Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Redirect Virus


  • This topic is locked This topic is locked
22 replies to this topic

#1 smallcrusher

smallcrusher

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 30 November 2011 - 10:59 PM

Google links redirect me to various advertisement sites. Also, my computer speakers will randomly begin playing ads when internet explorer is not open.

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Jeremy & Gina at 16:48:04 on 2011-11-30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.2447 [GMT -8:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Medialink\MWN-USB150N\UI.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Medialink Utilty] c:\program files\medialink\mwn-usb150n\UI.exe -s
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10x_ActiveX.exe -update activex
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://kponline.webex.com/client/T27L10NSP21EP4/webex/ieatgpc.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{2CC9517F-0AEF-4356-958E-723243071284} : DhcpNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [2010-10-10 291504]
R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 16720]
R3 NgLog;Aventail VPN Logging;c:\windows\system32\drivers\nglog.sys [2010-10-10 27160]
R3 NgVpn;Aventail VPN Adapter;c:\windows\system32\drivers\ngvpn.sys [2010-10-10 77336]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2011-8-19 709248]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-20 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-8-20 1684736]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-20 136176]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\drivers\ngfilter.sys [2010-10-10 23064]
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\drivers\ngwfp.sys [2010-10-10 25112]
.
=============== Created Last 30 ================
.
2011-11-30 23:55:59 799 ----a-w- c:\documents and settings\all users\application data\usouaaa.tmp
2011-11-30 23:49:35 -------- d-----w- C:\ComboFix
2011-11-29 03:54:25 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-29 03:52:59 -------- d-sha-r- C:\cmdcons
2011-11-29 03:48:28 98816 ----a-w- c:\windows\sed.exe
2011-11-29 03:48:28 518144 ----a-w- c:\windows\SWREG.exe
2011-11-29 03:48:28 256000 ----a-w- c:\windows\PEV.exe
2011-11-29 03:48:28 208896 ----a-w- c:\windows\MBR.exe
2011-11-26 08:06:07 -------- d-----w- c:\windows\system32\q3pmG5aQJdKf
2011-11-26 08:06:06 -------- d-----w- C:\qcA1ivD2oFaH
2011-11-20 19:22:07 -------- d-----w- c:\documents and settings\jeremy & gina\application data\Malwarebytes
2011-11-20 19:21:57 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-20 19:21:55 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-20 19:21:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-20 15:00:42 -------- d-----w- C:\$AVG
2011-11-10 21:25:11 -------- d-----w- c:\program files\MSECache
2011-11-05 15:29:01 -------- d-----w- c:\documents and settings\jeremy & gina\local settings\application data\PhotoChannel
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-11-05 15:19:28 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
.
==================== Find3M ====================
.
2011-10-24 21:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 21:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23:48 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21:42 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-30 04:27:28 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 13:30:10 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-02 04:29:08 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-02 04:29:08 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-20 03:27:48 5570000 ----a-w- c:\program files\AVG.exe
2011-08-20 03:19:58 1081480 ----a-w- c:\program files\SkypeSetup.exe
.
============= FINISH: 16:49:26.90 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 03 December 2011 - 11:04 PM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 04 December 2011 - 11:11 AM

I am still be re-directed from Google links. It doesn't occur with every link, however. Below is the Combofix log:


ComboFix 11-12-04.02 - Jeremy & Gina 12/04/2011 8:01.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.2732 [GMT -8:00]
Running from: c:\documents and settings\Jeremy & Gina\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\usouaaa.tmp
.
c:\windows\system32\winlogon.exe . . . is infected!!
.
c:\windows\system32\svchost.exe . . . is infected!!
.
c:\windows\explorer.exe . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-11-29 03:54 . 2011-07-15 13:29 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-27 07:13 . 2011-11-27 07:13 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2011-11-27 07:13 . 2011-11-27 07:13 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Temp
2011-11-26 08:06 . 2011-11-26 08:06 -------- d-----w- c:\windows\system32\q3pmG5aQJdKf
2011-11-26 08:06 . 2011-11-26 08:06 -------- d-----w- C:\qcA1ivD2oFaH
2011-11-25 12:31 . 2011-11-25 12:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-11-24 07:43 . 2011-11-24 07:43 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-11-21 01:31 . 2011-11-21 01:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Apple Computer
2011-11-21 01:31 . 2011-11-21 01:31 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Apple Computer
2011-11-20 19:22 . 2011-11-20 19:22 -------- d-----w- c:\documents and settings\Jeremy & Gina\Application Data\Malwarebytes
2011-11-20 19:21 . 2011-11-20 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-20 19:21 . 2011-11-20 19:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-20 19:21 . 2011-09-01 01:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-20 15:13 . 2011-11-20 15:13 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2011-11-20 15:13 . 2011-11-20 15:13 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-11-20 15:00 . 2011-11-20 15:00 -------- d-----w- C:\$AVG
2011-11-10 21:25 . 2011-11-10 21:25 -------- d-----w- c:\program files\MSECache
2011-11-05 15:29 . 2011-11-05 15:29 -------- d-----w- c:\documents and settings\Jeremy & Gina\Local Settings\Application Data\PhotoChannel
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-11-05 15:19 . 2011-11-05 15:19 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-11-05 15:19 . 2011-11-05 15:19 -------- d-----w- c:\program files\QuickTime
2011-11-04 23:58 . 2011-11-04 23:58 -------- d-----w- c:\documents and settings\LocalService\Application Data\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 21:29 . 2011-10-24 21:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 21:29 . 2011-10-24 21:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-10 14:22 . 2011-08-19 23:04 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2011-01-07 11:41 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2011-02-10 12:53 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-10-01 14:20 . 2011-10-01 14:20 53248 ----a-r- c:\documents and settings\Jeremy & Gina\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-09-30 04:27 . 2011-08-19 23:39 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-28 07:06 . 2008-04-14 10:41 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2001-08-23 11:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2001-08-23 11:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 13:30 . 2011-03-16 21:03 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-09-06 13:20 . 2008-04-14 06:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-20 03:27 . 2011-08-20 03:27 5570000 ----a-w- c:\program files\AVG.exe
2011-08-20 03:19 . 2011-08-20 03:19 1081480 ----a-w- c:\program files\SkypeSetup.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . 05EE0EDEADFC079ABB9F166207296857 . 544768 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
.
[-] 2008-04-14 . 87F42BB23FBBC44F193B804DDA4E3F24 . 39424 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
.
[-] 2008-04-14 . 51E29AE63EF43527320A0AD7987BD87C . 1058304 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-12-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot_2011-11-30_23.24.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-02 23:28 . 2011-12-02 23:28 16384 c:\windows\Temp\Perflib_Perfdata_61c.dat
+ 2001-08-23 11:00 . 2011-12-02 23:32 67516 c:\windows\system32\perfc009.dat
- 2001-08-23 11:00 . 2011-11-30 23:16 67516 c:\windows\system32\perfc009.dat
+ 2011-12-03 19:38 . 2011-12-03 19:38 17920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{6E807437-1DE6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 19:38 . 2011-12-03 19:38 20480 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{6E807434-1DE6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 22:36 . 2011-12-03 22:36 24576 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{4E28BB36-1DFF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:54 . 2011-12-02 23:54 29696 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FDB8D7CC-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 16:45 . 2011-12-02 16:45 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FA53AB11-1D04-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 05:59 . 2011-12-03 06:05 15872 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F961095B-1D73-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 11:59 . 2011-12-01 12:00 80896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F890006F-1C13-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 17:14 . 2011-12-01 17:19 59392 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F68B21FF-1C3F-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 05:09 . 2011-12-03 05:13 21504 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EEEF415C-1D6C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 10:55 . 2011-12-01 11:02 22528 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EDAD2A6D-1C0A-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 14:20 . 2011-12-03 14:20 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EBC9ADAB-1DB9-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 05:18 . 2011-12-01 05:23 14848 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EABE88F3-1BDB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 17:07 . 2011-12-01 17:08 19968 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EA7FE1A9-1C3E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:02 . 2011-12-02 13:09 28160 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E5ED2301-1CE5-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:19 . 2011-12-02 12:25 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DE1E943F-1CDF-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 19:28 . 2011-12-02 19:35 22016 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DB05F9F5-1D1B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 05:58 . 2011-12-03 06:05 79872 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D842DF37-1D73-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:05 . 2011-12-03 06:05 19456 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D4174177-1D74-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:08 . 2011-12-03 05:10 20480 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D2D3C857-1D6C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:53 . 2011-12-02 23:53 29184 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D1DB53F1-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:17 . 2011-12-02 23:19 16896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D00CAF57-1D3B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 14:26 . 2011-12-03 14:26 26624 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CA778F83-1DBA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 14:41 . 2011-12-02 14:44 51712 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C49595D7-1CF3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 08:22 . 2011-12-02 08:28 11776 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C2271733-1CBE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:28 . 2011-12-02 11:31 48128 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C1A9C84F-1CD8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 19:12 . 2011-12-03 19:19 69632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BBA2AB35-1DE2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 18:22 . 2011-12-03 18:29 72192 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BA9B4CA3-1DDB-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 13:51 . 2011-12-02 13:58 15360 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B97CE93F-1CEC-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 10:15 . 2011-12-03 10:20 11776 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B712E8C5-1D97-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 18:29 . 2011-12-03 18:35 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B67B9AA5-1DDC-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 11:57 . 2011-12-01 12:00 22016 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B54B0719-1C13-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 19:07 . 2011-12-01 19:14 31232 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B3233A55-1C4F-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:10 . 2011-12-03 17:11 16384 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B1A07E63-1DD1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:47 . 2011-12-01 07:54 30720 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B12ED349-1BF0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:15 . 2011-12-03 15:20 28160 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AD522B05-1DC1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:07 . 2011-12-03 05:14 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ACD912AF-1D6C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 17:40 . 2011-12-02 17:43 25088 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A9F0FC03-1D0C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:16 . 2011-12-02 15:18 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A7719433-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 16:43 . 2011-12-01 16:49 32256 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A6CE1F45-1C3B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:34 . 2011-12-02 11:37 26112 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A69E9B1F-1CD9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:24 . 2011-12-02 12:25 23552 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A5AA24CF-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 06:11 . 2011-12-03 06:12 74752 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A396EA49-1D75-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 10:24 . 2011-12-01 10:30 22016 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A0338321-1C06-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:11 . 2011-12-03 06:11 68096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9D9C448F-1D75-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:18 . 2011-12-01 07:18 25088 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{99A3FDDF-1BEC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 14:40 . 2011-12-02 14:44 55808 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9834F0A5-1CF3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 15:39 . 2011-12-01 15:42 19456 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9785F34B-1C32-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:57 . 2011-12-02 13:57 72192 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{945E0BA7-1CED-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:51 . 2011-12-02 23:51 29696 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{92A1172F-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 14:27 . 2011-12-01 14:28 16896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{91F65E9F-1C28-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 14:27 . 2011-12-01 14:28 16896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{91F65E9D-1C28-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 19:18 . 2011-12-03 19:18 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8C9FCC40-1DE3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:24 . 2011-12-02 12:24 23040 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8A81DBA6-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 11:56 . 2011-12-01 12:00 83968 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8797D3FF-1C13-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:03 . 2011-12-03 06:03 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{840FF279-1D74-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 11:35 . 2011-12-01 11:41 86528 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8402CDBF-1C10-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 19:13 . 2011-12-01 19:14 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7BF7CF69-1C50-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:17 . 2011-12-03 06:22 99328 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{76E0F02D-1D76-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 19:17 . 2011-12-03 19:19 16896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{76920BC0-1DE3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 02:28 . 2011-12-03 02:35 55296 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7517E523-1D56-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:19 . 2011-12-03 05:26 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{70F2FCEF-1D6E-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:14 . 2011-12-03 15:20 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7051C04D-1DC1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:10 . 2011-12-03 06:12 17920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6E3987D1-1D75-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 14:39 . 2011-12-02 14:45 13824 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6CF4C7FD-1CF3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 07:45 . 2011-12-01 07:47 16384 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6A5B17A3-1BF0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 19:17 . 2011-12-03 19:17 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{682C183D-1DE3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 05:07 . 2011-12-01 05:11 60928 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{64557773-1BDA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 18:35 . 2011-12-02 18:37 12288 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6178DBCE-1D14-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 17:44 . 2011-12-03 17:45 13824 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5FDDD66D-1DD6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:22 . 2011-12-02 12:25 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5EC81B11-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 16:48 . 2011-12-01 16:50 25088 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5BDD13FB-1C3C-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 19:16 . 2011-12-03 19:16 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{59430362-1DE3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 22:02 . 2011-12-02 22:07 81920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{58F37EC7-1D31-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 17:17 . 2011-12-01 17:19 27136 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5525B127-1C40-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:14 . 2011-12-02 15:15 15360 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{53F0F817-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 02:36 . 2011-12-01 02:43 19456 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{53A4101B-1BC5-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:49 . 2011-12-02 23:55 25600 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{53267AEE-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 18:34 . 2011-12-02 18:39 27136 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{48E4FE07-1D14-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 12:37 . 2011-12-01 12:44 89600 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{479AB28F-1C19-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 14:38 . 2011-12-02 14:40 27648 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{459B98A7-1CF3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 08:53 . 2011-12-03 08:58 38912 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4114F047-1D8C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 17:02 . 2011-12-01 17:09 37888 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4096CBC5-1C3E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 14:22 . 2011-12-03 14:26 49664 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3B3AC87B-1DBA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 14:45 . 2011-12-02 14:45 27648 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{39FCA1A2-1CF4-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 19:15 . 2011-12-03 19:19 20480 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3805DAA9-1DE3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 17:16 . 2011-12-01 17:19 49664 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3688DF91-1C40-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:19 . 2011-12-03 15:20 24576 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3332D6BA-1DC2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 15:13 . 2011-12-02 15:20 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{33264041-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:48 . 2011-12-02 23:49 17920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{325960BF-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 11:24 . 2011-12-02 11:28 22528 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{30B6509B-1CD8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:20 . 2011-12-02 15:27 96256 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2EFAA281-1CF9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 10:18 . 2011-12-03 10:20 15872 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2B8B8969-1D98-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 11:39 . 2011-12-01 11:41 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2B4B8C7E-1C11-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:27 . 2011-12-02 15:34 75264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2ACCA267-1CFA-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 08:25 . 2011-12-02 08:28 55808 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{26156777-1CBF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:55 . 2011-12-02 23:55 28672 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{24B2A916-1D41-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 19:15 . 2011-12-03 19:16 16896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{209E652F-1DE3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 08:52 . 2011-12-03 08:54 57856 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1B7BFB09-1D8C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 05:33 . 2011-12-02 05:34 54272 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1B5861E3-1CA7-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 09:56 . 2011-12-03 10:00 34304 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1B368FDF-1D95-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:36 . 2011-12-03 06:38 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{17229EFF-1D79-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 16:52 . 2011-12-02 16:53 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{16B0034F-1D06-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 07:19 . 2011-12-03 07:21 21504 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1634CFFD-1D7F-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 20:05 . 2011-12-03 20:12 25088 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{15EE7581-1DEA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:09 . 2011-12-03 05:14 20480 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0BA5B339-1D6D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:19 . 2011-12-02 23:19 24064 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{075C5D44-1D3C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:20 . 2011-12-02 12:25 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{06210A8D-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 13:46 . 2011-12-02 13:51 22016 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{05828549-1CEC-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 11:38 . 2011-12-01 11:41 33280 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0020D901-1C11-11E1-BAB3-001CC432139B}.dat
- 2011-11-20 15:31 . 2011-11-30 20:42 49152 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2011-11-20 15:31 . 2011-12-03 19:26 49152 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2011-11-23 23:41 . 2011-12-03 22:37 32768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
- 2011-11-23 23:41 . 2011-11-30 23:10 32768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
+ 2011-11-20 15:13 . 2011-12-03 22:37 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2011-11-20 15:13 . 2011-11-30 23:10 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2011-11-20 15:54 . 2011-11-29 19:51 32768 c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
+ 2011-11-20 15:54 . 2011-12-03 14:27 32768 c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
+ 2011-12-03 10:14 . 2011-12-03 10:14 3238 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8GEYSSED\spike[1].com
+ 2011-12-03 19:38 . 2011-12-03 19:38 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{6E807436-1DE6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 19:38 . 2011-12-03 19:38 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{6E807435-1DE6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 19:38 . 2011-12-03 19:38 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{6E807433-1DE6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:42 . 2011-12-03 22:36 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{02717593-1D7A-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 01:22 . 2011-12-01 01:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FEE15DBC-1BBA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 20:55 . 2011-12-02 20:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FE5A69BA-1D27-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 12:54 . 2011-12-03 12:54 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FD7F2E0A-1DAD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 01:29 . 2011-12-01 01:29 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FAB5BFFC-1BBB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 14:50 . 2011-12-02 14:55 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FA5C5F86-1CF4-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 16:45 . 2011-12-02 16:45 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FA53AB10-1D04-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 04:27 . 2011-12-02 04:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F9D3F990-1C9D-11E1-BAB3-001CC432139B}.dat
+ 2011-11-30 23:49 . 2011-11-30 23:49 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F7E38204-1BAD-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 11:24 . 2011-12-01 11:24 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F7AFC700-1C0E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 01:08 . 2011-12-01 01:08 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F7AD647A-1BB8-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 04:33 . 2011-12-03 04:33 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F787BF76-1D67-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 17:14 . 2011-12-01 17:19 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F68B21FE-1C3F-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 16:52 . 2011-12-02 16:56 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F625AAF6-1D05-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 06:01 . 2011-12-01 06:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F390F806-1BE1-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 09:42 . 2011-12-02 09:42 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F375B0EE-1CC9-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 02:48 . 2011-12-01 02:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F24B2AB8-1BC6-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 11:45 . 2011-12-01 11:45 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F11E0A0C-1C11-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:49 . 2011-12-03 06:49 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F0EAEBB2-1D7A-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 04:14 . 2011-12-01 04:14 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EFE2E1F6-1BD2-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 02:55 . 2011-12-01 02:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EE21EF52-1BC7-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 10:55 . 2011-12-01 10:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EDAD2A6C-1C0A-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:56 . 2011-12-03 06:56 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ECDE4C84-1D7B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 22:43 . 2011-12-01 22:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ECD38A4C-1C6D-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 01:57 . 2011-12-02 01:57 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EBE1E7EE-1C88-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 14:20 . 2011-12-03 14:27 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EBC9ADAA-1DB9-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 05:18 . 2011-12-01 05:18 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EABE88F2-1BDB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 20:12 . 2011-12-02 20:12 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E8C8075C-1D21-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 22:50 . 2011-12-01 22:50 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E8ACB140-1C6E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 07:53 . 2011-12-03 07:53 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E7AB25A4-1D83-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 14:27 . 2011-12-03 14:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E7A79952-1DBA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:04 . 2011-12-03 17:10 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E72AADC8-1DD0-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 13:02 . 2011-12-02 13:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E5ED2300-1CE5-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 18:53 . 2011-12-02 18:53 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E50B3FD6-1D16-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 21:43 . 2011-12-03 21:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E4E0C944-1DF7-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 15:19 . 2011-12-01 15:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E3BCA13E-1C2F-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:11 . 2011-12-03 17:11 1536 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E2FF1008-1DD1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 19:00 . 2011-12-02 19:00 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E0DADD62-1D17-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 21:50 . 2011-12-03 21:50 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E0B2C92A-1DF8-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 01:12 . 2011-12-03 01:12 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E046C4B8-1D4B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 19:21 . 2011-12-02 19:21 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DF365C68-1D1A-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:19 . 2011-12-02 12:25 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DE1E943E-1CDF-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 09:28 . 2011-12-01 09:28 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DCBB1CA2-1BFE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 19:28 . 2011-12-02 19:28 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DB05F9F4-1D1B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 05:58 . 2011-12-03 06:04 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D842DF36-1D73-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 19:35 . 2011-12-02 19:35 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D6D33526-1D1C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 00:01 . 2011-12-02 00:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D50B0CF4-1C78-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 21:08 . 2011-12-02 21:08 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D428AA4C-1D29-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 06:05 . 2011-12-03 06:11 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D4174176-1D74-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:19 . 2011-12-01 07:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D2784B1E-1BEC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 09:54 . 2011-12-03 10:00 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D1716D28-1D94-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 14:43 . 2011-12-01 14:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{CE50E440-1C2A-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 07:26 . 2011-12-01 07:26 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{CE4CAD5E-1BED-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 17:48 . 2011-12-02 17:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C9DE78EE-1D0D-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 07:03 . 2011-12-02 07:03 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C75197C8-1CB3-11E1-BAB3-001CC432139B}.dat
+ 2011-11-30 23:48 . 2011-11-30 23:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C5D22004-1BAD-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 21:23 . 2011-12-01 21:23 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C55AA3D4-1C62-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:02 . 2011-12-03 15:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C4521BE4-1DBF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 01:20 . 2011-12-02 01:20 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C2B54F46-1C83-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:37 . 2011-12-02 13:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C1D8E972-1CEA-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 09:06 . 2011-12-01 09:12 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C13DE1EC-1BFB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 00:44 . 2011-12-02 00:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BEC4B02A-1C7E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 01:27 . 2011-12-02 01:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BE89B186-1C84-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:44 . 2011-12-02 13:46 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BDAAE958-1CEB-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 01:56 . 2011-12-01 01:56 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BCD4D4DA-1BBF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 19:12 . 2011-12-03 19:18 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BBA2AB34-1DE2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 18:22 . 2011-12-03 18:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BA9B4CA2-1DDB-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:11 . 2011-12-01 07:18 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B992DDA4-1BEB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:51 . 2011-12-02 13:57 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B97CE93E-1CEC-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 18:29 . 2011-12-03 18:29 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B67B9AA4-1DDC-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 00:14 . 2011-12-03 00:14 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B6126A24-1D43-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:40 . 2011-12-01 07:45 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B54C22EC-1BEF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 12:09 . 2011-12-03 12:09 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B54797E0-1DA7-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 19:07 . 2011-12-01 19:13 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B3233A54-1C4F-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 07:17 . 2011-12-02 07:17 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B2FDE9D2-1CB5-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 18:36 . 2011-12-03 18:36 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B24B3830-1DDD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 00:21 . 2011-12-03 00:21 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B1E46A0A-1D44-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:47 . 2011-12-01 07:47 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B12ED348-1BF0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 05:00 . 2011-12-03 05:00 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B1024E14-1D6B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 03:06 . 2011-12-02 03:06 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B02F7F36-1C92-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 21:44 . 2011-12-01 21:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{AEF62B92-1C65-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 18:43 . 2011-12-03 18:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{AE1D3816-1DDE-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:30 . 2011-12-03 15:30 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ADFED3D8-1DC3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 12:19 . 2011-12-01 12:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ADABE06E-1C16-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 10:43 . 2011-12-03 10:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{AD3F3488-1D9B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:07 . 2011-12-03 05:13 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ACD912AE-1D6C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 22:25 . 2011-12-03 22:25 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{AA26B876-1DFD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:37 . 2011-12-03 15:40 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{A9DCBF80-1DC4-11E1-BAB5-001CC432139B}.dat
+ 2011-11-30 23:25 . 2011-11-30 23:32 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{A7AFC976-1BAA-11E1-BAB2-001CC432139B}.dat
+ 2011-12-01 16:43 . 2011-12-01 16:48 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{A6CE1F44-1C3B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 22:47 . 2011-12-02 22:47 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{A34F71CC-1D37-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 10:24 . 2011-12-01 10:24 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{A0338320-1C06-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 05:43 . 2011-12-02 05:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9F6D677E-1CA8-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 11:47 . 2011-12-03 11:47 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9E15793C-1DA4-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 10:01 . 2011-12-02 10:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9C73BD88-1CCC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 08:21 . 2011-12-02 08:25 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9B7BF386-1CBE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 02:57 . 2011-12-03 02:57 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9B1499CE-1D5A-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 11:54 . 2011-12-03 11:54 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{99E516C8-1DA5-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 12:23 . 2011-12-03 12:23 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{98BD0FD6-1DA9-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 14:39 . 2011-12-03 14:39 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{98862B98-1DBC-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 18:38 . 2011-12-01 18:38 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{97B16BA0-1C4B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 08:28 . 2011-12-02 08:33 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{974DF36C-1CBF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 03:05 . 2011-12-03 03:05 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{96E699B4-1D5B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:59 . 2011-12-03 17:59 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{961EF250-1DD8-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 12:01 . 2011-12-03 12:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{95B716AE-1DA6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 06:20 . 2011-12-01 06:20 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9056F760-1BE4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:38 . 2011-12-03 17:44 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9029B9E2-1DD5-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 20:22 . 2011-12-03 20:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8DBB3D26-1DEC-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 03:34 . 2011-12-02 03:34 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8CB35C68-1C96-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 12:37 . 2011-12-03 12:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8C1AB844-1DAB-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:45 . 2011-12-03 17:45 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8BF9576E-1DD6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:01 . 2011-12-02 23:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8BD386A8-1D39-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:32 . 2011-11-30 23:32 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8B5470B4-1BAB-11E1-BAB2-001CC432139B}.dat
+ 2011-12-02 06:40 . 2011-12-02 06:40 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8B28A3CA-1CB0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:29 . 2011-12-03 20:29 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{898615FE-1DED-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:08 . 2011-12-02 23:08 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{87A5868E-1D3A-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 11:56 . 2011-12-01 12:00 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8797D3FE-1C13-11E1-BAB3-001CC432139B}.dat
+ 2011-11-30 23:39 . 2011-11-30 23:39 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8739836A-1BAC-11E1-BAB2-001CC432139B}.dat
+ 2011-12-01 05:37 . 2011-12-01 05:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{86FA3FE8-1BDE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 21:20 . 2011-12-02 21:20 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8568FCFC-1D2B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 11:06 . 2011-12-01 11:06 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{85155F86-1C0C-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 11:35 . 2011-12-01 11:39 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8402CDBE-1C10-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 10:13 . 2011-12-03 10:18 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{83D780D6-1D97-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:15 . 2011-12-02 23:19 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8379E8CE-1D3B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:01 . 2011-12-02 15:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{80F78268-1CF6-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 22:02 . 2011-12-03 22:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7F19844A-1DFA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 08:04 . 2011-12-03 08:04 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7E75FF8A-1D85-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 10:15 . 2011-12-02 10:15 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7DBDB194-1CCE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 20:23 . 2011-12-02 20:23 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7C6D066E-1D23-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:58 . 2011-12-02 15:58 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7BD50BFE-1CFE-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 22:09 . 2011-12-03 22:09 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7AEDE68A-1DFB-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 17:39 . 2011-12-01 17:39 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7AD3387C-1C43-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 02:21 . 2011-12-03 02:21 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{794382E2-1D55-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 16:05 . 2011-12-02 16:05 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{77A96E3E-1CFF-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 06:17 . 2011-12-03 06:21 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{76E0F02C-1D76-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 09:37 . 2011-12-03 09:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{75B8F778-1D92-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 02:28 . 2011-12-03 02:28 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7517E522-1D56-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 07:14 . 2011-12-03 07:19 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7195F1C8-1D7E-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:19 . 2011-12-03 05:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{70F2FCEE-1D6E-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:14 . 2011-12-03 15:21 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7051C04C-1DC1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 17:02 . 2011-12-02 17:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6E72B1D8-1D07-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 06:31 . 2011-12-03 06:36 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6D9DABDE-1D78-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:44 . 2011-12-02 12:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6D619F3A-1CE3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 03:27 . 2011-12-01 03:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6CCCDB92-1BCC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 17:09 . 2011-12-02 17:09 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6A424F64-1D08-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 03:18 . 2011-12-03 03:18 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6A2795F2-1D5D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 10:08 . 2011-12-01 10:08 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6A271582-1C04-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 13:07 . 2011-12-01 13:07 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{688667FA-1C1D-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 05:07 . 2011-12-01 05:07 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{64557772-1BDA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 22:37 . 2011-12-03 22:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{642368EA-1DFF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 02:36 . 2011-12-02 02:36 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6319FAAE-1C8E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 03:48 . 2011-12-01 03:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{62DE6DB4-1BCF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 08:25 . 2011-12-03 08:25 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{627FC90C-1D88-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 03:39 . 2011-12-03 03:39 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6049D88A-1D60-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 00:19 . 2011-12-02 00:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{5A0EFD78-1C7B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 05:43 . 2011-12-01 05:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{599D6132-1BDF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 22:02 . 2011-12-02 22:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{58F37EC6-1D31-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 02:29 . 2011-12-01 02:29 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{57D6D4E8-1BC4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 10:55 . 2011-12-03 10:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{578CECF4-1D9D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 00:20 . 2011-12-01 00:20 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{56AD5CDE-1BB2-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 02:36 . 2011-12-01 02:36 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{53A4101A-1BC5-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 09:46 . 2011-12-01 09:46 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{52D5F84C-1C01-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 00:28 . 2011-12-01 00:28 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{527F5CC4-1BB3-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 00:35 . 2011-12-01 00:35 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{5054589A-1BB4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 09:53 . 2011-12-01 09:53 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4EB6464E-1C02-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 01:37 . 2011-12-03 01:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4CA6A6C0-1D4F-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 13:25 . 2011-12-03 13:25 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4AEF4BEE-1DB2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 10:00 . 2011-12-01 10:00 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4A8D0AE8-1C03-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:46 . 2011-12-02 11:46 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4A0342B2-1CDB-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 20:15 . 2011-12-01 20:15 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{483DC3E4-1C59-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 12:37 . 2011-12-01 12:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{479AB28E-1C19-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:53 . 2011-12-02 11:53 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{45DA074C-1CDC-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 14:38 . 2011-12-02 14:45 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{459B98A6-1CF3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:35 . 2011-12-02 23:35 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{441FCA60-1D3E-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 12:44 . 2011-12-01 12:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{43763BDC-1C1A-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 10:26 . 2011-12-03 10:26 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{415BCC88-1D99-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 17:02 . 2011-12-01 17:07 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4096CBC4-1C3E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 07:01 . 2011-12-01 07:07 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{402EE3A0-1BEA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 07:34 . 2011-12-03 07:41 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4010576C-1D81-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 08:24 . 2011-12-03 08:24 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3EBA20B2-1D88-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 20:41 . 2011-12-03 20:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3E388EC2-1DEF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 08:48 . 2011-12-01 08:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3AD450AC-1BF9-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 22:31 . 2011-12-01 22:31 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3A53BC80-1C6C-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:49 . 2011-12-03 20:49 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3A0CF102-1DF0-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 17:36 . 2011-12-02 17:40 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{39B52958-1D0C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 20:29 . 2011-12-01 20:29 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3714B576-1C5B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 02:40 . 2011-12-03 02:40 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{36EC119A-1D58-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 08:55 . 2011-12-01 08:58 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{36A8B2EC-1BFA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 00:54 . 2011-12-02 00:54 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3689D102-1C80-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 10:27 . 2011-12-02 10:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3611FF74-1CD0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:56 . 2011-12-03 20:56 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{35DC8E8E-1DF1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 15:13 . 2011-12-02 15:20 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{33264040-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 09:29 . 2011-12-02 09:29 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{32A7C722-1CC8-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:48 . 2011-12-02 23:55 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{325960BE-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 11:24 . 2011-12-02 11:28 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{30B6509A-1CD8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 14:24 . 2011-12-01 14:28 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2F799ADA-1C28-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:20 . 2011-12-02 15:20 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2EFAA280-1CF9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 11:31 . 2011-12-02 11:36 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2C8AB2DA-1CD9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 09:16 . 2011-12-01 09:16 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2C1CE9DA-1BFD-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 21:47 . 2011-12-02 21:47 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2C052F56-1D2F-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 22:22 . 2011-12-02 22:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2B527B5E-1D34-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:27 . 2011-12-02 15:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2ACCA266-1CFA-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 16:38 . 2011-12-03 16:38 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2A130EC2-1DCD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 05:11 . 2011-12-02 05:11 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{27EBEB98-1CA4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:34 . 2011-12-02 15:34 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{26A104A6-1CFB-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 18:33 . 2011-12-02 18:35 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{25B3277C-1D14-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 05:19 . 2011-12-02 05:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{23B6C470-1CA5-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 14:02 . 2011-12-01 14:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{20F7EE38-1C25-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 05:26 . 2011-12-02 05:26 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1F8B26B0-1CA6-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:19 . 2011-12-02 23:19 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1EFF6D8C-1D3C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 08:52 . 2011-12-03 08:53 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1B7BFB08-1D8C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 05:33 . 2011-12-02 05:33 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1B5861E2-1CA7-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:26 . 2011-12-02 23:26 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1AD3CFCC-1D3D-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 19:58 . 2011-12-03 19:58 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1A1089D8-1DE9-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 22:09 . 2011-12-01 22:09 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1821E4AA-1C69-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 15:35 . 2011-12-01 15:39 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{180FFBD2-1C32-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:05 . 2011-12-03 20:05 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{15EE7580-1DEA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 10:47 . 2011-12-02 10:54 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0FF7681C-1CD3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 17:58 . 2011-12-01 17:58 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0E719040-1C46-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 23:41 . 2011-12-01 23:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0B3B2172-1C76-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 18:05 . 2011-12-01 18:10 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0A4854DA-1C47-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 07:55 . 2011-12-02 07:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0A22D9CA-1CBB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 23:48 . 2011-12-01 23:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{070F83B2-1C77-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 01:44 . 2011-12-01 01:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0709069A-1BBE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 12:00 . 2011-12-01 12:00 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{06E2E126-1C14-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:12 . 2011-12-03 17:12 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{06BFF3AE-1DD2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 20:41 . 2011-12-02 20:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{06A81BD2-1D26-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 02:10 . 2011-12-03 02:10 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{04D64E40-1D54-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 08:25 . 2011-12-01 08:25 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{04AD2970-1BF6-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 20:48 . 2011-12-02 20:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{027C7E12-1D27-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 01:22 . 2011-12-01 01:23 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FEE15DBD-1BBA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:19 . 2011-12-02 15:20 8192 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FEB5665D-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 20:55 . 2011-12-02 20:56 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FE5A69BB-1D27-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 12:54 . 2011-12-03 12:54 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FD7F2E0B-1DAD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:06 . 2011-12-03 06:06 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FBEA08BA-1D74-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 01:29 . 2011-12-01 01:30 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FAB5BFFD-1BBB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 04:27 . 2011-12-02 04:28 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F9D3F991-1C9D-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:19 . 2011-12-02 15:19 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F8BD22FD-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:49 . 2011-11-30 23:49 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F7E38205-1BAD-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 11:24 . 2011-12-01 11:24 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F7AFC701-1C0E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 01:08 . 2011-12-01 01:08 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F7AD647B-1BB8-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 04:33 . 2011-12-03 04:33 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F787BF77-1D67-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 06:01 . 2011-12-01 06:02 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F390F807-1BE1-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 02:48 . 2011-12-01 02:48 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F24B2AB9-1BC6-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 11:45 . 2011-12-01 11:45 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F11E0A0D-1C11-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:18 . 2011-12-02 23:19 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F09242FF-1D3B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 04:14 . 2011-12-01 04:16 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EFE2E1F7-1BD2-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 05:09 . 2011-12-03 05:09 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EEEF415B-1D6C-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 02:55 . 2011-12-01 02:55 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EE21EF53-1BC7-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:56 . 2011-12-03 06:56 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ECDE4C85-1D7B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 22:43 . 2011-12-01 22:44 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ECD38A4D-1C6D-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 01:57 . 2011-12-02 01:57 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{EBE1E7EF-1C88-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 20:12 . 2011-12-02 20:12 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E8C8075D-1D21-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 22:50 . 2011-12-01 22:51 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E8ACB141-1C6E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 07:53 . 2011-12-03 07:53 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E7AB25A5-1D83-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 14:27 . 2011-12-03 14:27 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E7A79953-1DBA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 18:53 . 2011-12-02 18:56 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E50B3FD7-1D16-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 21:43 . 2011-12-03 21:43 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E4E0C945-1DF7-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 19:00 . 2011-12-02 19:00 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E0DADD63-1D17-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 21:50 . 2011-12-03 21:50 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E0B2C92B-1DF8-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:20 . 2011-12-03 06:20 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E09EFBCD-1D76-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 01:12 . 2011-12-03 01:12 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E046C4B9-1D4B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 15:18 . 2011-12-02 15:18 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DFDF5C50-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 14:27 . 2011-12-03 14:27 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DF7583EE-1DBA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 19:21 . 2011-12-02 19:22 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DF365C69-1D1A-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 09:28 . 2011-12-01 09:30 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DCBB1CA3-1BFE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:36 . 2011-12-02 11:38 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DACAD093-1CD9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 19:35 . 2011-12-02 19:36 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D6D33527-1D1C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 00:01 . 2011-12-02 00:02 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D50B0CF5-1C78-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 07:19 . 2011-12-01 07:20 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D2784B1F-1BEC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 07:05 . 2011-12-01 07:07 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D0FC35B5-1BEA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 14:43 . 2011-12-01 14:43 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CE50E441-1C2A-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 18:10 . 2011-12-01 18:11 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CADA2419-1C47-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:17 . 2011-12-02 15:17 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CA03AD32-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:25 . 2011-12-02 12:26 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C7E1A473-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:25 . 2011-12-02 12:25 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C7E1A472-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:48 . 2011-11-30 23:48 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C5D22005-1BAD-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 21:23 . 2011-12-01 21:24 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C55AA3D5-1C62-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 01:20 . 2011-12-02 01:20 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C2B54F47-1C83-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:37 . 2011-12-02 13:37 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C1D8E973-1CEA-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 00:44 . 2011-12-02 00:44 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BEC4B02B-1C7E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 01:27 . 2011-12-02 01:27 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BE89B187-1C84-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 01:56 . 2011-12-01 01:57 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BCD4D4DB-1BBF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 14:41 . 2011-12-02 14:41 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B99AA158-1CF3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 00:14 . 2011-12-03 00:15 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B6126A25-1D43-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 12:09 . 2011-12-03 12:09 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B54797E1-1DA7-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:25 . 2011-12-02 12:25 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B53A1E4C-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 07:17 . 2011-12-02 07:17 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B2FDE9D3-1CB5-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:04 . 2011-12-03 06:05 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B2B3F318-1D74-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 18:36 . 2011-12-03 18:36 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B24B3831-1DDD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 00:21 . 2011-12-03 00:21 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B1E46A0B-1D44-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:52 . 2011-12-02 23:52 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B13DE8C5-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:52 . 2011-12-02 23:52 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B13DE8C4-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:00 . 2011-12-03 05:00 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B1024E15-1D6B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 03:06 . 2011-12-02 03:07 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B02F7F37-1C92-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 21:44 . 2011-12-01 21:45 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AEF62B93-1C65-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 12:25 . 2011-12-02 12:25 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE700BFB-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:25 . 2011-12-02 12:25 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE700BFA-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 14:28 . 2011-12-01 14:28 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE6C70FE-1C28-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 14:28 . 2011-12-01 14:28 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE6C70FC-1C28-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 18:43 . 2011-12-03 18:43 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE1D3817-1DDE-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 10:43 . 2011-12-03 10:43 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AD3F3489-1D9B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 22:25 . 2011-12-03 22:25 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AA26B877-1DFD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 14:55 . 2011-12-02 14:55 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AA25E141-1CF5-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:25 . 2011-11-30 23:32 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A7AFC977-1BAA-11E1-BAB2-001CC432139B}.dat
+ 2011-12-02 22:47 . 2011-12-02 22:47 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A34F71CD-1D37-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:52 . 2011-12-02 23:53 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A0BD21CD-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 05:43 . 2011-12-02 05:45 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9F6D677F-1CA8-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 11:47 . 2011-12-03 11:47 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9E15793D-1DA4-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 10:01 . 2011-12-02 10:02 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9C73BD89-1CCC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 16:56 . 2011-12-02 16:56 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9C504F86-1D06-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 10:00 . 2011-12-03 10:00 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9BD42AF3-1D95-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 02:57 . 2011-12-03 02:58 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9B1499CF-1D5A-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 11:54 . 2011-12-03 11:54 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{99E516C9-1DA5-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:24 . 2011-12-02 12:24 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{99282EA8-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 12:23 . 2011-12-03 12:23 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{98BD0FD7-1DA9-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 14:39 . 2011-12-03 14:39 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{98862B99-1DBC-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 18:38 . 2011-12-01 18:39 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{97B16BA1-1C4B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 05:13 . 2011-12-03 05:14 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{97692D1E-1D6D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 03:05 . 2011-12-03 03:05 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{96E699B5-1D5B-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 08:58 . 2011-12-01 08:58 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{96340F97-1BFA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:59 . 2011-12-03 17:59 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{961EF251-1DD8-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:15 . 2011-12-03 15:17 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{95D07BAD-1DC1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 12:01 . 2011-12-03 12:01 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{95B716AF-1DA6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:24 . 2011-12-02 12:24 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{911C3EE8-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 06:20 . 2011-12-01 06:20 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9056F761-1BE4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 17:19 . 2011-12-01 17:19 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8EDA1B79-1C40-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:22 . 2011-12-03 20:22 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8DBB3D27-1DEC-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 03:34 . 2011-12-02 03:34 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8CB35C69-1C96-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 12:37 . 2011-12-03 12:37 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8C1AB845-1DAB-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:45 . 2011-12-03 17:45 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8BF9576F-1DD6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:01 . 2011-12-02 23:01 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8BD386A9-1D39-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:32 . 2011-11-30 23:32 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8B5470B5-1BAB-11E1-BAB2-001CC432139B}.dat
+ 2011-12-02 06:40 . 2011-12-02 06:41 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8B28A3CB-1CB0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 12:24 . 2011-12-02 12:24 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8A81DBA8-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 20:29 . 2011-12-03 20:31 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{898615FF-1DED-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 09:12 . 2011-12-01 09:12 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{88F1FA77-1BFC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:08 . 2011-12-02 23:08 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{87A5868F-1D3A-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:39 . 2011-11-30 23:39 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8739836B-1BAC-11E1-BAB2-001CC432139B}.dat
+ 2011-12-02 21:20 . 2011-12-02 21:21 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8568FCFD-1D2B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 11:06 . 2011-12-01 11:07 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{85155F87-1C0C-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 12:23 . 2011-12-02 12:23 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{82489F38-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 15:38 . 2011-12-01 15:42 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{814883C3-1C32-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:01 . 2011-12-02 15:01 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{80F78269-1CF6-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 22:02 . 2011-12-03 22:02 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7F19844B-1DFA-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 08:04 . 2011-12-03 08:06 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7E75FF8B-1D85-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 10:15 . 2011-12-02 10:16 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7DBDB195-1CCE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 15:58 . 2011-12-02 15:59 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7BD50BFF-1CFE-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 22:09 . 2011-12-03 22:09 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7AEDE68B-1DFB-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 17:39 . 2011-12-01 17:40 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7AD3387D-1C43-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 02:21 . 2011-12-03 02:21 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{794382E3-1D55-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:13 . 2011-12-03 05:13 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{78506140-1D6D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 16:05 . 2011-12-02 16:06 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{77A96E3F-1CFF-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 09:37 . 2011-12-03 09:37 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{75B8F779-1D92-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 15:15 . 2011-12-02 15:15 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{74B488E3-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:50 . 2011-12-02 23:50 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{724FF743-1D40-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 17:02 . 2011-12-02 17:03 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6E72B1D9-1D07-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 06:10 . 2011-12-03 06:10 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6E3987CF-1D75-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 12:44 . 2011-12-02 12:45 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6D619F3B-1CE3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 03:27 . 2011-12-01 03:28 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6CCCDB93-1BCC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 03:18 . 2011-12-03 03:18 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6A2795F3-1D5D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 10:08 . 2011-12-01 10:08 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6A271583-1C04-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 05:12 . 2011-12-03 05:12 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6A2143D3-1D6D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:21 . 2011-12-03 15:21 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{692FF6BD-1DC2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 13:07 . 2011-12-01 13:08 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{688667FB-1C1D-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 07:02 . 2011-12-01 07:07 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{67D45E37-1BEA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 10:50 . 2011-12-02 10:52 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6436C055-1CD3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 22:37 . 2011-12-03 22:37 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{642368EB-1DFF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 02:36 . 2011-12-02 02:36 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6319FAAF-1C8E-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 03:48 . 2011-12-01 03:49 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{62DE6DB5-1BCF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 08:25 . 2011-12-03 08:27 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{627FC90D-1D88-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 18:35 . 2011-12-02 18:35 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6178DBCD-1D14-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 03:39 . 2011-12-03 03:39 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6049D88B-1D60-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:43 . 2011-12-03 17:44 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5FDDD66B-1DD6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 05:12 . 2011-12-03 05:12 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5B0158E2-1D6D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 00:19 . 2011-12-02 00:20 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5A0EFD79-1C7B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 05:43 . 2011-12-01 05:43 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{599D6133-1BDF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 02:29 . 2011-12-01 02:30 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{57D6D4E9-1BC4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 10:55 . 2011-12-03 10:55 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{578CECF5-1D9D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 00:20 . 2011-12-01 00:21 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{56AD5CDF-1BB2-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 05:12 . 2011-12-03 05:12 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{546957FA-1D6D-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 16:54 . 2011-12-02 16:54 8704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5416F329-1D06-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 09:46 . 2011-12-01 09:47 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{52D5F84D-1C01-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 00:28 . 2011-12-01 00:28 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{527F5CC5-1BB3-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 00:35 . 2011-12-01 00:35 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5054589B-1BB4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 09:53 . 2011-12-01 09:54 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4EB6464F-1C02-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 01:37 . 2011-12-03 01:37 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4CA6A6C1-1D4F-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 13:25 . 2011-12-03 13:25 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4AEF4BEF-1DB2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 08:33 . 2011-12-02 08:34 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4AC9FAB9-1CC0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 10:00 . 2011-12-01 10:00 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4A8D0AE9-1C03-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:46 . 2011-12-02 11:47 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4A0342B3-1CDB-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 20:15 . 2011-12-01 20:16 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{483DC3E5-1C59-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:53 . 2011-12-02 11:54 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{45DA074D-1CDC-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:35 . 2011-12-02 23:35 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{441FCA61-1D3E-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 12:44 . 2011-12-01 12:46 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{43763BDD-1C1A-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 12:22 . 2011-12-02 12:22 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{429BF196-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 20:41 . 2011-12-03 20:42 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3E388EC3-1DEF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 08:48 . 2011-12-01 08:49 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3AD450AD-1BF9-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 22:31 . 2011-12-01 22:32 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3A53BC81-1C6C-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:49 . 2011-12-03 20:49 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3A0CF103-1DF0-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 20:29 . 2011-12-01 20:30 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3714B577-1C5B-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 02:40 . 2011-12-03 02:41 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{36EC119B-1D58-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 00:54 . 2011-12-02 00:55 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3689D103-1C80-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 10:27 . 2011-12-02 10:27 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3611FF75-1CD0-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 20:56 . 2011-12-03 20:56 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{35DC8E8F-1DF1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 09:29 . 2011-12-02 09:31 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{32A7C723-1CC8-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 14:24 . 2011-12-01 14:28 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2F799ADB-1C28-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 07:41 . 2011-12-03 07:41 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2C4FFB7F-1D82-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 09:16 . 2011-12-01 09:17 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2C1CE9DB-1BFD-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 21:47 . 2011-12-02 21:47 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2C052F57-1D2F-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 22:22 . 2011-12-02 22:23 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2B527B5F-1D34-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 16:38 . 2011-12-03 16:38 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2A130EC3-1DCD-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 05:11 . 2011-12-02 05:12 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{27EBEB99-1CA4-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:19 . 2011-12-03 15:19 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{226F4DEA-1DC2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 14:02 . 2011-12-01 14:03 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{20F7EE39-1C25-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 05:26 . 2011-12-02 05:26 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1F8B26B1-1CA6-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 23:19 . 2011-12-02 23:20 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1EFF6D8D-1D3C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:20 . 2011-12-02 15:20 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1C3DA725-1CF9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 23:26 . 2011-12-02 23:27 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1AD3CFCD-1D3D-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 19:58 . 2011-12-03 19:58 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1A1089D9-1DE9-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:14 . 2011-12-01 07:18 8704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{198BE67B-1BEC-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 22:09 . 2011-12-01 22:09 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1821E4AB-1C69-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:40 . 2011-12-03 15:43 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1350E23B-1DC5-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 15:19 . 2011-12-02 15:19 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{105DD0E6-1CF9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 17:58 . 2011-12-01 17:59 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0E719041-1C46-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 23:41 . 2011-12-01 23:42 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0B3B2173-1C76-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 07:55 . 2011-12-02 07:56 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0A22D9CB-1CBB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:21 . 2011-12-03 06:21 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{089CAD68-1D77-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 23:48 . 2011-12-01 23:49 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{070F83B3-1C77-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 01:44 . 2011-12-01 01:45 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0709069B-1BBE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 12:00 . 2011-12-01 12:01 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{06E2E127-1C14-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:12 . 2011-12-03 17:12 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{06BFF3AF-1DD2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 20:41 . 2011-12-02 20:42 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{06A81BD3-1D26-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 12:20 . 2011-12-02 12:20 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{06210A8B-1CE0-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 10:54 . 2011-12-02 10:54 8704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{05873BBF-1CD4-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 02:10 . 2011-12-03 02:10 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{04D64E41-1D54-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 08:25 . 2011-12-01 08:25 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{04AD2971-1BF6-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:18 . 2011-12-03 15:18 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{015123C4-1DC2-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 15:18 . 2011-12-03 15:18 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{015123C2-1DC2-11E1-BAB5-001CC432139B}.dat
+ 2011-11-20 15:26 . 2011-12-02 05:56 7198 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\frameiconcache.dat
+ 2001-08-23 11:00 . 2011-12-02 23:32 432686 c:\windows\system32\perfh009.dat
- 2001-08-23 11:00 . 2011-11-30 23:16 432686 c:\windows\system32\perfh009.dat
+ 2011-12-03 08:06 . 2011-12-03 22:37 229376 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011120320111204\index.dat
+ 2011-12-02 08:02 . 2011-12-03 07:59 278528 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011120220111203\index.dat
+ 2011-12-01 08:04 . 2011-12-02 07:55 344064 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011120120111202\index.dat
+ 2011-11-30 08:00 . 2011-12-01 07:58 393216 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011113020111201\index.dat
+ 2011-12-03 19:38 . 2011-12-03 19:38 162816 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{6E807438-1DE6-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 14:50 . 2011-12-02 14:57 145920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FA5C5F87-1CF4-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 16:52 . 2011-12-02 16:59 161792 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F625AAF7-1D05-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 09:42 . 2011-12-02 09:49 140288 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F375B0EF-1CC9-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 06:49 . 2011-12-03 06:55 193024 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F0EAEBB3-1D7A-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:04 . 2011-12-03 17:11 573440 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E72AADC9-1DD0-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 15:19 . 2011-12-01 15:26 105472 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E3BCA13F-1C2F-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 21:08 . 2011-12-02 21:15 141312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D428AA4D-1D29-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 09:54 . 2011-12-03 09:59 207360 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D1716D29-1D94-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:26 . 2011-12-01 07:30 299520 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CE4CAD5F-1BED-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 17:48 . 2011-12-02 17:55 141312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C9DE78EF-1D0D-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 07:03 . 2011-12-02 07:09 453120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C75197C9-1CB3-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:02 . 2011-12-03 15:03 108544 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C4521BE5-1DBF-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 08:29 . 2011-12-02 08:34 209920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C3A04A7F-1CBF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 09:06 . 2011-12-01 09:13 738816 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C13DE1ED-1BFB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 13:44 . 2011-12-02 13:50 604160 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BDAAE959-1CEB-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 07:11 . 2011-12-01 07:18 525824 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B992DDA5-1BEB-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 07:40 . 2011-12-01 07:46 153600 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B54C22ED-1BEF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:30 . 2011-12-03 15:37 209920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ADFED3D9-1DC3-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 12:19 . 2011-12-01 12:26 267264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ADABE06F-1C16-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 15:37 . 2011-12-03 15:44 116224 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A9DCBF81-1DC4-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 08:21 . 2011-12-02 08:28 156672 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9B7BF387-1CBE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 08:28 . 2011-12-02 08:34 240128 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{974DF36D-1CBF-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 17:09 . 2011-12-03 17:09 107008 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{934B3359-1DD1-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 17:38 . 2011-12-03 17:45 648704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9029B9E3-1DD5-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 05:37 . 2011-12-01 05:42 286208 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{86FA3FE9-1BDE-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 10:13 . 2011-12-03 10:20 248320 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{83D780D7-1D97-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 23:15 . 2011-12-02 23:19 106496 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8379E8CF-1D3B-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 20:23 . 2011-12-02 20:30 110080 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7C6D066F-1D23-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:15 . 2011-12-02 15:20 145920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7AACCC43-1CF8-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 07:14 . 2011-12-03 07:21 587264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7195F1C9-1D7E-11E1-BAB5-001CC432139B}.dat
+ 2011-12-03 06:31 . 2011-12-03 06:37 480768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6D9DABDF-1D78-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 17:09 . 2011-12-02 17:16 204288 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6A424F65-1D08-11E1-BAB4-001CC432139B}.dat
+ 2011-12-03 10:26 . 2011-12-03 10:32 451072 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{415BCC89-1D99-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 07:01 . 2011-12-01 07:07 119808 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{402EE3A1-1BEA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 07:34 . 2011-12-03 07:41 311808 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4010576D-1D81-11E1-BAB5-001CC432139B}.dat
+ 2011-12-02 17:36 . 2011-12-02 17:43 836096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{39B52959-1D0C-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 08:55 . 2011-12-01 09:02 968704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{36A8B2ED-1BFA-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 11:31 . 2011-12-02 11:36 562176 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2C8AB2DB-1CD9-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 15:34 . 2011-12-02 15:41 148992 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{26A104A7-1CFB-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 18:33 . 2011-12-02 18:40 624128 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{25B3277D-1D14-11E1-BAB4-001CC432139B}.dat
+ 2011-12-02 05:19 . 2011-12-02 05:25 265216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{23B6C471-1CA5-11E1-BAB3-001CC432139B}.dat
+ 2011-12-01 11:39 . 2011-12-01 11:39 123904 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1E35C48D-1C11-11E1-BAB3-001CC432139B}.dat
+ 2011-12-03 07:40 . 2011-12-03 07:41 103936 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1CCBEDCB-1D82-11E1-BAB5-001CC432139B}.dat
+ 2011-12-01 15:35 . 2011-12-01 15:42 264704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{180FFBD3-1C32-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 10:47 . 2011-12-02 10:54 923136 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0FF7681D-1CD3-11E1-BAB4-001CC432139B}.dat
+ 2011-12-01 18:05 . 2011-12-01 18:12 265216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0A4854DB-1C47-11E1-BAB3-001CC432139B}.dat
+ 2011-12-02 20:48 . 2011-12-02 20:55 116224 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{027C7E13-1D27-11E1-BAB4-001CC432139B}.dat
+ 2011-11-30 23:25 . 2011-12-03 22:37 196608 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-11-20 15:13 . 2011-12-03 22:33 6897664 c:\windows\system32\config\systemprofile\PrivacIE\index.dat
- 2011-08-19 23:19 . 2011-11-30 23:10 9781248 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-08-19 23:19 . 2011-12-03 22:37 9781248 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-08-19 23:19 . 2011-12-03 22:37 3850240 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-20 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Medialink Utilty"="c:\program files\Medialink\MWN-USB150N\UI.exe" [2009-08-21 2170904]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-12-17 1657448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-12-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-17 14884864]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"RTHDCPL"="RTHDCPL.EXE" [2009-11-02 18782720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-10 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10x_ActiveX.exe" [2011-09-30 243360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2/22/2011 5:13 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [3/16/2011 1:03 PM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [1/7/2011 3:41 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [4/4/2011 9:59 PM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [10/10/2010 3:09 PM 291504]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [8/19/2011 1:26 AM 450848]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [4/14/2011 6:28 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2/10/2011 4:53 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2/10/2011 4:53 AM 16720]
R3 NgLog;Aventail VPN Logging;c:\windows\system32\drivers\nglog.sys [10/10/2010 2:47 PM 27160]
R3 NgVpn;Aventail VPN Adapter;c:\windows\system32\drivers\ngvpn.sys [10/10/2010 2:47 PM 77336]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/20/2011 8:17 AM 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [8/20/2011 3:40 AM 1684736]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/20/2011 8:17 AM 136176]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\drivers\ngfilter.sys [10/10/2010 2:47 PM 23064]
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\drivers\ngwfp.sys [10/10/2010 2:47 PM 25112]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-20 16:17]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-20 16:17]
.
2011-12-04 c:\windows\Tasks\User_Feed_Synchronization-{EFB58665-CA85-41A6-94C1-82848AD5E317}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 08:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,70,57,7a,e7,0d,4e,03,49,9a,b2,52,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,70,57,7a,e7,0d,4e,03,49,9a,b2,52,\
.
Completion time: 2011-12-04 08:10:15
ComboFix-quarantined-files.txt 2011-12-04 16:10
ComboFix2.txt 2011-11-30 23:56
ComboFix3.txt 2011-11-30 23:25
ComboFix4.txt 2011-11-29 04:11
.
Pre-Run: 465,540,362,240 bytes free
Post-Run: 466,044,948,480 bytes free
.
- - End Of File - - 77706E423E86658BBE40445B33DD2D82

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 04 December 2011 - 12:33 PM

SystemLook:

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:filefind
explorer.exe
svchost.exe
winlogon.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 04 December 2011 - 12:45 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 09:45 on 04/12/2011 by Jeremy & Gina
Administrator - Elevation successful

========== filefind ==========

Searching for "explorer.exe"
C:\WINDOWS\explorer.exe --a---- 1058304 bytes [10:42 14/04/2008] [10:42 14/04/2008] 51E29AE63EF43527320A0AD7987BD87C

Searching for "svchost.exe"
C:\WINDOWS\system32\svchost.exe --a---- 39424 bytes [10:42 14/04/2008] [10:42 14/04/2008] 87F42BB23FBBC44F193B804DDA4E3F24

Searching for "winlogon.exe"
C:\WINDOWS\system32\winlogon.exe --a---- 544768 bytes [10:42 14/04/2008] [10:42 14/04/2008] 05EE0EDEADFC079ABB9F166207296857

-= EOF =-

#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 04 December 2011 - 01:14 PM

Hello


Do you have access to another XP computer to copy files from?


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 04 December 2011 - 01:28 PM

I don't. I have a netbook with Windows 7 Starter only.

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 06 December 2011 - 03:10 PM

Hello


you need to check with friends if they can let you copy those files

these are infected and need to be replaced and you do not have replacements on your computer




gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 06 December 2011 - 04:10 PM

Ok, I've found another XP machine to copy the files from.

#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 06 December 2011 - 09:25 PM

Hello

that is great news!! we will need a usbdrive or jumpdrive to move the files

On the clean computer navigate to this file
C:\WINDOWS\explorer.exe
right click on it and select copy
now open up the usb drive and right click on an empty space and select paste

now do this also for the rest of these files

C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe

now after you have all three files on the usb drive move over to the infected computer

double click on the my computer icon
double click on the usb drive
find the files we copied
right click on one of the files and select copy
double click on the C: drive
right click on an empty space and select past
do this for the rest of the files

Now rerun system look for me

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:filefind
explorer.exe
svchost.exe
winlogon.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 07 December 2011 - 10:37 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 19:38 on 07/12/2011 by Jeremy & Gina
Administrator - Elevation successful

========== filefind ==========

Searching for "explorer.exe"
C:\explorer.exe --a---- 1033728 bytes [03:37 08/12/2011] [13:42 14/04/2008] 12896823FB95BFB3DC9B46BCAEDC9923
C:\WINDOWS\explorer.exe --a---- 1058304 bytes [10:42 14/04/2008] [10:42 14/04/2008] 51E29AE63EF43527320A0AD7987BD87C

Searching for "svchost.exe"
C:\svchost.exe --a---- 14336 bytes [03:37 08/12/2011] [13:42 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18
C:\WINDOWS\system32\svchost.exe --a---- 39424 bytes [10:42 14/04/2008] [10:42 14/04/2008] 87F42BB23FBBC44F193B804DDA4E3F24

Searching for "winlogon.exe"
C:\winlogon.exe --a---- 507904 bytes [03:37 08/12/2011] [13:42 14/04/2008] ED0EF0A136DEC83DF69F04118870003E
C:\WINDOWS\system32\winlogon.exe --a---- 544768 bytes [10:42 14/04/2008] [10:42 14/04/2008] 05EE0EDEADFC079ABB9F166207296857

-= EOF =-

#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 08 December 2011 - 09:29 AM

Hello

that is very good now i would like you to run this.

Blitzblank.

Download BlitzBlank and save it to your desktop. Open Blitzblank.exe

  • Click OK at the warning (and take note of it, this is a VERY powerful tool!).
  • Click the Script tab and copy/paste the following text there:
CopyFile:
C:\explorer.exe C:\WINDOWS\explorer.exe
C:\winlogon.exe C:\WINDOWS\system32\winlogon.exe
C:\explorer.exe C:\WINDOWS\system32\dllcache\explorer.exe
C:\winlogon.exe C:\WINDOWS\system32\dllcache\winlogon.exe
C:\svchost.exe C:\WINDOWS\system32\svchost.exe
C:\svchost.exe C:\WINDOWS\system32\dllcache\svchost.exe

  • Click Execute Now. Your computer will need to reboot in order to replace the files.
  • When done, post me the report created by Blitzblank. you can find it at the root of the drive Normaly C:\

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 08 December 2011 - 09:42 AM

BlitzBlank 1.0.0.32

File/Registry Modification Engine native application
CopyFileOnReboot: sourceFile = "\??\c:\explorer.exe", destinationFile = "\??\c:\windows\explorer.exe"CopyFileOnReboot: sourceFile = "\??\c:\winlogon.exe", destinationFile = "\??\c:\windows\system32\winlogon.exe"CopyFileOnReboot: sourceFile = "\??\c:\explorer.exe", destinationFile = "\??\c:\windows\system32\dllcache\explorer.exe"CopyFileOnReboot: sourceFile = "\??\c:\winlogon.exe", destinationFile = "\??\c:\windows\system32\dllcache\winlogon.exe"CopyFileOnReboot: sourceFile = "\??\c:\svchost.exe", destinationFile = "\??\c:\windows\system32\svchost.exe"CopyFileOnReboot: sourceFile = "\??\c:\svchost.exe", destinationFile = "\??\c:\windows\system32\dllcache\svchost.exe"

#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,773 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:37 PM

Posted 08 December 2011 - 10:05 AM

how are things running now?



I would like you to download an updated version of combofix.

update combofix

Delete the version of combofix you have now on your desktop and download a new one from here

Link 1
Link 2
Link 3
**Note: It is important that it is saved directly to your desktop**

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note:Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer
[/list]
"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 smallcrusher

smallcrusher
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:37 PM

Posted 08 December 2011 - 11:10 PM

All links from Google appear to be working correctly today. Here is the Combofix log report:


ComboFix 11-12-08.01 - Jeremy & Gina 12/08/2011 20:05:56.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.2820 [GMT -8:00]
Running from: c:\documents and settings\Jeremy & Gina\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\otruaaa.tmp
C:\explorer.exe
C:\svchost.exe
C:\winlogon.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-09 to 2011-12-09 )))))))))))))))))))))))))))))))
.
.
2011-12-08 14:41 . 2011-12-08 14:41 507904 -c--a-w- c:\windows\system32\dllcache\winlogon.exe
2011-12-08 14:41 . 2011-12-08 14:41 14336 -c--a-w- c:\windows\system32\dllcache\svchost.exe
2011-12-08 14:41 . 2011-12-08 14:41 1033728 -c--a-w- c:\windows\system32\dllcache\explorer.exe
2011-11-29 03:54 . 2011-07-15 13:29 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-26 08:06 . 2011-11-26 08:06 -------- d-----w- c:\windows\system32\q3pmG5aQJdKf
2011-11-26 08:06 . 2011-11-26 08:06 -------- d-----w- C:\qcA1ivD2oFaH
2011-11-25 12:31 . 2011-11-25 12:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-11-24 07:43 . 2011-11-24 07:43 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-11-20 19:22 . 2011-11-20 19:22 -------- d-----w- c:\documents and settings\Jeremy & Gina\Application Data\Malwarebytes
2011-11-20 19:21 . 2011-11-20 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-20 19:21 . 2011-11-20 19:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-20 19:21 . 2011-09-01 01:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-20 15:13 . 2011-11-20 15:13 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2011-11-20 15:13 . 2011-11-20 15:13 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-11-20 15:00 . 2011-11-20 15:00 -------- d-----w- C:\$AVG
2011-11-10 21:25 . 2011-11-10 21:25 -------- d-----w- c:\program files\MSECache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-08 14:41 . 2008-04-14 10:42 14336 ----a-w- c:\windows\system32\svchost.exe
2011-12-08 14:41 . 2008-04-14 10:42 507904 ----a-w- c:\windows\system32\winlogon.exe
2011-12-08 14:41 . 2008-04-14 10:42 1033728 ----a-w- c:\windows\explorer.exe
2011-10-24 21:29 . 2011-10-24 21:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 21:29 . 2011-10-24 21:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-10 14:22 . 2011-08-19 23:04 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2011-01-07 11:41 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2011-02-10 12:53 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-10-01 14:20 . 2011-10-01 14:20 53248 ----a-r- c:\documents and settings\Jeremy & Gina\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-09-30 04:27 . 2011-08-19 23:39 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-28 07:06 . 2008-04-14 10:41 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2001-08-23 11:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2001-08-23 11:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 13:30 . 2011-03-16 21:03 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-08-20 03:27 . 2011-08-20 03:27 5570000 ----a-w- c:\program files\AVG.exe
2011-08-20 03:19 . 2011-08-20 03:19 1081480 ----a-w- c:\program files\SkypeSetup.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-12-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot_2011-12-04_16.08.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-08 14:42 . 2011-12-08 14:42 16384 c:\windows\Temp\Perflib_Perfdata_688.dat
+ 2001-08-23 11:00 . 2011-12-08 14:46 67516 c:\windows\system32\perfc009.dat
- 2001-08-23 11:00 . 2011-12-02 23:32 67516 c:\windows\system32\perfc009.dat
+ 2011-12-07 08:02 . 2011-12-07 10:55 81920 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011120720111208\index.dat
+ 2011-12-07 10:22 . 2011-12-07 10:22 12288 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{6503224A-20BD-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:41 . 2011-12-07 10:41 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{00801D12-20C0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:16 . 2011-12-06 14:23 12288 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DBEA7140-2014-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:54 . 2011-12-06 16:55 15360 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FFA80147-202A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:17 . 2011-12-06 14:23 43008 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FEE0AD03-2014-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:33 . 2011-12-07 05:40 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F0FFBDAF-2094-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:40 . 2011-12-07 05:46 24064 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ECD8E4A3-2095-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:47 . 2011-12-07 05:53 21504 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E8B932A5-2096-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:54 . 2011-12-06 21:56 19456 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E8473331-2054-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:54 . 2011-12-07 05:59 63488 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E48B328B-2097-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:36 . 2011-12-06 17:43 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DD6C5919-2030-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:16 . 2011-12-06 14:18 10752 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DBEA7141-2014-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:05 . 2011-12-07 07:12 92672 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DA1ABF3D-20A1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:43 . 2011-12-06 17:50 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D93BF6A5-2031-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:33 . 2011-12-07 02:36 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D90FD42C-207B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:50 . 2011-12-06 17:57 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D50DF68B-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:53 . 2011-12-06 16:55 26112 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C2D01E85-202A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:32 . 2011-12-07 02:36 16896 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B6AB07DB-207B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:52 . 2011-12-06 16:56 20480 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A8C38D33-202A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:04 . 2011-12-07 07:04 71168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A3E466C7-20A1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:21 . 2011-12-06 14:23 18432 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9A06D3AE-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:17 . 2011-12-06 18:23 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9785426B-2036-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 15:18 . 2011-12-06 15:24 17920 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{9588DF87-201D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:12 . 2011-12-06 20:14 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8F519F9F-2046-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:21 . 2011-12-06 14:22 23040 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{85B4889C-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:50 . 2011-12-06 19:54 29696 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8176D79B-2043-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:20 . 2011-12-06 14:21 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7FB9E2DF-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:51 . 2011-12-06 16:57 14336 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{79C9B7EF-202A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:20 . 2011-12-06 14:20 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{74B7C752-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:51 . 2011-12-06 21:51 11776 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6C51AFE5-2054-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 15:17 . 2011-12-06 15:24 51712 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{637EA499-201D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:19 . 2011-12-06 14:19 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4F1548A8-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:08 . 2011-12-07 07:12 45568 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4E3FED8F-20A2-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:50 . 2011-12-06 21:56 70656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{40B48B8B-2054-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:46 . 2011-12-06 17:49 27648 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3ED76E2F-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:55 . 2011-12-06 20:02 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3CE23275-2044-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:19 . 2011-12-06 14:19 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3B736B98-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:06 . 2011-12-06 21:13 11264 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{339BC519-204E-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:55 . 2011-12-06 19:55 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3383B4C4-2044-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:18 . 2011-12-06 14:18 13312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{315AF687-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:39 . 2011-12-06 14:46 46080 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2A05B8B5-2018-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:55 . 2011-12-06 16:55 50176 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{21AFD1E2-202B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:41 . 2011-12-07 05:41 11776 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{153D1B59-2096-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:18 . 2011-12-06 19:22 92672 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1083D337-203F-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:09 . 2011-12-07 06:14 31744 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0D037B93-209A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:09 . 2011-12-07 06:10 20992 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0D037B91-209A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 01:30 . 2011-12-07 01:37 15360 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0BD44D83-2073-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 01:37 . 2011-12-07 01:41 10240 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{07A8AFC3-2074-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:41 . 2011-12-07 10:44 54272 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{00DF7B27-20C0-11E1-BAB7-001CC432139B}.dat
+ 2011-11-20 15:31 . 2011-12-07 10:20 65536 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2011-11-23 23:41 . 2011-12-07 10:55 32768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
- 2011-11-23 23:41 . 2011-12-03 22:37 32768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
- 2011-11-20 15:13 . 2011-12-03 22:37 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2011-11-20 15:13 . 2011-12-07 10:55 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2011-11-20 15:54 . 2011-12-07 10:20 32768 c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
- 2011-11-20 15:54 . 2011-12-03 14:27 32768 c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
+ 2011-12-07 10:22 . 2011-12-07 10:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{65032249-20BD-11E1-BAB7-001CC432139B}.dat
+ 2011-12-03 06:42 . 2011-12-07 10:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{02717593-1D7A-11E1-BAB5-001CC432139B}.dat
- 2011-12-03 06:42 . 2011-12-03 22:36 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{02717593-1D7A-11E1-BAB5-001CC432139B}.dat
+ 2011-12-07 10:48 . 2011-12-07 10:48 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FCB17B0C-20C0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:50 . 2011-12-07 04:50 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F9F4B7BC-208E-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:55 . 2011-12-07 10:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F885DD4C-20C1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:57 . 2011-12-07 04:57 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F5C45548-208F-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:07 . 2011-12-07 04:07 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F4F3CCCC-2088-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:07 . 2011-12-06 20:13 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F26417CE-2045-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:33 . 2011-12-07 05:33 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F0FFBDAE-2094-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:59 . 2011-12-06 14:59 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ED95DA50-201A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 23:27 . 2011-12-06 23:27 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ED3FB0A2-2061-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:40 . 2011-12-07 05:41 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ECD8E4A2-2095-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 23:34 . 2011-12-06 23:34 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E911B088-2062-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:47 . 2011-12-07 05:47 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E8B932A4-2096-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:54 . 2011-12-07 05:54 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E48B328A-2097-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:08 . 2011-12-07 06:15 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{E41037C2-2099-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:58 . 2011-12-07 07:04 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DE4D840A-20A0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:36 . 2011-12-06 17:36 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DD6C5918-2030-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:05 . 2011-12-07 07:08 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DA1ABF3C-20A1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:43 . 2011-12-06 17:50 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D93BF6A4-2031-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:50 . 2011-12-06 17:50 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D50DF68A-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 08:02 . 2011-12-07 08:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D49B4D1C-20A9-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 09:28 . 2011-12-07 09:28 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{CAD52044-20B5-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:45 . 2011-12-07 00:45 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C30420D8-206C-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:07 . 2011-12-07 06:07 3072 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C04CF1C2-2099-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:41 . 2011-12-06 20:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{BC45B346-204A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:17 . 2011-12-06 21:17 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ABC9CD68-204F-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:24 . 2011-12-06 21:24 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{A79BCD4E-2050-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 03:28 . 2011-12-07 03:28 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{98A14160-2083-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:17 . 2011-12-06 18:17 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{9785426A-2036-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:24 . 2011-12-06 18:24 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{93574250-2037-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 22:56 . 2011-12-06 22:56 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8A44F394-205D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:02 . 2011-12-07 02:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{817DB7CC-2077-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:02 . 2011-12-07 10:02 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{81495260-20BA-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 23:53 . 2011-12-06 23:53 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{80590476-2065-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:00 . 2011-12-07 00:00 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7C2D66B6-2066-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:51 . 2011-12-06 16:57 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{79C9B7EE-202A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:25 . 2011-12-07 04:25 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{78EA5396-208B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 08:49 . 2011-12-07 08:50 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{71870EBC-20B0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 08:57 . 2011-12-07 08:57 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6D5DD356-20B1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:44 . 2011-12-07 02:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6CB270E8-207D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:15 . 2011-12-07 05:15 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6ADDB2FA-2092-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:51 . 2011-12-07 02:51 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{688470CE-207E-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:22 . 2011-12-07 10:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{67C73CAA-20BD-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 15:17 . 2011-12-06 15:18 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{637EA498-201D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:15 . 2011-12-07 02:15 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{5D122A56-2079-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:22 . 2011-12-07 02:22 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{58E68C96-207A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:29 . 2011-12-07 02:33 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{54B88C7C-207B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:41 . 2011-12-06 19:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4534A940-2042-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:01 . 2011-12-06 18:01 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{41A61182-2034-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:48 . 2011-12-06 19:55 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{4110328E-2043-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:50 . 2011-12-06 21:54 5120 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{40B48B8A-2054-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:55 . 2011-12-06 19:55 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3CE23274-2044-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:34 . 2011-12-07 00:34 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3A1C1920-206B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:59 . 2011-12-06 20:59 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{37C9C532-204D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:06 . 2011-12-06 21:06 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{339BC518-204E-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:12 . 2011-12-07 00:12 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3152505A-2068-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:32 . 2011-12-06 14:32 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2E33B8CE-2017-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:39 . 2011-12-06 14:39 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{2A05B8B4-2018-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:43 . 2011-12-07 07:43 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{227598EC-20A7-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:50 . 2011-12-07 07:50 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1E453678-20A8-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:57 . 2011-12-06 18:57 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1DF5179E-203C-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 22:24 . 2011-12-06 22:24 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{115DD6F2-2059-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:18 . 2011-12-06 19:18 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{1083D336-203F-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 01:30 . 2011-12-07 01:30 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0BD44D82-2073-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 01:37 . 2011-12-07 01:37 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{07A8AFC2-2074-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 01:44 . 2011-12-07 01:44 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{037AAFA8-2075-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:41 . 2011-12-07 10:41 3584 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{00DF7B26-20C0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:17 . 2011-12-06 14:17 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FEE0AD01-2014-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:48 . 2011-12-07 10:48 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FCB17B0D-20C0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:50 . 2011-12-07 04:50 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F9F4B7BD-208E-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:55 . 2011-12-07 10:55 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F885DD4D-20C1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:57 . 2011-12-07 04:58 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F5C45549-208F-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:07 . 2011-12-07 04:07 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F4F3CCCD-2088-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 23:27 . 2011-12-06 23:28 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ED3FB0A3-2061-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 23:34 . 2011-12-06 23:35 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E911B089-2062-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:53 . 2011-12-06 16:54 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E3D1AC74-202A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:15 . 2011-12-07 06:15 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DD9EDC36-209A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:23 . 2011-12-06 14:23 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D552F015-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:23 . 2011-12-06 14:23 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D552F014-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 08:02 . 2011-12-07 08:03 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D49B4D1D-20A9-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:13 . 2011-12-06 20:14 5632 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{D2589BD1-2046-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:50 . 2011-12-06 17:50 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CFB7D314-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:23 . 2011-12-06 14:23 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CED78B67-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:23 . 2011-12-06 14:23 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CED78B66-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:23 . 2011-12-06 14:23 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CED78B65-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:23 . 2011-12-06 14:23 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CED78B64-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:33 . 2011-12-07 02:33 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CC0D1F0B-207B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 09:28 . 2011-12-07 09:28 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{CAD52045-20B5-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:45 . 2011-12-07 00:45 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C30420D9-206C-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:50 . 2011-12-06 17:50 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{C113E26C-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:41 . 2011-12-06 20:42 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{BC45B347-204A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:22 . 2011-12-06 14:22 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B3CBDE75-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:22 . 2011-12-06 14:22 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B3CBDE74-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:49 . 2011-12-06 17:49 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE27380E-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:49 . 2011-12-06 17:49 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AE27380C-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:22 . 2011-12-06 14:22 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AD553E79-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:22 . 2011-12-06 14:22 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{AD553E78-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:24 . 2011-12-06 21:25 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{A79BCD4F-2050-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 03:28 . 2011-12-07 03:29 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{98A14161-2083-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:24 . 2011-12-06 18:25 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{93574251-2037-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:21 . 2011-12-06 14:21 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{85B4889A-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:21 . 2011-12-06 14:21 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{85B48899-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:02 . 2011-12-07 02:02 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{817DB7CD-2077-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:50 . 2011-12-06 19:50 8704 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8176D799-2043-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:02 . 2011-12-07 10:02 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{81495261-20BA-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 23:53 . 2011-12-06 23:53 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{80590477-2065-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:00 . 2011-12-07 00:01 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{7C2D66B7-2066-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 04:25 . 2011-12-07 04:25 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{78EA5397-208B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 08:50 . 2011-12-07 08:50 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{71870EBD-20B0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:57 . 2011-12-06 16:57 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6D69A273-202B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:57 . 2011-12-06 16:57 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6D69A272-202B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:57 . 2011-12-06 16:57 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6D69A271-202B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 08:57 . 2011-12-07 08:57 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6D5DD357-20B1-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:44 . 2011-12-07 02:45 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6CB270E9-207D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 05:15 . 2011-12-07 05:15 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6ADDB2FB-2092-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:51 . 2011-12-07 02:52 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{688470CF-207E-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 10:22 . 2011-12-07 10:23 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{67C73CAB-20BD-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:15 . 2011-12-07 02:16 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{5D122A57-2079-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:22 . 2011-12-07 02:23 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{58E68C97-207A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 16:57 . 2011-12-06 16:57 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{567BC4E4-202B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:19 . 2011-12-06 14:19 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{550FEE63-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:19 . 2011-12-06 14:19 7168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4F1548AA-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:19 . 2011-12-06 14:19 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{428C2B74-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:01 . 2011-12-06 18:01 4096 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{41A61183-2034-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 17:46 . 2011-12-06 17:46 9728 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3ED76E2D-2032-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:34 . 2011-12-07 00:34 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3A1C1921-206B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 20:59 . 2011-12-06 21:00 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{37C9C533-204D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 00:12 . 2011-12-07 00:13 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{3152505B-2068-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:18 . 2011-12-06 14:18 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2B4FA04F-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:18 . 2011-12-06 14:18 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2B4FA04E-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:43 . 2011-12-07 07:43 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{227598ED-20A7-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 07:50 . 2011-12-07 07:50 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1E453679-20A8-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:17 . 2011-12-06 14:18 9216 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{17C33860-2015-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 22:24 . 2011-12-06 22:25 6656 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{115DD6F3-2059-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 01:44 . 2011-12-07 01:45 6144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{037AAFA9-2075-11E1-BAB7-001CC432139B}.dat
- 2001-08-23 11:00 . 2011-12-02 23:32 432686 c:\windows\system32\perfh009.dat
+ 2001-08-23 11:00 . 2011-12-08 14:46 432686 c:\windows\system32\perfh009.dat
+ 2011-12-06 14:10 . 2011-12-07 07:57 311296 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011120620111207\index.dat
+ 2011-12-06 20:07 . 2011-12-06 20:14 149504 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{F26417CF-2045-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:59 . 2011-12-06 15:06 144384 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ED95DA51-201A-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:08 . 2011-12-07 06:15 499712 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{E41037C3-2099-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 06:58 . 2011-12-07 07:05 309248 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{DE4D840B-20A0-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 21:17 . 2011-12-06 21:24 141312 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{ABC9CD69-204F-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 22:56 . 2011-12-06 23:03 269824 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{8A44F395-205D-11E1-BAB7-001CC432139B}.dat
+ 2011-12-07 02:29 . 2011-12-07 02:35 135168 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{54B88C7D-207B-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:41 . 2011-12-06 19:48 148480 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4534A941-2042-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 19:48 . 2011-12-06 19:54 139776 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{4110328F-2043-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:32 . 2011-12-06 14:39 429056 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2E33B8CF-2017-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 18:57 . 2011-12-06 19:03 294912 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{1DF5179F-203C-11E1-BAB7-001CC432139B}.dat
+ 2011-12-06 14:09 . 2011-12-07 11:02 147456 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-11-20 15:13 . 2011-12-07 10:41 7536640 c:\windows\system32\config\systemprofile\PrivacIE\index.dat
- 2011-08-19 23:19 . 2011-12-03 22:37 9781248 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-08-19 23:19 . 2011-12-07 11:02 9781248 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-12-06 14:10 . 2011-12-06 14:09 1359872 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011112820111205\index.dat
+ 2011-08-19 23:19 . 2011-12-07 11:02 3850240 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-08-19 23:19 . 2011-12-03 22:37 3850240 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-20 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Medialink Utilty"="c:\program files\Medialink\MWN-USB150N\UI.exe" [2009-08-21 2170904]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-12-17 1657448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-12-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-17 14884864]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"RTHDCPL"="RTHDCPL.EXE" [2009-11-02 18782720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-10 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10x_ActiveX.exe" [2011-09-30 243360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2/22/2011 5:13 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [3/16/2011 1:03 PM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [1/7/2011 3:41 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [4/4/2011 9:59 PM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [10/10/2010 3:09 PM 291504]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [8/19/2011 1:26 AM 450848]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [4/14/2011 6:28 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2/10/2011 4:53 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2/10/2011 4:53 AM 16720]
R3 NgLog;Aventail VPN Logging;c:\windows\system32\drivers\nglog.sys [10/10/2010 2:47 PM 27160]
R3 NgVpn;Aventail VPN Adapter;c:\windows\system32\drivers\ngvpn.sys [10/10/2010 2:47 PM 77336]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/20/2011 8:17 AM 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [8/20/2011 3:40 AM 1684736]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/20/2011 8:17 AM 136176]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\drivers\ngfilter.sys [10/10/2010 2:47 PM 23064]
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\drivers\ngwfp.sys [10/10/2010 2:47 PM 25112]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2011-12-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-20 16:17]
.
2011-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-20 16:17]
.
2011-12-08 c:\windows\Tasks\User_Feed_Synchronization-{EFB58665-CA85-41A6-94C1-82848AD5E317}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-08 20:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,70,57,7a,e7,0d,4e,03,49,9a,b2,52,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,70,57,7a,e7,0d,4e,03,49,9a,b2,52,\
.
Completion time: 2011-12-08 20:11:35
ComboFix-quarantined-files.txt 2011-12-09 04:11
ComboFix2.txt 2011-12-04 16:10
ComboFix3.txt 2011-11-30 23:56
ComboFix4.txt 2011-11-30 23:25
ComboFix5.txt 2011-12-09 04:03
.
Pre-Run: 465,864,429,568 bytes free
Post-Run: 466,158,632,960 bytes free
.
- - End Of File - - 1B68FABB4D8A676DFB8FC622DC9BCF86




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users