279ACE21BEA91396A0054FC -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\hidserv.dll [2006/11/02 11:46:05 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=8FA640195279ACE21BEA91396A0054FC -- C:\Windows.old\Windows\System32\hidserv.dll [2006/11/02 11:46:05 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=8FA640195279ACE21BEA91396A0054FC -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\hidserv.dll [2006/11/02 11:46:05 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=8FA640195279ACE21BEA91396A0054FC -- C:\Windows\System32\hidserv.dll [2006/11/02 11:46:05 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=8FA640195279ACE21BEA91396A0054FC -- C:\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\hidserv.dll [color=#A23BEC]< MD5 for: IASTORV.SYS >[/color] [2008/01/19 09:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys [2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows.old.000\Windows\System32\drivers\iaStorV.sys [2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys [2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows.old\Windows\System32\drivers\iaStorV.sys [2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys [2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys [2006/11/02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys [color=#A23BEC]< MD5 for: IMM32.DLL >[/color] [2008/01/19 09:34:33 | 000,114,688 | ---- | M] (Microsoft Corporation) MD5=EC17194A193CD8E90D27CFB93DFA9A2E -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\imm32.dll [2006/11/02 11:46:05 | 000,115,200 | ---- | M] (Microsoft Corporation) MD5=EE12864398F1C3BF5BEE91F6AF9842E1 -- C:\Windows.old.000\Windows\System32\imm32.dll [2006/11/02 11:46:05 | 000,115,200 | ---- | M] (Microsoft Corporation) MD5=EE12864398F1C3BF5BEE91F6AF9842E1 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6000.16386_none_5a1f5c1a7d7fec2e\imm32.dll [2006/11/02 11:46:05 | 000,115,200 | ---- | M] (Microsoft Corporation) MD5=EE12864398F1C3BF5BEE91F6AF9842E1 -- C:\Windows.old\Windows\System32\imm32.dll [2006/11/02 11:46:05 | 000,115,200 | ---- | M] (Microsoft Corporation) MD5=EE12864398F1C3BF5BEE91F6AF9842E1 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6000.16386_none_5a1f5c1a7d7fec2e\imm32.dll [2006/11/02 11:46:05 | 000,115,200 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\imm32.dll [2006/11/02 11:46:05 | 000,115,200 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6000.16386_none_5a1f5c1a7d7fec2e\imm32.dll [color=#A23BEC]< MD5 for: KERNEL32.DLL >[/color] [2011/12/28 00:03:48 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=1987D817D08F5EAF0B7F334026FDDB79 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22376_none_9401d8206f9c7e67\kernel32.dll [2006/11/02 11:46:05 | 000,874,496 | ---- | M] (Microsoft Corporation) MD5=1E36AE445E4DA83B82D51FEB2D4F8772 -- C:\Windows.old.000\Windows\System32\kernel32.dll [2006/11/02 11:46:05 | 000,874,496 | ---- | M] (Microsoft Corporation) MD5=1E36AE445E4DA83B82D51FEB2D4F8772 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16386_none_91872345596077da\kernel32.dll [2006/11/02 11:46:05 | 000,874,496 | ---- | M] (Microsoft Corporation) MD5=1E36AE445E4DA83B82D51FEB2D4F8772 -- C:\Windows.old\Windows\System32\kernel32.dll [2006/11/02 11:46:05 | 000,874,496 | ---- | M] (Microsoft Corporation) MD5=1E36AE445E4DA83B82D51FEB2D4F8772 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16386_none_91872345596077da\kernel32.dll [2006/11/02 11:46:05 | 000,874,496 | ---- | M] (Microsoft Corporation) MD5=1E36AE445E4DA83B82D51FEB2D4F8772 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16386_none_91872345596077da\kernel32.dll [2011/12/28 00:03:50 | 000,875,520 | ---- | M] (Microsoft Corporation) MD5=BB792054BD990EC05D9E260D50FEAD39 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.21010_none_92564f68724ae108\kernel32.dll [2011/12/28 00:03:49 | 000,888,832 | ---- | M] (Microsoft Corporation) MD5=DB6E3731E6F5C8AE2843F80B5787F7C6 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_93b81a93564f1da0\kernel32.dll [2008/01/19 09:34:36 | 000,888,320 | ---- | M] (Microsoft Corporation) MD5=DC2338093F91BA4E0512208E60206DDD -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_93bde541564b88ae\kernel32.dll [2011/12/28 00:03:50 | 000,875,520 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\kernel32.dll [2011/12/28 00:03:50 | 000,875,520 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16820_none_91c20a8f593529ed\kernel32.dll [color=#A23BEC]< MD5 for: MSWSOCK.DLL >[/color] [2006/11/02 11:46:10 | 000,227,328 | ---- | M] (Microsoft Corporation) MD5=54E9576169A248AD62A1EB9773225826 -- C:\Windows.old.000\Windows\System32\mswsock.dll [2006/11/02 11:46:10 | 000,227,328 | ---- | M] (Microsoft Corporation) MD5=54E9576169A248AD62A1EB9773225826 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6000.16386_none_b61c950a3060adba\mswsock.dll [2006/11/02 11:46:10 | 000,227,328 | ---- | M] (Microsoft Corporation) MD5=54E9576169A248AD62A1EB9773225826 -- C:\Windows.old\Windows\System32\mswsock.dll [2006/11/02 11:46:10 | 000,227,328 | ---- | M] (Microsoft Corporation) MD5=54E9576169A248AD62A1EB9773225826 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6000.16386_none_b61c950a3060adba\mswsock.dll [2006/11/02 11:46:10 | 000,227,328 | ---- | M] (Microsoft Corporation) MD5=54E9576169A248AD62A1EB9773225826 -- C:\Windows\System32\mswsock.dll [2006/11/02 11:46:10 | 000,227,328 | ---- | M] (Microsoft Corporation) MD5=54E9576169A248AD62A1EB9773225826 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6000.16386_none_b61c950a3060adba\mswsock.dll [2008/01/19 09:35:15 | 000,223,232 | ---- | M] (Microsoft Corporation) MD5=89FD0595EEA4E505CABEFCF7008F2612 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6001.18000_none_b85357062d4bbe8e\mswsock.dll [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2006/11/02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows.old.000\Windows\System32\drivers\ndis.sys [2006/11/02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_a59069cb1f23fc44\ndis.sys [2006/11/02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows.old\Windows\System32\drivers\ndis.sys [2006/11/02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_a59069cb1f23fc44\ndis.sys [2006/11/02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows\System32\drivers\ndis.sys [2006/11/02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_a59069cb1f23fc44\ndis.sys [2008/01/19 09:43:31 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color] [2006/11/02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows.old.000\Windows\System32\netlogon.dll [2006/11/02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll [2006/11/02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows.old\Windows\System32\netlogon.dll [2006/11/02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll [2006/11/02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\System32\netlogon.dll [2006/11/02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll [2008/01/19 09:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll [color=#A23BEC]< MD5 for: NTFS.SYS >[/color] [2011/12/28 00:16:34 | 001,060,920 | ---- | M] (Microsoft Corporation) MD5=2620822A21B76375F5FD6E0986407CD1 -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16586_none_a43a6b8d2000830d\ntfs.sys [2011/12/28 00:31:38 | 001,060,920 | ---- | M] (Microsoft Corporation) MD5=37430AA7A66D7A63407ADC2C0D05E9F6 -- C:\Windows\System32\drivers\ntfs.sys [2011/12/28 00:31:38 | 001,060,920 | ---- | M] (Microsoft Corporation) MD5=37430AA7A66D7A63407ADC2C0D05E9F6 -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16615_none_a4851c9d1fc8a346\ntfs.sys [2006/11/02 11:51:47 | 001,056,360 | ---- | M] (Microsoft Corporation) MD5=3F379380A4A2637F559444E338CF1B51 -- C:\Windows.old.000\Windows\System32\drivers\ntfs.sys [2006/11/02 11:51:47 | 001,056,360 | ---- | M] (Microsoft Corporation) MD5=3F379380A4A2637F559444E338CF1B51 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16386_none_a43a67c1200088bf\ntfs.sys [2006/11/02 11:51:47 | 001,056,360 | ---- | M] (Microsoft Corporation) MD5=3F379380A4A2637F559444E338CF1B51 -- C:\Windows.old\Windows\System32\drivers\ntfs.sys [2006/11/02 11:51:47 | 001,056,360 | ---- | M] (Microsoft Corporation) MD5=3F379380A4A2637F559444E338CF1B51 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16386_none_a43a67c1200088bf\ntfs.sys [2006/11/02 11:51:47 | 001,056,360 | ---- | M] (Microsoft Corporation) MD5=3F379380A4A2637F559444E338CF1B51 -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16386_none_a43a67c1200088bf\ntfs.sys [2008/01/19 09:43:40 | 001,081,912 | ---- | M] (Microsoft Corporation) MD5=B4EFFE29EB4F15538FD8A9681108492D -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6001.18000_none_a67129bd1ceb9993\ntfs.sys [2011/12/28 00:16:34 | 001,061,432 | ---- | M] (Microsoft Corporation) MD5=B5BE45B1F554DF9E1976CBC855365E60 -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.20709_none_a51d8a7c38da8c7b\ntfs.sys [2011/12/28 00:31:37 | 001,061,944 | ---- | M] (Microsoft Corporation) MD5=F08824715CA6076F5E73E005AB83B9C8 -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.20740_none_a4e9483239031830\ntfs.sys [color=#A23BEC]< MD5 for: NTMSSVC.DLL >[/color] [2006/11/02 14:36:25 | 000,460,288 | ---- | M] (Microsoft Corporation) MD5=957CC0F372BB5D79C477363952276859 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-r..emanagement-service_31bf3856ad364e35_6.0.6000.16386_none_0c076ff411279f33\ntmssvc.dll [2006/11/02 14:36:25 | 000,460,288 | ---- | M] (Microsoft Corporation) MD5=957CC0F372BB5D79C477363952276859 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-r..emanagement-service_31bf3856ad364e35_6.0.6000.16386_none_0c076ff411279f33\ntmssvc.dll [2006/11/02 14:36:25 | 000,460,288 | ---- | M] (Microsoft Corporation) MD5=957CC0F372BB5D79C477363952276859 -- C:\Windows\winsxs\x86_microsoft-windows-r..emanagement-service_31bf3856ad364e35_6.0.6000.16386_none_0c076ff411279f33\ntmssvc.dll [2008/01/19 09:35:58 | 000,460,288 | ---- | M] (Microsoft Corporation) MD5=A7DFF9642D510BE1EEC6664CD0369953 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-r..emanagement-service_31bf3856ad364e35_6.0.6001.18000_none_0e3e31f00e12b007\ntmssvc.dll [color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color] [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows.old.000\Windows\System32\drivers\nvstor.sys [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows.old\Windows\System32\drivers\nvstor.sys [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2008/01/19 09:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys [color=#A23BEC]< MD5 for: PROQUOTA.EXE >[/color] [2006/11/02 11:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows.old.000\Windows\System32\proquota.exe [2006/11/02 11:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-proquota_31bf3856ad364e35_6.0.6000.16386_none_259035db957a1715\proquota.exe [2006/11/02 11:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows.old\Windows\System32\proquota.exe [2006/11/02 11:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-proquota_31bf3856ad364e35_6.0.6000.16386_none_259035db957a1715\proquota.exe [2006/11/02 11:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows\System32\proquota.exe [2006/11/02 11:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows\winsxs\x86_microsoft-windows-proquota_31bf3856ad364e35_6.0.6000.16386_none_259035db957a1715\proquota.exe [color=#A23BEC]< MD5 for: QMGR.DLL >[/color] [2008/01/19 09:36:13 | 000,758,272 | ---- | M] (Microsoft Corporation) MD5=02ED7B4DBC2A3232A389106DA7515C3D -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\qmgr.dll [2006/11/02 11:46:12 | 000,749,568 | ---- | M] (Microsoft Corporation) MD5=733FB484A06B9D6A44DD9CA1D3BE937B -- C:\Windows.old.000\Windows\System32\qmgr.dll [2006/11/02 11:46:12 | 000,749,568 | ---- | M] (Microsoft Corporation) MD5=733FB484A06B9D6A44DD9CA1D3BE937B -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16386_none_215a02f0fc86fab8\qmgr.dll [2006/11/02 11:46:12 | 000,749,568 | ---- | M] (Microsoft Corporation) MD5=733FB484A06B9D6A44DD9CA1D3BE937B -- C:\Windows.old\Windows\System32\qmgr.dll [2006/11/02 11:46:12 | 000,749,568 | ---- | M] (Microsoft Corporation) MD5=733FB484A06B9D6A44DD9CA1D3BE937B -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16386_none_215a02f0fc86fab8\qmgr.dll [2006/11/02 11:46:12 | 000,749,568 | ---- | M] (Microsoft Corporation) MD5=733FB484A06B9D6A44DD9CA1D3BE937B -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16386_none_215a02f0fc86fab8\qmgr.dll [2011/12/27 17:55:11 | 000,750,080 | ---- | M] (Microsoft Corporation) MD5=DA551697E34D2B9943C8B1C8EAFFE89A -- C:\Windows\System32\qmgr.dll [2011/12/27 17:55:11 | 000,750,080 | ---- | M] (Microsoft Corporation) MD5=DA551697E34D2B9943C8B1C8EAFFE89A -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16531_none_218b14e6fc62ea9e\qmgr.dll [2011/12/27 17:55:11 | 000,750,080 | ---- | M] (Microsoft Corporation) MD5=F1148566FA5173A4FD48AF8E8BC09401 -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.20647_none_220fe38215833e63\qmgr.dll [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color] [2008/01/19 09:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll [2006/11/02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows.old.000\Windows\System32\scecli.dll [2006/11/02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll [2006/11/02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows.old\Windows\System32\scecli.dll [2006/11/02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll [2006/11/02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\System32\scecli.dll [2006/11/02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll [color=#A23BEC]< MD5 for: SPOOLSV.EXE >[/color] [2008/01/19 09:33:32 | 000,125,952 | ---- | M] (Microsoft Corporation) MD5=846CDF9A3CF4DA9B306ADFB7D55EE4C2 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_d64ba321c188c516\spoolsv.exe [2006/11/02 11:45:46 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=DA612EF2556776DF2630B68BF2D48935 -- C:\Windows.old.000\Windows\System32\spoolsv.exe [2006/11/02 11:45:46 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=DA612EF2556776DF2630B68BF2D48935 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6000.16386_none_d414e125c49db442\spoolsv.exe [2006/11/02 11:45:46 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=DA612EF2556776DF2630B68BF2D48935 -- C:\Windows.old\Windows\System32\spoolsv.exe [2006/11/02 11:45:46 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=DA612EF2556776DF2630B68BF2D48935 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6000.16386_none_d414e125c49db442\spoolsv.exe [2006/11/02 11:45:46 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=DA612EF2556776DF2630B68BF2D48935 -- C:\Windows\System32\spoolsv.exe [2006/11/02 11:45:46 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=DA612EF2556776DF2630B68BF2D48935 -- C:\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6000.16386_none_d414e125c49db442\spoolsv.exe [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color] [2006/11/02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows.old.000\Windows\System32\svchost.exe [2006/11/02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe [2006/11/02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows.old\Windows\System32\svchost.exe [2006/11/02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe [2006/11/02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\System32\svchost.exe [2006/11/02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe [2008/01/19 09:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe [color=#A23BEC]< MD5 for: TERMSRV.DLL >[/color] [2008/01/19 09:36:39 | 000,448,512 | ---- | M] (Microsoft Corporation) MD5=D605031E225AACCBCEB5B76A4F1603A6 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6001.18000_none_8e9f41c854441762\termsrv.dll [2006/11/02 11:46:13 | 000,427,520 | ---- | M] (Microsoft Corporation) MD5=FAD71C1E8E4047B154E899AE31EB8CAA -- C:\Windows.old.000\Windows\System32\termsrv.dll [2006/11/02 11:46:13 | 000,427,520 | ---- | M] (Microsoft Corporation) MD5=FAD71C1E8E4047B154E899AE31EB8CAA -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6000.16386_none_8c687fcc5759068e\termsrv.dll [2006/11/02 11:46:13 | 000,427,520 | ---- | M] (Microsoft Corporation) MD5=FAD71C1E8E4047B154E899AE31EB8CAA -- C:\Windows.old\Windows\System32\termsrv.dll [2006/11/02 11:46:13 | 000,427,520 | ---- | M] (Microsoft Corporation) MD5=FAD71C1E8E4047B154E899AE31EB8CAA -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6000.16386_none_8c687fcc5759068e\termsrv.dll [2006/11/02 11:46:13 | 000,427,520 | ---- | M] (Microsoft Corporation) MD5=FAD71C1E8E4047B154E899AE31EB8CAA -- C:\Windows\System32\termsrv.dll [2006/11/02 11:46:13 | 000,427,520 | ---- | M] (Microsoft Corporation) MD5=FAD71C1E8E4047B154E899AE31EB8CAA -- C:\Windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6000.16386_none_8c687fcc5759068e\termsrv.dll [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color] [2008/01/19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe [2006/11/02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows.old.000\Windows\System32\userinit.exe [2006/11/02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe [2006/11/02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows.old\Windows\System32\userinit.exe [2006/11/02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe [2006/11/02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\System32\userinit.exe [2006/11/02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe [color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color] [2006/11/02 11:51:18 | 000,208,488 | ---- | M] (Microsoft Corporation) MD5=11EF6C1CAEF76B685233450A126125D6 -- C:\Windows.old.000\Windows\System32\drivers\volsnap.sys [2006/11/02 11:51:18 | 000,208,488 | ---- | M] (Microsoft Corporation) MD5=11EF6C1CAEF76B685233450A126125D6 -- C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\volume.inf_9320b452\volsnap.sys [2006/11/02 11:51:18 | 000,208,488 | ---- | M] (Microsoft Corporation) MD5=11EF6C1CAEF76B685233450A126125D6 -- C:\Windows.old\Windows\System32\drivers\volsnap.sys [2006/11/02 11:51:18 | 000,208,488 | ---- | M] (Microsoft Corporation) MD5=11EF6C1CAEF76B685233450A126125D6 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\volume.inf_9320b452\volsnap.sys [2006/11/02 11:51:18 | 000,208,488 | ---- | M] (Microsoft Corporation) MD5=11EF6C1CAEF76B685233450A126125D6 -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_9320b452\volsnap.sys [2011/12/28 00:16:32 | 000,211,000 | ---- | M] (Microsoft Corporation) MD5=327639D2EC931B057F3826A51ADC73E9 -- C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6000.20709_none_146318401803edb5\volsnap.sys [2011/12/28 00:16:32 | 000,211,000 | ---- | M] (Microsoft Corporation) MD5=80DC0C9BCB579ED9815001A4D37CBFD5 -- C:\Windows\System32\drivers\volsnap.sys [2011/12/28 00:16:32 | 000,211,000 | ---- | M] (Microsoft Corporation) MD5=80DC0C9BCB579ED9815001A4D37CBFD5 -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_f47b2c78\volsnap.sys [2011/12/28 00:16:32 | 000,211,000 | ---- | M] (Microsoft Corporation) MD5=80DC0C9BCB579ED9815001A4D37CBFD5 -- C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6000.16586_none_137ff950ff29e447\volsnap.sys [2008/01/19 09:42:48 | 000,227,896 | ---- | M] (Microsoft Corporation) MD5=D8B4A53DD2769F226B3EB374374987C9 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_volume.inf_31bf3856ad364e35_6.0.6001.18000_none_15b6b780fc14facd\volsnap.sys [color=#A23BEC]< MD5 for: WININET.DLL >[/color] [2006/11/02 11:46:14 | 000,822,272 | ---- | M] (Microsoft Corporation) MD5=214A456AADCC7DD1B36E2287BA71A9CA -- C:\Windows.old.000\Windows\System32\wininet.dll [2006/11/02 11:46:14 | 000,822,272 | ---- | M] (Microsoft Corporation) MD5=214A456AADCC7DD1B36E2287BA71A9CA -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16386_none_ffb23181a4e80112\wininet.dll [2006/11/02 11:46:14 | 000,822,272 | ---- | M] (Microsoft Corporation) MD5=214A456AADCC7DD1B36E2287BA71A9CA -- C:\Windows.old\Windows\System32\wininet.dll [2006/11/02 11:46:14 | 000,822,272 | ---- | M] (Microsoft Corporation) MD5=214A456AADCC7DD1B36E2287BA71A9CA -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16386_none_ffb23181a4e80112\wininet.dll [2006/11/02 11:46:14 | 000,822,272 | ---- | M] (Microsoft Corporation) MD5=214A456AADCC7DD1B36E2287BA71A9CA -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16386_none_ffb23181a4e80112\wininet.dll [2011/12/28 00:52:31 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=27DFDEA0533477C8923FC874F6439CF0 -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18385_none_01977b41a20f6796\wininet.dll [2008/01/19 09:36:55 | 000,825,856 | ---- | M] (Microsoft Corporation) MD5=455D715A840579BDC1CF8E5C1DA76849 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18000_none_01e8f37da1d311e6\wininet.dll [2011/12/28 00:52:31 | 000,834,048 | ---- | M] (Microsoft Corporation) MD5=4D36519B1212659127A4CFCC19E33049 -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22585_none_022119f2bb2d0487\wininet.dll [2011/12/28 00:52:33 | 000,834,048 | ---- | M] (Microsoft Corporation) MD5=565B8A25FB59E8E1F5ED59C95F72B7D7 -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18167_none_03958f7b9f23b4ad\wininet.dll [2011/12/28 00:52:50 | 000,841,216 | ---- | M] (Microsoft Corporation) MD5=6F837BD5085F73A8FF0425AA6705A8D1 -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21184_none_0039b13ebe07905a\wininet.dll [2011/12/28 00:52:50 | 000,832,512 | ---- | M] (Microsoft Corporation) MD5=C7A318E74FEF945EBFF855C1513CD96C -- C:\Windows\System32\wininet.dll [2011/12/28 00:52:50 | 000,832,512 | ---- | M] (Microsoft Corporation) MD5=C7A318E74FEF945EBFF855C1513CD96C -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16982_none_ffae3bbda4eb8aa0\wininet.dll [2011/12/28 00:52:33 | 000,834,048 | ---- | M] (Microsoft Corporation) MD5=C86BBCF0DA44F2B36C9AA59032916EF0 -- C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22290_none_03f7ba7cb85ff6e9\wininet.dll [color=#A23BEC]< MD5 for: WININIT.EXE >[/color] [2008/01/19 09:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe [2006/11/02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows.old.000\Windows\System32\wininit.exe [2006/11/02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe [2006/11/02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows.old\Windows\System32\wininit.exe [2006/11/02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe [2006/11/02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\System32\wininit.exe [2006/11/02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old.000\Windows\System32\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old.000\Windows\System32\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old\Windows\System32\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old\Windows\System32\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\System32\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\System32\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2006/11/02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2008/01/19 09:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe [2008/01/19 09:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe [color=#A23BEC]< MD5 for: WS2_32.DLL >[/color] [2008/01/19 09:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll [2006/11/02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=D99A071C1018BB3D4ABAAD4B62048AC2 -- C:\Windows.old.000\Windows\System32\ws2_32.dll [2006/11/02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=D99A071C1018BB3D4ABAAD4B62048AC2 -- C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6000.16386_none_f080eec6d16af4f0\ws2_32.dll [2006/11/02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=D99A071C1018BB3D4ABAAD4B62048AC2 -- C:\Windows.old\Windows\System32\ws2_32.dll [2006/11/02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=D99A071C1018BB3D4ABAAD4B62048AC2 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6000.16386_none_f080eec6d16af4f0\ws2_32.dll [2006/11/02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\ws2_32.dll [2006/11/02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6000.16386_none_f080eec6d16af4f0\ws2_32.dll [color=#A23BEC]< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s >[/color] "Debug" = "" = mnmsrvc "Kmode" = \SystemRoot\System32\win32k.sys "Optional" = Posix [binary data] "Posix" = %SystemRoot%\system32\psxss.exe "Required" = DebugWindows [binary data] "Windows" = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\CSRSS] "CsrSrvSharedSectionBase" = 2137980928 [color=#A23BEC]< %systemroot%\*. /mp /s >[/color] [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] [2011/12/28 00:52:49 | 000,347,136 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\dxtmsft.dll [2011/12/28 00:52:49 | 000,214,528 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\dxtrans.dll [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color] [2006/11/02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV [2006/11/02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV [2006/11/02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV [2006/11/02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV [2006/11/02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV [color=#A23BEC]< c:\$recycle.bin\*.* /s >[/color] [2006/11/02 15:04:17 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500\desktop.ini [2012/04/20 13:55:36 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I0J25CR.lnk [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I0YBY84.mp3 [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I13APH1.jpg [2013/01/06 13:21:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I15ZKDA.docx [2012/12/01 18:00:37 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I1Q8IEC.rbs [2012/10/17 18:54:34 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I24IPFL.pptx [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I2A3YPN.jpg [2012/11/25 21:22:09 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I2BUCLB.asd [2013/02/18 13:27:06 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I2R42V0.pptx [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I2R63GI.jpg [2012/04/19 22:14:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I3BFIWV.jpg [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I3OVB4O.jpg [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I3XV4UD.jpg [2013/04/02 22:55:30 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I3ZIAST [2012/09/23 19:25:26 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I4DSZ40 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I4JWEM3.mp3 [2012/05/02 21:32:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I4RCB2H.wma [2012/10/08 19:18:15 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I53SXJB.doc [2012/12/07 18:28:48 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I53UF9C.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I5FKLDQ.mp3 [2012/11/16 17:16:52 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I5IAGMN.pptx [2012/12/01 18:21:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I5IAY7H.rbs [2012/04/20 14:22:45 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I5SXCZL.htm [2012/10/07 18:00:41 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I659J7T.mp3 [2012/12/05 22:40:14 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I6FC7UM.pdf [2012/02/09 22:40:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I6FOZQK.jpg [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I78CAGJ.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I7EH5SY.mp3 [2012/10/07 18:00:41 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I7EUINT.mp3 [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I7SYKIE.mp3 [2012/05/02 21:41:24 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I7YEWLF.mp3 [2013/01/21 22:13:17 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I812HH3.zip [2013/03/14 20:53:44 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I8GOR8M [2012/05/02 21:14:19 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I8HNNYC.mp3 [2012/12/01 18:03:35 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I8IJ6IV.mp3 [2012/12/18 01:03:53 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I8LXJG9.exe [2012/12/27 23:01:32 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I8LYDWH.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I9A0AK0.mp3 [2012/12/27 23:01:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I9GC214.pdf [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I9OWNLS.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$I9PN8LU.mp3 [2012/01/12 15:03:10 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IAO2VY1.jpg [2012/12/07 18:28:45 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IATOMHH.jpg [2012/04/19 22:14:30 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IAVCOAR.jpg [2012/12/24 18:19:48 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IB1Z7W8 [2013/01/31 14:45:17 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IBAHE4Q [2012/11/21 20:29:07 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IBMDKOA.jpg [2012/10/07 16:18:24 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IC2QWHT.jpg [2012/10/07 16:26:24 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IC8YZAQ.rbs [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ICGZVE8.jpg [2012/05/02 21:41:40 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ICVAY6I.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ICVCMIA.mp3 [2012/09/29 23:20:40 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ICVI5F7.docx [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ID5GRT4.mp3 [2012/12/01 18:21:36 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IDCLOZD.mp3 [2012/01/14 17:20:58 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IDLLMBG.html [2012/09/03 12:09:26 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IDOY2VH.lnk [2012/02/09 22:41:56 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IED1CU0.jpg [2013/01/21 22:13:17 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IEEMI3D [2012/02/09 22:40:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IEXWGLW.jpg [2012/05/02 21:33:57 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IFGYEEN.mp3 [2012/10/07 16:53:38 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IFKMII7.rbs [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IGD5CB5.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IGDW9GS.mp3 [2012/12/16 12:28:44 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IGOHD3B.exe [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IHAG9PK.jpg [2013/04/12 11:21:47 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IHJ858G.nt [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IIGL5JG.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IIL7346.rbs [2012/10/07 16:29:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IITB3CW.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IIV63VC.mp3 [2012/05/02 21:20:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IIWLUSE.mp3 [2012/12/27 23:01:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IJG6CR4.pdf [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IK56J4R.mp3 [2012/05/02 21:13:04 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IKDO7AY.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IKNTSBO.mp3 [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IL3RKGF.jpg [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IL5AECH.jpg [2012/09/23 19:25:18 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ILEXGOP [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ILJXPFD.mp3 [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ILM3EAD.jpg [2012/05/02 21:45:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ILOW8BB.mp3 [2012/05/02 21:45:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMBFAWM.mp3 [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMCPD7I.jpg [2012/11/21 20:27:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMGMLD7.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMID8WE.mp3 [2012/12/01 18:21:26 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMTNO00.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMUDA9D.mp3 [2013/02/18 13:34:53 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IMX6NQ4.pptx [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IN9ZI1W.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$INU6HSD.mp3 [2012/11/21 19:56:28 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$INVB4CO.jpg [2012/11/18 18:20:59 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IO92AJJ.doc [2012/10/31 19:58:44 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IOBSS48.jpg [2012/11/16 16:57:23 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IOEZTSP.xps [2012/11/20 00:35:26 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IOG043W.htm [2012/10/31 19:58:37 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IORLO7R.jpg [2013/04/02 22:55:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IOVSEZ3 [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IOYD5Y9.jpg [2012/05/02 21:45:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IP56NAU.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IPGB24W.mp3 [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IPGY7RA.jpg [2012/11/25 21:22:09 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IPWEH7L.asd [2013/02/10 22:27:18 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQ5FAJF.doc [2013/02/25 15:38:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQ623HL.jpg [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQ7XKHC.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQFI5BG.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQH450G.mp3 [2012/12/27 23:01:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQJJ9AY.jpg [2012/12/16 12:31:59 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQKG7ZD.lnk [2013/04/26 22:20:29 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IQPA4FB.Txt [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IR127Q7.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IR64246.mp3 [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRAWD3T.jpg [2012/12/16 12:31:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRBO6EL.lnk [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRLVCWN.mp3 [2012/05/02 21:45:23 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRT2JZY.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRU5ZRM.mp3 [2012/02/09 22:40:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRVHNE6.jpg [2012/01/22 21:49:15 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IRXBZ05.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IS4EJMQ.mp3 [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ISBM8T9.jpg [2013/01/20 12:32:40 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ISELZMO [2013/02/15 19:54:26 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ISSOG26.txt [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IT2NFKA.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ITLX6DK.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ITN0ON3.mp3 [2012/09/02 17:56:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IU2OT4H.pdf [2013/04/12 16:54:19 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IUCWO0I.EXE [2013/02/10 22:27:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IUIRUFH.doc [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IUJ2SFJ.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IULX7IO.mp3 [2013/04/26 22:20:29 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IUSI49U.Txt [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IUTELCC.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IUVP3J5.mp3 [2012/02/09 22:40:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IV17SHA.jpg [2012/10/08 19:18:15 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IV3SJ07.doc [2013/01/05 13:55:33 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IVUB4R4.doc [2012/12/01 18:24:10 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IVVQAFX.mp3 [2013/02/10 22:27:33 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IVX3KML.doc [2013/01/31 14:45:17 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IW2B0JM [2012/01/14 17:20:58 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IWEF7O9.htm [2013/02/10 22:27:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IWEXNBN.doc [2013/04/01 16:03:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IWG5LEJ.pptx [2012/12/07 18:28:45 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IWGG4EX.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IWMO15N.mp3 [2012/12/27 23:01:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IX37BC2.jpg [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IXDNOZB.mp3 [2013/04/12 11:26:15 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IXF820M.pif [2012/12/27 23:04:53 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IXIGQ25 [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IXRSOF6.mp3 [2012/05/02 21:44:20 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IYOAIV9.mp3 [2012/09/02 17:22:17 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IYQ73A4.docx [2012/01/14 17:20:58 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IYT7U6W [2012/03/07 10:57:12 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IYXYPMF.jpg [2012/10/07 16:24:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IYY3PCD.rbs [2013/01/20 12:32:39 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZ27NN8.zip [2012/12/01 18:04:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZAZANW.mp3 [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZHA4D7.mp3 [2012/12/27 23:01:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZHODG6.pdf [2012/04/16 23:53:22 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZJZQ5Q.jpg [2012/10/07 18:00:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZKBDOW.mp3 [2013/04/01 15:51:50 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZKD458 [2013/01/06 13:21:14 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$IZMOI8G.doc [2012/04/20 13:52:38 | 000,000,659 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R0J25CR.lnk [2012/05/02 21:35:38 | 006,570,409 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R0YBY84.mp3 [2012/04/16 23:45:49 | 001,733,043 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R13APH1.jpg [2012/11/04 19:49:22 | 000,016,261 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R15ZKDA.docx [2012/12/01 18:00:27 | 001,476,439 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R1Q8IEC.rbs [2012/10/17 18:54:07 | 000,218,857 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R24IPFL.pptx [2012/04/16 23:45:48 | 002,558,942 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R2A3YPN.jpg [2012/11/25 21:11:30 | 000,029,184 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R2BUCLB.asd [2013/02/18 11:23:38 | 000,559,117 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R2R42V0.pptx [2012/03/07 10:53:16 | 000,654,456 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R2R63GI.jpg [2012/04/19 22:14:03 | 000,836,659 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R3BFIWV.jpg [2012/03/07 10:53:17 | 000,662,470 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R3OVB4O.jpg [2012/03/07 10:53:16 | 000,445,228 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R3XV4UD.jpg [2012/05/02 21:37:10 | 004,046,558 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R4JWEM3.mp3 [2012/05/02 21:31:33 | 000,000,297 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R4RCB2H.wma [2012/10/07 17:43:00 | 000,034,816 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R53SXJB.doc [2012/12/05 22:43:42 | 000,039,451 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R53UF9C.jpg [2012/05/02 21:13:58 | 004,478,294 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R5FKLDQ.mp3 [2012/11/16 17:10:05 | 000,934,640 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R5IAGMN.pptx [2012/12/01 18:06:09 | 000,898,926 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R5IAY7H.rbs [2012/04/20 14:00:22 | 000,035,274 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R5SXCZL.htm [2012/10/07 16:52:29 | 001,752,090 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R659J7T.mp3 [2012/11/24 13:27:33 | 000,041,805 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R6FC7UM.pdf [2012/02/09 22:37:07 | 000,662,936 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R6FOZQK.jpg [2012/03/07 10:53:16 | 000,745,186 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R78CAGJ.jpg [2012/05/02 21:36:10 | 004,178,672 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R7EH5SY.mp3 [2012/10/07 16:51:05 | 002,394,112 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R7EUINT.mp3 [2012/10/07 17:06:20 | 003,831,936 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R7SYKIE.mp3 [2012/05/02 21:37:35 | 003,966,976 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R7YEWLF.mp3 [2013/01/20 13:04:05 | 002,702,340 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R812HH3.zip [2012/05/02 21:03:22 | 004,478,294 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R8HNNYC.mp3 [2012/12/01 18:01:30 | 002,962,553 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R8IJ6IV.mp3 [2012/12/18 01:01:20 | 000,235,080 | ---- | M] (Big Fish Games) -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R8LXJG9.exe [2012/11/29 23:15:09 | 000,508,499 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R8LYDWH.jpg [2012/05/02 21:03:49 | 003,713,484 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R9A0AK0.mp3 [2012/11/15 09:32:41 | 000,071,107 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R9GC214.pdf [2012/10/07 16:52:17 | 004,852,789 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R9OWNLS.mp3 [2012/05/02 21:16:42 | 004,368,547 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R9PN8LU.mp3 [2012/01/12 14:44:58 | 000,084,024 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RAO2VY1.jpg [2012/12/05 22:44:11 | 000,001,878 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RATOMHH.jpg [2012/04/19 22:14:03 | 001,191,858 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RAVCOAR.jpg [2012/11/21 20:28:22 | 000,655,617 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RBMDKOA.jpg [2012/02/19 19:15:32 | 000,102,918 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RC2QWHT.jpg [2012/10/07 16:25:59 | 001,453,452 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RC8YZAQ.rbs [2012/03/07 10:53:16 | 000,780,158 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RCGZVE8.jpg [2012/05/02 21:40:09 | 002,666,289 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RCVAY6I.mp3 [2012/05/02 21:28:53 | 003,778,688 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RCVCMIA.mp3 [2012/09/29 23:18:28 | 000,198,941 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RCVI5F7.docx [2012/05/02 21:01:04 | 007,031,220 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RD5GRT4.mp3 [2012/12/01 18:07:05 | 001,780,297 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RDCLOZD.mp3 [2012/01/14 17:03:56 | 000,000,122 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RDLLMBG.html [2012/08/08 21:56:23 | 000,001,892 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RDOY2VH.lnk [2012/02/09 22:41:43 | 000,102,956 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RED1CU0.jpg [2012/02/09 22:37:07 | 000,734,911 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$REXWGLW.jpg [2012/05/02 21:33:43 | 001,704,411 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RFGYEEN.mp3 [2012/10/07 16:51:43 | 002,432,671 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RFKMII7.rbs [2012/10/07 16:51:30 | 002,955,887 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RGD5CB5.mp3 [2012/05/02 21:38:03 | 003,208,291 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RGDW9GS.mp3 [2012/12/16 12:27:25 | 000,235,080 | ---- | M] (Big Fish Games) -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RGOHD3B.exe [2012/03/07 10:53:15 | 000,607,699 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RHAG9PK.jpg [2006/09/18 23:43:36 | 000,001,688 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RHJ858G.nt [2012/03/07 10:53:13 | 000,712,462 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RIGL5JG.jpg [2012/05/02 21:20:21 | 000,607,190 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RIL7346.rbs [2012/10/07 16:23:59 | 001,538,088 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RITB3CW.mp3 [2012/05/02 21:40:39 | 001,856,566 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RIV63VC.mp3 [2012/05/02 21:18:52 | 001,704,411 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RIWLUSE.mp3 [2012/11/25 19:32:21 | 000,147,856 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RJG6CR4.pdf [2012/05/02 21:31:13 | 001,065,511 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RK56J4R.mp3 [2012/05/02 21:02:53 | 009,051,327 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RKDO7AY.mp3 [2012/05/02 21:00:12 | 001,969,177 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RKNTSBO.mp3 [2012/04/16 23:45:50 | 001,728,331 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RL3RKGF.jpg [2012/03/07 10:53:14 | 000,744,567 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RL5AECH.jpg [2012/05/02 20:59:49 | 002,356,363 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RLJXPFD.mp3 [2012/03/07 10:53:15 | 000,788,322 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RLM3EAD.jpg [2012/05/02 21:36:36 | 002,638,000 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RLOW8BB.mp3 [2012/04/20 14:22:45 | 007,057,201 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMBFAWM.mp3 [2012/04/16 23:45:50 | 001,916,377 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMCPD7I.jpg [2012/11/21 19:47:22 | 000,656,910 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMGMLD7.jpg [2012/05/02 21:29:52 | 003,449,743 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMID8WE.mp3 [2012/12/01 18:07:04 | 006,862,959 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMTNO00.mp3 [2012/05/02 21:36:56 | 005,015,552 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMUDA9D.mp3 [2013/02/18 13:30:51 | 000,559,117 | R--- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RMX6NQ4.pptx [2012/10/07 16:55:07 | 005,276,152 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RN9ZI1W.mp3 [2012/05/02 21:37:59 | 005,211,116 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RNU6HSD.mp3 [2012/11/21 19:47:22 | 000,656,910 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RNVB4CO.jpg [2012/08/29 16:16:42 | 000,124,416 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RO92AJJ.doc [2012/10/31 19:35:36 | 000,543,371 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ROBSS48.jpg [2012/11/16 16:56:21 | 001,623,381 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ROEZTSP.xps [2012/11/20 00:35:12 | 000,003,258 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ROG043W.htm [2012/10/31 19:35:36 | 000,428,970 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RORLO7R.jpg [2012/04/16 23:45:50 | 001,904,299 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ROYD5Y9.jpg [2012/05/02 21:10:24 | 005,720,853 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RP56NAU.mp3 [2012/05/02 21:17:01 | 003,535,482 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RPGB24W.mp3 [2012/03/07 10:53:14 | 000,439,623 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RPGY7RA.jpg [2012/11/25 21:19:54 | 000,030,208 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RPWEH7L.asd [2013/01/05 13:55:16 | 007,229,952 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQ5FAJF.doc [2013/02/25 15:34:58 | 000,728,559 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQ623HL.jpg [2012/03/07 10:53:17 | 000,496,813 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQ7XKHC.jpg [2012/05/02 21:17:35 | 001,188,916 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQFI5BG.mp3 [2012/05/02 21:21:26 | 002,838,656 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQH450G.mp3 [2012/11/29 23:15:10 | 000,286,352 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQJJ9AY.jpg [2012/12/16 12:28:40 | 000,001,564 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQKG7ZD.lnk [2013/04/26 22:00:50 | 000,145,404 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RQPA4FB.Txt [2012/10/07 16:51:37 | 001,941,007 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RR127Q7.mp3 [2012/05/02 21:16:23 | 003,271,750 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RR64246.mp3 [2012/03/07 10:53:13 | 000,441,350 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRAWD3T.jpg [2012/12/16 12:28:40 | 000,001,794 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRBO6EL.lnk [2012/04/20 13:58:35 | 003,510,911 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRLVCWN.mp3 [2012/05/02 21:01:53 | 000,910,262 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRT2JZY.mp3 [2012/04/20 14:02:31 | 003,525,980 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRU5ZRM.mp3 [2012/02/09 22:37:07 | 000,774,224 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRVHNE6.jpg [2012/01/22 21:38:07 | 003,325,022 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RRXBZ05.mp3 [2012/05/02 21:36:21 | 003,533,426 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RS4EJMQ.mp3 [2012/04/16 23:45:48 | 001,114,236 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RSBM8T9.jpg [2011/09/17 17:52:44 | 000,001,453 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RSSOG26.txt [2012/03/07 10:53:15 | 000,438,326 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RT2NFKA.jpg [2012/04/20 14:07:19 | 004,519,924 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RTLX6DK.mp3 [2012/05/02 21:17:24 | 002,395,615 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RTN0ON3.mp3 [2012/09/02 17:33:33 | 000,070,903 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RU2OT4H.pdf [2013/04/12 16:24:26 | 000,195,278 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RUCWO0I.EXE [2013/01/06 16:07:11 | 000,029,696 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RUIRUFH.doc [2012/04/16 23:45:48 | 002,800,615 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RUJ2SFJ.jpg [2012/05/02 21:00:35 | 002,930,258 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RULX7IO.mp3 [2013/04/26 22:03:18 | 000,037,392 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RUSI49U.Txt [2012/03/07 10:53:14 | 000,606,315 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RUTELCC.jpg [2012/05/02 21:35:55 | 009,000,920 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RUVP3J5.mp3 [2012/02/09 22:37:06 | 000,816,789 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RV17SHA.jpg [2012/10/07 16:14:39 | 000,031,744 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RV3SJ07.doc [2013/01/05 13:51:06 | 007,076,864 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RVUB4R4.doc [2012/12/01 18:23:52 | 003,642,062 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RVVQAFX.mp3 [2012/12/16 22:28:33 | 000,026,624 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RVX3KML.doc [2012/01/14 17:01:41 | 000,008,235 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RWEF7O9.htm [2013/01/06 13:59:30 | 000,031,744 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RWEXNBN.doc [2013/02/18 13:39:48 | 000,559,117 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RWG5LEJ.pptx [2012/12/05 22:44:03 | 000,045,751 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RWGG4EX.jpg [2012/05/02 21:29:35 | 002,569,741 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RWMO15N.mp3 [2012/11/29 23:15:10 | 000,297,137 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RX37BC2.jpg [2012/05/02 21:30:57 | 003,103,152 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RXDNOZB.mp3 [2013/04/12 11:25:57 | 000,002,855 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RXF820M.pif [2012/10/07 16:27:14 | 003,933,871 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RXRSOF6.mp3 [2012/05/02 21:16:03 | 004,040,998 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYOAIV9.mp3 [2012/08/29 20:24:51 | 000,116,004 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYQ73A4.docx [2012/03/07 10:53:17 | 000,528,202 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYXYPMF.jpg [2012/10/07 16:23:41 | 001,672,671 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYY3PCD.rbs [2013/01/19 14:59:41 | 013,590,590 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZ27NN8.zip [2012/12/01 18:00:45 | 000,006,174 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZAZANW.mp3 [2012/10/07 16:51:55 | 003,707,711 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZHA4D7.mp3 [2012/11/29 09:30:17 | 000,094,801 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZHODG6.pdf [2012/04/16 23:45:49 | 001,260,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZJZQ5Q.jpg [2012/10/07 16:55:30 | 005,871,744 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZKBDOW.mp3 [2012/10/08 19:18:54 | 000,034,304 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZMOI8G.doc [2011/12/26 23:08:07 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\desktop.ini [2012/11/13 12:38:24 | 000,452,499 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$R3ZIAST\exam_1.docx [2012/12/02 12:27:38 | 001,498,935 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RB1Z7W8\AWRO Newsletter 2012.pdf [2012/12/02 15:13:48 | 000,025,439 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RB1Z7W8\Newsletter_Feedback_Form_Rev.docx [2012/12/02 13:56:35 | 000,098,304 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RB1Z7W8\traduction.doc [2012/11/13 13:21:42 | 000,000,162 | -H-- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RBAHE4Q\~$exam_1.docx [2012/05/07 12:16:52 | 001,036,290 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$REEMI3D\INTERFACES SF sizing & deployment Lodish.pdf [2012/12/18 22:18:22 | 000,018,407 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$REEMI3D\SYNTEX Input data.xlsx [2012/10/04 12:20:44 | 001,965,849 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$REEMI3D\SYNTEX Labs CASE (Marketing Engineering).pdf [2012/11/13 12:21:42 | 000,000,162 | -H-- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$ROVSEZ3\~$exam_1.docx [2012/12/05 19:09:54 | 003,871,965 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RSELZMO\Différenciation stratégique Article RfG.pdf [2012/12/05 19:10:40 | 001,001,241 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RSELZMO\INTERFACES SF sizing & deployment Lodish.pdf [2012/12/05 19:09:10 | 008,021,694 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RSELZMO\Strategic change (Moroney Attraction Models) Censored(1).pdf [2012/12/05 19:10:52 | 001,969,442 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RSELZMO\SYNTEX Labs CASE (Marketing Engineering).pdf [2012/11/13 16:52:09 | 000,000,162 | -H-- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RW2B0JM\~$exam_4.docx [2012/01/14 17:00:18 | 000,003,686 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\2012-01-14T103852Z_1_APAE80D0TKX00_RTROPTP_2_OFRTP-FRANCE-DE.JPG [2012/01/14 17:00:18 | 000,000,108 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\a.htm [2012/01/14 17:00:18 | 000,000,108 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\a_002.htm [2012/01/14 17:00:18 | 000,003,896 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\blank.htm [2012/01/14 17:00:18 | 000,041,984 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo [2012/01/14 17:00:18 | 000,086,204 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo.css [2012/01/14 17:00:18 | 000,246,628 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo.js [2012/01/14 17:00:18 | 000,063,858 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_002 [2012/01/14 17:00:18 | 000,019,992 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_002.css [2012/01/14 17:00:18 | 000,030,602 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_002.js [2012/01/14 17:00:18 | 000,031,662 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_003.css [2012/01/14 17:00:18 | 000,005,863 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_003.js [2012/01/14 17:00:18 | 000,011,545 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_004.js [2012/01/14 17:00:18 | 000,488,621 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_005.js [2012/01/14 17:00:18 | 000,164,239 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_006.js [2012/01/14 17:00:18 | 000,056,249 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_007.js [2012/01/14 17:00:18 | 000,002,594 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_008.js [2012/01/14 17:00:18 | 000,004,893 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\combo_009.js [2012/01/14 17:00:18 | 000,004,202 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller.htm [2012/01/14 17:00:18 | 000,002,423 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure.htm [2012/01/14 17:00:18 | 000,003,122 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_002.htm [2012/01/14 17:00:18 | 000,002,308 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_003.htm [2012/01/14 17:00:18 | 000,011,105 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\fc.htm [2012/01/14 17:00:18 | 000,012,723 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\launch-ltr-55366.png [2012/01/14 17:00:18 | 000,027,815 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\launch_3654.js [2012/01/14 17:00:18 | 000,000,336 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\profile_16e.png [2012/01/14 17:00:18 | 000,009,915 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\rto1_78.js [2012/01/14 17:00:18 | 000,008,240 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\uh-sprite-2-15.png [2012/01/14 17:00:18 | 000,008,060 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\view.htm [2012/01/14 17:00:18 | 000,000,816 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\view_002.htm [2012/01/14 17:00:18 | 000,001,965 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\wsclient_3654.swf [2012/01/14 17:00:18 | 000,497,996 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yimapp.htm [2012/01/14 17:00:18 | 000,000,196 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yql [2012/01/14 17:00:18 | 000,006,999 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\blank_data\combo.css [2012/01/14 17:00:18 | 000,107,935 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\blank_data\combo_002.css [2012/01/14 17:00:18 | 000,034,909 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\combo [2012/01/14 17:00:18 | 000,061,453 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\combo.js [2012/01/14 17:00:18 | 000,007,576 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\combo_002 [2012/01/14 17:00:18 | 000,035,910 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\combo_002.js [2012/01/14 17:00:18 | 000,007,211 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\common.js [2012/01/14 17:00:18 | 000,027,064 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\om-min.js [2012/01/14 17:00:18 | 000,073,606 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\pp_fr-FR.js [2012/01/14 17:00:18 | 000,053,548 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\controller_data\stub.js [2012/01/14 17:00:18 | 000,017,841 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data\darla-ers-min.js [2012/01/14 17:00:18 | 000,005,518 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data\st.htm [2012/01/14 17:00:18 | 000,033,983 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data\st_data\15b6c046163ae047641b1722e375c782.swf [2012/01/14 17:00:18 | 000,001,389 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data\st_data\imp.js [2012/01/14 17:00:18 | 000,001,301 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data_002\soccer_22_052609.gif [2012/01/14 17:00:18 | 000,005,580 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data_003\st.htm [2012/01/14 17:00:18 | 000,036,020 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data_003\st_data\d4f9b7c8d28ac665319bdf840f0e80f3.swf [2012/01/14 17:00:18 | 000,001,383 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\ext-render-secure_data_003\st_data\imp.js [2012/01/14 17:00:18 | 000,001,973 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\fc_data\bc_2.js [2012/01/14 17:00:18 | 000,020,917 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\view_data\combo.css [2012/01/14 17:00:18 | 000,025,431 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\view_data\combo_002.css [2012/01/14 17:00:18 | 000,000,355 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yimapp_data\a.htm [2012/01/14 17:00:18 | 000,016,643 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yimapp_data\javascript [2012/01/14 17:00:18 | 000,003,231 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yimapp_data\xframe-proxy_20110929.htm [2012/01/14 17:00:18 | 000,003,146 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yimapp_data\xframe-proxy_20110929_002.htm [2012/01/14 17:00:18 | 000,010,519 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RYT7U6W\yimapp_data\xframe-proxy_20110929_data\xframe-min.js [2012/12/02 12:27:38 | 001,498,935 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZKD458\AWRO Newsletter 2012.pdf [2012/12/02 15:13:48 | 000,025,439 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZKD458\Newsletter_Feedback_Form_Rev.docx [2012/12/02 13:56:35 | 000,098,304 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4133778607-2017990771-4136200423-1000\$RZKD458\traduction.doc [2006/11/02 15:01:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2006/11/02 15:01:49 | 000,032,552 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2012/11/02 16:37:48 | 000,001,002 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job [2012/11/17 17:03:35 | 000,001,052 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2012/11/17 17:03:36 | 000,001,056 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:A2B3764A @Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:9033BDFB @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:D2249B7E @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:67421CB3 @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:A1D3FEF0 < End of report >