Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Removing consrv.dll virus


  • This topic is locked This topic is locked
2 replies to this topic

#1 deathlyhaven

deathlyhaven

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:02 PM

Posted 22 January 2012 - 12:17 AM

I unfortunately was running my computer with no virus protection for quite some time. I was looking at other threads and it seems like other people with similar problems were helped with this problem. I currently downloaded the full version of Norton but it seems like its too late and the computer file has infected the system in a way that each boots makes it act as if though the computer needs to be fixed. I got a log from frst64.exe. I'm currently using windows 7. Here is the log.

Scan result of Farbar Recovery Tool (FRST written by farbar) Version: 17-01-2012 00
Ran by SYSTEM at 2012-01-22 00:05:40
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [] [x]
HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167256 2011-04-07] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [391000 2011-04-07] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [418136 2011-04-07] (Intel Corporation)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [561152 2011-04-20] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [296824 2010-09-25] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [967544 2011-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11780712 2011-03-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 /MAXX3 [2189416 2011-03-01] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated)
HKLM\...\Run: [ThpSrv] C:\windows\system32\thpsrv /logon [x]
HKLM\...\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r [1544104 2011-04-07] (TOSHIBA Corporation)
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2011-01-05] (Intel® Corporation)
HKLM\...\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-08] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe [711576 2011-04-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [595816 2010-04-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2011-03-30] (TOSHIBA Corporation)
HKLM-x32\...\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL [532480 2010-11-09] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP [423936 2010-03-04] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM [34160 2010-08-16] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [x]
HKLM-x32\...\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [1294712 2010-11-29] (TOSHIBA Corporation)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [296056 2012-01-05] (RealNetworks, Inc.)
HKLM-x32\...\Run: [GIDDesktop] C:\Program Files (x86)\SFT\GuardedID\gidd.exe /s [395528 2011-07-05] (StrikeForce Technologies Inc.)
HKU\Haven\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [641400 2011-10-27] (BitTorrent, Inc.)
HKU\Haven\...\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent [40376 2011-12-29] (Overwolf)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
SubSystems: [Windows] ==> ZeroAccess

==================== Services (Whitelisted) ======

3 1394hub; C:\Windows\System32\svchost.exe -k netsvcs [27648 2011-03-01] (Microsoft Corporation)
2 IDVaultSvc; "C:\Program Files (x86)\Constant Guard Protection Suite\IDVaultSvc.exe" [63048 2011-12-17] (White Sky, Inc.)
2 IviRegMgr; "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe" [110736 2010-05-20] (InterVideo)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-01-05] ()
2 N360; "C:\Program Files (x86)\Norton Security Suite\Engine\5.0.0.125\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton Security Suite\Engine\5.0.0.125\diMaster.dll" /prefetch:1 [262584 2010-12-02] (Symantec Corporation)
3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\\OverwolfUpdater.exe [17848 2011-12-29] (Overwolf Ltd)
2 PSI_SVC_2; "C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe" [193824 2010-03-11] (Protexis Inc.)
2 Thpsrv; C:\windows\system32\ThpSrv.exe [526848 2010-12-24] (TOSHIBA Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe" [2656280 2011-02-01] (Intel Corporation)

========================== Drivers (Whitelisted) =============

1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20101123.003\BHDrvx64.sys [953904 2010-11-22] (Symantec Corporation)
3 bpenum; C:\Windows\System32\DRIVERS\bpenum.sys [75264 2011-02-17] (Intel Corporation)
3 bpmp; C:\Windows\System32\DRIVERS\bpmp.sys [174080 2011-02-17] (Intel Corporation)
3 bpusb; C:\Windows\System32\Drivers\bpusb.sys [81920 2011-02-17] (Intel Corporation)
3 CeKbFilter; C:\Windows\System32\DRIVERS\CeKbFilter.sys [20592 2011-05-23] (Compal Electronics, INC.)
3 easytether; C:\Windows\System32\DRIVERS\easytthr.sys [21072 2010-08-29] (Mobile Stream)
1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [482936 2012-01-19] (Symantec Corporation)
3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138360 2012-01-19] (Symantec Corporation)
1 GIDv2; C:\Windows\System32\Drivers\GIDv2.sys [29288 2011-07-05] (StrikeForce Technologies, Inc.)
1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20101201.001\IDSVia64.sys [476792 2010-11-10] (Symantec Corporation)
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120120.004\ENG64.SYS [117880 2012-01-19] (Symantec Corporation)
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120120.004\EX64.SYS [2048632 2012-01-19] (Symantec Corporation)
3 NETwNs64; C:\Windows\System32\DRIVERS\NETwNs64.sys [8507392 2011-01-04] (Intel Corporation)
2 regi; \??\C:\windows\system32\drivers\regi.sys [14112 2007-04-17] (InterVideo)
0 SMR210; C:\Windows\System32\drivers\SMR210.SYS [96376 2012-01-21] (Symantec Corporation)
1 SRTSP; C:\Windows\System32\drivers\N360x64\0500000.07D\SRTSP64.SYS [735864 2010-11-22] (Symantec Corporation)
1 SRTSPX; C:\Windows\System32\drivers\N360x64\0500000.07D\SRTSPX64.SYS [40568 2010-11-22] (Symantec Corporation)
0 SymDS; C:\Windows\System32\drivers\N360x64\0500000.07D\SYMDS64.SYS [450608 2010-10-20] (Symantec Corporation)
0 SymEFA; C:\Windows\System32\drivers\N360x64\0500000.07D\SYMEFA64.SYS [802864 2010-11-17] (Symantec Corporation)
3 SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174640 2012-01-21] (Symantec Corporation)
1 SymIRON; C:\Windows\System32\drivers\N360x64\0500000.07D\Ironx64.SYS [171128 2010-11-15] (Symantec Corporation)
1 SymNetS; C:\Windows\System32\drivers\N360x64\0500000.07D\SYMNETS.SYS [382072 2010-11-30] (Symantec Corporation)
3 TsUsbGD; C:\Windows\System32\drivers\TsUsbGD.sys [31232 2010-11-20] (Microsoft Corporation)
3 wdkmd; C:\Windows\System32\DRIVERS\WDKMD.sys [42392 2010-12-25] (Intel Corporation)
3 dump_wmimmc; \??\C:\gPotato\Rappelz\GameGuard\dump_wmimmc.sys [x]
3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [x]
3 npggsvc; C:\windows\system32\GameMon.des -service [x]
3 NPPTNT2; \??\C:\windows\system32\npptNT2.sys [x]
3 X6va005; \??\C:\Users\Haven\AppData\Local\Temp\005532E.tmp [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2012-01-22 00:05 - 2012-01-22 00:06 - 0000000 ____D C:\FRST
2012-01-21 21:01 - 2012-01-21 21:01 - 1379845 ____A C:\Users\Haven\Downloads\FRST64.exe
2012-01-21 20:39 - 2012-01-21 20:39 - 0096376 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR210.SYS
2012-01-21 20:39 - 2012-01-21 20:39 - 0000020 ____A C:\Windows\System32\Drivers\SMR210.dat
2012-01-21 20:31 - 2012-01-21 21:01 - 0019526 ____A C:\Windows\ntbtlog.txt
2012-01-21 19:57 - 2012-01-21 19:57 - 0000766 ____A C:\Users\Haven\AppData\Roaming\SMRBackup210.dat
2012-01-21 19:49 - 2012-01-21 19:49 - 0000000 ____D C:\Program Files\Symantec
2012-01-21 10:59 - 2012-01-21 20:41 - 0000000 ____D C:\Users\Haven\AppData\Local\NPE
2012-01-21 10:59 - 2012-01-21 10:59 - 2562040 ____A (Symantec Corporation) C:\Users\Haven\Downloads\NPE.exe
2012-01-21 10:56 - 2012-01-21 23:08 - 0000000 ____D C:\Program Files\Common Files\Symantec Shared
2012-01-21 10:56 - 2012-01-21 10:56 - 0174640 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-01-21 10:56 - 2012-01-21 10:56 - 0007440 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-01-21 10:56 - 2012-01-21 10:56 - 0002605 ____A C:\Users\Public\Desktop\Norton Security Suite.lnk
2012-01-21 10:56 - 2012-01-21 10:56 - 0000854 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.INF
2012-01-21 10:56 - 2010-08-20 20:59 - 0125872 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi64.dll
2012-01-21 10:56 - 2010-08-20 20:59 - 0106928 ____A (GEAR Software Inc.) C:\Windows\SysWOW64\GEARAspi.dll
2012-01-21 10:56 - 2010-08-20 20:59 - 0034152 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-01-21 10:55 - 2012-01-21 23:08 - 0000000 ____D C:\Windows\System32\Drivers\N360x64
2012-01-21 10:55 - 2012-01-21 23:08 - 0000000 ____D C:\Program Files (x86)\Norton Security Suite
2012-01-21 10:14 - 2012-01-21 23:06 - 0000000 ____D C:\Program Files (x86)\NortonInstaller
2012-01-21 10:14 - 2012-01-21 10:14 - 0000000 ____D C:\Users\Haven\Documents\Symantec
2012-01-21 10:11 - 2012-01-21 10:55 - 0001379 ____A C:\Users\Haven\Desktop\Norton Installation Files.lnk
2012-01-21 10:11 - 2012-01-21 10:11 - 0000000 ____D C:\Users\Public\Downloads\Norton
2012-01-21 10:04 - 2012-01-21 10:54 - 0000000 ____D C:\Users\Haven\AppData\Roaming\ID Vault
2012-01-21 10:04 - 2012-01-21 10:05 - 0000000 ____D C:\Users\Haven\AppData\Local\ID Vault
2012-01-21 10:04 - 2012-01-21 10:04 - 0000000 ____D C:\Users\All Users\IsolatedStorage
2012-01-21 10:04 - 2012-01-21 10:04 - 0000000 ____D C:\ProgramData\IsolatedStorage
2012-01-21 10:03 - 2012-01-21 10:04 - 0000000 ____D C:\Program Files (x86)\Constant Guard Protection Suite
2012-01-21 10:03 - 2012-01-21 10:03 - 0002320 ____A C:\Users\All Users\Start Menu\Programs\Startup\Constant Guard.lnk
2012-01-21 10:03 - 2012-01-21 10:03 - 0002302 ____A C:\Users\Public\Desktop\Constant Guard.lnk
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\Users\All Users\White Sky, Inc
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\Users\All Users\GID
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\ProgramData\White Sky, Inc
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\ProgramData\GID
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\Program Files (x86)\SFT
2012-01-21 10:03 - 2011-07-05 07:25 - 0467224 ____N (StrikeForce Technologies Inc.) C:\Windows\System32\GIDHOOK64.DLL
2012-01-21 10:03 - 2011-07-05 07:25 - 0065816 ____N (StrikeForce Technologies Inc.) C:\Windows\System32\GIDLogonCP64.dll
2012-01-21 10:03 - 2011-07-05 07:24 - 0446752 ____N (StrikeForce Technologies Inc.) C:\Windows\System32\GIDHookLogon64.dll
2012-01-21 10:03 - 2011-07-05 07:23 - 0206608 ____N (StrikeForce Technologies Inc.) C:\Windows\System32\GIDBIN1.DLL
2012-01-21 10:03 - 2011-07-05 07:23 - 0102160 ____N (StrikeForce Technologies Inc.) C:\Windows\System32\GIDBIN3.DLL
2012-01-21 10:03 - 2011-07-05 07:18 - 0029288 ____N (StrikeForce Technologies, Inc.) C:\Windows\System32\Drivers\gidv2.sys
2012-01-21 10:03 - 2009-06-12 13:32 - 0109064 ____N C:\Windows\System32\EasyHook64.dll
2012-01-21 10:00 - 2012-01-21 10:01 - 21631488 ____A (White Sky, Inc.) C:\Users\Haven\Downloads\constantguard.exe
2012-01-19 10:00 - 2012-01-19 10:00 - 0015717 ____A C:\Windows\SysWOW64\hs_err_pid11308.log
2012-01-18 18:06 - 2011-10-26 12:25 - 1797029888 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix ff0-d1.iso
2012-01-18 17:57 - 2011-03-04 00:22 - 1702998016 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).iso
2012-01-18 17:30 - 2012-01-18 17:45 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part11.rar
2012-01-18 17:30 - 2012-01-18 17:31 - 5167768 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part12.rar
2012-01-18 17:29 - 2012-01-18 17:45 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part10.rar
2012-01-18 17:29 - 2012-01-18 17:45 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part09.rar
2012-01-18 17:29 - 2012-01-18 17:45 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part08.rar
2012-01-18 17:29 - 2012-01-18 17:45 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part07.rar
2012-01-18 17:29 - 2012-01-18 17:44 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part06.rar
2012-01-18 17:29 - 2012-01-18 17:44 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part05.rar
2012-01-18 17:29 - 2012-01-18 17:44 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part04.rar
2012-01-18 17:28 - 2012-01-18 17:42 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part03.rar
2012-01-18 17:13 - 2012-01-18 17:24 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part02.rar
2012-01-18 17:01 - 2012-01-18 17:13 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part01.rar
2012-01-18 16:51 - 2012-01-18 17:14 - 395968992 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part4.rar
2012-01-18 16:50 - 2012-01-18 18:04 - 1044381696 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part3.rar
2012-01-18 16:49 - 2012-01-18 18:05 - 1044381696 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part2.rar
2012-01-18 16:48 - 2012-01-18 17:23 - 1044381696 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part1.rar
2012-01-18 14:39 - 2012-01-18 15:15 - 0000000 ____D C:\Users\Haven\Downloads\Kingdom Hearts
2012-01-18 14:37 - 2012-01-18 14:37 - 0029446 ____A C:\Users\Haven\Downloads\Kingdom_Hearts_iso.torrent
2012-01-18 14:36 - 2012-01-18 14:36 - 0015318 ____A C:\Users\Haven\Downloads\_PS2__Kingdom_Hearts__NTSC_.torrent
2012-01-18 09:40 - 2012-01-18 09:40 - 0015703 ____A C:\Windows\SysWOW64\hs_err_pid14224.log
2012-01-18 02:08 - 2012-01-18 03:28 - 609581921 ____A C:\Users\Haven\Downloads\AIKA2_SETUP_HESTIA.exe
2012-01-17 15:05 - 2012-01-17 15:06 - 0000000 ____D C:\Users\Haven\Documents\EmuCR-Pcsx2-r5068
2012-01-17 15:03 - 2012-01-17 15:04 - 5288799 ____A C:\Users\Haven\Downloads\EmuCR-Pcsx2-r5068.7z
2012-01-17 14:48 - 2012-01-17 14:51 - 0000000 ____D C:\Users\Haven\Documents\PCSX2-0.9.9
2012-01-17 14:44 - 2012-01-17 14:45 - 21111399 ____A C:\Users\Haven\Downloads\PCSX2.v0.9.9-r4873.COMPLETE.MULTi.WinALL.21-08-2011-m3Zz.7z
2012-01-17 02:22 - 2012-01-17 02:26 - 0000000 ____D C:\aaaaa
2012-01-17 02:20 - 2012-01-17 02:20 - 4057033 ____A C:\Users\Haven\Downloads\english_rev5 (1).kh2patch
2012-01-17 02:19 - 2012-01-17 02:19 - 0012288 ____A C:\Users\Haven\Downloads\KH2PatcherRev4.exe
2012-01-17 02:17 - 2012-01-17 02:17 - 12780479 ____A C:\Users\Haven\Downloads\pcsx2-0.9.8-r4600-setup (1).exe
2012-01-16 19:01 - 2012-01-16 19:01 - 0001918 ____A C:\Users\Public\Desktop\gPotato.lnk
2012-01-16 19:01 - 2012-01-16 19:01 - 0000000 ____D C:\Program Files (x86)\Overwolf
2012-01-16 19:00 - 2012-01-16 19:00 - 1200872 ____A (Overwolf) C:\Users\Haven\Downloads\gPotatoInstaller (1).exe
2012-01-16 13:14 - 2012-01-16 13:14 - 0000000 ____D C:\Users\Haven\AppData\Roaming\RenPy
2012-01-16 13:11 - 2012-01-16 13:12 - 0000000 ____D C:\Program Files (x86)\Katawa Shoujo
2012-01-16 13:03 - 2012-01-16 13:10 - 441375029 ____A C:\Users\Haven\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-01-16 13:02 - 2012-01-16 13:02 - 0033983 ____A C:\Users\Haven\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe.torrent
2012-01-16 05:39 - 2012-01-16 05:39 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Tific
2012-01-16 05:39 - 2012-01-16 05:39 - 0000000 ____D C:\Users\Haven\AppData\Local\Symantec
2012-01-15 23:48 - 2012-01-15 23:50 - 0000000 ____D C:\Users\Haven\Downloads\Kingdom_Hearts_2_Final_Mix_Plus_JAP_PS2DVD-GANT
2012-01-15 23:47 - 2012-01-15 23:47 - 0042467 ____A C:\Users\Haven\Downloads\Kingdom_Hearts_2_Final_Mix.torrent
2012-01-15 23:47 - 2011-11-16 22:49 - 0152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-01-15 23:47 - 2011-11-16 22:49 - 0095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-01-15 23:47 - 2011-11-16 22:44 - 0459232 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-01-15 23:47 - 2011-11-16 22:35 - 1447936 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-01-15 23:47 - 2011-11-16 22:35 - 0395776 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll
2012-01-15 23:47 - 2011-11-16 22:35 - 0340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-01-15 23:47 - 2011-11-16 22:35 - 0136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2012-01-15 23:47 - 2011-11-16 22:35 - 0029184 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2012-01-15 23:47 - 2011-11-16 22:35 - 0028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2012-01-15 23:47 - 2011-11-16 22:33 - 0031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2012-01-15 23:47 - 2011-11-16 21:35 - 0314880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2012-01-15 23:47 - 2011-11-16 21:34 - 0224768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-01-15 23:47 - 2011-11-16 21:34 - 0022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-01-15 23:47 - 2011-11-16 21:28 - 0096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-01-15 19:54 - 2012-01-15 19:54 - 0138559 ____A C:\Users\Haven\Downloads\Kingdom_Hearts_II_Final_Mix______II_______JPN_NTSC.torrent
2012-01-15 18:07 - 2012-01-15 18:07 - 4057033 ____A C:\Users\Haven\Downloads\english_rev5.kh2patch
2012-01-15 16:36 - 2012-01-15 16:42 - 0000000 ____D C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_49-98_[720p][BATCH]
2012-01-15 16:35 - 2012-01-15 16:35 - 0086385 ____A C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_49-98_[720p][BATCH].torrent
2012-01-15 16:34 - 2012-01-15 16:34 - 0013448 ____A C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_65_[720p][0B864CDD].torrent
2012-01-15 16:34 - 2012-01-15 16:34 - 0013448 ____A C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_64_[720p][DEAA00FF].torrent
2012-01-15 16:31 - 2012-01-15 16:31 - 0053646 ____A C:\Users\Haven\Downloads\Fairy_Tail_Season_1_720p_Ryugan.torrent
2012-01-15 01:55 - 2012-01-21 23:08 - 0000000 ____D C:\Users\Haven\AppData\Local\SanctionedMedia
2012-01-15 01:55 - 2012-01-21 11:02 - 0008935 ____A C:\Users\Haven\AppData\Roaming\54bd6181
2012-01-15 01:55 - 2012-01-21 11:02 - 0008910 ____A C:\Users\Haven\AppData\Local\fb721a21
2012-01-15 01:55 - 2012-01-21 11:02 - 0008876 ____A C:\Users\All Users\2be2b9a
2012-01-15 01:55 - 2012-01-21 11:02 - 0008876 ____A C:\ProgramData\2be2b9a
2012-01-15 01:55 - 2012-01-15 01:55 - 0000000 ____D C:\Windows\system64
2012-01-15 01:54 - 2012-01-15 01:54 - 0000012 ____A C:\Windows\srun.log
2012-01-15 01:43 - 2012-01-15 01:43 - 0000000 ____D C:\Windows\Sun
2012-01-15 00:02 - 2012-01-15 00:02 - 39827080 ____A C:\Users\Haven\Downloads\SWTOR_setup.exe
2012-01-13 11:53 - 2012-01-13 12:08 - 0000000 ____D C:\Users\Haven\eligium_0_90_1_en
2012-01-13 11:53 - 2012-01-13 11:53 - 0000000 ____D C:\Users\Haven\AppData\Roaming\FOG Downloader
2012-01-13 11:52 - 2012-01-13 11:52 - 1051456 ____A C:\Users\Haven\Downloads\Eligium_0_90_1_en.exe
2012-01-11 00:49 - 2012-01-11 00:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{5EEADB11-66AC-47FD-BF12-9CD1F7A39433}
2012-01-11 00:49 - 2012-01-11 00:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{43ED504D-5C87-4EFB-B42F-4BBB73AABB79}
2012-01-10 18:23 - 2011-11-19 06:58 - 0077312 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll
2012-01-10 18:23 - 2011-11-19 06:01 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2012-01-10 18:23 - 2011-11-16 22:41 - 1731920 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2012-01-10 18:23 - 2011-11-16 21:38 - 1292080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2012-01-10 18:23 - 2011-10-25 21:25 - 1572864 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll
2012-01-10 18:23 - 2011-10-25 21:25 - 0366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-01-10 18:23 - 2011-10-25 20:32 - 1328128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2012-01-10 18:23 - 2011-10-25 20:32 - 0514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-01-07 22:19 - 2012-01-07 22:19 - 0114776 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-01-06 19:16 - 2012-01-08 12:52 - 0000000 ____D C:\Users\Haven\riotsGamesLogs
2012-01-06 18:05 - 2012-01-06 18:05 - 0001216 ____A C:\Users\Haven\Desktop\Dragona-enUS-GameClub.lnk
2012-01-06 17:58 - 2010-02-04 07:01 - 0530776 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_6.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0528216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0238936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0176984 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_6.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0078680 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_4.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0074072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0024920 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_7.dll
2012-01-06 17:58 - 2010-02-04 07:01 - 0022360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2012-01-06 17:58 - 2009-09-04 14:44 - 0517960 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_5.dll
2012-01-06 17:58 - 2009-09-04 14:44 - 0238936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2012-01-06 17:58 - 2009-09-04 14:44 - 0176968 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_5.dll
2012-01-06 17:58 - 2009-09-04 14:44 - 0073544 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_3.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 5554512 ____A (Microsoft Corporation) C:\Windows\System32\d3dcsx_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 5501792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 2582888 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 2475352 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 1974616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 1892184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 0285024 ____A (Microsoft Corporation) C:\Windows\System32\d3dx11_42.dll
2012-01-06 17:58 - 2009-09-04 14:29 - 0235344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2012-01-06 17:58 - 2009-03-16 11:18 - 0521560 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_4.dll
2012-01-06 17:58 - 2009-03-16 11:18 - 0517448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2012-01-06 17:58 - 2009-03-16 11:18 - 0235352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2012-01-06 17:58 - 2009-03-16 11:18 - 0174936 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_4.dll
2012-01-06 17:58 - 2009-03-16 11:18 - 0024920 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_6.dll
2012-01-06 17:58 - 2009-03-16 11:18 - 0022360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2012-01-06 17:58 - 2009-03-09 12:27 - 5425496 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_41.dll
2012-01-06 17:58 - 2009-03-09 12:27 - 2430312 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_41.dll
2012-01-06 17:58 - 2009-03-09 12:27 - 0520544 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_41.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0518480 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_3.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0514384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0235856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0175440 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_3.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0074576 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_2.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0070992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0025936 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_5.dll
2012-01-06 17:58 - 2008-10-27 07:04 - 0023376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2012-01-06 17:58 - 2008-10-15 03:22 - 5631312 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_40.dll
2012-01-06 17:58 - 2008-10-15 03:22 - 4379984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2012-01-06 17:58 - 2008-10-15 03:22 - 2605920 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_40.dll
2012-01-06 17:58 - 2008-10-15 03:22 - 2036576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2012-01-06 17:58 - 2008-10-15 03:22 - 0519000 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_40.dll
2012-01-06 17:58 - 2008-10-15 03:22 - 0452440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2012-01-06 17:58 - 2008-07-31 07:41 - 0238088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2012-01-06 17:58 - 2008-07-31 07:41 - 0177672 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_2.dll
2012-01-06 17:58 - 2008-07-31 07:41 - 0072200 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_1.dll
2012-01-06 17:58 - 2008-07-31 07:41 - 0068616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2012-01-06 17:58 - 2008-07-31 07:40 - 0513544 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_2.dll
2012-01-06 17:58 - 2008-07-31 07:40 - 0509448 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2012-01-06 17:58 - 2008-07-10 08:00 - 4992520 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
2012-01-06 17:58 - 2008-07-10 08:00 - 1942552 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
2012-01-06 17:58 - 2008-07-10 08:00 - 0540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
2012-01-06 17:58 - 2008-05-30 11:19 - 0511496 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_1.dll
2012-01-06 17:58 - 2008-05-30 11:19 - 0507400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2012-01-06 17:58 - 2008-05-30 11:18 - 0238088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2012-01-06 17:58 - 2008-05-30 11:18 - 0177672 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_1.dll
2012-01-06 17:58 - 2008-05-30 11:17 - 0068104 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_0.dll
2012-01-06 17:58 - 2008-05-30 11:17 - 0065032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2012-01-06 17:58 - 2008-05-30 11:17 - 0025608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2012-01-06 17:58 - 2008-05-30 11:16 - 0028168 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_4.dll
2012-01-06 17:58 - 2008-05-30 11:11 - 4991496 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_38.dll
2012-01-06 17:58 - 2008-05-30 11:11 - 3850760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2012-01-06 17:58 - 2008-05-30 11:11 - 1941528 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_38.dll
2012-01-06 17:58 - 2008-05-30 11:11 - 1491992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2012-01-06 17:58 - 2008-05-30 11:11 - 0540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_38.dll
2012-01-06 17:58 - 2008-05-30 11:11 - 0467984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2012-01-06 17:58 - 2008-03-05 13:04 - 0489480 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_0.dll
2012-01-06 17:58 - 2008-03-05 13:03 - 0479752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2012-01-06 17:58 - 2008-03-05 13:03 - 0238088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2012-01-06 17:58 - 2008-03-05 13:03 - 0177672 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_0.dll
2012-01-06 17:58 - 2008-03-05 13:00 - 0028168 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_3.dll
2012-01-06 17:58 - 2008-03-05 13:00 - 0025608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2012-01-06 17:58 - 2008-03-05 12:56 - 4910088 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_37.dll
2012-01-06 17:58 - 2008-03-05 12:56 - 3786760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2012-01-06 17:58 - 2008-03-05 12:56 - 1860120 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_37.dll
2012-01-06 17:58 - 2008-03-05 12:56 - 1420824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2012-01-06 17:58 - 2008-02-05 20:07 - 0529424 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_37.dll
2012-01-06 17:58 - 2008-02-05 20:07 - 0462864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2012-01-06 17:46 - 2012-01-06 17:46 - 0000000 ____D C:\Program Files (x86)\GameClub
2012-01-06 16:59 - 2012-01-06 17:26 - 1722671524 ____A C:\Users\Haven\Desktop\Dragona-enUS-GameClub-Serv-1.0.20.526-Setup.exe
2012-01-06 16:55 - 2012-01-06 16:55 - 2514504 ____A C:\Users\Haven\Downloads\Dragona-enUS-GameClub-Serv-1.0.20.526-downloader.exe
2012-01-06 11:55 - 2012-01-06 11:55 - 1645248 ____A (W3i, LLC) C:\Users\Haven\Downloads\mplayer_tuguu_1277.exe
2012-01-06 11:42 - 2012-01-06 11:42 - 0508816 ____A C:\Users\Haven\Downloads\fbdownloader_184686_116235_010412211455 (1).exe
2012-01-05 15:37 - 2012-01-14 16:25 - 0000000 ____D C:\Users\Haven\AppData\Local\Conduit
2012-01-05 15:37 - 2012-01-05 15:37 - 0000000 ____D C:\Program Files (x86)\Conduit
2012-01-05 15:36 - 2012-01-05 15:36 - 0527288 ____A C:\Users\Haven\Downloads\dislike-20111227.exe
2012-01-05 15:36 - 2012-01-05 15:36 - 0067208 ____A C:\Users\Haven\Downloads\setup.exe
2012-01-05 15:36 - 2012-01-05 15:36 - 0000147 ____A C:\Users\Haven\Downloads\dislike.ini
2012-01-05 15:33 - 2012-01-05 15:33 - 0000182 ____A C:\Users\Haven\Desktop\Play Pickle.url
2012-01-05 15:32 - 2012-01-14 16:20 - 0000000 ____D C:\Program Files (x86)\Shop To Win
2012-01-05 15:32 - 2012-01-05 15:32 - 0000000 ____D C:\Users\Haven\Documents\ShopToWin
2012-01-05 15:32 - 2012-01-05 15:32 - 0000000 ____D C:\Users\Haven\Documents\DealRunner
2012-01-05 15:32 - 2012-01-05 15:32 - 0000000 ____D C:\Program Files (x86)\kitara
2012-01-05 15:31 - 2012-01-05 15:31 - 0915288 ____A C:\Users\Haven\Downloads\playpickle-setup.exe
2012-01-05 15:18 - 2012-01-05 15:18 - 0839960 ____A C:\Users\Haven\Downloads\SlotSetup_CH.exe
2012-01-05 15:18 - 2012-01-05 15:18 - 0839960 ____A C:\Users\Haven\Downloads\SlotSetup_CH (1).exe
2012-01-05 11:12 - 2012-01-14 16:14 - 0000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2012-01-05 11:11 - 2012-01-05 11:11 - 0248400 ____A (OpenInstall ) C:\Users\Haven\Downloads\PageRage.exe
2012-01-05 11:09 - 2012-01-14 16:13 - 0000000 ____D C:\Program Files (x86)\fbDownloader
2012-01-05 11:09 - 2012-01-05 11:09 - 0000000 ____D C:\Program Files (x86)\SDIV 2.0
2012-01-05 11:07 - 2012-01-05 11:07 - 0508816 ____A C:\Users\Haven\Downloads\fbdownloader_184686_116235_010412211455.exe
2012-01-05 10:55 - 2012-01-05 10:55 - 0543024 ____A (Microsoft Corporation) C:\Users\Haven\Downloads\IE9-Windows7-x64-enu.exe
2012-01-05 10:51 - 2012-01-14 16:09 - 0000000 ____D C:\Program Files (x86)\Babylon
2012-01-05 10:51 - 2012-01-05 10:51 - 0920176 ____A (Babylon Ltd.) C:\Users\Haven\Downloads\Babylon9_setup.exe
2012-01-05 10:51 - 2012-01-05 10:51 - 0000000 ____D C:\Program Files\Babylon
2012-01-05 10:49 - 2012-01-05 10:49 - 0001279 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-01-05 10:48 - 2012-01-21 23:06 - 0000000 ____D C:\Users\All Users\Real
2012-01-05 10:48 - 2012-01-21 23:06 - 0000000 ____D C:\ProgramData\Real
2012-01-05 10:48 - 2012-01-05 10:50 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Real
2012-01-05 10:48 - 2012-01-05 10:49 - 0000000 ____D C:\Program Files (x86)\Real
2012-01-05 10:48 - 2012-01-05 10:48 - 0272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2012-01-05 10:48 - 2012-01-05 10:48 - 0198832 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2012-01-05 10:48 - 2012-01-05 10:48 - 0006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2012-01-05 10:48 - 2012-01-05 10:48 - 0005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2012-01-05 10:47 - 2012-01-05 10:47 - 0266928 ____A C:\Users\Haven\Downloads\RealSetup.exe
2012-01-05 01:54 - 2012-01-05 01:54 - 0000064 ____A C:\Windows\GPlrLanc.dat
2012-01-05 01:54 - 2010-07-07 11:01 - 0017542 ____N C:\Windows\FRGN.ico
2012-01-05 01:53 - 2012-01-14 16:23 - 0000000 ____D C:\Users\All Users\Tarma Installer
2012-01-05 01:53 - 2012-01-14 16:23 - 0000000 ____D C:\ProgramData\Tarma Installer
2012-01-05 01:51 - 2012-01-05 01:51 - 0241760 ____A (OpenInstall ) C:\Users\Haven\Downloads\ShareGreetingCards.exe
2012-01-04 18:53 - 2012-01-04 18:53 - 0022604 ____A C:\Users\Haven\Downloads\havenavatar.jpg
2012-01-04 15:52 - 2012-01-04 15:52 - 0049068 ____A C:\Users\Haven\Downloads\100277.jpg
2011-12-26 11:21 - 2011-12-26 11:21 - 0000000 ____D C:\Users\Haven\AppData\Local\{DF97B74E-004C-404B-B390-5D8CFFE9C722}
2011-12-26 11:20 - 2011-12-26 11:20 - 0262144 ____A C:\Windows\Minidump\122611-30092-01.dmp
2011-12-24 09:25 - 2011-12-24 09:26 - 0000000 ____D C:\Users\Haven\AppData\Local\{A4813902-B20C-4B0A-A1EC-C369025BB2A4}
2011-12-24 09:25 - 2011-12-24 09:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{ABAC5914-C95C-4FA2-A4D2-58C22D6F97D6}
2011-12-23 21:25 - 2011-12-23 21:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{CF54056C-2A54-4059-87FA-033497037480}
2011-12-23 21:25 - 2011-12-23 21:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{44E5C090-50A9-4287-B62C-AD156F255DBE}
2011-12-23 09:25 - 2011-12-23 09:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{47C09822-A9BC-46FB-B424-D9DC8B8E94D9}
2011-12-23 09:24 - 2011-12-23 09:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{9A1E3785-41A6-46CA-8156-FF271F725CAF}

============ 3 Months Modified Files and Folders =============

2012-01-22 00:06 - 2012-01-22 00:05 - 0000000 ____D C:\FRST
2012-01-21 23:08 - 2012-01-21 10:56 - 0000000 ____D C:\Program Files\Common Files\Symantec Shared
2012-01-21 23:08 - 2012-01-21 10:55 - 0000000 ____D C:\Windows\System32\Drivers\N360x64
2012-01-21 23:08 - 2012-01-21 10:55 - 0000000 ____D C:\Program Files (x86)\Norton Security Suite
2012-01-21 23:08 - 2012-01-15 01:55 - 0000000 ____D C:\Users\Haven\AppData\Local\SanctionedMedia
2012-01-21 23:08 - 2011-11-25 07:55 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Mozilla
2012-01-21 23:08 - 2011-05-23 06:24 - 0000000 ____D C:\Users\All Users\Norton
2012-01-21 23:08 - 2011-05-23 06:24 - 0000000 ____D C:\ProgramData\Norton
2012-01-21 23:08 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\AppCompat
2012-01-21 23:07 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\registration
2012-01-21 23:06 - 2012-01-21 10:14 - 0000000 ____D C:\Program Files (x86)\NortonInstaller
2012-01-21 23:06 - 2012-01-05 10:48 - 0000000 ____D C:\Users\All Users\Real
2012-01-21 23:06 - 2012-01-05 10:48 - 0000000 ____D C:\ProgramData\Real
2012-01-21 21:02 - 2011-05-23 06:10 - 1084176 ____A C:\Windows\WindowsUpdate.log
2012-01-21 21:01 - 2012-01-21 21:01 - 1379845 ____A C:\Users\Haven\Downloads\FRST64.exe
2012-01-21 21:01 - 2012-01-21 20:31 - 0019526 ____A C:\Windows\ntbtlog.txt
2012-01-21 20:58 - 2009-07-13 21:13 - 0727182 ____A C:\Windows\System32\PerfStringBackup.INI
2012-01-21 20:55 - 2011-11-04 22:50 - 0000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1964205424-1089152527-2808200303-1001UA.job
2012-01-21 20:45 - 2011-05-23 06:25 - 0000912 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-01-21 20:43 - 2009-07-13 20:45 - 0025120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-01-21 20:43 - 2009-07-13 20:45 - 0025120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-01-21 20:41 - 2012-01-21 10:59 - 0000000 ____D C:\Users\Haven\AppData\Local\NPE
2012-01-21 20:39 - 2012-01-21 20:39 - 0096376 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR210.SYS
2012-01-21 20:39 - 2012-01-21 20:39 - 0000020 ____A C:\Windows\System32\Drivers\SMR210.dat
2012-01-21 20:36 - 2011-05-23 06:25 - 0000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-01-21 20:35 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-01-21 20:34 - 2011-07-25 17:20 - 0000000 ____D C:\Users\Haven\AppData\Roaming\uTorrent
2012-01-21 20:32 - 2011-09-01 07:58 - 0000000 ____D C:\Users\Haven\AppData\Local\Overwolf
2012-01-21 20:32 - 2009-07-13 21:08 - 0015172 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-01-21 20:31 - 2011-06-24 09:04 - 0000000 ____D C:\users\Haven
2012-01-21 20:31 - 2011-05-23 05:58 - 463486976 __ASH C:\hiberfil.sys
2012-01-21 20:31 - 2009-07-13 20:51 - 0047217 ____A C:\Windows\setupact.log
2012-01-21 20:31 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR
2012-01-21 19:57 - 2012-01-21 19:57 - 0000766 ____A C:\Users\Haven\AppData\Roaming\SMRBackup210.dat
2012-01-21 19:49 - 2012-01-21 19:49 - 0000000 ____D C:\Program Files\Symantec
2012-01-21 19:43 - 2011-05-23 06:24 - 0000000 ____D C:\Users\All Users\NortonInstaller
2012-01-21 19:43 - 2011-05-23 06:24 - 0000000 ____D C:\ProgramData\NortonInstaller
2012-01-21 11:02 - 2012-01-15 01:55 - 0008935 ____A C:\Users\Haven\AppData\Roaming\54bd6181
2012-01-21 11:02 - 2012-01-15 01:55 - 0008910 ____A C:\Users\Haven\AppData\Local\fb721a21
2012-01-21 11:02 - 2012-01-15 01:55 - 0008876 ____A C:\Users\All Users\2be2b9a
2012-01-21 11:02 - 2012-01-15 01:55 - 0008876 ____A C:\ProgramData\2be2b9a
2012-01-21 11:00 - 2010-11-20 19:47 - 0264168 ____A C:\Windows\PFRO.log
2012-01-21 10:59 - 2012-01-21 10:59 - 2562040 ____A (Symantec Corporation) C:\Users\Haven\Downloads\NPE.exe
2012-01-21 10:56 - 2012-01-21 10:56 - 0174640 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-01-21 10:56 - 2012-01-21 10:56 - 0007440 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-01-21 10:56 - 2012-01-21 10:56 - 0002605 ____A C:\Users\Public\Desktop\Norton Security Suite.lnk
2012-01-21 10:56 - 2012-01-21 10:56 - 0000854 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.INF
2012-01-21 10:55 - 2012-01-21 10:11 - 0001379 ____A C:\Users\Haven\Desktop\Norton Installation Files.lnk
2012-01-21 10:54 - 2012-01-21 10:04 - 0000000 ____D C:\Users\Haven\AppData\Roaming\ID Vault
2012-01-21 10:14 - 2012-01-21 10:14 - 0000000 ____D C:\Users\Haven\Documents\Symantec
2012-01-21 10:11 - 2012-01-21 10:11 - 0000000 ____D C:\Users\Public\Downloads\Norton
2012-01-21 10:05 - 2012-01-21 10:04 - 0000000 ____D C:\Users\Haven\AppData\Local\ID Vault
2012-01-21 10:04 - 2012-01-21 10:04 - 0000000 ____D C:\Users\All Users\IsolatedStorage
2012-01-21 10:04 - 2012-01-21 10:04 - 0000000 ____D C:\ProgramData\IsolatedStorage
2012-01-21 10:04 - 2012-01-21 10:03 - 0000000 ____D C:\Program Files (x86)\Constant Guard Protection Suite
2012-01-21 10:04 - 2011-06-24 09:05 - 0000000 ____D C:\Users\Haven\AppData\LocalLow
2012-01-21 10:03 - 2012-01-21 10:03 - 0002320 ____A C:\Users\All Users\Start Menu\Programs\Startup\Constant Guard.lnk
2012-01-21 10:03 - 2012-01-21 10:03 - 0002302 ____A C:\Users\Public\Desktop\Constant Guard.lnk
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\Users\All Users\White Sky, Inc
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\Users\All Users\GID
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\ProgramData\White Sky, Inc
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\ProgramData\GID
2012-01-21 10:03 - 2012-01-21 10:03 - 0000000 ____D C:\Program Files (x86)\SFT
2012-01-21 10:01 - 2012-01-21 10:00 - 21631488 ____A (White Sky, Inc.) C:\Users\Haven\Downloads\constantguard.exe
2012-01-20 11:55 - 2011-11-04 22:50 - 0000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1964205424-1089152527-2808200303-1001Core.job
2012-01-19 10:00 - 2012-01-19 10:00 - 0015717 ____A C:\Windows\SysWOW64\hs_err_pid11308.log
2012-01-18 18:05 - 2012-01-18 16:49 - 1044381696 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part2.rar
2012-01-18 18:04 - 2012-01-18 16:50 - 1044381696 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part3.rar
2012-01-18 17:45 - 2012-01-18 17:30 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part11.rar
2012-01-18 17:45 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part10.rar
2012-01-18 17:45 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part09.rar
2012-01-18 17:45 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part08.rar
2012-01-18 17:45 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part07.rar
2012-01-18 17:44 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part06.rar
2012-01-18 17:44 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part05.rar
2012-01-18 17:44 - 2012-01-18 17:29 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part04.rar
2012-01-18 17:42 - 2012-01-18 17:28 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part03.rar
2012-01-18 17:31 - 2012-01-18 17:30 - 5167768 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part12.rar
2012-01-18 17:24 - 2012-01-18 17:13 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part02.rar
2012-01-18 17:23 - 2012-01-18 16:48 - 1044381696 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part1.rar
2012-01-18 17:14 - 2012-01-18 16:51 - 395968992 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix.ff0-d1.d2.jap.part4.rar
2012-01-18 17:13 - 2012-01-18 17:01 - 100000000 ____A C:\Users\Haven\Downloads\Kingdom Hearts Birth By Sleep Final Mix (JP+EngTrans).part01.rar
2012-01-18 15:42 - 2011-06-24 09:10 - 0000000 ____D C:\Users\Haven\AppData\Local\CrashDumps
2012-01-18 15:15 - 2012-01-18 14:39 - 0000000 ____D C:\Users\Haven\Downloads\Kingdom Hearts
2012-01-18 14:37 - 2012-01-18 14:37 - 0029446 ____A C:\Users\Haven\Downloads\Kingdom_Hearts_iso.torrent
2012-01-18 14:36 - 2012-01-18 14:36 - 0015318 ____A C:\Users\Haven\Downloads\_PS2__Kingdom_Hearts__NTSC_.torrent
2012-01-18 09:40 - 2012-01-18 09:40 - 0015703 ____A C:\Windows\SysWOW64\hs_err_pid14224.log
2012-01-18 03:28 - 2012-01-18 02:08 - 609581921 ____A C:\Users\Haven\Downloads\AIKA2_SETUP_HESTIA.exe
2012-01-17 15:06 - 2012-01-17 15:05 - 0000000 ____D C:\Users\Haven\Documents\EmuCR-Pcsx2-r5068
2012-01-17 15:04 - 2012-01-17 15:03 - 5288799 ____A C:\Users\Haven\Downloads\EmuCR-Pcsx2-r5068.7z
2012-01-17 14:51 - 2012-01-17 14:48 - 0000000 ____D C:\Users\Haven\Documents\PCSX2-0.9.9
2012-01-17 14:45 - 2012-01-17 14:44 - 21111399 ____A C:\Users\Haven\Downloads\PCSX2.v0.9.9-r4873.COMPLETE.MULTi.WinALL.21-08-2011-m3Zz.7z
2012-01-17 02:26 - 2012-01-17 02:22 - 0000000 ____D C:\aaaaa
2012-01-17 02:20 - 2012-01-17 02:20 - 4057033 ____A C:\Users\Haven\Downloads\english_rev5 (1).kh2patch
2012-01-17 02:19 - 2012-01-17 02:19 - 0012288 ____A C:\Users\Haven\Downloads\KH2PatcherRev4.exe
2012-01-17 02:18 - 2011-07-28 18:39 - 0000000 ____D C:\Windows\SysWOW64\directx
2012-01-17 02:18 - 2011-07-28 18:38 - 0000000 ____D C:\Program Files (x86)\PCSX2 0.9.8
2012-01-17 02:18 - 2011-05-23 06:26 - 0000000 ___HD C:\Windows\msdownld.tmp
2012-01-17 02:17 - 2012-01-17 02:17 - 12780479 ____A C:\Users\Haven\Downloads\pcsx2-0.9.8-r4600-setup (1).exe
2012-01-17 02:17 - 2011-07-28 18:38 - 0002000 ____A C:\Users\Public\Desktop\PCSX2 0.9.8 (r4600).lnk
2012-01-16 19:01 - 2012-01-16 19:01 - 0001918 ____A C:\Users\Public\Desktop\gPotato.lnk
2012-01-16 19:01 - 2012-01-16 19:01 - 0000000 ____D C:\Program Files (x86)\Overwolf
2012-01-16 19:00 - 2012-01-16 19:00 - 1200872 ____A (Overwolf) C:\Users\Haven\Downloads\gPotatoInstaller (1).exe
2012-01-16 13:14 - 2012-01-16 13:14 - 0000000 ____D C:\Users\Haven\AppData\Roaming\RenPy
2012-01-16 13:12 - 2012-01-16 13:11 - 0000000 ____D C:\Program Files (x86)\Katawa Shoujo
2012-01-16 13:10 - 2012-01-16 13:03 - 441375029 ____A C:\Users\Haven\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-01-16 13:02 - 2012-01-16 13:02 - 0033983 ____A C:\Users\Haven\Downloads\[4ls]_katawa_shoujo_[windows][C3798628].exe.torrent
2012-01-16 05:39 - 2012-01-16 05:39 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Tific
2012-01-16 05:39 - 2012-01-16 05:39 - 0000000 ____D C:\Users\Haven\AppData\Local\Symantec
2012-01-16 05:19 - 2011-06-24 09:11 - 0000000 ____D C:\Program Files (x86)\Pando Networks
2012-01-16 05:19 - 2011-05-12 21:21 - 0000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-01-15 23:50 - 2012-01-15 23:48 - 0000000 ____D C:\Users\Haven\Downloads\Kingdom_Hearts_2_Final_Mix_Plus_JAP_PS2DVD-GANT
2012-01-15 23:47 - 2012-01-15 23:47 - 0042467 ____A C:\Users\Haven\Downloads\Kingdom_Hearts_2_Final_Mix.torrent
2012-01-15 23:43 - 2011-12-11 15:14 - 0000000 ____D C:\Users\Haven\Downloads\The_Red_Jumpsuit_Apparatus-Am_I_The_Enemy-2011-CR
2012-01-15 19:54 - 2012-01-15 19:54 - 0138559 ____A C:\Users\Haven\Downloads\Kingdom_Hearts_II_Final_Mix______II_______JPN_NTSC.torrent
2012-01-15 18:07 - 2012-01-15 18:07 - 4057033 ____A C:\Users\Haven\Downloads\english_rev5.kh2patch
2012-01-15 16:42 - 2012-01-15 16:36 - 0000000 ____D C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_49-98_[720p][BATCH]
2012-01-15 16:35 - 2012-01-15 16:35 - 0086385 ____A C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_49-98_[720p][BATCH].torrent
2012-01-15 16:34 - 2012-01-15 16:34 - 0013448 ____A C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_65_[720p][0B864CDD].torrent
2012-01-15 16:34 - 2012-01-15 16:34 - 0013448 ____A C:\Users\Haven\Downloads\[Kyuubi]_Fairy_Tail_64_[720p][DEAA00FF].torrent
2012-01-15 16:31 - 2012-01-15 16:31 - 0053646 ____A C:\Users\Haven\Downloads\Fairy_Tail_Season_1_720p_Ryugan.torrent
2012-01-15 01:55 - 2012-01-15 01:55 - 0000000 ____D C:\Windows\system64
2012-01-15 01:55 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Resources
2012-01-15 01:54 - 2012-01-15 01:54 - 0000012 ____A C:\Windows\srun.log
2012-01-15 01:43 - 2012-01-15 01:43 - 0000000 ____D C:\Windows\Sun
2012-01-15 00:02 - 2012-01-15 00:02 - 39827080 ____A C:\Users\Haven\Downloads\SWTOR_setup.exe
2012-01-14 16:25 - 2012-01-05 15:37 - 0000000 ____D C:\Users\Haven\AppData\Local\Conduit
2012-01-14 16:25 - 2011-11-11 16:21 - 0000000 ____D C:\War of the Immortals
2012-01-14 16:23 - 2012-01-05 01:53 - 0000000 ____D C:\Users\All Users\Tarma Installer
2012-01-14 16:23 - 2012-01-05 01:53 - 0000000 ____D C:\ProgramData\Tarma Installer
2012-01-14 16:22 - 2011-09-18 12:27 - 0000000 ____D C:\Program Files (x86)\Yahoo!
2012-01-14 16:20 - 2012-01-05 15:32 - 0000000 ____D C:\Program Files (x86)\Shop To Win
2012-01-14 16:15 - 2011-05-23 06:31 - 0000000 ____D C:\Windows\SysWOW64\SDA
2012-01-14 16:15 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\Downloaded Program Files
2012-01-14 16:14 - 2012-01-05 11:12 - 0000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2012-01-14 16:13 - 2012-01-05 11:09 - 0000000 ____D C:\Program Files (x86)\fbDownloader
2012-01-14 16:11 - 2011-12-03 18:27 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Easy Macro Recorder
2012-01-14 16:11 - 2011-09-25 14:21 - 0001220 ____A C:\prefs.js
2012-01-14 16:10 - 2011-12-03 18:52 - 0000000 ____D C:\Program Files (x86)\Do It Again
2012-01-14 16:09 - 2012-01-05 10:51 - 0000000 ____D C:\Program Files (x86)\Babylon
2012-01-14 16:08 - 2011-12-03 18:40 - 0000000 ____D C:\Program Files\AutoHotkey
2012-01-14 16:08 - 2010-11-20 23:16 - 0000000 ____D C:\Windows\ShellNew
2012-01-13 12:08 - 2012-01-13 11:53 - 0000000 ____D C:\Users\Haven\eligium_0_90_1_en
2012-01-13 11:53 - 2012-01-13 11:53 - 0000000 ____D C:\Users\Haven\AppData\Roaming\FOG Downloader
2012-01-13 11:52 - 2012-01-13 11:52 - 1051456 ____A C:\Users\Haven\Downloads\Eligium_0_90_1_en.exe
2012-01-11 00:51 - 2011-08-04 22:53 - 0000000 ____D C:\Users\Haven\AppData\Local\Windows Live
2012-01-11 00:50 - 2012-01-11 00:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{5EEADB11-66AC-47FD-BF12-9CD1F7A39433}
2012-01-11 00:49 - 2012-01-11 00:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{43ED504D-5C87-4EFB-B42F-4BBB73AABB79}
2012-01-11 00:47 - 2011-07-20 04:00 - 0000000 ____D C:\Users\Haven\Tracing
2012-01-11 00:04 - 2011-07-07 10:55 - 54008112 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-01-08 12:52 - 2012-01-06 19:16 - 0000000 ____D C:\Users\Haven\riotsGamesLogs
2012-01-07 22:19 - 2012-01-07 22:19 - 0114776 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-01-07 10:27 - 2011-08-13 07:59 - 0000059 ____A C:\Users\Haven\Desktop\neoxephons info.txt
2012-01-06 18:05 - 2012-01-06 18:05 - 0001216 ____A C:\Users\Haven\Desktop\Dragona-enUS-GameClub.lnk
2012-01-06 17:58 - 2011-05-12 21:29 - 0223437 ____A C:\Windows\DirectX.log
2012-01-06 17:46 - 2012-01-06 17:46 - 0000000 ____D C:\Program Files (x86)\GameClub
2012-01-06 17:26 - 2012-01-06 16:59 - 1722671524 ____A C:\Users\Haven\Desktop\Dragona-enUS-GameClub-Serv-1.0.20.526-Setup.exe
2012-01-06 16:55 - 2012-01-06 16:55 - 2514504 ____A C:\Users\Haven\Downloads\Dragona-enUS-GameClub-Serv-1.0.20.526-downloader.exe
2012-01-06 11:55 - 2012-01-06 11:55 - 1645248 ____A (W3i, LLC) C:\Users\Haven\Downloads\mplayer_tuguu_1277.exe
2012-01-06 11:42 - 2012-01-06 11:42 - 0508816 ____A C:\Users\Haven\Downloads\fbdownloader_184686_116235_010412211455 (1).exe
2012-01-05 15:37 - 2012-01-05 15:37 - 0000000 ____D C:\Program Files (x86)\Conduit
2012-01-05 15:36 - 2012-01-05 15:36 - 0527288 ____A C:\Users\Haven\Downloads\dislike-20111227.exe
2012-01-05 15:36 - 2012-01-05 15:36 - 0067208 ____A C:\Users\Haven\Downloads\setup.exe
2012-01-05 15:36 - 2012-01-05 15:36 - 0000147 ____A C:\Users\Haven\Downloads\dislike.ini
2012-01-05 15:33 - 2012-01-05 15:33 - 0000182 ____A C:\Users\Haven\Desktop\Play Pickle.url
2012-01-05 15:32 - 2012-01-05 15:32 - 0000000 ____D C:\Users\Haven\Documents\ShopToWin
2012-01-05 15:32 - 2012-01-05 15:32 - 0000000 ____D C:\Users\Haven\Documents\DealRunner
2012-01-05 15:32 - 2012-01-05 15:32 - 0000000 ____D C:\Program Files (x86)\kitara
2012-01-05 15:31 - 2012-01-05 15:31 - 0915288 ____A C:\Users\Haven\Downloads\playpickle-setup.exe
2012-01-05 15:18 - 2012-01-05 15:18 - 0839960 ____A C:\Users\Haven\Downloads\SlotSetup_CH.exe
2012-01-05 15:18 - 2012-01-05 15:18 - 0839960 ____A C:\Users\Haven\Downloads\SlotSetup_CH (1).exe
2012-01-05 11:12 - 2011-07-16 07:47 - 0000000 ____D C:\Users\Haven\AppData\Local\Adobe
2012-01-05 11:12 - 2011-06-24 09:10 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Adobe
2012-01-05 11:11 - 2012-01-05 11:11 - 0248400 ____A (OpenInstall ) C:\Users\Haven\Downloads\PageRage.exe
2012-01-05 11:09 - 2012-01-05 11:09 - 0000000 ____D C:\Program Files (x86)\SDIV 2.0
2012-01-05 11:07 - 2012-01-05 11:07 - 0508816 ____A C:\Users\Haven\Downloads\fbdownloader_184686_116235_010412211455.exe
2012-01-05 10:56 - 2011-07-07 10:50 - 0004913 ____A C:\Windows\IE9_main.log
2012-01-05 10:55 - 2012-01-05 10:55 - 0543024 ____A (Microsoft Corporation) C:\Users\Haven\Downloads\IE9-Windows7-x64-enu.exe
2012-01-05 10:51 - 2012-01-05 10:51 - 0920176 ____A (Babylon Ltd.) C:\Users\Haven\Downloads\Babylon9_setup.exe
2012-01-05 10:51 - 2012-01-05 10:51 - 0000000 ____D C:\Program Files\Babylon
2012-01-05 10:50 - 2012-01-05 10:48 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Real
2012-01-05 10:49 - 2012-01-05 10:49 - 0001279 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-01-05 10:49 - 2012-01-05 10:48 - 0000000 ____D C:\Program Files (x86)\Real
2012-01-05 10:48 - 2012-01-05 10:48 - 0272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2012-01-05 10:48 - 2012-01-05 10:48 - 0198832 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2012-01-05 10:48 - 2012-01-05 10:48 - 0006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2012-01-05 10:48 - 2012-01-05 10:48 - 0005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2012-01-05 10:48 - 2009-05-21 04:21 - 0499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2012-01-05 10:48 - 2009-05-21 02:57 - 0348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2012-01-05 10:47 - 2012-01-05 10:47 - 0266928 ____A C:\Users\Haven\Downloads\RealSetup.exe
2012-01-05 01:54 - 2012-01-05 01:54 - 0000064 ____A C:\Windows\GPlrLanc.dat
2012-01-05 01:51 - 2012-01-05 01:51 - 0241760 ____A (OpenInstall ) C:\Users\Haven\Downloads\ShareGreetingCards.exe
2012-01-04 18:53 - 2012-01-04 18:53 - 0022604 ____A C:\Users\Haven\Downloads\havenavatar.jpg
2012-01-04 15:52 - 2012-01-04 15:52 - 0049068 ____A C:\Users\Haven\Downloads\100277.jpg
2011-12-26 11:21 - 2011-12-26 11:21 - 0000000 ____D C:\Users\Haven\AppData\Local\{DF97B74E-004C-404B-B390-5D8CFFE9C722}
2011-12-26 11:20 - 2011-12-26 11:20 - 0262144 ____A C:\Windows\Minidump\122611-30092-01.dmp
2011-12-26 11:20 - 2011-12-03 18:58 - 594196686 ____A C:\Windows\MEMORY.DMP
2011-12-26 11:20 - 2011-12-03 18:58 - 0000000 ____D C:\Windows\Minidump
2011-12-24 09:26 - 2011-12-24 09:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{A4813902-B20C-4B0A-A1EC-C369025BB2A4}
2011-12-24 09:25 - 2011-12-24 09:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{ABAC5914-C95C-4FA2-A4D2-58C22D6F97D6}
2011-12-23 21:25 - 2011-12-23 21:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{CF54056C-2A54-4059-87FA-033497037480}
2011-12-23 21:25 - 2011-12-23 21:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{44E5C090-50A9-4287-B62C-AD156F255DBE}
2011-12-23 09:25 - 2011-12-23 09:25 - 0000000 ____D C:\Users\Haven\AppData\Local\{47C09822-A9BC-46FB-B424-D9DC8B8E94D9}
2011-12-23 09:25 - 2011-12-23 09:24 - 0000000 ____D C:\Users\Haven\AppData\Local\{9A1E3785-41A6-46CA-8156-FF271F725CAF}
2011-12-22 21:24 - 2011-12-22 21:24 - 0000000 ____D C:\Users\Haven\AppData\Local\{6F149B22-D1DE-40BD-AFEF-1E197D304981}
2011-12-22 21:24 - 2011-12-22 21:24 - 0000000 ____D C:\Users\Haven\AppData\Local\{3E309A23-5CC6-415F-B9AB-FCE19932E795}
2011-12-22 09:24 - 2011-12-22 09:24 - 0000000 ____D C:\Users\Haven\AppData\Local\{5C9F4987-BFDB-4661-8A3D-EDD9E4849B97}
2011-12-22 09:24 - 2011-12-22 09:24 - 0000000 ____D C:\Users\Haven\AppData\Local\{2E82CB9A-CB45-472D-B904-90D45323DB2C}
2011-12-21 21:24 - 2011-12-21 21:24 - 0000000 ____D C:\Users\Haven\AppData\Local\{7E416894-E868-43D9-8AB9-0D0D8380F1C7}
2011-12-21 21:24 - 2011-12-21 21:23 - 0000000 ____D C:\Users\Haven\AppData\Local\{F38A5E1F-548D-4786-A50E-FC5FF9D86E94}
2011-12-21 09:23 - 2011-12-21 09:23 - 0000000 ____D C:\Users\Haven\AppData\Local\{F387DD85-BD0A-4FFD-A1D4-4C39D077B5FA}
2011-12-21 09:23 - 2011-12-21 09:23 - 0000000 ____D C:\Users\Haven\AppData\Local\{2437FFE9-75E3-4209-B20D-8ECA7B6C40E6}
2011-12-20 21:23 - 2011-12-20 21:23 - 0000000 ____D C:\Users\Haven\AppData\Local\{7F6FDA10-A4E0-427A-8D72-190A43E28EA5}
2011-12-20 21:23 - 2011-12-20 21:23 - 0000000 ____D C:\Users\Haven\AppData\Local\{4A67BBB0-0132-4B53-8CF7-A0A33293AA23}
2011-12-20 08:35 - 2011-12-20 08:34 - 0000000 ____D C:\Users\Haven\AppData\Local\{CA8C0C5F-82D6-4BF5-A204-B9FD32FA138E}
2011-12-20 08:34 - 2011-12-20 08:34 - 0000000 ____D C:\Users\Haven\AppData\Local\{23B32D02-1804-4C71-B6A1-EDD8D5AF188D}
2011-12-19 20:34 - 2011-12-19 20:34 - 0000000 ____D C:\Users\Haven\AppData\Local\{FE38357E-DFB3-4D6A-98AA-3032AB62D45C}
2011-12-19 20:34 - 2011-12-19 20:34 - 0000000 ____D C:\Users\Haven\AppData\Local\{E1B15ECC-5B45-4C65-9C46-979B7F46F3DF}
2011-12-19 08:34 - 2011-12-19 08:34 - 0000000 ____D C:\Users\Haven\AppData\Local\{EFBFA7E8-C829-49B1-9C58-A4B373FDC2FF}
2011-12-19 08:34 - 2011-12-19 08:34 - 0000000 ____D C:\Users\Haven\AppData\Local\{41E6ED9A-B566-4573-81A9-646A33EC267B}
2011-12-18 19:32 - 2011-12-18 19:32 - 0000000 ____D C:\Users\Haven\AppData\Local\{DE633FFD-5464-4457-A7F6-ED3BF0CD03E1}
2011-12-18 19:32 - 2011-12-18 19:32 - 0000000 ____D C:\Users\Haven\AppData\Local\{980F9A23-ABEB-442B-8651-B4CE736BADDD}
2011-12-18 07:32 - 2011-12-18 07:31 - 0000000 ____D C:\Users\Haven\AppData\Local\{FF65A3AB-517F-4A88-BB3B-174BA6CA9936}
2011-12-18 07:31 - 2011-12-18 07:31 - 0000000 ____D C:\Users\Haven\AppData\Local\{8095DA8C-4F6F-4182-B4F7-BCDF47D73A9E}
2011-12-17 19:07 - 2011-12-17 19:07 - 0000000 ____D C:\Users\Haven\AppData\Local\{D4D0D674-B2A8-4CBB-A5AC-7F3A6BA1E8BD}
2011-12-17 19:07 - 2011-12-17 19:07 - 0000000 ____D C:\Users\Haven\AppData\Local\{159EA09C-F5E6-4744-8FB4-86467243AB28}
2011-12-17 07:07 - 2011-12-17 07:07 - 0000000 ____D C:\Users\Haven\AppData\Local\{320029AA-263E-40F7-929B-47FE6DB1F188}
2011-12-17 07:06 - 2011-12-17 07:06 - 0000000 ____D C:\Users\Haven\AppData\Local\{9527A775-BDEC-44B9-B320-451035761A4E}
2011-12-16 19:06 - 2011-12-16 19:06 - 0000000 ____D C:\Users\Haven\AppData\Local\{9D7E45E9-7CA7-46B5-8284-0292C130D485}
2011-12-16 19:06 - 2011-12-16 19:06 - 0000000 ____D C:\Users\Haven\AppData\Local\{7D2FBDC3-CBE8-4BA8-8F2C-6BC76F2BE686}
2011-12-16 07:06 - 2011-12-16 07:06 - 0000000 ____D C:\Users\Haven\AppData\Local\{D48FA2EA-E3D6-4450-93C9-61DB9DF001F7}
2011-12-16 07:06 - 2011-12-16 07:06 - 0000000 ____D C:\Users\Haven\AppData\Local\{784AD666-8786-4BC6-BAEE-A1356096DEFB}
2011-12-15 17:18 - 2011-12-15 17:18 - 0773400 ____A C:\Users\Haven\Downloads\Aika_Downloader.exe
2011-12-15 14:56 - 2011-12-15 14:56 - 0000000 ____D C:\Users\Haven\AppData\Local\{8F389D5F-EC03-4545-822E-91618DCF851E}
2011-12-15 14:56 - 2011-12-15 14:56 - 0000000 ____D C:\Users\Haven\AppData\Local\{210EB13F-784C-4A89-AA59-38042ACD9F8E}
2011-12-15 07:49 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\rescache
2011-12-15 07:12 - 2009-07-13 20:45 - 0276080 ____A C:\Windows\System32\FNTCACHE.DAT
2011-12-14 23:52 - 2011-12-14 23:52 - 0000000 ____D C:\Users\Haven\AppData\Local\{E1E810CB-9AE6-412C-BD16-BE301A9B11A3}
2011-12-14 23:52 - 2011-12-14 23:52 - 0000000 ____D C:\Users\Haven\AppData\Local\{A6117F99-551C-453A-B2EA-BB42D366C02A}
2011-12-14 11:52 - 2011-12-14 11:51 - 0000000 ____D C:\Users\Haven\AppData\Local\{144E5863-C2C7-4402-A3F0-38E36626EAA5}
2011-12-14 11:51 - 2011-12-14 11:51 - 0000000 ____D C:\Users\Haven\AppData\Local\{CEEC1206-B923-4CD1-AD94-E25E4AB836E1}
2011-12-13 23:51 - 2011-12-13 23:51 - 0000000 ____D C:\Users\Haven\AppData\Local\{87CACFEF-98AD-4646-9522-A8AA79D2C87C}
2011-12-13 23:51 - 2011-12-13 23:51 - 0000000 ____D C:\Users\Haven\AppData\Local\{29FF1A8B-BB5E-4696-B98A-B2D5308FD2D9}
2011-12-13 11:51 - 2011-12-13 11:51 - 0000000 ____D C:\Users\Haven\AppData\Local\{2E4CD18B-0EA9-4314-B0BF-18527E518789}
2011-12-13 11:51 - 2011-12-13 11:51 - 0000000 ____D C:\Users\Haven\AppData\Local\{03754163-D230-4ED8-A9A3-F153D96407C3}
2011-12-12 23:51 - 2011-12-12 23:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{226C969C-633E-4010-98FA-D7AF0E13DB54}
2011-12-12 23:50 - 2011-12-12 23:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{67F3035B-88B0-474B-AFC0-6358F21776AF}
2011-12-12 11:50 - 2011-12-12 11:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{FBA11000-FCA8-493D-B2B8-7F8AF957374F}
2011-12-12 11:50 - 2011-12-12 11:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{868D5EAD-6CE0-4FD6-9377-397545548FA2}
2011-12-11 23:50 - 2011-12-11 23:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{54EB15AD-3C9C-46F8-AF52-3A90636884F1}
2011-12-11 23:50 - 2011-12-11 23:50 - 0000000 ____D C:\Users\Haven\AppData\Local\{246A41A2-ABF9-4E6D-B694-41CA7AE4602A}
2011-12-11 15:14 - 2011-12-11 15:14 - 0014963 ____A C:\Users\Haven\Downloads\[kat.ph]the.red.jumpsuit.apparatus.am.i.the.enemy.2011.cr.torrent
2011-12-11 11:49 - 2011-12-11 11:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{62EBB458-4BE4-48BF-B1C8-C97C7E258B36}
2011-12-11 11:49 - 2011-12-11 11:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{3C833584-9F2C-4FBA-ABFC-4E159E096A3A}
2011-12-10 23:49 - 2011-12-10 23:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{E341AC59-2679-4EEB-8C3A-FDD01077013A}
2011-12-10 23:49 - 2011-12-10 23:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{89B4B38C-0D85-4B84-A657-2CE0EA22FA3A}
2011-12-10 11:49 - 2011-12-10 11:49 - 0000000 ____D C:\Users\Haven\AppData\Local\{F4699038-F2D7-4BE3-AA32-911DA5510526}
2011-12-10 11:49 - 2011-12-10 11:48 - 0000000 ____D C:\Users\Haven\AppData\Local\{B369B681-F12C-4AF6-BB32-E8E189FC22B1}
2011-12-09 23:48 - 2011-12-09 23:48 - 0000000 ____D C:\Users\Haven\AppData\Local\{BA1A976C-9BBB-4C65-BCDF-061C2C51FC5A}
2011-12-09 23:48 - 2011-12-09 23:48 - 0000000 ____D C:\Users\Haven\AppData\Local\{2C01390C-924A-41A3-BC64-3BB908256C1E}
2011-12-09 20:27 - 2011-12-09 19:43 - 621838456 ____A (Neonga AG ) C:\Users\Haven\Downloads\DragonSoul_Setup_OB.exe
2011-12-09 12:27 - 2011-06-24 09:07 - 0000174 ___SH C:\Users\Haven\Start Menu\Programs\Startup\desktop.ini
2011-12-09 12:27 - 2011-06-24 09:07 - 0000174 ___SH C:\Users\Haven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2011-12-09 11:48 - 2011-12-09 11:48 - 0000000 ____D C:\Users\Haven\AppData\Local\{38A8C41B-13CB-4FC9-9D22-A1F170CF0D70}
2011-12-09 11:48 - 2011-12-09 11:47 - 0000000 ____D C:\Users\Haven\AppData\Local\{57388421-0E1F-4C32-A43C-518D874817CE}
2011-12-09 11:43 - 2011-12-09 11:43 - 0000000 ____D C:\Windows\en
2011-12-09 11:41 - 2011-05-12 21:30 - 0000000 ____D C:\Program Files (x86)\Windows Live
2011-12-09 11:41 - 2011-05-12 21:29 - 0000000 ____D C:\Program Files\Windows Live
2011-12-09 11:41 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\Microsoft Shared
2011-12-09 11:38 - 2011-12-09 11:38 - 0000000 ____D C:\Users\Haven\AppData\Local\{8B6E3EE0-A3BB-4039-A483-21E2907723E7}
2011-12-09 11:38 - 2011-12-09 11:38 - 0000000 ____D C:\Users\Haven\AppData\Local\{630036E1-05E8-4E60-98E6-582F637E0E58}
2011-12-09 11:36 - 2011-12-09 11:36 - 0468264 ____A C:\Windows\Minidump\120911-19702-01.dmp
2011-12-08 18:12 - 2011-12-08 18:12 - 0001163 ____A C:\Users\Haven\Downloads\Excio Guild Mark.zip
2011-12-03 19:04 - 2011-12-03 19:04 - 0000000 ____D C:\Users\Haven\AppData\Local\{9E616190-E821-4DA1-983B-AA6FEDF7378B}
2011-12-03 18:58 - 2011-12-03 18:58 - 0262144 ____A C:\Windows\Minidump\120311-25911-01.dmp
2011-12-03 18:57 - 2011-12-03 18:57 - 0000000 ____D C:\Users\All Users\Free Labs
2011-12-03 18:57 - 2011-12-03 18:57 - 0000000 ____D C:\ProgramData\Free Labs
2011-12-03 18:56 - 2011-12-03 18:56 - 0417792 ____A C:\Users\Haven\Downloads\macrorecorderseup.msi
2011-12-03 18:56 - 2011-12-03 18:56 - 0000000 ____D C:\Program Files (x86)\Free Labs
2011-12-03 18:51 - 2011-12-03 18:51 - 0671744 ____A C:\Users\Haven\Downloads\SetupDoItAgain.msi
2011-12-03 18:41 - 2011-12-03 18:41 - 0001351 ____A C:\Users\Haven\Documents\AutoHotkey.ahk
2011-12-03 18:40 - 2011-12-03 18:40 - 2680882 ____A C:\Users\Haven\Downloads\AutoHotkey110503_Install.exe
2011-12-03 18:34 - 2011-12-03 18:27 - 0000000 ____D C:\Users\Haven\Documents\Easy Macro Recorder
2011-12-03 18:27 - 2011-12-03 18:27 - 1762543 ____A (GoldSolution Software, Inc. ) C:\Users\Haven\Downloads\EasyMacroRecorder.exe
2011-12-03 18:27 - 2011-12-03 18:27 - 0463080 ____A (CNET Download.com) C:\Users\Haven\Downloads\cnet_EasyMacroRecorder_exe.exe
2011-11-29 23:18 - 2011-07-31 21:49 - 0000000 ____D C:\Program Files (x86)\RIFT Game
2011-11-29 18:51 - 2011-11-29 18:52 - 0099900 ____A C:\Users\Haven\Downloads\152835.jpg
2011-11-25 13:09 - 2011-11-25 13:09 - 0000000 ____D C:\Users\Haven\AppData\Local\{F8F5D233-E63D-44DE-8A32-C241F03CCFD7}
2011-11-25 13:09 - 2011-11-25 13:09 - 0000000 ____D C:\Users\Haven\AppData\Local\{3675FDA8-4E8A-425E-A923-A99C4BA8C420}
2011-11-25 13:04 - 2011-11-25 13:01 - 0000000 ____D C:\Users\Haven\Downloads\Linkin Park - A Thousand Suns [2010-MP3-Cov][Bubanee]
2011-11-25 13:02 - 2011-11-25 13:02 - 0011861 ____A C:\Users\Haven\Downloads\Linkin_Park___A_Thousand_Suns__2010_MP3_Cov__Bubanee_ (1).torrent
2011-11-25 13:00 - 2011-11-25 13:00 - 0011861 ____A C:\Users\Haven\Downloads\Linkin_Park___A_Thousand_Suns__2010_MP3_Cov__Bubanee_.torrent
2011-11-25 07:19 - 2011-11-25 07:19 - 0000000 ____D C:\Users\Haven\AppData\Local\{9EED98E0-D605-4601-901C-9C60D7A77A0C}
2011-11-25 07:19 - 2011-11-25 07:19 - 0000000 ____D C:\Users\Haven\AppData\Local\{11EEE079-9255-4661-A3A3-A1FB05BE627F}
2011-11-23 20:52 - 2011-12-14 16:01 - 3145216 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2011-11-23 17:59 - 2011-11-23 17:59 - 0039899 ____A C:\Users\Haven\Downloads\387372_10150486672627345_646512344_10326384_794573161_n.jpg
2011-11-22 08:48 - 2011-11-22 08:48 - 0000020 ____A C:\Users\Haven\Desktop\audi.txt
2011-11-19 06:58 - 2012-01-10 18:23 - 0077312 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll
2011-11-19 06:01 - 2012-01-10 18:23 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2011-11-17 12:15 - 2011-12-08 18:12 - 0001196 ____A C:\Users\Haven\Documents\Excio Guild Mark.bmp
2011-11-16 22:49 - 2012-01-15 23:47 - 0152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2011-11-16 22:49 - 2012-01-15 23:47 - 0095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2011-11-16 22:44 - 2012-01-15 23:47 - 0459232 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2011-11-16 22:41 - 2012-01-10 18:23 - 1731920 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2011-11-16 22:35 - 2012-01-15 23:47 - 1447936 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2011-11-16 22:35 - 2012-01-15 23:47 - 0395776 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll
2011-11-16 22:35 - 2012-01-15 23:47 - 0340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2011-11-16 22:35 - 2012-01-15 23:47 - 0136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2011-11-16 22:35 - 2012-01-15 23:47 - 0029184 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2011-11-16 22:35 - 2012-01-15 23:47 - 0028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2011-11-16 22:33 - 2012-01-15 23:47 - 0031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2011-11-16 21:38 - 2012-01-10 18:23 - 1292080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2011-11-16 21:35 - 2012-01-15 23:47 - 0314880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2011-11-16 21:34 - 2012-01-15 23:47 - 0224768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2011-11-16 21:34 - 2012-01-15 23:47 - 0022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2011-11-16 21:28 - 2012-01-15 23:47 - 0096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2011-11-15 15:24 - 2011-11-15 15:24 - 0000037 ____A C:\Users\Haven\Desktop\bankacct.txt
2011-11-14 08:43 - 2011-11-14 08:43 - 0000000 ____D C:\Users\Haven\AppData\Local\{F841B8D5-E122-4EE4-A69C-AB0D5BF4C919}
2011-11-14 08:43 - 2011-11-14 08:43 - 0000000 ____D C:\Users\Haven\AppData\Local\{EF3B03E6-A537-4E7B-B8B4-6A3A96BE556A}
2011-11-14 08:43 - 2011-07-07 17:02 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2011-11-11 15:07 - 2011-11-11 15:07 - 2240496 ____A C:\Users\Haven\Downloads\WOI_Downloader_EN_1103.exe
2011-11-11 15:07 - 2011-10-02 19:51 - 0000000 ____D C:\Perfect World Entertainment
2011-11-11 14:28 - 2011-11-11 14:27 - 2096176 ____A C:\Users\Haven\Downloads\BOI_Downloader2_V198_0708.exe
2011-11-09 19:46 - 2011-11-09 19:45 - 0000000 ____D C:\Users\Haven\AppData\Local\{EE352019-0415-4531-AF26-04D49F1E1124}
2011-11-09 19:45 - 2011-11-09 19:45 - 0000000 ____D C:\Users\Haven\AppData\Local\{B49516B8-9DE5-4BF5-AD4C-A2EDCF46142E}
2011-11-09 19:40 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\System
2011-11-04 22:51 - 2011-06-24 09:10 - 0000000 ____D C:\Users\Haven\AppData\Local\Google
2011-11-04 21:32 - 2011-12-14 16:01 - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2011-11-04 20:34 - 2011-11-04 20:34 - 0000013 ____A C:\Users\Haven\Desktop\referencenumpaymentumuc.txt
2011-11-04 20:26 - 2011-12-14 16:01 - 0002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2011-11-04 10:35 - 2011-11-04 10:35 - 0000000 ____D C:\Users\Haven\AppData\Local\{478EB40A-54CF-491D-B703-2ECA96B4041C}
2011-11-04 10:35 - 2011-11-04 10:35 - 0000000 ____D C:\Users\Haven\AppData\Local\{1DFE6180-3B1A-4433-A7EA-11F05C48F813}
2011-11-04 10:28 - 2011-11-04 10:27 - 0000000 ____D C:\Users\Haven\AppData\Local\{7751B9F3-11C9-4C39-AC69-FD454AB5DB55}
2011-11-04 10:27 - 2011-11-04 10:27 - 0000000 ____D C:\Users\Haven\AppData\Local\{58B51D37-6EED-49A0-A4CF-9B0B568BAFDA}
2011-11-03 18:38 - 2011-12-15 00:00 - 17786368 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-11-03 17:59 - 2011-12-15 00:00 - 10886656 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-11-03 17:53 - 2011-12-15 00:00 - 2309120 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2011-11-03 17:46 - 2011-12-15 00:01 - 1345536 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-11-03 17:44 - 2011-12-15 00:00 - 1493504 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2011-11-03 17:44 - 2011-12-15 00:00 - 1390080 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-11-03 17:43 - 2011-12-15 00:01 - 0237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-11-03 17:41 - 2011-12-15 00:00 - 0085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-11-03 17:39 - 2011-12-15 00:00 - 0818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2011-11-03 17:36 - 2011-12-15 00:01 - 2144256 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-11-03 17:35 - 2011-12-15 00:01 - 0096256 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-11-03 17:34 - 2011-12-15 00:01 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-11-03 17:30 - 2011-12-15 00:01 - 0248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2011-11-03 15:02 - 2011-12-15 00:00 - 12279808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2011-11-03 14:47 - 2011-12-15 00:00 - 1798144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2011-11-03 14:46 - 2011-12-15 00:00 - 9705472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2011-11-03 14:40 - 2011-12-15 00:01 - 1103360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2011-11-03 14:40 - 2011-12-15 00:00 - 1427456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2011-11-03 14:39 - 2011-12-15 00:00 - 1127424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2011-11-03 14:38 - 2011-12-15 00:01 - 0231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2011-11-03 14:37 - 2011-12-15 00:00 - 0065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2011-11-03 14:34 - 2011-12-15 00:00 - 0716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2011-11-03 14:32 - 2011-12-15 00:01 - 1792000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2011-11-03 14:32 - 2011-12-15 00:01 - 0072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2011-11-03 14:31 - 2011-12-15 00:01 - 2382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2011-11-03 14:28 - 2011-12-15 00:01 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2011-10-30 19:22 - 2011-07-08 19:38 - 0000952 __ASH C:\Users\All Users\KGyGaAvL.sys
2011-10-30 19:22 - 2011-07-08 19:38 - 0000952 __ASH C:\ProgramData\KGyGaAvL.sys
2011-10-30 10:38 - 2011-07-14 13:51 - 0000000 ____D C:\Users\Haven\AppData\Local\ElevatedDiagnostics
2011-10-28 22:27 - 2011-10-28 22:27 - 0000000 ____D C:\Users\Haven\AppData\Local\{09CDA2E6-91FC-46E6-9D4A-F676D4C6882F}
2011-10-28 22:27 - 2011-10-28 22:26 - 0000000 ____D C:\Users\Haven\AppData\Local\{2407A0F9-66E3-4EB1-B690-AA19003967F4}
2011-10-26 21:22 - 2011-10-26 21:22 - 0112630 ____A C:\Users\Haven\Downloads\Geek_Girls_The_Gamers_XXX_DVDRip_XviD_STARLETS.torrent
2011-10-26 21:19 - 2011-10-26 21:19 - 0014985 ____A C:\Users\Haven\Downloads\My_Little_Panties_2_XXX_DVDRiP_XviD_DivXfacTory.torrent
2011-10-26 21:17 - 2011-10-26 21:17 - 0015013 ____A C:\Users\Haven\Downloads\Too_Young_To_Know_Better_XXX_DVDRip_XviD_CLiT.torrent
2011-10-26 21:03 - 2011-10-26 21:00 - 0000000 ____D C:\Users\Haven\AppData\Roaming\Origin
2011-10-26 21:03 - 2011-10-26 20:59 - 0000000 ____D C:\Users\All Users\Origin
2011-10-26 21:03 - 2011-10-26 20:59 - 0000000 ____D C:\ProgramData\Origin
2011-10-26 20:59 - 2011-10-26 20:59 - 0000994 ____A C:\Users\Public\Desktop\Origin.lnk
2011-10-26 20:59 - 2011-10-26 20:59 - 0000531 ____A C:\Windows\KB893803v2.log
2011-10-26 20:59 - 2011-10-26 20:59 - 0000000 ____D C:\Users\Haven\AppData\Local\Origin
2011-10-26 20:59 - 2011-10-26 20:59 - 0000000 ____D C:\Users\All Users\Electronic Arts
2011-10-26 20:59 - 2011-10-26 20:59 - 0000000 ____D C:\ProgramData\Electronic Arts
2011-10-26 20:59 - 2011-10-26 20:59 - 0000000 ____D C:\Program Files (x86)\Origin Games
2011-10-26 20:59 - 2011-10-26 20:59 - 0000000 ____D C:\Program Files (x86)\Origin
2011-10-26 20:58 - 2011-10-26 20:58 - 48106400 ____A (Electronic Arts, Inc.) C:\Users\Haven\Downloads\OriginSetup.exe
2011-10-26 12:25 - 2012-01-18 18:06 - 1797029888 ____A C:\Users\Haven\Downloads\jfoised.com-hmx-fix ff0-d1.iso
2011-10-25 21:25 - 2012-01-10 18:23 - 1572864 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll
2011-10-25 21:25 - 2012-01-10 18:23 - 0366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2011-10-25 21:21 - 2011-12-14 16:01 - 0043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2011-10-25 20:32 - 2012-01-10 18:23 - 1328128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2011-10-25 20:32 - 2012-01-10 18:23 - 0514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2011-10-25 14:27 - 2011-10-25 14:27 - 0075776 ____A C:\Users\Haven\Downloads\Bohrer4 40.doc
2011-10-25 14:27 - 2011-10-07 17:29 - 0000000 ____D C:\Users\Haven\AppData\Roaming\SoftGrid Client

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys
[2011-05-12 21:14] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B


========================= Memory info ======================

Percentage of memory in use: 11%
Total physical RAM: 6050.69 MB
Available physical RAM: 5365.75 MB
Total Pagefile: 6048.89 MB
Available Pagefile: 5347.93 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

======================= Partitions =========================

1 Drive c: (TI106169W0D) (Fixed) (Total:683.08 GB) (Free:490 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive f: (CDROM) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
5 Drive g: () (Removable) (Total:29.71 GB) (Free:17.5 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 29 GB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 1500 MB 1024 KB
Partition 2 Primary 683 GB 1501 MB
Partition 3 Primary 14 GB 684 GB

Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D System NTFS Partition 1500 MB Healthy Hidden

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C TI106169W0D NTFS Partition 683 GB Healthy

Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 29 GB 4096 KB

Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 29 GB Healthy

==========================================================

Last Boot: 2012-01-21 14:46

======================= End Of Log ==========================

BC AdBot (Login to Remove)

 


#2 deathlyhaven

deathlyhaven
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:02 PM

Posted 22 January 2012 - 10:28 AM

Please Delete/Lock, my fiance ended up installing windows 7 again since she didn't care for the contents and was happy with a complete reboot.

#3 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:02 AM

Posted 22 January 2012 - 05:28 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users