Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

black screen at startup


  • This topic is locked This topic is locked
102 replies to this topic

#1 Jen42

Jen42

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 13 October 2011 - 08:43 PM

I've had a problem with the external drive not working, so I tried to restore to last week. The computer froze through the restore, so I had to restart using the on button. I then got the black screen with nothing but the white cursor. i tried alt ctr del, didn't work. I tried restarting with a repair, but then I just get the cursor on a pretty blue screen with images on it (I assume it's some kind of windows screen). Safe mode doesn't work either.

I'm really stuck, I don't want to lose everything! Can someone please help?

Thankyou

BC AdBot (Login to Remove)

 


#2 Layback Bear

Layback Bear

  • Members
  • 1,880 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Northern Ohio
  • Local time:10:01 PM

Posted 14 October 2011 - 07:28 AM

Remove the external hard drive.

#3 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 14 October 2011 - 05:39 PM

Remove the external hard drive.



Did that!!

#4 Layback Bear

Layback Bear

  • Members
  • 1,880 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Northern Ohio
  • Local time:10:01 PM

Posted 15 October 2011 - 09:38 AM

Did you remove the drive and shut down and the do a complete Cold Start. If so is the problem still there? Their are so many things that can cause this problem. If it was my computer I would start with looking in the Bios and checking the boot order. I would also unplug everything from the computer not needed, i.e. printers, ect. Do you have access to a Windows 7 C/D to match you system. If so I would try a repair using it. If you have the C/D you will have to go back in Bios and set it to (boot from C/D first). Have you used a registry cleaner or tune up program? I know that I ask a lot of questions but they are need to understand what we are working with. This allows me and others to be able to help.
http://www.bleepingcomputer.com/tutorials/repair-windows-with-windows-startup-repair/

Edited by Layback Bear, 15 October 2011 - 09:41 AM.


#5 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 15 October 2011 - 07:30 PM

I've tried removing it, then restating it, again and again. I've tried running the repair disk, at first it didn't work, but now it has, but tells me there's no problem. There seems to be no system restore points anymore and the backup was on the ext drive. I tried running the memory check, it says there was no problems, but then when I ran it on advanced mode, it hangs at 10%.

By the way I'm running win 7, not Vista.

Everything is unplugged.

Any other ideas?

Thanks

#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,558 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:11:01 PM

Posted 16 October 2011 - 11:09 PM

:welcome:

The tools I 'll be using are usually for the malware forum. I am requesting the topic to be moved to that area.

No promises.

Lets try to scan the computer. You will need a USB (Flash) pendrive.

For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Click on Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the flash drive. Please copy and paste it to your reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 17 October 2011 - 12:15 AM

Couldn't get the f8 button to work, but managed to do all this with the repair disk.

Thankyou

Here's the log: Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.2.4
Ran by SYSTEM at 2011-10-17 16:10:33
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [85160 2009-06-17] (Elaborate Bytes AG)
HKLM-x32\...\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui [3722416 2011-09-06] (AVAST Software)
HKLM-x32\...\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2010-04-12] (PowerISO Computing, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-06-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-04-07] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKU\Dana\...\Run: [Steam] "R:\Games\Steam\steam.exe" -silent [x]
HKU\Mum\...\Run: [Weather Tracker3] C:\Program Files (x86)\Weatherzone Tracker\weather_tracker.exe [2888403 2009-07-16] ()
HKU\Mum\...\Run: [Epson Stylus TX550W(Network)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIP.EXE /FU "C:\Users\Mum\AppData\Local\Temp\E_S5E38.tmp" /EF "HKCU" [x]
HKU\Mum\...\Run: [EPSON0A5052] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIP.EXE /FU "C:\Windows\TEMP\E_SD8F1.tmp" /EF "HKCU" [x]
HKU\Mum\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKLM\...\RunOnce: [*Restore] C:\Windows\System32\rstrui.exe /runonce [296960 2010-11-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

==================== Services (Whitelisted) ======

2 avast! Antivirus; "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" [44768 2011-09-06] (AVAST Software)
2 Lavasoft Ad-Aware Service; "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe" [2151640 2011-09-14] (Lavasoft Limited)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 NAUpdate; "C:\Program Files (x86)\Nero\Update\NASvc.exe" [503080 2010-05-03] (Nero AG)
2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [62208 2009-08-12] (NewTech Infosystems, Inc.)
2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-18] (Adobe Systems Incorporated)
2 TVersityMediaServer; "C:\ProgramData\TVersity\Media Server\MediaServer.exe" [921600 2010-11-24] ()
2 Akamai; c:\program files (x86)\common files\akamai\netsession_win_b31de1e.dll [x]
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]

========================== Drivers (Whitelisted) =============

2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [24408 2011-09-06] (AVAST Software)
2 aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [65368 2011-09-06] (AVAST Software)
1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [42328 2011-09-06] (AVAST Software)
1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [601944 2011-09-06] (AVAST Software)
1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [301912 2011-09-06] (AVAST Software)
1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [58200 2011-09-06] (AVAST Software)
3 e1yexpress; C:\Windows\System32\DRIVERS\e1y62x64.sys [287960 2009-06-12] (Intel Corporation)
1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [34472 2009-12-17] (Elaborate Bytes AG)
3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [17152 2011-09-14] ()
0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [69376 2011-08-17] (Lavasoft AB)
3 pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [82816 2010-04-17] (VSO Software)
1 SCDEmu; C:\Windows\System32\Drivers\SCDEmu.sys [91568 2010-04-12] (PowerISO Computing, Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2011-03-21] (Duplex Secure Ltd.)
3 VClone; C:\Windows\System32\DRIVERS\VClone.sys [36352 2009-08-09] (Elaborate Bytes AG)
3 cpuz132; \??\C:\Users\Mum\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
3 dump_wmimmc; \??\C:\gPotato\IrisOnline\GameGuard\dump_wmimmc.sys [x]
3 npggsvc; C:\Windows\system32\GameMon.des -service [x]
3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x64\Sandra.sys [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2011-10-13 16:32 - 2011-10-16 20:56 - 0809958 ____A C:\Windows\ntbtlog.txt
2011-10-13 16:25 - 2011-10-15 21:28 - 0066700 ____A C:\Windows\PFRO.log
2011-10-13 15:29 - 2011-10-13 15:30 - 0000000 ____D C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery
2011-10-13 15:29 - 2011-10-13 15:29 - 0000000 ____D C:\Log
2011-10-13 12:33 - 2011-10-13 12:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{D43C83AC-B1D9-43B3-92E6-CCC24E5796C4}
2011-10-13 12:33 - 2011-10-13 12:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{3E664938-5BA8-4CC6-8F93-63C9C4032A79}
2011-10-13 00:32 - 2011-10-13 00:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{8CD02307-037C-4E6E-AA09-390685A03DAC}
2011-10-13 00:32 - 2011-10-13 00:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{37B9C8D6-3916-4EC6-A232-F486E8774AB0}
2011-10-12 22:46 - 2011-10-12 22:50 - 0000000 ____D C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_Season_1
2011-10-12 20:48 - 2011-10-12 20:48 - 0000000 ____D C:\Users\Mum\Downloads\PaniPoni Dash!
2011-10-12 20:47 - 2011-10-12 20:48 - 0000000 ____D C:\Users\Mum\Downloads\[Fnolli] .hack//Quantum
2011-10-12 20:46 - 2011-10-12 20:47 - 23788356 ____A C:\Users\Mum\Downloads\[Zenyaku] Hayate no Gotoku Movie -Heaven is a Place on Earth- PV [D685BF7E].mkv
2011-10-12 20:46 - 2011-10-12 20:46 - 0000000 ____D C:\Users\Mum\Downloads\[gg]Puella Magi Madoka Magica(720p)(TV)
2011-10-12 13:10 - 2011-10-12 22:47 - 0000000 ____D C:\Users\Mum\Downloads\[AQS-Anime] Negima Ala Alba OAD 1-3 H264
2011-10-12 12:32 - 2011-10-12 12:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{BB10B481-C58C-4E20-A0AE-6A0ADFFD95B3}
2011-10-12 12:32 - 2011-10-12 12:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{599A6C95-26A4-49B3-A546-96C8CA2EDA59}
2011-10-12 00:34 - 2011-10-12 01:58 - 0000000 ____D C:\Users\Mum\Downloads\hack//Quantum-101-walking-party-eng-subs[Oj]
2011-10-12 00:31 - 2011-10-12 00:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{FF1C1F30-FAA3-46AC-A30A-A1FD4D713779}
2011-10-12 00:31 - 2011-10-12 00:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{0FDC50D3-C80D-4780-9985-F9168299A730}
2011-10-11 22:22 - 2011-10-12 01:17 - 0000000 ____D C:\Users\Mum\Downloads\[AQS-Anime] Negima Ala Alba OAD [h.264]
2011-10-11 22:03 - 2011-10-11 22:11 - 0000000 ____D C:\Users\Mum\Downloads\Mahou Shoujo Madoka?Magica
2011-10-11 21:56 - 2011-10-12 13:08 - 0000000 ____D C:\Users\Mum\Downloads\[SS-Eclipse] Hayate no Gotoku [h.264]
2011-10-11 12:31 - 2011-10-11 12:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{76528ECC-9DF5-4135-B71E-824B37CB7918}
2011-10-11 12:30 - 2011-10-11 12:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{7B2DDA1A-9B5C-47C3-B0B8-EFED4588AE22}
2011-10-11 00:30 - 2011-10-11 00:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{DA28ABFF-3D37-404F-A9BA-6F17DAE359B0}
2011-10-11 00:30 - 2011-10-11 00:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{46A58FA6-5FDA-4BB6-A7DE-CC9DE87F845E}
2011-10-10 12:29 - 2011-10-10 12:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{AB9ED603-DF68-4448-AA67-E37FB9E633DB}
2011-10-10 12:29 - 2011-10-10 12:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{0536238A-6C4B-4D17-966B-6318ED820BBD}
2011-10-10 00:15 - 2011-10-10 00:16 - 0000000 ____D C:\Users\Mum\AppData\Local\{0A665709-B354-4EF7-A853-94C1E4422CBB}
2011-10-10 00:15 - 2011-10-10 00:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{1486E497-EB71-460F-B904-7964F131A7C9}
2011-10-09 21:56 - 2011-10-09 21:56 - 0000000 ____D C:\Users\Mum\Downloads\Mahou Sensei Negima! [ED]
2011-10-09 21:54 - 2011-10-09 21:55 - 0000000 ____D C:\Users\Mum\Downloads\[Kmimi-psp] Mahou Sensei Negima! Shiroki Tsubasa Ala Alba (Complete)
2011-10-09 21:28 - 2011-10-11 21:38 - 0000000 ____D C:\Users\Mum\Downloads\[LuPerry]_dot_hack_GU_TRILOGY_1920x1080(x264_AC3)
2011-10-09 21:24 - 2011-10-11 21:47 - 0000000 ____D C:\Users\Mum\Documents\Hayate the Combat Butler (Sub)
2011-10-09 12:15 - 2011-10-09 12:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{70F20020-DBF4-4C7C-9907-9221C509CB7A}
2011-10-09 12:15 - 2011-10-09 12:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{05777C8A-B612-4A90-848C-B235B817168C}
2011-10-08 16:03 - 2011-10-08 16:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{95EB73F9-292A-400A-BDB4-FCF2E8D3755C}
2011-10-08 16:02 - 2011-10-08 16:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{90BF7123-FA5A-4C04-8BA0-23583032E712}
2011-10-08 15:27 - 2011-10-08 15:27 - 0000000 ____D C:\Users\Mum\AppData\Roaming\Malwarebytes
2011-10-08 13:45 - 2011-10-08 13:46 - 0000000 ____D C:\Users\Mum\AppData\Local\{DFD693CA-1B8B-4BFE-8E88-9670FEC9A55B}
2011-10-08 13:45 - 2011-10-08 13:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{3ACE2F37-B553-4373-86D6-73BDFE852802}
2011-10-07 22:54 - 2011-10-07 22:54 - 0000000 ____D C:\Users\Mum\AppData\Local\{EABE6D5F-5FD0-4924-AC96-E36B784C0F7C}
2011-10-07 22:54 - 2011-10-07 22:54 - 0000000 ____D C:\Users\Mum\AppData\Local\{EA3B494E-050B-485F-A8AC-6879412EE109}
2011-10-07 22:51 - 2011-10-12 22:50 - 0000000 ____D C:\Users\Mum\Downloads\Pani Poni Dash
2011-10-07 22:16 - 2011-10-07 23:43 - 503376780 ____A C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_-_01_[0557C1C6](1).mkv
2011-10-07 22:14 - 2011-10-07 22:14 - 0000242 ____A C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_-_01_[0557C1C6].mkv
2011-10-07 22:00 - 2011-10-07 22:09 - 66444770 ____A C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_-_01_[0557C1C6].mkv.part
2011-10-07 21:15 - 2011-10-07 21:42 - 736422540 ____A C:\Users\Dana\Downloads\UWOnline_20100928.exe.part
2011-10-07 21:15 - 2011-10-07 21:42 - 712352436 ____A C:\Users\Dana\Downloads\OnRPG_edeneternal_install_20110528.exe.part
2011-10-07 18:58 - 2011-10-07 18:58 - 0747499 ____A C:\Users\Dana\Downloads\Wrye_Mash_84-27588.zip
2011-10-07 13:59 - 2011-10-07 13:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{5E51ED3F-D7D2-4F54-B83B-E44AF90B3753}
2011-10-07 01:59 - 2011-10-07 01:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{FCB83AF3-66B1-48BF-A235-433E723EA4A2}
2011-10-07 01:59 - 2011-10-07 01:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{91FB4505-12B2-4908-BF50-B452B1E71CDB}
2011-10-06 17:25 - 2011-10-06 17:25 - 0020240 ____A C:\Users\Mum\Downloads\309618_2268830433440_1028964556_32484823_2016651666_n(2).jpg
2011-10-06 17:24 - 2011-10-06 17:24 - 0020240 ____A C:\Users\Mum\Downloads\309618_2268830433440_1028964556_32484823_2016651666_n(1).jpg
2011-10-06 17:23 - 2011-10-06 17:23 - 0020240 ____A C:\Users\Mum\Downloads\309618_2268830433440_1028964556_32484823_2016651666_n.jpg
2011-10-06 15:53 - 2011-10-06 15:53 - 0009418 ____A C:\Users\Mum\Downloads\313201_248987081814769_187581424622002_665693_1127712695_n.jpg
2011-10-06 13:58 - 2011-10-06 13:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{751578A2-69A1-4967-B2BF-8F837ED1E57C}
2011-10-06 13:58 - 2011-10-06 13:58 - 0000000 ____D C:\Users\Mum\AppData\Local\{2D233B00-F50F-4D92-827D-0B52F7381BBA}
2011-10-06 01:05 - 2011-10-06 01:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{B2E694DF-FD35-4C36-8AEE-AF25F38719C7}
2011-10-06 01:05 - 2011-10-06 01:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{7C60FC1A-7187-44BC-8D5F-93B312B041FE}
2011-10-05 13:05 - 2011-10-05 13:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{9924944B-AC3A-4A7C-B645-91CD8D166DE3}
2011-10-05 13:05 - 2011-10-05 13:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{4D5BF3D8-1204-4B90-BA80-DC8DE8275D1D}
2011-10-05 01:04 - 2011-10-05 01:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{0368A7E8-9F5B-4C27-AF42-EE512D97B338}
2011-10-05 01:04 - 2011-10-05 01:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{023F65EF-82A1-4772-BD93-DF58C40FDDAA}
2011-10-04 17:31 - 2011-10-04 21:38 - 0000000 ____D C:\Users\Dana\Downloads\Blood and Mud
2011-10-04 13:04 - 2011-10-04 13:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{A404FCC2-0EFE-4FC8-B086-7804354C4658}
2011-10-04 13:03 - 2011-10-04 13:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{6B53B5EF-6757-497D-9E7A-9DE630DAD656}
2011-10-04 01:03 - 2011-10-04 01:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{E7611FE6-954C-40F6-9A59-82EEE163B4CE}
2011-10-04 01:03 - 2011-10-04 01:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{D04F520B-4733-470E-BA1E-C81EF91A14C9}
2011-10-03 13:03 - 2011-10-03 13:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{E6E40B64-96D8-4631-A42C-5DEAC3F53975}
2011-10-03 13:02 - 2011-10-03 13:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{A05C549C-ED6B-4BDE-9988-A30E29888049}
2011-10-02 15:51 - 2011-10-02 15:51 - 0000000 ____D C:\Users\Mum\AppData\Local\{F414BFB6-DBEE-4ABE-8F3C-5898B562BFC9}
2011-10-02 15:51 - 2011-10-02 15:51 - 0000000 ____D C:\Users\Mum\AppData\Local\{684222BF-CA0A-47A8-B272-01E16A3F7A66}
2011-10-02 15:35 - 2011-10-02 15:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{074F9B17-6195-4247-BF36-21E241718285}
2011-10-02 15:35 - 2011-10-02 15:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{C7422649-68CB-4FE9-BE2E-E1CC7D0DE6D7}
2011-10-02 13:52 - 2011-10-02 13:52 - 0000000 ____D C:\Users\Mum\AppData\Local\{3F9275BE-C33E-49FD-8A48-CAE28936FD6F}
2011-10-02 13:52 - 2011-10-02 13:52 - 0000000 ____D C:\Users\Mum\AppData\Local\{08D6E459-7A20-4D22-9C1B-E208D3B09A3D}
2011-10-02 13:39 - 2011-10-02 13:39 - 0000408 ____A C:\Windows\Tasks\Ad-Aware Update (Weekly).job
2011-10-01 17:46 - 2011-10-13 16:21 - 0000000 ____D C:\Users\Dana\Downloads\Staelth Overhual
2011-10-01 17:36 - 2011-10-13 16:21 - 0000000 ____D C:\Users\Dana\Downloads\Proximity Based Sneak
2011-10-01 17:24 - 2011-10-13 16:21 - 0000000 ____D C:\Users\Dana\Downloads\Combat Archery
2011-10-01 14:22 - 2011-10-01 14:23 - 0000000 ____D C:\Users\Mum\AppData\Local\{7EAA5203-E269-4CFF-A24D-8E6ABECDB540}
2011-10-01 14:22 - 2011-10-01 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{B4EC65FC-119A-46AD-AE2A-C87BF6FECEFA}
2011-09-30 14:06 - 2011-09-30 14:06 - 0000000 ____D C:\Users\Mum\AppData\Local\{EAB9FBC9-82F4-4127-93EB-1EAF9F0FE432}
2011-09-30 14:06 - 2011-09-30 14:06 - 0000000 ____D C:\Users\Mum\AppData\Local\{1BC815A8-70BB-4A1F-8218-9C736011635E}
2011-09-29 22:39 - 2011-09-29 22:39 - 0000205 ____A C:\Users\Dana\Desktop\Team Fortress 2.url
2011-09-29 22:35 - 2011-09-29 22:35 - 0000184 ____A C:\Users\Dana\Desktop\Rise of Immortals.url
2011-09-29 13:53 - 2011-09-29 13:53 - 0000000 ____D C:\Users\Mum\AppData\Local\{B26FAC65-F916-4442-918F-7AC7259A1272}
2011-09-29 13:52 - 2011-09-29 13:53 - 0000000 ____D C:\Users\Mum\AppData\Local\{18EB17F1-88F2-40E1-A918-28B9DACC984A}
2011-09-28 17:02 - 2011-09-28 17:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{7A0182B0-9464-4923-83D1-B705127D4253}
2011-09-28 17:02 - 2011-09-28 17:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{6B5554A7-9929-4F59-8C93-7FE645178954}
2011-09-28 16:46 - 2011-09-28 16:46 - 0000207 ____A C:\Users\Dana\Desktop\Forsaken World .url
2011-09-28 16:40 - 2011-09-28 16:40 - 0000207 ____A C:\Users\Dana\Desktop\Spiral Knights.url
2011-09-27 19:38 - 2011-09-27 19:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{6D8158F9-3A06-4304-8D37-D22E8A58EBC4}
2011-09-27 19:37 - 2011-09-27 19:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{5C3F0CB6-17EC-4634-86D6-51216DF32DB3}
2011-09-27 19:34 - 2011-10-13 16:22 - 0000952 ____A C:\Windows\setupact.log
2011-09-27 19:34 - 2011-09-27 19:34 - 0000000 ____A C:\Windows\setuperr.log
2011-09-26 13:49 - 2011-09-26 13:49 - 0000000 ____D C:\Users\Mum\AppData\Local\{ED5E1B14-6040-4756-A3FC-6E0F2C263715}
2011-09-26 13:49 - 2011-09-26 13:49 - 0000000 ____D C:\Users\Mum\AppData\Local\{AF54E38C-CD66-4A78-A3AF-5C269CB23B3B}
2011-09-25 22:51 - 2011-09-25 22:51 - 0000000 ____D C:\Users\Mum\Desktop\centrelink
2011-09-25 14:19 - 2011-09-25 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{40748038-5AF3-4260-A7DF-B3AC46C3545E}
2011-09-25 14:19 - 2011-09-25 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{0D446DFB-E4A5-4BCC-B500-14575CFC5B5E}
2011-09-24 14:22 - 2011-09-24 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{D08A83A2-3BF3-42A0-B20F-CD74EDD64634}
2011-09-24 14:22 - 2011-09-24 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{5150180A-43AC-436E-8D26-4076644CB024}
2011-09-23 14:45 - 2011-09-23 14:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{DB5BF5B3-640E-4B0C-8A98-B182BCA1D20C}
2011-09-23 14:45 - 2011-09-23 14:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{63BC173E-49B5-40B0-B9F6-910D35F71D72}
2011-09-22 14:10 - 2011-09-22 14:10 - 0000000 ____D C:\Users\Mum\AppData\Local\{F676C0F0-460B-49AB-9125-72161C70B053}
2011-09-22 14:10 - 2011-09-22 14:10 - 0000000 ____D C:\Users\Mum\AppData\Local\{05579D4F-7522-49C1-BBBF-1F9F8EBC65AE}
2011-09-21 23:31 - 2011-09-21 23:31 - 0112003 ____A C:\Users\Mum\Desktop\youth allowance.pdf
2011-09-21 15:03 - 2011-09-21 15:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{7C183128-335B-4D86-A230-53B4BB052861}
2011-09-21 15:03 - 2011-09-21 15:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{D5EF3F70-8247-4D3E-BF55-BB9EA08A8920}
2011-09-20 13:44 - 2011-09-20 13:44 - 0000000 ____D C:\Users\Mum\AppData\Local\{76BC0091-0420-4A50-A7B9-FE511BF9442E}
2011-09-20 13:44 - 2011-09-20 13:44 - 0000000 ____D C:\Users\Mum\AppData\Local\{4E573FE8-D5C7-45D4-9C2D-35583DD8E521}
2011-09-19 14:18 - 2011-09-19 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{61F41DD8-5C7E-425E-B299-91C8ECFC17D9}
2011-09-19 14:18 - 2011-09-19 14:18 - 0000000 ____D C:\Users\Mum\AppData\Local\{5FE7947D-6629-462C-9250-429C9507DBA1}
2011-09-18 14:53 - 2011-09-18 14:53 - 0000000 ____D C:\Users\Mum\AppData\Local\{9AFE7360-3CCC-40D6-BD75-9B82D7857C93}
2011-09-18 14:52 - 2011-09-18 14:53 - 0000000 ____D C:\Users\Mum\AppData\Local\{D3F9615B-67E6-45BC-B94C-57EC5B3573F5}
2011-09-17 23:20 - 2011-09-17 23:20 - 0438232 ____A C:\Users\Mum\Downloads\A99Y_CoiledEarwire.AHJ019.pdf
2011-09-17 23:19 - 2011-09-17 23:19 - 0940783 ____A C:\Users\Mum\Downloads\J4M1L0L4_HolidayStardust.JML003.pdf
2011-09-17 23:19 - 2011-09-17 23:19 - 0785535 ____A C:\Users\Mum\Downloads\80881_10MinutePendant.MYI009.pdf
2011-09-17 23:18 - 2011-09-17 23:18 - 0327651 ____A C:\Users\Mum\Downloads\80881_AddingSafetyChain.MYI008.pdf
2011-09-17 23:14 - 2011-09-17 23:14 - 0603344 ____A C:\Users\Mum\Downloads\SH3R1D4n_FavoriteBasicHoops.JJD004.pdf
2011-09-17 23:14 - 2011-09-17 23:14 - 0593418 ____A C:\Users\Mum\Downloads\80881_OldFashionedChain.MYI007.pdf
2011-09-17 23:13 - 2011-09-17 23:13 - 1761614 ____A C:\Users\Mum\Downloads\Kr1stin_SpiralAdorned.KSJ006.pdf
2011-09-17 23:13 - 2011-09-17 23:13 - 0546383 ____A C:\Users\Mum\Downloads\A99Y_Figure8Chain.AHJ020.pdf
2011-09-17 17:57 - 2011-09-17 17:57 - 1613001 ____A C:\Users\Mum\Downloads\TwinHeartsRing.DCHFOC01.pdf
2011-09-17 17:55 - 2011-09-17 17:55 - 1653336 ____A C:\Users\Mum\Downloads\K1K1_CHAEARCUFFs.BNQ006.pdf
2011-09-17 15:17 - 2011-09-17 15:17 - 0000000 ____D C:\Users\Mum\AppData\Local\{84A53D9B-1DB0-4B4D-9001-270ADE17E6E8}
2011-09-17 15:17 - 2011-09-17 15:17 - 0000000 ____D C:\Users\Mum\AppData\Local\{16F736D4-8729-40DA-B894-08C8713C94EB}


============ 3 Months Modified Files and Folders =============

2011-10-17 16:10 - 2011-10-17 16:10 - 0000000 ____D C:\FRST
2011-10-16 20:56 - 2011-10-13 16:32 - 0809958 ____A C:\Windows\ntbtlog.txt
2011-10-16 20:54 - 2010-02-08 22:43 - 3220549632 __ASH C:\hiberfil.sys
2011-10-15 22:20 - 2010-04-17 14:07 - 0000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2011-10-15 22:12 - 2009-07-13 20:45 - 0009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2011-10-15 22:12 - 2009-07-13 20:45 - 0009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2011-10-15 22:07 - 2011-03-21 23:20 - 1862311 ____A C:\Windows\WindowsUpdate.log
2011-10-15 22:05 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2011-10-15 21:28 - 2011-10-13 16:25 - 0066700 ____A C:\Windows\PFRO.log
2011-10-14 18:24 - 2010-07-01 19:24 - 0000248 ____A C:\Windows\Tasks\Epson Printer Software Downloader.job
2011-10-13 17:04 - 2010-09-24 06:00 - 0000271 ____A C:\Windows\SysWOW64\tversity.cookies
2011-10-13 16:22 - 2011-09-27 19:34 - 0000952 ____A C:\Windows\setupact.log
2011-10-13 16:22 - 2011-01-10 00:32 - 0000000 ____D C:\Program Files (x86)\aTube Catcher
2011-10-13 16:22 - 2010-04-16 02:26 - 0000000 ____D C:\users\Mum
2011-10-13 16:22 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR
2011-10-13 16:21 - 2011-10-01 17:46 - 0000000 ____D C:\Users\Dana\Downloads\Staelth Overhual
2011-10-13 16:21 - 2011-10-01 17:36 - 0000000 ____D C:\Users\Dana\Downloads\Proximity Based Sneak
2011-10-13 16:21 - 2011-10-01 17:24 - 0000000 ____D C:\Users\Dana\Downloads\Combat Archery
2011-10-13 16:21 - 2011-09-06 21:33 - 0000000 ____D C:\Users\All Users\McAfee Security Scan
2011-10-13 16:21 - 2011-09-06 21:33 - 0000000 ____D C:\ProgramData\McAfee Security Scan
2011-10-13 16:21 - 2011-05-11 23:58 - 0000000 ____D C:\users\Dana
2011-10-13 16:21 - 2010-10-20 02:25 - 0000000 ____D C:\Windows\en
2011-10-13 16:21 - 2010-10-20 02:24 - 0000000 ____D C:\Program Files\Windows Live
2011-10-13 16:21 - 2010-04-19 14:40 - 0000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2011-10-13 16:21 - 2010-04-19 14:40 - 0000000 ____D C:\ProgramData\Spybot - Search & Destroy
2011-10-13 16:21 - 2010-04-17 18:08 - 0000000 ____D C:\Users\Mum\AppData\Roaming\uTorrent
2011-10-13 16:21 - 2010-02-08 22:59 - 0000000 ____D C:\Program Files (x86)\Windows Live
2011-10-13 16:21 - 2009-07-13 19:20 - 0000000 __RHD C:\Users\Public\Libraries
2011-10-13 16:21 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\AppCompat
2011-10-13 16:20 - 2011-09-06 21:33 - 0000000 ____D C:\Program Files (x86)\McAfee Security Scan
2011-10-13 16:20 - 2011-04-19 18:00 - 0000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2011-10-13 16:20 - 2010-04-19 16:41 - 0000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-10-13 16:17 - 2010-04-19 16:41 - 0000000 ____D C:\Users\All Users\Malwarebytes
2011-10-13 16:17 - 2010-04-19 16:41 - 0000000 ____D C:\ProgramData\Malwarebytes
2011-10-13 16:17 - 2010-04-16 02:26 - 0000000 ____D C:\Users\Mum\AppData\LocalLow
2011-10-13 16:17 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\Microsoft Shared
2011-10-13 16:00 - 2010-04-21 23:16 - 0149641 ____A C:\aaw7boot.log
2011-10-13 15:38 - 2010-04-16 02:25 - 0000000 __SHD C:\Recovery
2011-10-13 15:35 - 2010-04-16 03:03 - 0000000 ____D C:\Users\Mum\AppData\Local\ElevatedDiagnostics
2011-10-13 15:30 - 2011-10-13 15:29 - 0000000 ____D C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery
2011-10-13 15:29 - 2011-10-13 15:29 - 0000000 ____D C:\Log
2011-10-13 12:33 - 2011-10-13 12:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{D43C83AC-B1D9-43B3-92E6-CCC24E5796C4}
2011-10-13 12:33 - 2011-10-13 12:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{3E664938-5BA8-4CC6-8F93-63C9C4032A79}
2011-10-13 12:33 - 2010-10-19 23:20 - 0000000 ____D C:\Users\Mum\AppData\Local\Windows Live
2011-10-13 00:32 - 2011-10-13 00:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{8CD02307-037C-4E6E-AA09-390685A03DAC}
2011-10-13 00:32 - 2011-10-13 00:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{37B9C8D6-3916-4EC6-A232-F486E8774AB0}
2011-10-12 22:50 - 2011-10-12 22:46 - 0000000 ____D C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_Season_1
2011-10-12 22:50 - 2011-10-07 22:51 - 0000000 ____D C:\Users\Mum\Downloads\Pani Poni Dash
2011-10-12 22:47 - 2011-10-12 13:10 - 0000000 ____D C:\Users\Mum\Downloads\[AQS-Anime] Negima Ala Alba OAD 1-3 H264
2011-10-12 20:48 - 2011-10-12 20:48 - 0000000 ____D C:\Users\Mum\Downloads\PaniPoni Dash!
2011-10-12 20:48 - 2011-10-12 20:47 - 0000000 ____D C:\Users\Mum\Downloads\[Fnolli] .hack//Quantum
2011-10-12 20:47 - 2011-10-12 20:46 - 23788356 ____A C:\Users\Mum\Downloads\[Zenyaku] Hayate no Gotoku Movie -Heaven is a Place on Earth- PV [D685BF7E].mkv
2011-10-12 20:46 - 2011-10-12 20:46 - 0000000 ____D C:\Users\Mum\Downloads\[gg]Puella Magi Madoka Magica(720p)(TV)
2011-10-12 13:08 - 2011-10-11 21:56 - 0000000 ____D C:\Users\Mum\Downloads\[SS-Eclipse] Hayate no Gotoku [h.264]
2011-10-12 12:32 - 2011-10-12 12:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{BB10B481-C58C-4E20-A0AE-6A0ADFFD95B3}
2011-10-12 12:32 - 2011-10-12 12:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{599A6C95-26A4-49B3-A546-96C8CA2EDA59}
2011-10-12 01:58 - 2011-10-12 00:34 - 0000000 ____D C:\Users\Mum\Downloads\hack//Quantum-101-walking-party-eng-subs[Oj]
2011-10-12 01:17 - 2011-10-11 22:22 - 0000000 ____D C:\Users\Mum\Downloads\[AQS-Anime] Negima Ala Alba OAD [h.264]
2011-10-12 00:31 - 2011-10-12 00:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{FF1C1F30-FAA3-46AC-A30A-A1FD4D713779}
2011-10-12 00:31 - 2011-10-12 00:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{0FDC50D3-C80D-4780-9985-F9168299A730}
2011-10-11 22:11 - 2011-10-11 22:03 - 0000000 ____D C:\Users\Mum\Downloads\Mahou Shoujo Madoka?Magica
2011-10-11 21:47 - 2011-10-09 21:24 - 0000000 ____D C:\Users\Mum\Documents\Hayate the Combat Butler (Sub)
2011-10-11 21:38 - 2011-10-09 21:28 - 0000000 ____D C:\Users\Mum\Downloads\[LuPerry]_dot_hack_GU_TRILOGY_1920x1080(x264_AC3)
2011-10-11 12:31 - 2011-10-11 12:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{76528ECC-9DF5-4135-B71E-824B37CB7918}
2011-10-11 12:31 - 2011-10-11 12:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{7B2DDA1A-9B5C-47C3-B0B8-EFED4588AE22}
2011-10-11 00:30 - 2011-10-11 00:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{DA28ABFF-3D37-404F-A9BA-6F17DAE359B0}
2011-10-11 00:30 - 2011-10-11 00:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{46A58FA6-5FDA-4BB6-A7DE-CC9DE87F845E}
2011-10-10 12:29 - 2011-10-10 12:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{AB9ED603-DF68-4448-AA67-E37FB9E633DB}
2011-10-10 12:29 - 2011-10-10 12:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{0536238A-6C4B-4D17-966B-6318ED820BBD}
2011-10-10 00:16 - 2011-10-10 00:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{0A665709-B354-4EF7-A853-94C1E4422CBB}
2011-10-10 00:15 - 2011-10-10 00:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{1486E497-EB71-460F-B904-7964F131A7C9}
2011-10-09 21:56 - 2011-10-09 21:56 - 0000000 ____D C:\Users\Mum\Downloads\Mahou Sensei Negima! [ED]
2011-10-09 21:55 - 2011-10-09 21:54 - 0000000 ____D C:\Users\Mum\Downloads\[Kmimi-psp] Mahou Sensei Negima! Shiroki Tsubasa Ala Alba (Complete)
2011-10-09 12:15 - 2011-10-09 12:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{70F20020-DBF4-4C7C-9907-9221C509CB7A}
2011-10-09 12:15 - 2011-10-09 12:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{05777C8A-B612-4A90-848C-B235B817168C}
2011-10-09 01:25 - 2010-07-01 21:05 - 0000132 ____A C:\Users\Mum\AppData\Roaming\Adobe PNG Format CS5 Prefs
2011-10-08 16:03 - 2011-10-08 16:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{95EB73F9-292A-400A-BDB4-FCF2E8D3755C}
2011-10-08 16:02 - 2011-10-08 16:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{90BF7123-FA5A-4C04-8BA0-23583032E712}
2011-10-08 15:27 - 2011-10-08 15:27 - 0000000 ____D C:\Users\Mum\AppData\Roaming\Malwarebytes
2011-10-08 13:46 - 2011-10-08 13:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{DFD693CA-1B8B-4BFE-8E88-9670FEC9A55B}
2011-10-08 13:45 - 2011-10-08 13:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{3ACE2F37-B553-4373-86D6-73BDFE852802}
2011-10-07 23:43 - 2011-10-07 22:16 - 503376780 ____A C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_-_01_[0557C1C6](1).mkv
2011-10-07 22:54 - 2011-10-07 22:54 - 0000000 ____D C:\Users\Mum\AppData\Local\{EABE6D5F-5FD0-4924-AC96-E36B784C0F7C}
2011-10-07 22:54 - 2011-10-07 22:54 - 0000000 ____D C:\Users\Mum\AppData\Local\{EA3B494E-050B-485F-A8AC-6879412EE109}
2011-10-07 22:14 - 2011-10-07 22:14 - 0000242 ____A C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_-_01_[0557C1C6].mkv
2011-10-07 22:09 - 2011-10-07 22:00 - 66444770 ____A C:\Users\Mum\Downloads\[gg]_Puella_Magi_Madoka_Magica_-_01_[0557C1C6].mkv.part
2011-10-07 21:42 - 2011-10-07 21:15 - 736422540 ____A C:\Users\Dana\Downloads\UWOnline_20100928.exe.part
2011-10-07 21:42 - 2011-10-07 21:15 - 712352436 ____A C:\Users\Dana\Downloads\OnRPG_edeneternal_install_20110528.exe.part
2011-10-07 18:58 - 2011-10-07 18:58 - 0747499 ____A C:\Users\Dana\Downloads\Wrye_Mash_84-27588.zip
2011-10-07 13:59 - 2011-10-07 13:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{5E51ED3F-D7D2-4F54-B83B-E44AF90B3753}
2011-10-07 01:59 - 2011-10-07 01:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{FCB83AF3-66B1-48BF-A235-433E723EA4A2}
2011-10-07 01:59 - 2011-10-07 01:59 - 0000000 ____D C:\Users\Mum\AppData\Local\{91FB4505-12B2-4908-BF50-B452B1E71CDB}
2011-10-06 17:25 - 2011-10-06 17:25 - 0020240 ____A C:\Users\Mum\Downloads\309618_2268830433440_1028964556_32484823_2016651666_n(2).jpg
2011-10-06 17:24 - 2011-10-06 17:24 - 0020240 ____A C:\Users\Mum\Downloads\309618_2268830433440_1028964556_32484823_2016651666_n(1).jpg
2011-10-06 17:23 - 2011-10-06 17:23 - 0020240 ____A C:\Users\Mum\Downloads\309618_2268830433440_1028964556_32484823_2016651666_n.jpg
2011-10-06 15:53 - 2011-10-06 15:53 - 0009418 ____A C:\Users\Mum\Downloads\313201_248987081814769_187581424622002_665693_1127712695_n.jpg
2011-10-06 13:59 - 2011-10-06 13:58 - 0000000 ____D C:\Users\Mum\AppData\Local\{751578A2-69A1-4967-B2BF-8F837ED1E57C}
2011-10-06 13:58 - 2011-10-06 13:58 - 0000000 ____D C:\Users\Mum\AppData\Local\{2D233B00-F50F-4D92-827D-0B52F7381BBA}
2011-10-06 01:05 - 2011-10-06 01:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{B2E694DF-FD35-4C36-8AEE-AF25F38719C7}
2011-10-06 01:05 - 2011-10-06 01:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{7C60FC1A-7187-44BC-8D5F-93B312B041FE}
2011-10-05 13:05 - 2011-10-05 13:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{9924944B-AC3A-4A7C-B645-91CD8D166DE3}
2011-10-05 13:05 - 2011-10-05 13:05 - 0000000 ____D C:\Users\Mum\AppData\Local\{4D5BF3D8-1204-4B90-BA80-DC8DE8275D1D}
2011-10-05 01:04 - 2011-10-05 01:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{0368A7E8-9F5B-4C27-AF42-EE512D97B338}
2011-10-05 01:04 - 2011-10-05 01:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{023F65EF-82A1-4772-BD93-DF58C40FDDAA}
2011-10-04 21:38 - 2011-10-04 17:31 - 0000000 ____D C:\Users\Dana\Downloads\Blood and Mud
2011-10-04 13:04 - 2011-10-04 13:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{A404FCC2-0EFE-4FC8-B086-7804354C4658}
2011-10-04 13:04 - 2011-10-04 13:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{6B53B5EF-6757-497D-9E7A-9DE630DAD656}
2011-10-04 01:03 - 2011-10-04 01:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{E7611FE6-954C-40F6-9A59-82EEE163B4CE}
2011-10-04 01:03 - 2011-10-04 01:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{D04F520B-4733-470E-BA1E-C81EF91A14C9}
2011-10-03 13:03 - 2011-10-03 13:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{E6E40B64-96D8-4631-A42C-5DEAC3F53975}
2011-10-03 13:03 - 2011-10-03 13:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{A05C549C-ED6B-4BDE-9988-A30E29888049}
2011-10-02 15:51 - 2011-10-02 15:51 - 0000000 ____D C:\Users\Mum\AppData\Local\{F414BFB6-DBEE-4ABE-8F3C-5898B562BFC9}
2011-10-02 15:51 - 2011-10-02 15:51 - 0000000 ____D C:\Users\Mum\AppData\Local\{684222BF-CA0A-47A8-B272-01E16A3F7A66}
2011-10-02 15:36 - 2011-10-02 15:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{074F9B17-6195-4247-BF36-21E241718285}
2011-10-02 15:35 - 2011-10-02 15:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{C7422649-68CB-4FE9-BE2E-E1CC7D0DE6D7}
2011-10-02 14:03 - 2010-04-17 14:07 - 0000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2011-10-02 13:52 - 2011-10-02 13:52 - 0000000 ____D C:\Users\Mum\AppData\Local\{3F9275BE-C33E-49FD-8A48-CAE28936FD6F}
2011-10-02 13:52 - 2011-10-02 13:52 - 0000000 ____D C:\Users\Mum\AppData\Local\{08D6E459-7A20-4D22-9C1B-E208D3B09A3D}
2011-10-02 13:43 - 2009-07-13 21:13 - 0741390 ____A C:\Windows\System32\PerfStringBackup.INI
2011-10-02 13:39 - 2011-10-02 13:39 - 0000408 ____A C:\Windows\Tasks\Ad-Aware Update (Weekly).job
2011-10-01 23:46 - 2011-08-16 14:20 - 0000000 ___RD C:\Program Files (x86)\Skype
2011-10-01 23:46 - 2011-08-16 14:20 - 0000000 ____D C:\Users\Mum\AppData\Roaming\Skype
2011-10-01 23:46 - 2011-08-16 14:20 - 0000000 ____D C:\Users\All Users\Skype
2011-10-01 23:46 - 2011-08-16 14:20 - 0000000 ____D C:\ProgramData\Skype
2011-10-01 18:36 - 2011-09-03 00:10 - 0000000 ____D C:\Users\Dana\Downloads\=------Oblivion Mods
2011-10-01 17:12 - 2011-05-07 17:30 - 0000064 ____A C:\Windows\SysWOW64\rp_stats.dat
2011-10-01 17:12 - 2011-05-07 17:30 - 0000044 ____A C:\Windows\SysWOW64\rp_rules.dat
2011-10-01 14:23 - 2011-10-01 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{7EAA5203-E269-4CFF-A24D-8E6ABECDB540}
2011-10-01 14:22 - 2011-10-01 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{B4EC65FC-119A-46AD-AE2A-C87BF6FECEFA}
2011-10-01 14:22 - 2010-04-16 03:23 - 0000000 ____D C:\Program Files (x86)\Mozilla Firefox
2011-10-01 00:24 - 2011-09-07 00:17 - 0000000 ____D C:\Users\Dana\AppData\Roaming\uTorrent
2011-09-30 14:06 - 2011-09-30 14:06 - 0000000 ____D C:\Users\Mum\AppData\Local\{EAB9FBC9-82F4-4127-93EB-1EAF9F0FE432}
2011-09-30 14:06 - 2011-09-30 14:06 - 0000000 ____D C:\Users\Mum\AppData\Local\{1BC815A8-70BB-4A1F-8218-9C736011635E}
2011-09-29 22:39 - 2011-09-29 22:39 - 0000205 ____A C:\Users\Dana\Desktop\Team Fortress 2.url
2011-09-29 22:35 - 2011-09-29 22:35 - 0000184 ____A C:\Users\Dana\Desktop\Rise of Immortals.url
2011-09-29 13:53 - 2011-09-29 13:53 - 0000000 ____D C:\Users\Mum\AppData\Local\{B26FAC65-F916-4442-918F-7AC7259A1272}
2011-09-29 13:53 - 2011-09-29 13:52 - 0000000 ____D C:\Users\Mum\AppData\Local\{18EB17F1-88F2-40E1-A918-28B9DACC984A}
2011-09-29 13:52 - 2011-06-22 13:27 - 0404640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2011-09-28 17:02 - 2011-09-28 17:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{7A0182B0-9464-4923-83D1-B705127D4253}
2011-09-28 17:02 - 2011-09-28 17:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{6B5554A7-9929-4F59-8C93-7FE645178954}
2011-09-28 16:46 - 2011-09-28 16:46 - 0000207 ____A C:\Users\Dana\Desktop\Forsaken World .url
2011-09-28 16:40 - 2011-09-28 16:40 - 0000207 ____A C:\Users\Dana\Desktop\Spiral Knights.url
2011-09-27 19:41 - 2010-04-16 17:33 - 49062856 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2011-09-27 19:38 - 2011-09-27 19:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{6D8158F9-3A06-4304-8D37-D22E8A58EBC4}
2011-09-27 19:38 - 2011-09-27 19:37 - 0000000 ____D C:\Users\Mum\AppData\Local\{5C3F0CB6-17EC-4634-86D6-51216DF32DB3}
2011-09-27 19:34 - 2011-09-27 19:34 - 0000000 ____A C:\Windows\setuperr.log
2011-09-26 17:57 - 2010-04-25 02:35 - 0000000 ____D C:\Users\Mum\Desktop\Danzey's Stuff
2011-09-26 13:49 - 2011-09-26 13:49 - 0000000 ____D C:\Users\Mum\AppData\Local\{ED5E1B14-6040-4756-A3FC-6E0F2C263715}
2011-09-26 13:49 - 2011-09-26 13:49 - 0000000 ____D C:\Users\Mum\AppData\Local\{AF54E38C-CD66-4A78-A3AF-5C269CB23B3B}
2011-09-25 22:51 - 2011-09-25 22:51 - 0000000 ____D C:\Users\Mum\Desktop\centrelink
2011-09-25 14:19 - 2011-09-25 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{40748038-5AF3-4260-A7DF-B3AC46C3545E}
2011-09-25 14:19 - 2011-09-25 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{0D446DFB-E4A5-4BCC-B500-14575CFC5B5E}
2011-09-24 14:22 - 2011-09-24 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{D08A83A2-3BF3-42A0-B20F-CD74EDD64634}
2011-09-24 14:22 - 2011-09-24 14:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{5150180A-43AC-436E-8D26-4076644CB024}
2011-09-23 14:45 - 2011-09-23 14:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{DB5BF5B3-640E-4B0C-8A98-B182BCA1D20C}
2011-09-23 14:45 - 2011-09-23 14:45 - 0000000 ____D C:\Users\Mum\AppData\Local\{63BC173E-49B5-40B0-B9F6-910D35F71D72}
2011-09-22 14:10 - 2011-09-22 14:10 - 0000000 ____D C:\Users\Mum\AppData\Local\{F676C0F0-460B-49AB-9125-72161C70B053}
2011-09-22 14:10 - 2011-09-22 14:10 - 0000000 ____D C:\Users\Mum\AppData\Local\{05579D4F-7522-49C1-BBBF-1F9F8EBC65AE}
2011-09-21 23:31 - 2011-09-21 23:31 - 0112003 ____A C:\Users\Mum\Desktop\youth allowance.pdf
2011-09-21 15:04 - 2011-09-21 15:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{7C183128-335B-4D86-A230-53B4BB052861}
2011-09-21 15:03 - 2011-09-21 15:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{D5EF3F70-8247-4D3E-BF55-BB9EA08A8920}
2011-09-20 13:44 - 2011-09-20 13:44 - 0000000 ____D C:\Users\Mum\AppData\Local\{76BC0091-0420-4A50-A7B9-FE511BF9442E}
2011-09-20 13:44 - 2011-09-20 13:44 - 0000000 ____D C:\Users\Mum\AppData\Local\{4E573FE8-D5C7-45D4-9C2D-35583DD8E521}
2011-09-19 14:19 - 2011-09-19 14:18 - 0000000 ____D C:\Users\Mum\AppData\Local\{61F41DD8-5C7E-425E-B299-91C8ECFC17D9}
2011-09-19 14:18 - 2011-09-19 14:18 - 0000000 ____D C:\Users\Mum\AppData\Local\{5FE7947D-6629-462C-9250-429C9507DBA1}
2011-09-18 14:53 - 2011-09-18 14:53 - 0000000 ____D C:\Users\Mum\AppData\Local\{9AFE7360-3CCC-40D6-BD75-9B82D7857C93}
2011-09-18 14:53 - 2011-09-18 14:52 - 0000000 ____D C:\Users\Mum\AppData\Local\{D3F9615B-67E6-45BC-B94C-57EC5B3573F5}
2011-09-17 23:20 - 2011-09-17 23:20 - 0438232 ____A C:\Users\Mum\Downloads\A99Y_CoiledEarwire.AHJ019.pdf
2011-09-17 23:19 - 2011-09-17 23:19 - 0940783 ____A C:\Users\Mum\Downloads\J4M1L0L4_HolidayStardust.JML003.pdf
2011-09-17 23:19 - 2011-09-17 23:19 - 0785535 ____A C:\Users\Mum\Downloads\80881_10MinutePendant.MYI009.pdf
2011-09-17 23:18 - 2011-09-17 23:18 - 0327651 ____A C:\Users\Mum\Downloads\80881_AddingSafetyChain.MYI008.pdf
2011-09-17 23:14 - 2011-09-17 23:14 - 0603344 ____A C:\Users\Mum\Downloads\SH3R1D4n_FavoriteBasicHoops.JJD004.pdf
2011-09-17 23:14 - 2011-09-17 23:14 - 0593418 ____A C:\Users\Mum\Downloads\80881_OldFashionedChain.MYI007.pdf
2011-09-17 23:13 - 2011-09-17 23:13 - 1761614 ____A C:\Users\Mum\Downloads\Kr1stin_SpiralAdorned.KSJ006.pdf
2011-09-17 23:13 - 2011-09-17 23:13 - 0546383 ____A C:\Users\Mum\Downloads\A99Y_Figure8Chain.AHJ020.pdf
2011-09-17 17:57 - 2011-09-17 17:57 - 1613001 ____A C:\Users\Mum\Downloads\TwinHeartsRing.DCHFOC01.pdf
2011-09-17 17:55 - 2011-09-17 17:55 - 1653336 ____A C:\Users\Mum\Downloads\K1K1_CHAEARCUFFs.BNQ006.pdf
2011-09-17 15:17 - 2011-09-17 15:17 - 0000000 ____D C:\Users\Mum\AppData\Local\{84A53D9B-1DB0-4B4D-9001-270ADE17E6E8}
2011-09-17 15:17 - 2011-09-17 15:17 - 0000000 ____D C:\Users\Mum\AppData\Local\{16F736D4-8729-40DA-B894-08C8713C94EB}
2011-09-16 20:57 - 2011-09-16 20:57 - 0000000 ____D C:\Users\Mum\AppData\Local\{4CFE6CA2-7B39-449D-BEEF-D0EFB4619537}
2011-09-16 20:57 - 2011-09-16 20:57 - 0000000 ____D C:\Users\Mum\AppData\Local\{1C6C7422-7DDE-4EF0-84CD-4A99B1439A3D}
2011-09-16 15:04 - 2011-09-16 15:04 - 0000000 ____D C:\Users\Mum\AppData\Local\{35A215B7-6B8F-4067-BE7F-A951597F23C5}
2011-09-15 14:39 - 2011-09-15 14:39 - 0000000 ____D C:\Users\Mum\AppData\Local\{25CCBBA2-E36F-48C6-BDA0-0BB309499DC7}
2011-09-15 14:39 - 2011-09-15 14:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{B31FB3CA-2830-440E-9F9C-D645BFAE59D5}
2011-09-15 02:47 - 2009-10-12 19:15 - 0000000 ____D C:\Users\All Users\Microsoft Help
2011-09-15 02:47 - 2009-10-12 19:15 - 0000000 ____D C:\ProgramData\Microsoft Help
2011-09-14 18:11 - 2011-09-14 18:11 - 0001064 ____A C:\Users\Public\Desktop\Ad-Aware.lnk
2011-09-14 18:11 - 2011-09-14 18:11 - 0000000 ____D C:\Program Files (x86)\Lavasoft
2011-09-14 18:11 - 2010-04-21 17:23 - 0000000 ____D C:\Users\All Users\Lavasoft
2011-09-14 18:11 - 2010-04-21 17:23 - 0000000 ____D C:\ProgramData\Lavasoft
2011-09-14 17:33 - 2011-09-14 17:32 - 10268672 ____A C:\Users\Mum\Downloads\Ad-Aware95Install.msi
2011-09-14 14:19 - 2011-09-14 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{F7D050C6-DC50-4F25-A85A-D2A6578A51DE}
2011-09-14 14:19 - 2011-09-14 14:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{A40381A0-D1C5-4B3F-853C-E06CC0563F62}
2011-09-12 15:01 - 2011-09-12 15:01 - 0000000 ____D C:\Users\Mum\AppData\Local\{404A8AEF-EE5C-438E-9B57-137A253159D7}
2011-09-12 15:01 - 2011-09-12 15:00 - 0000000 ____D C:\Users\Mum\AppData\Local\{D3128E20-41D7-498B-AD1A-84350A5F3754}
2011-09-11 22:30 - 2011-09-06 21:33 - 0001866 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2011-09-11 22:30 - 2011-09-06 21:33 - 0001864 ____A C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
2011-09-11 17:10 - 2011-09-11 17:10 - 0000000 ____D C:\Users\Mum\AppData\Local\{7319F895-D983-4702-9BA8-44317DC9D579}
2011-09-11 17:10 - 2011-09-11 17:10 - 0000000 ____D C:\Users\Mum\AppData\Local\{56A9D622-D8C2-489F-80A0-6E1D3FFC1E3A}
2011-09-11 15:49 - 2010-06-15 14:25 - 0000000 ____A C:\Windows\SysWOW64\config.nt
2011-09-11 12:22 - 2011-09-11 12:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{EC1142AF-4853-4235-B6EB-573F320901D9}
2011-09-11 12:22 - 2011-09-11 12:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{3966183C-B295-405B-BE7B-9B67F927D2E1}
2011-09-10 23:07 - 2011-09-10 23:07 - 0000000 ____D C:\Users\Mum\AppData\Local\{A3419DE4-9657-4F44-867D-2B328088E6E5}
2011-09-10 23:07 - 2011-09-10 23:07 - 0000000 ____D C:\Users\Mum\AppData\Local\{89496410-ECAB-4658-A6A2-38842132F0CF}
2011-09-10 21:17 - 2011-07-16 02:20 - 0000000 ____D C:\Users\Dana\AppData\Local\Oblivion
2011-09-10 21:11 - 2011-09-10 20:59 - 0000000 ____D C:\Python27
2011-09-10 20:59 - 2010-12-30 00:17 - 0000000 ____D C:\Python25
2011-09-10 17:52 - 2011-09-09 20:14 - 0000000 ____D C:\Users\Dana\Downloads\=------Sims 3
2011-09-10 14:37 - 2011-09-10 14:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{FC913019-3A26-42C5-A315-C867028FA1C3}
2011-09-10 14:36 - 2011-09-10 14:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{6E705BA7-BC61-4CB1-867F-B2FDC33466E4}
2011-09-10 02:48 - 2011-09-10 02:48 - 0000000 ____D C:\Users\Mum\AppData\Local\{BF847578-02EE-4DE2-878F-5ADFBF0A0144}
2011-09-10 02:48 - 2011-09-10 02:48 - 0000000 ____D C:\Users\Mum\AppData\Local\{6CCC6ABC-2002-471C-9113-645A3921FDD5}
2011-09-09 21:30 - 2010-12-29 22:31 - 0000023 ____A C:\Windows\BlendSettings.ini
2011-09-09 14:28 - 2011-09-09 14:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{5E87EDCC-6BAC-44B4-B828-42D078BC3FEA}
2011-09-09 14:27 - 2011-09-09 14:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{D59EE5D8-8BE6-4F0C-8960-416F78721FE7}
2011-09-08 22:16 - 2011-09-08 22:16 - 0000000 ____D C:\Users\Mum\AppData\Local\{D93A4748-76A1-4AE9-B7DE-D10BB3E95666}
2011-09-08 22:16 - 2011-09-08 22:16 - 0000000 ____D C:\Users\Mum\AppData\Local\{4990F9F0-29CB-40BC-AD7A-E08A621E06CA}
2011-09-08 13:23 - 2011-09-08 13:23 - 0000000 ____D C:\Users\Mum\AppData\Local\{98F8ABE3-FBBA-4BC0-AFE0-CA5A563283AB}
2011-09-08 13:23 - 2011-09-08 13:23 - 0000000 ____D C:\Users\Mum\AppData\Local\{0A724D2B-12DE-4997-AFED-52C3E8410066}
2011-09-07 23:35 - 2011-09-07 23:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{B960DE26-0F46-41D0-A227-8641708E5564}
2011-09-07 23:35 - 2011-09-07 23:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{409F9A99-431F-4612-8FA2-538C68554FB6}
2011-09-07 13:20 - 2011-09-07 13:20 - 0000000 ____D C:\Users\Mum\AppData\Local\{E335A2F3-5022-4869-A7B9-B21DAF9486A3}
2011-09-07 13:20 - 2011-09-07 13:20 - 0000000 ____D C:\Users\Mum\AppData\Local\{AD0657B3-94B1-47BA-8797-D2E2A3F2464E}
2011-09-07 03:24 - 2011-09-07 03:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{6F94BE33-712B-4848-94E5-DC2D4F99E6BB}
2011-09-07 03:24 - 2011-09-07 03:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{370C8629-B1C7-4AF7-832F-AD4EB5B7C798}
2011-09-06 22:13 - 2011-08-12 19:49 - 0000000 ____D C:\Users\Dana\Downloads\=------Morrowind Mods
2011-09-06 22:12 - 2011-07-06 21:09 - 0000000 ____D C:\Users\Dana\AppData\Roaming\Estsoft
2011-09-06 22:05 - 2011-09-06 22:05 - 0000207 ____A C:\Users\Dana\Desktop\The Elder Scrolls IV Oblivion - Game of the Year Edition.url
2011-09-06 21:33 - 2011-09-06 21:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{1394D2EE-FB1B-4850-9106-F9ED044F4932}
2011-09-06 21:33 - 2011-09-06 21:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{605E83FD-9557-4056-9E1C-66F28028CA1B}
2011-09-06 13:36 - 2011-09-06 13:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{F3EB492F-36F3-4D4F-B84E-20B59EC6A4F4}
2011-09-06 13:36 - 2011-09-06 13:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{6F349438-0412-4540-961B-8E3718E1D03B}
2011-09-06 12:45 - 2011-01-17 22:22 - 0254400 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2011-09-06 12:45 - 2010-06-30 02:27 - 0041184 ____A (AVAST Software) C:\Windows\avastSS.scr
2011-09-06 12:45 - 2010-06-15 14:25 - 0199304 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2011-09-06 12:38 - 2011-05-20 19:08 - 0601944 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2011-09-06 12:38 - 2010-06-15 14:25 - 0301912 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2011-09-06 12:36 - 2010-06-15 14:25 - 0065368 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2011-09-06 12:36 - 2010-06-15 14:25 - 0058200 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2011-09-06 12:36 - 2010-06-15 14:25 - 0042328 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr.sys
2011-09-06 12:36 - 2010-06-15 14:25 - 0024408 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2011-09-05 13:24 - 2011-09-05 13:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{9C7398CA-6203-405F-B675-A0F18DF8CB1D}
2011-09-05 13:24 - 2011-09-05 13:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{76A00A10-2562-420C-B104-C57DC6250BA6}
2011-09-04 13:37 - 2011-09-04 13:37 - 0000000 ____D C:\Users\Mum\AppData\Local\{CABF407E-D177-4520-9FE0-92AD099D4456}
2011-09-04 13:37 - 2011-09-04 13:37 - 0000000 ____D C:\Users\Mum\AppData\Local\{C3DB3A9E-6A70-4C89-9285-C6F55951736B}
2011-09-03 15:03 - 2011-09-03 15:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{A35483FF-A5B2-4589-8FBC-320FD28C39AA}
2011-09-03 15:03 - 2011-09-03 15:03 - 0000000 ____D C:\Users\Mum\AppData\Local\{95DE9034-7FC0-4E10-A450-376C5D578702}
2011-09-02 23:26 - 2011-03-18 16:59 - 0000000 ____D C:\Users\All Users\NexonUS
2011-09-02 23:26 - 2011-03-18 16:59 - 0000000 ____D C:\ProgramData\NexonUS
2011-09-02 16:33 - 2011-09-02 16:33 - 1913233 ____A C:\Users\Mum\Desktop\t hub manual.pdf
2011-09-02 14:38 - 2011-09-02 14:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{F8A6711E-5AC6-4204-ABB3-658E42082433}
2011-09-02 14:38 - 2011-09-02 14:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{E229A5CB-9604-46D4-A348-F856111AAC4D}
2011-09-01 13:23 - 2011-09-01 13:23 - 0000000 ____D C:\Users\Mum\AppData\Local\{5F89FC42-88DE-4EB9-8D72-0D38745C33B9}
2011-09-01 13:23 - 2011-09-01 13:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{62BACE98-C260-4F57-9C62-585F70B5D2FA}
2011-08-31 23:11 - 2011-08-31 23:11 - 1975863 ____A C:\Users\Mum\Downloads\JMD-Chain-Maille.pdf
2011-08-31 13:27 - 2011-08-31 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{F5F0AE99-AEEE-4054-8CC1-643007D6EDCB}
2011-08-31 13:27 - 2011-08-31 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{4F474C13-742A-42D0-9798-BD96822D1F7F}
2011-08-30 16:19 - 2011-08-30 16:19 - 0000000 ____D C:\Users\Mum\AppData\Local\{9CE1DF3A-2F4B-4C41-A26E-4A06C16FCDBD}
2011-08-30 16:19 - 2011-08-30 16:18 - 0000000 ____D C:\Users\Mum\AppData\Local\{1094790A-4F23-4C0A-9E39-EA42D3226531}
2011-08-28 15:22 - 2011-08-28 15:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{9B2137E8-0EA6-4F00-9FF3-D0BC7D6A77CD}
2011-08-28 15:22 - 2011-08-28 15:22 - 0000000 ____D C:\Users\Mum\AppData\Local\{1989BCB0-65F0-497F-BBF1-97DF5D1BE0F7}
2011-08-27 15:14 - 2011-08-27 15:14 - 0000000 ____D C:\Users\Mum\AppData\Local\{8594A1D5-C2F2-42C0-A03A-538C43767D68}
2011-08-27 15:14 - 2011-08-27 15:14 - 0000000 ____D C:\Users\Mum\AppData\Local\{6A78AD27-F35C-4E9D-B297-9DC27B84DE12}
2011-08-25 01:15 - 2011-08-25 01:15 - 0001787 ____A C:\Users\Public\Desktop\iTunes.lnk
2011-08-25 01:15 - 2011-08-25 01:14 - 0000000 ____D C:\Program Files\iTunes
2011-08-25 01:15 - 2011-08-25 01:14 - 0000000 ____D C:\Program Files (x86)\iTunes
2011-08-25 01:14 - 2011-08-25 01:14 - 0000000 ____D C:\Program Files\iPod
2011-08-24 15:02 - 2011-08-24 15:01 - 0000000 ____D C:\Users\Mum\AppData\Local\{CEA8A13D-CED9-4D51-AC12-8252DAC6B545}
2011-08-24 15:01 - 2011-08-24 15:01 - 0000000 ____D C:\Users\Mum\AppData\Local\{95D30690-49BB-49DC-82D3-C98EA955F00C}
2011-08-24 15:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\rescache
2011-08-23 16:01 - 2011-08-23 16:00 - 0000000 ____D C:\Users\Mum\AppData\Local\{5C87CC34-4E81-4F96-8E3D-DE3B41F9F937}
2011-08-23 16:00 - 2011-08-23 16:00 - 0000000 ____D C:\Users\Mum\AppData\Local\{EDA45C2B-6C10-4D9B-8789-4287C0682B4E}
2011-08-21 13:26 - 2011-08-21 13:25 - 0000000 ____D C:\Users\Mum\AppData\Local\{9D23EBDE-65A0-4EDA-B01D-FDA989E250F6}
2011-08-21 13:25 - 2011-08-21 13:25 - 0000000 ____D C:\Users\Mum\AppData\Local\{CE3067AE-A7E7-4AEE-B5E8-0673A1A74105}
2011-08-20 14:39 - 2011-08-20 14:39 - 0000000 ____D C:\Users\Mum\AppData\Local\{7D3AEEE1-CBE6-4845-B3EA-704D7F498105}
2011-08-20 14:39 - 2011-08-20 14:38 - 0000000 ____D C:\Users\Mum\AppData\Local\{A7578C9B-3B35-4D4B-8FBE-8DB17FEE7087}
2011-08-19 14:21 - 2011-08-19 14:21 - 0000000 ____D C:\Users\Mum\AppData\Local\{CAC59AA4-46B9-40CE-821A-0C3BF339632B}
2011-08-19 14:21 - 2011-08-19 14:21 - 0000000 ____D C:\Users\Mum\AppData\Local\{01ADBCE5-ABE9-4751-A371-0078065225E8}
2011-08-18 17:27 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\NDF
2011-08-18 17:11 - 2010-04-22 21:24 - 0000000 ____D C:\Users\Mum\AppData\Roaming\QuickScan
2011-08-18 13:34 - 2011-08-18 13:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{A531065B-A5C9-448B-A3C4-467AE65286E7}
2011-08-18 13:33 - 2011-08-18 13:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{C777658B-93D6-4AD4-B706-B0B2CDE63B79}
2011-08-17 21:25 - 2011-09-14 18:11 - 0069376 ____A (Lavasoft AB) C:\Windows\System32\Drivers\Lbd.sys
2011-08-17 13:24 - 2011-08-17 13:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{7C1F0605-DB63-404F-B86C-11B4CB8FF852}
2011-08-17 13:24 - 2011-08-17 13:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{5C95079F-C12E-494A-B971-96BC38AC52A5}
2011-08-16 14:19 - 2011-08-16 14:19 - 1081480 ____A (Skype Technologies S.A.) C:\Users\Mum\Downloads\SkypeSetup.exe
2011-08-16 13:27 - 2011-08-16 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{B5E802E5-3429-4948-A7F0-314DE4842315}
2011-08-16 13:27 - 2011-08-16 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{2F465B63-0358-474F-9019-0080BCFF4E7D}
2011-08-16 12:58 - 2009-07-13 21:08 - 0032564 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2011-08-15 13:30 - 2011-08-15 13:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{77FFCF9E-E5F6-4F3F-B970-6CF35960DA70}
2011-08-15 13:30 - 2011-08-15 13:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{342D9B4E-67F6-4F78-BD8C-40782CD83AF3}
2011-08-15 00:41 - 2011-08-15 00:41 - 0016654 ____A C:\Users\Mum\Downloads\Assessment_Guide.pdf
2011-08-14 13:21 - 2011-08-14 13:21 - 0000000 ____D C:\Users\Mum\AppData\Local\{F7007DD9-1C6E-49D8-9722-F2C271D4B8D9}
2011-08-14 13:21 - 2011-08-14 13:21 - 0000000 ____D C:\Users\Mum\AppData\Local\{900E6A22-F5E1-4FE2-BC9D-802EAE989B66}
2011-08-13 23:15 - 2011-08-13 23:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{C3EC6446-AAEB-44AC-978C-62354101C3E4}
2011-08-13 23:15 - 2011-08-13 23:15 - 0000000 ____D C:\Users\Mum\AppData\Local\{3BB867C7-8D07-4B8B-93BE-993254584110}
2011-08-13 21:03 - 2011-08-13 03:22 - 0000000 ____D C:\Users\Dana\Downloads\=------Other
2011-08-13 14:55 - 2011-08-13 14:54 - 0000000 ____D C:\Users\Mum\AppData\Local\{D910F115-BD7E-45E7-8623-FE808DEB57E3}
2011-08-13 14:54 - 2011-08-13 14:54 - 0000000 ____D C:\Users\Mum\AppData\Local\{BE2941A1-62B6-4CE0-82AD-366BE09818DB}
2011-08-13 03:27 - 2011-08-13 03:27 - 0000000 ____D C:\Users\Dana\Documents\PCSX2
2011-08-13 03:25 - 2010-08-04 00:00 - 0000000 ____D C:\Windows\SysWOW64\directx
2011-08-13 01:02 - 2011-08-13 01:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{7A64CA61-F276-4089-A821-769D9EC8317C}
2011-08-13 01:02 - 2011-08-13 01:02 - 0000000 ____D C:\Users\Mum\AppData\Local\{510DBEB4-7663-4FB8-B60E-D04C79076F48}
2011-08-12 20:43 - 2011-08-12 20:38 - 0000000 ____D C:\Users\Dana\AppData\Local\Microsoft Games
2011-08-12 19:31 - 2011-05-11 23:58 - 0000000 ____D C:\Users\Dana\AppData\Local\VirtualStore
2011-08-12 17:49 - 2011-08-12 17:49 - 0000207 ____A C:\Users\Dana\Desktop\Beat Hazard.url
2011-08-12 17:48 - 2011-08-12 17:48 - 0000207 ____A C:\Users\Dana\Desktop\The Elder Scrolls III Morrowind - Game of the Year Edition.url
2011-08-12 17:18 - 2011-08-12 17:18 - 0000000 ____D C:\Users\Mum\AppData\Local\{5879770C-5BF9-43C3-94B8-384699818167}
2011-08-12 17:18 - 2011-08-12 17:18 - 0000000 ____D C:\Users\Mum\AppData\Local\{0D35E9B2-098B-4F41-9F60-D40EB0BA7512}
2011-08-12 17:01 - 2011-08-12 17:01 - 0000644 ____A C:\Users\Public\Desktop\Steam.lnk
2011-08-12 16:50 - 2011-07-30 23:54 - 0000000 ____D C:\Users\Dana\Documents\Electronic Arts
2011-08-12 16:50 - 2009-10-12 18:49 - 0000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2011-08-12 14:55 - 2011-08-12 14:55 - 0000000 ____D C:\Users\Mum\AppData\Local\{F7408C30-CDCD-49EE-ADA6-AAD28A287A05}
2011-08-12 14:55 - 2011-08-12 14:55 - 0000000 ____D C:\Users\Mum\AppData\Local\{8B37D89E-4CE5-4160-8111-FFF4498B2964}
2011-08-11 13:27 - 2011-08-11 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{551B3AB2-0771-4484-B29E-F75BC52F6515}
2011-08-11 13:27 - 2011-08-11 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{4CAF4509-5B7B-43FA-AA3D-D058F946C9DE}
2011-08-10 23:51 - 2011-08-10 23:51 - 0001849 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2011-08-10 23:51 - 2011-08-10 23:51 - 0000000 ____D C:\Program Files (x86)\QuickTime
2011-08-10 13:27 - 2011-08-10 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{A0197CAA-0583-41A8-B0A3-7805B9752610}
2011-08-10 13:27 - 2011-08-10 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{221B72AF-DCB6-4F83-BD0F-261CF0C7861E}
2011-08-09 14:21 - 2011-08-09 14:21 - 0000000 ____D C:\Users\Mum\AppData\Local\{FCFDEA3B-EB19-47A3-A379-62214E607BD5}
2011-08-09 14:21 - 2011-08-09 14:21 - 0000000 ____D C:\Users\Mum\AppData\Local\{6222C5BC-CA83-4A87-ABC1-80A418F5568F}
2011-08-08 14:24 - 2011-08-08 14:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{8AA67E1B-8139-430E-90B1-2AA879061892}
2011-08-04 22:07 - 2011-08-04 22:07 - 0000025 ____A C:\Windows\cdplayer.ini
2011-08-03 23:49 - 2011-08-03 23:49 - 0000000 ____D C:\Users\Dana\AppData\Local\Apple
2011-08-03 00:47 - 2011-08-03 00:47 - 0000000 ____D C:\Users\Dana\AppData\Roaming\EPSON
2011-08-03 00:44 - 2011-06-21 18:29 - 0000000 ____D C:\Users\Dana\AppData\Roaming\Adobe
2011-08-03 00:43 - 2011-08-03 00:43 - 0000000 ____D C:\Users\Dana\AppData\Local\IsolatedStorage
2011-08-01 14:37 - 2011-08-01 14:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{8EB0D593-3790-4278-AD57-98D818C1EE25}
2011-08-01 02:36 - 2011-08-01 02:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{B24AF72A-F55B-4294-9178-D7F5F429AEC5}
2011-07-31 14:36 - 2011-07-31 14:36 - 0000000 ____D C:\Users\Mum\AppData\Local\{FE4DAEC5-85ED-43C6-B2C4-9F319C342376}
2011-07-31 02:36 - 2011-07-31 02:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{FCD354A7-001A-4F9D-8ADD-78F1E96BF66D}
2011-07-30 22:14 - 2011-07-30 22:14 - 0000000 ____D C:\Users\All Users\Electronic Arts
2011-07-30 22:14 - 2011-07-30 22:14 - 0000000 ____D C:\ProgramData\Electronic Arts
2011-07-30 22:13 - 2011-07-30 22:13 - 0000000 ____D C:\Program Files (x86)\Electronic Arts
2011-07-30 22:12 - 2011-07-30 22:12 - 0000000 ____D C:\Program Files (x86)\Microsoft WSE
2011-07-30 14:35 - 2011-07-30 14:35 - 0000000 ____D C:\Users\Mum\AppData\Local\{CFBBBDF3-694F-4736-97FF-BBAD8E08DB8E}
2011-07-29 23:24 - 2011-07-29 23:24 - 0000000 ____D C:\Users\Mum\AppData\Local\{7A65606E-5F5B-476B-B76F-02DC21F6C84E}
2011-07-29 23:15 - 2010-12-28 22:07 - 0000000 ____D C:\Users\Mum\AppData\Roaming\SystemRequirementsLab
2011-07-29 23:15 - 2010-12-28 22:07 - 0000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2011-07-29 03:33 - 2011-07-29 03:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{FBF219D8-A9E4-43A5-BC64-43C8A493CD78}
2011-07-28 21:18 - 2011-07-28 21:18 - 0132281 ____A C:\Users\Mum\Downloads\Application10542009(2).pdf
2011-07-28 15:33 - 2011-07-28 15:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{9BC32A2A-1947-477E-A285-C3935E6BEA21}
2011-07-28 03:33 - 2011-07-28 03:33 - 0000000 ____D C:\Users\Mum\AppData\Local\{01F1D497-7DDF-4496-B087-EE645ED244EF}
2011-07-28 01:20 - 2011-07-28 01:20 - 2265534 ____A C:\Users\Mum\Downloads\CM_5FREEFlowers7.25.pdf
2011-07-27 15:33 - 2011-07-27 15:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{63D15FAE-2462-4AD3-AD04-B61F4EC4FEB7}
2011-07-27 03:32 - 2011-07-27 03:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{51AE47DC-EABB-4608-BC13-AD043AFD740D}
2011-07-26 15:32 - 2011-07-26 15:32 - 0000000 ____D C:\Users\Mum\AppData\Local\{44ED5B81-5FD3-4A7B-84F2-A52A16812BFC}
2011-07-26 03:31 - 2011-07-26 03:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{9928167A-066A-41C9-A30E-E978C1A34552}
2011-07-25 15:31 - 2011-07-25 15:31 - 0000000 ____D C:\Users\Mum\AppData\Local\{BDBE81D2-770F-4622-AAE7-85304872BD0F}
2011-07-25 14:38 - 2011-07-25 14:38 - 0132259 ____A C:\Users\Mum\Downloads\Application10542009(1).pdf
2011-07-25 03:30 - 2011-07-25 03:30 - 0000000 ____D C:\Users\Mum\AppData\Local\{6B2199A6-CAED-4A0F-82E8-8FEE0F9BC95F}
2011-07-25 00:01 - 2011-07-25 00:01 - 0132154 ____A C:\Users\Mum\Downloads\Application10542009.pdf
2011-07-24 15:30 - 2011-07-24 15:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{8920018B-5B80-42B8-91F1-71662B3B593A}
2011-07-24 03:29 - 2011-07-24 03:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{308FDB3D-0927-4E4C-85D5-A5FD9EDCE6F2}
2011-07-23 22:00 - 2011-07-23 21:27 - 0000000 ____D C:\Users\Dana\AppData\Roaming\Real
2011-07-23 15:28 - 2011-07-23 15:28 - 0000000 ____D C:\Users\Mum\AppData\Local\{2E765861-323F-45B2-8439-CDBC0A269E7C}
2011-07-23 02:44 - 2011-07-23 02:44 - 0000000 ____D C:\Users\Mum\AppData\Local\{0C593DF4-C528-46BD-8734-E0215C1575DD}
2011-07-22 14:43 - 2011-07-22 14:43 - 0000000 ____D C:\Users\Mum\AppData\Local\{80F59FE9-5A73-4C04-AFD7-511F33169898}
2011-07-22 01:29 - 2011-07-22 01:29 - 0000000 ____D C:\Users\Mum\AppData\Local\{BC68DF6B-0743-4F16-B72A-427A00F47816}
2011-07-21 21:54 - 2011-05-11 23:58 - 0000000 ____D C:\Users\Dana\AppData\LocalLow
2011-07-21 21:54 - 2011-05-11 23:58 - 0000000 ____D C:\Users\Dana\AppData\Local\Adobe
2011-07-21 21:52 - 2011-08-10 03:41 - 17782272 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-07-21 21:42 - 2011-08-10 03:41 - 2303488 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2011-07-21 21:40 - 2011-08-10 03:41 - 10886144 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-07-21 21:36 - 2011-08-10 03:41 - 1389056 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-07-21 21:36 - 2011-08-10 03:41 - 1344512 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-07-21 21:35 - 2011-08-10 03:41 - 0237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-07-21 21:34 - 2011-08-10 03:41 - 0085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-07-21 21:33 - 2011-08-10 03:41 - 2143232 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-07-21 21:33 - 2011-08-10 03:41 - 0818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2011-07-21 21:32 - 2011-08-10 03:41 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-07-21 21:32 - 2011-08-10 03:41 - 0096256 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-07-21 21:30 - 2011-08-10 03:41 - 0248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2011-07-21 18:54 - 2011-08-10 03:41 - 1797632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2011-07-21 18:54 - 2011-08-10 03:41 - 12273664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2011-07-21 18:51 - 2011-08-10 03:41 - 9704448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2011-07-21 18:49 - 2011-08-10 03:41 - 1102848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2011-07-21 18:48 - 2011-08-10 03:41 - 1126912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2011-07-21 18:47 - 2011-08-10 03:41 - 0231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2011-07-21 18:46 - 2011-08-10 03:41 - 0065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2011-07-21 18:45 - 2011-08-10 03:41 - 0716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2011-07-21 18:44 - 2011-08-10 03:41 - 2382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2011-07-21 18:44 - 2011-08-10 03:41 - 1791488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2011-07-21 18:44 - 2011-08-10 03:41 - 0072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2011-07-21 18:43 - 2011-08-10 03:41 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2011-07-21 13:28 - 2011-07-21 13:28 - 0000000 ____D C:\Users\Mum\AppData\Local\{56216927-A078-4496-BFD5-DA56EB02A964}
2011-07-21 01:28 - 2011-07-21 01:28 - 0000000 ____D C:\Users\Mum\AppData\Local\{D9A53FD5-857C-492D-817A-65833C50FDB1}
2011-07-21 00:08 - 2011-07-21 00:08 - 0000000 ____D C:\Program Files\Bonjour
2011-07-21 00:08 - 2011-07-21 00:08 - 0000000 ____D C:\Program Files (x86)\Bonjour
2011-07-20 23:43 - 2011-07-20 23:42 - 3448656 ____A C:\Users\Mum\Downloads\Xtudos_alternate_Bruses-28977.rar
2011-07-20 13:27 - 2011-07-20 13:27 - 0000000 ____D C:\Users\Mum\AppData\Local\{2C99324C-32FB-4137-88FD-034F81C681A0}
2011-07-20 13:06 - 2010-07-28 23:54 - 0000679 ____A C:\Windows\SysWOW64\TVersityMediaServer.log
2011-07-20 01:23 - 2011-07-20 01:23 - 0000000 ____D C:\Users\Mum\AppData\Local\{1425A6DF-AF28-450D-BC0B-DE5EDCE60C1E}
2011-07-20 01:19 - 2011-07-20 01:19 - 0084480 ____A C:\Users\Mum\Desktop\Tax Invoice.doc
2011-07-20 00:27 - 2011-07-20 00:27 - 0117039 ____A C:\Users\Mum\Desktop\BDM_ProofOfIdentity_Web.pdf

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 17%
Total physical RAM: 4095.14 MB
Available physical RAM: 3385 MB
Total Pagefile: 4093.29 MB
Available Pagefile: 3371.06 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

======================= Partitions =========================

1 Drive c: (Acer) (Fixed) (Total:291.95 GB) (Free:46.69 GB) NTFS
2 Drive e: (DATA) (Fixed) (Total:292.12 GB) (Free:166.66 GB) NTFS
3 Drive f: (PQSERVICE) (Fixed) (Total:12 GB) (Free:2.39 GB) NTFS
4 Drive g: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.25 GB) (Free:0 GB) UDF
5 Drive h: (FISHY) (Removable) (Total:0.99 GB) (Free:0.17 GB) FAT
11 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
12 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==========================================================

Last Boot: 2011-10-11 12:48

======================= End Of Log ==========================

#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,558 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:11:01 PM

Posted 17 October 2011 - 11:38 AM

Lets try this fix:

Download the enclosed file to the USB drive, then insert it in the ailing computer.

Now please enter System Recovery Options.

Run FRST as you did before and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Attempt to boot in Normal mode and let me know the outcome.

Edited by JSntgRvr, 17 October 2011 - 11:38 AM.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#9 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 17 October 2011 - 04:02 PM

Still black screen with white cursor. Here's the log:

Fix result of Farbars's Recovery Tool (FRST written by farbar version 2.2.4)
Ran by SYSTEM at 2011-10-18 07:55:53 R:1
Running from H:\

==============================================


========= bcdedit /set {default} winpe no =========

The operation completed successfully.

========= End of CMD: =========


=========== Control: ===========

The operation completed successfully.

==== End of Control: ====

==== End of Fixlog ====

#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,558 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:11:01 PM

Posted 17 October 2011 - 06:38 PM

Lets check the Master Boot Record. This fix will also remove the System Restore Command it was created upon your request from the registry.

Download MBRFix from here.

Save and extract its contents to the desktop. Once extracted, open the folder drive and only copy MBRFix64.exe to the USB drive.

Also download the enclosed file.

Save this to the USB drive also, replacing the existing one.

Once done insert the drive in the ailing computer.

Now please enter System Recovery Options.

Run FRST as you did berore and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply. It will also produce another report, MBRDUMP.txt. This file is a hex file and should be attached to your reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 17 October 2011 - 07:30 PM

Fix result of Farbars's Recovery Tool (FRST written by farbar version 2.2.4)
Ran by SYSTEM at 2011-10-18 11:26:10 R:2
Running from H:\

==============================================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\*Restore Value deleted successfully.

========= Dir /a c:\ =========

Volume in drive C is Acer
Volume Serial Number is 22CF-8D72

Directory of c:\

05/11/2011 11:58 PM <DIR> $Recycle.Bin
10/13/2011 04:00 PM 149,641 aaw7boot.log
02/08/2010 10:50 PM <DIR> book
10/12/2009 07:43 PM 8,192 BOOTSECT.BAK
04/16/2010 02:27 AM 174 desktop.ini
07/13/2009 09:08 PM <JUNCTION> Documents and Settings [C:\Users]
10/17/2011 04:11 PM <DIR> FRST
10/17/2011 02:16 PM 3,220,549,632 hiberfil.sys
10/12/2009 06:49 PM <DIR> Intel
05/24/2010 01:10 AM <DIR> Legacy
10/13/2011 03:29 PM <DIR> Log
05/02/2010 05:54 PM 109 mbam-error.txt
12/01/2006 10:37 PM 904,704 msdia80.dll
04/26/2010 09:34 PM <DIR> MSOCache
10/16/2010 09:35 PM <DIR> My Games
05/16/2010 03:32 PM <DIR> MyHeritage
06/21/2011 08:20 PM <DIR> Nexon
04/16/2010 02:27 AM <DIR> OEM
10/17/2011 02:16 PM 4,294,066,176 pagefile.sys
07/13/2009 07:20 PM <DIR> PerfLogs
10/13/2011 04:21 PM <DIR> Program Files
10/13/2011 04:20 PM <DIR> Program Files (x86)
10/13/2011 04:21 PM <DIR> ProgramData
09/10/2011 08:59 PM <DIR> Python25
09/10/2011 09:11 PM <DIR> Python27
10/13/2011 03:38 PM <DIR> Recovery
02/08/2010 10:48 PM 2,035 RHDSetup.log
10/13/2011 07:41 PM <DIR> System Volume Information
05/11/2011 11:58 PM <DIR> Users
10/13/2011 04:32 PM <DIR> Windows
04/29/2010 01:01 AM 10 xrjmns.tce
9 File(s) 7,515,680,673 bytes
22 Dir(s) 50,025,037,824 bytes free

========= End of CMD: =========


========= H:\MbrFix64 /drive 0 savembr H:\MBRDUMP.txt =========


========= End of CMD: =========


==== End of Fixlog ====

thanks

Attached Files



#12 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,558 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:11:01 PM

Posted 17 October 2011 - 07:51 PM

Everything reads fine.

Lets check the boot store.

Download the enclosed file.

Save this to the USB drive, replacing the existing one.

Insert the drive in the ailing computer.

Now please enter System Recovery Options.

Run FRST as you did before and press the Fix button just once and wait.
The tool will make a log on the flash drive (Fixlog.txt) please post it to your reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#13 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 17 October 2011 - 08:22 PM

Fix result of Farbars's Recovery Tool (FRST written by farbar version 2.2.4)
Ran by SYSTEM at 2011-10-18 12:18:48 R:3
Running from H:\

==============================================


========= Dir /a c:\book =========

Volume in drive C is Acer
Volume Serial Number is 22CF-8D72

Directory of c:\book

02/08/2010 10:50 PM <DIR> .
02/08/2010 10:50 PM <DIR> ..
07/20/2009 07:47 PM 338,679 AcerDT.pdf
1 File(s) 338,679 bytes
2 Dir(s) 50,094,329,856 bytes free

========= End of CMD: =========


========= BCDEDIT /ENUM =========


Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=Y:
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {default}
resumeobject {4a8b904a-0281-11df-abf8-002511aa4859}
displayorder {default}
toolsdisplayorder {memdiag}
timeout 30

Windows Boot Loader
-------------------
identifier {default}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale en-US
inherit {bootloadersettings}
recoverysequence {4a8b904c-0281-11df-abf8-002511aa4859}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {4a8b904a-0281-11df-abf8-002511aa4859}
nx OptIn
winpe No

========= End of CMD: =========


==== End of Fixlog ====

#14 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,558 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:11:01 PM

Posted 17 October 2011 - 08:32 PM

No problems there. Lets restore the registry hives from the registry backups made by the system prior to the issue.

Download the enclosed file.

Save this to the USB drive, replacing the existing one.

Insert the drive in the ailing computer.

Now please enter System Recovery Options.

Run FRST as you did before and press the Fix button just once and wait.
The tool will make a log on the flash drive (Fixlog.txt) please post it to your reply.

Edited by JSntgRvr, 17 October 2011 - 08:32 PM.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#15 Jen42

Jen42
  • Topic Starter

  • Members
  • 316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Australia
  • Local time:01:01 PM

Posted 18 October 2011 - 12:01 AM

Fix result of Farbars's Recovery Tool (FRST written by farbar version 2.2.4)
Ran by SYSTEM at 2011-10-18 15:58:09 R:4
Running from H:\

==============================================


========= Dir /a Y:\ =========

Volume in drive Y is SYSTEM RESERVED
Volume Serial Number is B2CE-8A0B

Directory of Y:\

02/22/2011 02:12 PM <DIR> Boot
11/20/2010 04:40 AM 383,786 bootmgr
09/18/2011 01:00 AM <DIR> System Volume Information
1 File(s) 383,786 bytes
2 Dir(s) 73,760,768 bytes free

========= End of CMD: =========

DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.

==== End of Fixlog ====




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users